Brushing method and device of electronic control unit, storage medium and electronic equipment
By automatically matching the configuration information set with the ECU serial number and dynamically selecting the parallel flashing protocol, the problem of low efficiency in traditional ECU flashing is solved, and an efficient and safe ECU flashing process is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- FOSS (HANGZHOU) INTELLIGENT TECH CO LTD
- Filing Date
- 2025-12-24
- Publication Date
- 2026-04-17
AI Technical Summary
In the traditional process of flashing automotive electronic control units (ECUs), only one ECU can be operated at a time, and parameters need to be manually configured, resulting in long flashing time and low efficiency.
By obtaining the ECU's serial number, the system automatically matches the configuration information set, dynamically selects the target flashing protocol, and executes the flashing operation in parallel, simplifying the preparation steps and reducing the complexity and error rate of manual configuration.
It significantly shortens ECU flashing time, improves flashing efficiency, enhances compatibility and security, and ensures data integrity and system stability.
Smart Images

Figure CN121879800A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle-mounted detection technology, and more specifically, to a method and apparatus for flashing electronic control units, a storage medium, and an electronic device. Background Technology
[0002] In the traditional process of flashing automotive electronic control units (ECUs), the serial flashing method allows only one ECU to be operated on at a time. Furthermore, each ECU requires manual configuration of flashing protocols and other parameters before each operation, which increases the workload and makes the flashing time too long, resulting in low flashing efficiency. Summary of the Invention
[0003] This application provides a method and apparatus for flashing an electronic control unit, a storage medium, and an electronic device, to at least solve the technical problem of low flashing efficiency of electronic control units in related technologies.
[0004] According to one aspect of the embodiments of this application, a method for flashing an electronic control unit is provided, comprising: in response to flashing requests from at least two electronic control units, obtaining serial numbers associated with at least two electronic control units, wherein the at least two electronic control units include a first electronic control unit and a second electronic control unit; matching a first configuration information set corresponding to the first serial number associated with the first electronic control unit from a configuration information set library, and matching a second configuration information set corresponding to the second serial number associated with the second electronic control unit from the configuration information set library, wherein the configuration information set library is used to store configuration information sets corresponding to each serial number, and a configuration information set includes configuration information indicating multiple candidate flashing protocols corresponding to an electronic control unit and configuration information for determining a target flashing protocol from the multiple candidate flashing protocols; performing a first flashing operation on the first electronic control unit according to the first target flashing protocol determined based on the first configuration information set, and performing a second flashing operation on the second electronic control unit according to the second target flashing protocol determined based on the second configuration information set, wherein the first flashing operation and the second flashing operation are performed in parallel.
[0005] According to another aspect of the embodiments of this application, a flashing device for an electronic control unit is also provided, comprising: an acquisition unit, configured to acquire serial numbers associated with at least two electronic control units in response to flashing requests from at least two electronic control units, wherein the at least two electronic control units include a first electronic control unit and a second electronic control unit; a matching unit, configured to match a first configuration information set corresponding to the first serial number associated with the first electronic control unit from a configuration information set library, and to match a second configuration information set corresponding to the second serial number associated with the second electronic control unit from the configuration information set library, wherein the configuration information set library is used to store configuration information sets corresponding to each serial number, and a configuration information set includes configuration information indicating multiple candidate flashing protocols corresponding to an electronic control unit and configuration information for determining a target flashing protocol from multiple candidate flashing protocols; and a flashing unit, configured to perform a first flashing operation on the first electronic control unit according to the first target flashing protocol determined based on the first configuration information set, and to perform a second flashing operation on the second electronic control unit according to the second target flashing protocol determined based on the second configuration information set, wherein the first flashing operation and the second flashing operation are performed in parallel.
[0006] According to another aspect of the embodiments of this application, a computer-readable storage medium is also provided, wherein a computer program is stored in the computer-readable storage medium, and the computer program is configured to execute the above-described electronic control unit writing method when running.
[0007] According to another aspect of the embodiments of this application, a computer program product is provided, the computer program product including a computer program / instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer program / instructions from the computer-readable storage medium, and executes the computer program / instructions, causing the computer device to perform the flashing method for the electronic control unit as described above.
[0008] According to another aspect of the embodiments of this application, an electronic device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the above-described electronic control unit flashing method through the computer program.
[0009] In this embodiment, when a flashing request is received from multiple electronic control units (ECUs), the serial numbers of these ECUs are first obtained. Since each ECU has unique configuration requirements, the serial number is crucial for identifying and distinguishing different ECUs. A specific configuration information set is then matched from the configuration information set library using the ECU serial number. This configuration information set contains all flashing parameters for the ECU, such as communication protocols, and also includes information for determining the actual flashing protocol. This automation and precision greatly simplifies the preparation steps before flashing, reducing the complexity and error rate of manual configuration. The parameters extracted from the configuration information set are used to determine the target flashing protocol suitable for the current ECU. Subsequently, flashing operations are performed in parallel on each ECU (e.g., the first and second ECUs) according to the selected protocol, significantly shortening the overall flashing time and improving flashing efficiency. Therefore, in this embodiment, by responding to ECU flashing requests, dynamically matching configuration information sets based on serial numbers, determining the target flashing protocol, and performing parallel operations, the technical effect of improving the flashing efficiency of ECUs is achieved, solving the technical problem of low flashing efficiency of ECUs in related technologies. Attached Figure Description
[0010] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0011] Figure 1 This is a schematic diagram of the hardware environment for an optional electronic control unit flashing method according to an embodiment of this application;
[0012] Figure 2 This is a flowchart of an optional electronic control unit flashing method according to an embodiment of this application;
[0013] Figure 3 This is an architecture diagram of an optional AUTOSAR-based dynamic protocol extension and parallel writing system according to an embodiment of this application.
[0014] Figure 4 This is a flowchart of an optional dynamic protocol extension and parallel writing method based on the AUTOSAR architecture according to an embodiment of this application;
[0015] Figure 5 This is a schematic diagram of an optional electronic control unit writing device according to an embodiment of this application;
[0016] Figure 6 This is a schematic diagram of an optional electronic device according to an embodiment of this application. Detailed Implementation
[0017] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0018] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0019] According to one aspect of the embodiments of this application, a method for flashing an electronic control unit is provided. As an optional implementation, the above-described method for flashing an electronic control unit can be applied, but is not limited to, to applications such as... Figure 1 The illustrated electronic control unit flashing system is shown in the hardware environment. Optionally, the above-described electronic control unit flashing method can be applied to a vehicle terminal. Figure 1 A side view of a vehicle terminal 101 is shown, which is mounted on and capable of traversing a travel surface 113. The vehicle terminal 101 includes an onboard navigation system 103, a computer-readable storage device or medium (memory) 102 including a digital road map 104, a spatial monitoring system 117, a vehicle controller 109, a GPS (Global Positioning System) sensor 110, an HMI (Human / Machine Interface) device 111, and also includes an autonomous controller 112 and a telematics controller 114. The vehicle terminal 101 may include, but is not limited to, commercial vehicles, industrial vehicles, agricultural vehicles, passenger vehicles, all-terrain vehicles, personal mobile devices, robots, and similar mobile platforms to achieve the purposes of this application.
[0020] In one embodiment, the spatial monitoring system 117 includes: one or more spatial sensors and systems arranged to monitor a visible area 105 in front of the vehicle terminal 101; and a spatial monitoring controller 118. Spatial sensors for monitoring the visible area 105 include, for example, a lidar sensor 106, a radar sensor 107, a camera 108, and so on. The placement of the spatial sensors allows the spatial monitoring controller 118 to monitor traffic flow, including approaching vehicles, intersections, lane markings, and other objects surrounding the vehicle terminal 101. The spatial sensors of the spatial monitoring system 117 may include object location sensing devices. The lidar sensor 106 uses pulsed and reflected laser beams to measure the range or distance to an object. The radar sensor 107 uses radio waves to determine the range, angle, and / or speed of an object. The camera 108 includes an image sensor, a lens, and a camera controller.
[0021] Camera 108 is advantageously mounted and positioned on vehicle terminal 101 in a location that allows for capturing images of a visible area 105, wherein at least a portion of the visible area 105 includes the area in front of vehicle terminal 101 and a portion of the travel surface 113 of the trajectory of vehicle terminal 101. The visible area 105 may also include the surrounding environment. Other cameras (not shown) may also be employed, for example, including a second camera positioned on the rear or side portion of vehicle terminal 101 to monitor the rear of vehicle terminal 101 and one of the right or left sides of vehicle terminal 101.
[0022] The autonomous controller 112 is configured to implement autonomous driving or advanced driver assistance system (ADAS) vehicle functionality. Such functionality may include an onboard vehicle control system capable of providing a certain level of driving automation. Driving automation may include a series of dynamic driving and vehicle operations. Driving automation may include simultaneous automatic control of vehicle driving functions (including steering, acceleration, and braking), wherein the driver relinquishes control of the vehicle for a period of time during the journey. Driving automation may include simultaneous automatic control of vehicle driving functions (including steering, acceleration, and braking), wherein the driver relinquishes control of the vehicle terminal 101 for the entire journey. Driving automation includes hardware and controllers configured to monitor the spatial environment in various driving modes to perform various driving tasks during dynamic vehicle operations. By way of non-limiting example, autonomous vehicle functionality includes adaptive cruise control (ACC) operation, lane guidance and lane keeping operation, lane changing operation, steering assist operation, object avoidance operation, parking assist operation, vehicle braking operation, vehicle speed and acceleration operation, vehicle lateral movement operation, for example, as part of lane guidance, lane keeping, and lane changing operations, etc.
[0023] The aforementioned autonomous controller can be equipped with an operating system and an autonomous driving system. The operating system is responsible for managing the hardware resources (including sensors, system bus, network, etc.) of the vehicle terminal 101 and scheduling computing resources. The autonomous driving system can implement various algorithms required for autonomous driving, including localization, environmental perception, path planning, and control, and can make decisions in situations such as driving on curves, driving in straight lines, driving in complex road conditions, and changing lanes.
[0024] When testing the program under test using the vehicle terminal 101, the steps of the above-described method for flashing the electronic control unit can be executed in the vehicle terminal 101.
[0025] The vehicle terminal 101 may include a telematics controller 114, which includes a wireless telematics communication system capable of performing off-vehicle communications (including communications with a communication network 16 having both wireless and wired communication capabilities). Optionally or additionally, the telematics controller 114 may perform off-vehicle communications directly by communicating with a non-airborne server 116 via the communication network 16.
[0026] In alternative implementations, such as Figure 2 As shown, the above-mentioned electronic control unit flashing method includes the following steps:
[0027] S202, in response to a flashing request from at least two electronic control units, obtain the serial numbers associated with at least two electronic control units, wherein the at least two electronic control units include a first electronic control unit and a second electronic control unit;
[0028] S204, based on the first serial number associated with the first electronic control unit, a first configuration information set corresponding to the first serial number is matched from the configuration information set library, and based on the second serial number associated with the second electronic control unit, a second configuration information set corresponding to the second serial number is matched from the configuration information set library. The configuration information set library is used to store the configuration information set corresponding to each serial number. A configuration information set includes configuration information indicating multiple candidate flashing protocols corresponding to an electronic control unit and configuration information used to determine the target flashing protocol from multiple candidate flashing protocols.
[0029] S206, according to the first target flashing protocol determined based on the first configuration information set, a first flashing operation is performed on the first electronic control unit, and according to the second target flashing protocol determined based on the second configuration information set, a second flashing operation is performed on the second electronic control unit, wherein the first flashing operation and the second flashing operation are performed in parallel.
[0030] Optionally, in this embodiment, the Electronic Control Unit (ECU) is a computer system inside the vehicle used to control specific functions. It is responsible for receiving sensor data and actuator instructions, such as managing the vehicle's electrical system.
[0031] Optionally, in this embodiment, the serial number is a number used to uniquely identify each ECU, and is used to locate and identify the correct ECU configuration information during the flashing process.
[0032] Optionally, in this embodiment, the configuration information collection library is a database that stores flashing parameters and protocol information related to each ECU serial number, including communication protocol, baud rate, block size, etc., as well as methods and rules for determining the actual flashing protocol.
[0033] Optionally, in this embodiment, the flashing operation is used to indicate the process of downloading a new software version to the ECU, typically used to update the ECU firmware, enabling the vehicle to obtain the latest functions or fix known software defects.
[0034] Optionally, in this embodiment, the candidate flashing protocol is a variety of communication protocols that the ECU may support, such as the DoIP protocol, the DoCAN protocol, and some proprietary protocols. The target flashing protocol is the best protocol selected from the candidate flashing protocols based on the specific requirements of the ECU and the current environment, and is used to perform the flashing operation.
[0035] Optionally, in this embodiment, when the system receives flashing requests from multiple ECUs, it begins processing the requests and obtains the ECU serial numbers associated with these requests. The serial numbers are used to subsequently determine the correct configuration information.
[0036] After obtaining the serial number, the system searches for and matches the first and second configuration information sets in the configuration information set library based on the serial numbers of the first and second electronic control units. The configuration information set contains the flashing parameters and protocol descriptors specific to each ECU.
[0037] The system parses the configuration information set and automatically selects the most suitable target flashing protocol for the current flashing scenario based on the ECU's hardware characteristics and network environment. This process takes into account the latest requirements of the ECU, making flashing more efficient and compatible.
[0038] The system performs flashing operations on both the first and second electronic control units simultaneously, according to the defined target flashing protocol. This step achieves true parallel flashing, significantly reducing the time required for flashing the entire vehicle.
[0039] Optionally, in this embodiment, personalized and automated flashing parameter configuration for each ECU is achieved through automated serial number matching and configuration information set lookup, reducing the workload and error rate of manual configuration. Through flexible selection of target flashing protocols, the system can support different ECU types and network environments, enhancing the compatibility and scalability of the flashing process.
[0040] Optionally, in this embodiment, processing multiple ECU flashing requests simultaneously significantly improves flashing efficiency. Through dynamic configuration information matching and protocol adaptation, this embodiment ensures high efficiency while also prioritizing data security and result reliability during the flashing process. The system's built-in verification mechanisms (such as CRC checksum and digital signature verification) monitor data integrity in real time, preventing malicious tampering or transmission errors. The distributed transaction protocol guarantees the atomicity of parallel flashing operations for multiple ECUs, ensuring that even if some operations fail, the system can automatically roll back, avoiding data corruption and system failures, and improving the overall security and stability of the flashing process.
[0041] To illustrate further, suppose a modern car is equipped with more than 120 ECUs, including a powertrain ECU (first electronic control unit) and an entertainment system ECU (second electronic control unit). During a software update, the system first responds to the flashing requests from these two ECUs and obtains their respective serial numbers.
[0042] Next, the system queries the configuration information set library based on the serial number, matching a first configuration information set containing DoIP protocol parameters for the powertrain ECU, and a second configuration information set containing DoCAN and proprietary protocol parameters for the entertainment system ECU. This process ensures that the flashing parameters for each ECU are customized according to its hardware characteristics and software requirements.
[0043] Then, the system dynamically selects the target flashing protocol based on the configuration information set. The powertrain ECU may be more suitable for the DoIP protocol, while the infotainment ECU may use the DoCAN protocol. The system then performs flashing operations on both ECUs simultaneously according to the selected protocol, using a dynamic time window scheduling algorithm and an incremental differential engine to optimize data transmission and bus resource allocation, ultimately reducing the flashing time from more than 2 hours to less than 12 minutes, meeting the production line cycle time requirements.
[0044] Optionally, during the entire flashing process, data integrity and authenticity can be ensured through real-time CRC checksum and digital signature verification, but not limited to this. If any anomaly is detected, such as data errors or security threats, the system will immediately trigger a rollback mechanism under the distributed transaction protocol to ensure that the state of all ECUs remains consistent, thus avoiding potential functional failures and security risks.
[0045] According to the embodiments provided in this application, when a flashing request is received from multiple ECUs, the serial numbers of these ECUs are first obtained. Since each ECU has unique configuration requirements, the serial number is crucial information for identifying and distinguishing different ECUs. A specific configuration information set is then matched from the configuration information set library using the ECU serial number. This configuration information set contains all flashing parameters for the ECU, such as communication protocols, and also includes information used to determine the actual flashing protocol. The automation and precision of this process greatly simplifies the preparation steps before flashing, reducing the complexity and error rate of manual configuration. The parameters extracted from the configuration information set are used to determine the target flashing protocol suitable for the current ECU. Subsequently, flashing operations are performed in parallel on each ECU (e.g., the first electronic control unit and the second electronic control unit) according to the selected protocol, which can significantly shorten the overall flashing time and improve flashing efficiency. Therefore, in the embodiments of this application, by responding to ECU flashing requests, dynamically matching configuration information sets based on serial numbers, determining the target flashing protocol, and performing parallel operations, the technical effect of improving the flashing efficiency of electronic control units is achieved.
[0046] As an optional approach, before performing the first flashing operation on the first electronic control unit according to the first target flashing protocol determined based on the first configuration information set, the method further includes:
[0047] Multiple first candidate flashing protocols corresponding to the first electronic control unit are determined from the first configuration information in the first configuration information set;
[0048] Based on the first selection parameters stored in the second configuration information in the first configuration information set, the first target flashing protocol is determined from multiple first candidate flashing protocols;
[0049] Before performing the second flashing operation on the second electronic control unit according to the second target flashing protocol determined based on the second configuration information set, the method further includes:
[0050] Multiple second candidate flashing protocols corresponding to the second electronic control unit are determined from the third configuration information in the second configuration information set;
[0051] Based on the second selection parameter stored in the fourth configuration information in the second configuration information set, the second target flashing protocol is determined from multiple second candidate flashing protocols.
[0052] Optionally, in this embodiment, the first candidate flashing protocol is a series of applicable flashing protocols identified from the configuration information set based on the characteristics of the first electronic control unit. It may include, but is not limited to, standard protocols such as DoIP protocol / DoCAN protocol, as well as proprietary protocols of specific vendors.
[0053] Optionally, in this embodiment, the first selection parameter is a rule or standard that indicates the selection of the best protocol from the first candidate flashing protocols. It can be implemented, but is not limited to, through specific parameter values. For example, parameter value a represents the best flashing protocol for the first protocol, and parameter value b represents the best flashing protocol for the second protocol. The selection parameter can be, but is not limited to, a comprehensive consideration of the ECU's hardware and software compatibility, network environment, data transmission efficiency, etc., to ensure the optimal selection of the target protocol.
[0054] Optionally, in this embodiment, the second candidate flashing protocol and the second selection parameter are similar to the first candidate flashing protocol and the first selection parameter, and are used to determine the most suitable second target flashing protocol for the specific needs and environment of the second electronic control unit.
[0055] Optionally, in this embodiment, before performing a flashing operation on the first electronic control unit, the system first extracts first configuration information from the first configuration information set and determines multiple first candidate flashing protocols that match the first electronic control unit based on the data therein. This step ensures that the system's flashing of the first electronic control unit can take into account the widest range of protocol possibilities.
[0056] Further analysis of the second configuration information within the first configuration information set reveals that this information includes first selection parameters, which are specific rules for selecting the target flashing protocol. Based on these parameters, the system can accurately determine the first target flashing protocol from the first candidate flashing protocols, preparing for the flashing operation of the first electronic control unit.
[0057] For the second electronic control unit, third configuration information is extracted from the second configuration information set to determine multiple second candidate flashing protocols. This step is equally important, ensuring that the flashing operation of the second electronic control unit can be performed based on its unique requirements.
[0058] Finally, based on the fourth configuration information in the second configuration information set, namely the second selection parameter, the system determines the second target flashing protocol from the second candidate flashing protocols. This selection takes into account the network environment, hardware characteristics, and software compatibility of the second ECU, ensuring the efficiency, safety, and compatibility of the flashing operation.
[0059] Optionally, in this embodiment, candidate flashing protocols are determined from the configuration information set, and the best target flashing protocol is automatically selected from the candidate protocols based on the selection parameters. The setting of the selection parameters takes into account the specific needs of the ECU and the network environment, ensuring the efficiency, compatibility and security of the flashing operation.
[0060] To further illustrate, consider a car equipped with DoIP and DoCAN networks, where the powertrain ECU (first electronic control unit) and the infotainment ECU (second electronic control unit) require software upgrades. The system first identifies several first candidate flashing protocols matching the powertrain ECU from a first set of configuration information, including DoIP, DoCAN, and powertrain supplier-specific proprietary protocols.
[0061] Next, based on the selection parameters in the first configuration information set, such as network load, ECU hardware compatibility, and software version matching requirements, the system automatically selected DoIP as the first target flashing protocol from these first candidate flashing protocols, because DoIP provides the highest data transmission efficiency in the current network environment.
[0062] For the infotainment system ECU, the system also identifies several candidate flashing protocols from the second configuration information set. Considering that the infotainment system may prioritize stability and compatibility, the system may have selected DoCAN as the second target flashing protocol based on the second selection parameter, as it offers better stability in complex network environments.
[0063] After determining the first and second target flashing protocols, the system performs flashing operations on the two ECUs in parallel, significantly improving the efficiency of flashing the entire vehicle.
[0064] Through the embodiments provided in this application, during the ECU software upgrade process, by determining candidate flashing protocols from the configuration information set and automatically selecting the best target flashing protocol from the candidate protocols based on the selection parameters, not only can multi-protocol adaptation be supported, but also the efficiency and stability of software updates can be significantly improved through automated protocol selection and parallel operation.
[0065] As an optional approach, after performing a first flashing operation on the first electronic control unit according to a first target flashing protocol determined based on a first configuration information set, the method further includes:
[0066] In response to a third flash request triggered by the first electronic control unit, a third target flash protocol indicated by the first flash request is obtained, wherein the third flash request is used to request that a flash operation be performed on the first electronic control unit in accordance with the third target flash protocol;
[0067] In the case where multiple first candidate flashing protocols include a third target flashing protocol, the first selection parameter stored in the second configuration information is modified to a third selection parameter, wherein the third selection parameter is a parameter used to indicate the third target flashing protocol to be matched from multiple first candidate flashing protocols.
[0068] Optionally, in this embodiment, the third flashing request refers to a subsequent flashing request initiated for the same ECU after the first successful flashing, used to perform software updates, repairs or other maintenance operations, wherein the request uses a third target flashing protocol different from the previous flashing.
[0069] Optionally, in this embodiment, the third target flashing protocol is a new protocol required by the third flashing request for reflashing the first electronic control unit. Optionally, the third flashing request / third target flashing protocol is to adapt to the latest requirements of the ECU, changes in the network environment, or to achieve more efficient data transmission.
[0070] Optionally, in this embodiment, a third flashing request is received for the first electronic control unit, indicating that flashing should be performed using a specific third target flashing protocol. This may be due to the ECU's software version needing an update, or a software problem requiring urgent repair discovered during diagnostics.
[0071] Based on the third flash request, the system searches for and confirms whether the third target flash protocol is part of a list of known first candidate flash protocols. If the third target flash protocol is in the candidate list, the system can quickly locate and use it.
[0072] To ensure the correct selection and application of the third target flushing protocol, the system needs to update the first selection parameter to become the third selection parameter. This parameter adjustment covers all necessary configuration information, such as baud rate, block size, diagnostic request response ID, and the encryption algorithm and key management rules in the security policy descriptor, to adapt to the requirements of the newly selected protocol.
[0073] Optionally, in this embodiment, the flashing strategy can be dynamically adjusted according to changes in the ECU and network environment, including reselecting the optimal flashing protocol and updating configuration parameters. This step ensures that each flashing operation is performed under the most suitable conditions, which not only improves efficiency but also guarantees the safety and accuracy of the flashing process.
[0074] To illustrate further, suppose a car equipped with a powertrain ECU has already undergone its first flash via the DoIP protocol. Shortly after, the manufacturer receives a report of a software defect in the ECU requiring immediate fixing. Therefore, the system receives a third flash request for the same ECU, requesting flashing using the DoCAN protocol to accommodate the powertrain ECU's higher performance requirements in a specific network environment.
[0075] The system first checks whether the DoCAN protocol is one of the multiple first-choice flashing protocols for the powertrain ECU, meaning it falls within the range of protocols preset during the initial flash. In this example, the answer is yes, because DoCAN is one of the protocols supported by the ECU.
[0076] Subsequently, the system updates the first selection parameter to become the third selection parameter to meet the requirements of the DoCAN protocol. This may involve adjusting the baud rate to a higher 5 Mbps, optimizing the block size for better transmission efficiency, and reconfiguring the encryption algorithm to ensure communication security.
[0077] After the parameters were adjusted, the system performed a flashing operation based on the third target flashing protocol, which fixed the software defects and verified the data integrity, ensuring the normal operation of the ECU function and the safety of the entire vehicle system.
[0078] The embodiments provided in this application enable the dynamic selection of the most suitable flashing protocol for the current scenario and seamless adjustment of relevant configuration parameters to ensure that each flashing operation is performed under optimal conditions, thereby effectively improving the efficiency and security of software updates.
[0079] As an optional approach, after determining the first target flashing protocol from multiple first candidate flashing protocols based on the first selection parameters stored in the second configuration information in the first configuration information set, the method further includes:
[0080] According to the first target refresh protocol and the channel configuration information indicated by the first configuration information, a transmission channel is established between the first electronic control unit and the flashing package that matches the first serial number. The transmission channel is used to transmit the target flashing file that matches the first serial number in the flashing package to the first electronic control unit.
[0081] If the transmission channel passes the first security check and the flashing package passes the second security check, the first electronic control unit is flashed using the target flashing file.
[0082] Optionally, in this embodiment, the transmission channel is a communication path established under the first target flashing protocol, used to transmit the target flashing file in the flashing package to a specific ECU. This path must meet the protocol requirements to ensure the correct and complete transmission of data.
[0083] Optionally, in this embodiment, the channel configuration information includes all the specific parameters required to establish the transmission channel, such as the communication protocol type, baud rate, sampling point, diagnostic request response ID, etc., as well as the hardware physical channel information that matches the first sequence number.
[0084] Optionally, in this embodiment, the first security check is used to indicate the security check performed on the established transmission channel to ensure that the channel meets security standards and can prevent data from being tampered with or subjected to other security threats during transmission. The second security check is used to indicate the verification of the flash packet to confirm that the flash packet has not been tampered with and that its CRC checksum or digital signature is consistent with expectations, thereby ensuring the authenticity and integrity of the flash file.
[0085] Optionally, in this embodiment, after determining the first target flashing protocol, the system dynamically establishes a transmission channel matching the first electronic control unit based on the channel configuration information in the first configuration information set. This process ensures the efficiency and security of data transmission, and the establishment of the channel follows the specific requirements of the selected protocol.
[0086] The established transmission channel undergoes a first security check to confirm that its configuration complies with security standards and that there are no potential vulnerabilities or risks. This is to prevent data from being maliciously attacked or accidentally damaged during transmission.
[0087] At the same time, the system performs a second security check on the flashing package, verifying the CRC checksum or digital signature of the target flashing file to ensure the authenticity and integrity of the file, thereby avoiding flashing failure or system malfunction due to the use of tampered or damaged files.
[0088] After both the transmission channel and the flashing package pass security verification, the system uses the target flashing file to flash the first electronic control unit. This operation, while ensuring data security, performs a software update, improving the ECU's performance or fixing potential software defects.
[0089] Optionally, in this embodiment, before performing the ECU flashing operation, the system needs to establish a secure transmission channel and perform strict security verification on the flashing package to ensure the security of data transmission and the integrity of the flashing file. By dynamically configuring the transmission channel and implementing multi-layer security verification, data security risks that may occur during the flashing process, such as data leakage, tampering, or damage, can be effectively prevented, while ensuring the efficiency and accuracy of each flashing operation.
[0090] To further illustrate, consider a Hyundai vehicle equipped with the AUTOSAR architecture. Its powertrain ECU (Electronic Control Unit) is initially flashed via the DoIP protocol. After determining DoIP as the primary flashing protocol, the system automatically establishes a transmission channel matching the primary electronic control unit based on the channel configuration information indicated by the first configuration information set.
[0091] During the channel establishment process, the system implemented a first security check to confirm that the channel's encryption algorithm, key management rules, and other aspects met security standards, effectively preventing data from being eavesdropped on or attacked midway. Simultaneously, the system performed a second security check on the flashing packet, ensuring that its CRC checksum matched the pre-stored checksum, thus verifying the authenticity and integrity of the file.
[0092] After passing these two safety checks, the system uses the target flashing file in the flashing package to begin updating the powertrain ECU software. During the flashing process, the system further implements closed-loop management, embedding real-time probe verification to ensure real-time monitoring of data transmission and immediate response in abnormal situations, guaranteeing the smooth progress of the flashing operation and ultimately achieving an efficient and safe ECU software upgrade.
[0093] The embodiments provided in this application include a security preparation and inspection mechanism before the flashing operation, as well as real-time monitoring of data integrity and system status during the implementation process. This not only improves the efficiency of software upgrades but also ensures the security and reliability of the entire process.
[0094] As an optional approach, before flashing the first electronic control unit using the target flash file, the method further includes:
[0095] Before the transmission channel is established, the target encryption function corresponding to the first electronic control unit is obtained according to the first serial number and the security level of the first electronic control unit. The target encryption function is the encryption function corresponding to the security level among multiple encryption functions corresponding to the sequence range of the first serial number.
[0096] The first key for the first electronic control unit is generated using the target encryption function;
[0097] After the transmission channel is established, a second key is generated based on the random seed generated by the first electronic control unit;
[0098] If the first key matches the second key, the transmission channel is confirmed to have passed the first security check.
[0099] Optionally, in this embodiment, the security level is divided into different levels based on the importance and sensitivity of the ECU, which is used to determine the encryption strength and the strictness of the security policy.
[0100] Optionally, in this embodiment, the target encryption function is an encryption algorithm corresponding to the security level of the ECU, used to generate a key that ensures the security of data transmission during the flashing process.
[0101] Optionally, in this embodiment, the first key is a key generated by the target encryption function before the transmission channel is established, used for preliminary identity authentication and secure communication with the ECU.
[0102] Optionally, in this embodiment, the random seed is a random number generated by the ECU after the transmission channel is established, used to generate the second key to ensure that the security of each interaction is unique and to enhance the security of the flashing process. The second key is a key jointly generated by the random seed generated by the ECU and the target encryption function, which is compared with the first key to verify the security of the transmission channel.
[0103] Optionally, in this embodiment, before the transmission channel is established, the system selects a target encryption function from multiple predefined encryption functions based on the first serial number and the security level of the first electronic control unit. This ensures that the encryption strength matches the importance and sensitivity of the ECU.
[0104] The target encryption function is used to generate a first key, which will be compared with the second key generated by the ECU in subsequent security checks.
[0105] After the transmission channel is established, the first electronic control unit generates a random seed and uses this seed and the target encryption function to regenerate a second key for subsequent security verification.
[0106] The system compares the first key with the second key generated by the ECU. Once they match, the transmission channel passes the first security check. This step ensures the security of the transmission channel and prevents unauthorized access and data tampering.
[0107] Optionally, in this embodiment, an encryption function is determined based on the ECU serial number and security level to generate a first key for initial security verification. Then, the ECU generates a random seed and a second key for secondary verification, ensuring that each flashing operation is performed in a highly secure environment, effectively preventing data leakage and improving the overall security of the vehicle's internal system.
[0108] To further illustrate, consider a modern electric vehicle. Its battery management system (ECU, or first electronic control unit) is considered a high-security component because the accuracy and security of battery data are crucial to vehicle performance and passenger safety. Before reprogramming the software, the system first selects the AES-256-bit advanced encryption standard as the target encryption function based on the ECU's serial number and security level.
[0109] Next, the system uses AES-256 to generate a first key, which is used for initial authentication to ensure the security of the communication channel between the system and the ECU.
[0110] Once the transmission channel is established, the battery management system ECU generates a random seed and uses this seed and AES-256 to generate a second key. Before the actual flashing operation begins, the system compares the first key with the second key generated by the ECU. Once the two are confirmed to match, the transmission channel passes the first security check, and the flashing operation can continue.
[0111] The embodiments provided in this application not only enhance the security of data transmission by dynamically selecting encryption functions and implementing a two-layer key mechanism, but also increase the difficulty for attackers to crack the keys, ensuring that even in complex network environments, ECU software updates can be performed under the highest level of security protection, thereby safeguarding vehicle safety.
[0112] As an optional approach, before flashing the first electronic control unit using the target flashing file, the method further includes obtaining the driving style label of a reference vehicle and then:
[0113] Obtain the flash verification data associated with the flash package, wherein the flash verification data embeds the first file identification information of the target flash file;
[0114] Obtain the second file identification information stored in the second configuration information, wherein the second file identification information is used to indicate the file to be flashed in the first electronic control unit;
[0115] If the first file identification information and the second file identification information are consistent, the flash package is determined to have passed the second security check.
[0116] Optionally, in this embodiment, the flash verification data is included in the flash package and is used to verify the authenticity and integrity of the target flash file. This typically includes file identification information, CRC checksums, or digital signatures to ensure the file's correctness.
[0117] Optionally, in this embodiment, the first file identification information is embedded in the flash verification data. This information is used to uniquely identify the target flash file and can be the file name, version number, serial number, or any other identifier that can distinguish the file's identity.
[0118] Optionally, in this embodiment, the second file identification information, a file identifier stored in the second configuration information, is used to indicate the specific software version or file to be flashed on the first electronic control unit. It matches the first file identification information to ensure the correct execution of the flashing operation.
[0119] Optionally, in this embodiment, before performing a flashing operation on the first electronic control unit, the system first extracts flashing verification data from the flashing package, which includes the first file identification information of the target flashing file. This step provides basic data for subsequent file verification.
[0120] Next, the system retrieves the second file identification information from the second configuration information. This information indicates the current or upcoming software version or file to be flashed for the first electronic control unit. This is to ensure that the system knows the exact file and version required by the target ECU.
[0121] The system compares the consistency of the first file identifier information and the second file identifier information. If they match, it determines that the flashing package has passed the second security check, meaning that the target flashing file is correct, complete, and suitable for the target ECU. This step ensures that incorrect or incompatible files are not used during the flashing process, avoiding potential functional abnormalities or security risks.
[0122] Optionally, in this embodiment, by obtaining the first file identification information of the target file to be flashed and the second file identification information indicating the file to be flashed, and performing a strict consistency comparison, the method of the present invention can exclude incorrect files before the flashing process officially begins, thus ensuring the accuracy and security of the software update.
[0123] To illustrate further, suppose a smart car equipped with multiple ECUs is undergoing a software update for its powertrain ECU (first electronic control unit). Before the flashing operation, the system extracts flashing verification data from the flashing package for the target flashing file that matches the powertrain ECU. This data includes first file identification information, such as the filename "PowerSystem_Firmware_1.2.3.bin" and the version number "1.2.3".
[0124] At the same time, the system reads the second file identification information from the second configuration information, which indicates the software version currently required by the first electronic control unit, which is also "PowerSystem_Firmware_1.2.3.bin" and version number "1.2.3".
[0125] Through consistency verification, the system confirmed that the target flash file in the flash package completely matches the file to be flashed on the first electronic control unit. The file name is "PowerSystem_Firmware_1.2.3.bin", and the version numbers are the same, both being "1.2.3". This means that the flash package has passed the second security check, and the system can safely use the target flash file to perform flashing operations on the first electronic control unit without worrying about functional abnormalities or security issues caused by using an incorrect file version.
[0126] By obtaining the first file identifier information of the target file to be flashed and the second file identifier information indicating the file to be flashed through the embodiments provided in this application, and performing a strict consistency comparison, the method of the present invention can exclude incorrect files before the flashing process officially begins, thus ensuring the accuracy and security of the software update.
[0127] As an optional approach, a first flashing operation is performed on the first electronic control unit according to a first target flashing protocol determined based on a first configuration information set, including:
[0128] Multiple first candidate flashing protocols corresponding to the first electronic control unit are determined from the first configuration information in the first configuration information set;
[0129] When the second configuration information in the first configuration information set stores global selection parameters, the first electronic control unit is flashed sequentially according to each flashing protocol in the multiple first candidate flashing protocols to obtain multiple flashing results;
[0130] The flashing results from multiple flashing processes are integrated to obtain the flashing report for the first electronic control unit.
[0131] Optionally, in this embodiment, the flashing result refers to the result of the flashing operation corresponding to each protocol after attempting to perform flashing operations on the first electronic control unit using different candidate flashing protocols. This may include details such as the success or failure of the operation, the time consumed, the amount of data transmitted, and error messages.
[0132] Optionally, in this embodiment, the write report is a summary document generated by the system after a series of write operations have been completed and their results collected. It reports the write performance under each first candidate protocol and recommends the best protocol. This report can assist in decision-making and determine the most effective write strategy.
[0133] Optionally, in this embodiment, before performing a flashing operation on the first electronic control unit, the system obtains multiple first candidate flashing protocols matching the ECU from a first configuration information set. This step provides multiple possible options for subsequent flashing operations.
[0134] If the second configuration information stores global selection parameters, the system will attempt to perform a flashing operation on the first electronic control unit using each of the first candidate flashing protocols, collecting the flashing results for each operation. The purpose of this is to evaluate the flashing performance and success rate under different protocols.
[0135] The system analyzes and integrates all the flashing results to generate a detailed flashing report. This report not only records the specifics of each flashing operation but also compares the advantages and disadvantages of different protocols to guide subsequent flashing decisions.
[0136] To illustrate further, suppose the powertrain ECU (first electronic control unit) of a smart car needs a software update, and this ECU supports three different communication protocols: DoIP, DoCAN, and proprietary protocol X. Before starting the actual flashing process, the system obtains these three first candidate flashing protocols from the first configuration information set, and based on the global selection parameters in the second configuration information, begins to attempt to flash the first electronic control unit using these protocols one by one.
[0137] The DoIP protocol was used for flashing, and the operation took 10 minutes with a data transfer volume of 2GB. There were no obvious errors, but the operation took a little longer than expected.
[0138] The DoCAN protocol was used for flashing, and the recording operation took 12 minutes with a data transfer volume of 2.1GB. During this time, a minor bus contention issue occurred, causing the operation to be interrupted and restarted, increasing the time to 6 minutes.
[0139] Using the proprietary X protocol for flashing, the operation took 8 minutes and the data transfer volume was 1.6GB. The entire process was stable and error-free, with the highest transmission efficiency.
[0140] After completing all attempts, the system integrated and analyzed the three flashing results, generating a detailed flashing report. The report showed that although the DoIP and DoCAN protocols could complete the flashing task, the proprietary protocol X performed best in terms of efficiency and stability, taking the least time and without data transmission errors. Therefore, it was recommended as the preferred protocol for this flashing operation.
[0141] The embodiments provided in this application involve trying different first-candidate flashing protocols one by one, collecting and analyzing their performance during the actual flashing process. This method can objectively evaluate the applicability and efficiency of various protocols, thereby helping to determine the target flashing protocol most suitable for the current ECU and environmental conditions. This process is both a concrete manifestation of the dynamic protocol extension layer function and a comprehensive test of the performance of the parallel flashing layer, ensuring the efficiency, safety and accuracy of the flashing operation.
[0142] As an optional solution, in order to better understand the process of the above-mentioned electronic control unit flashing method, the following describes the execution flow of the above-mentioned electronic control unit flashing method in conjunction with optional embodiments, but it is not intended to limit the technical solution of the embodiments of this application.
[0143] With the rapid development of automotive electronics technology, the number of ECUs (Electronic Control Units) in modern automotive systems is increasing daily, and their functions are becoming increasingly complex. To adapt to the trend of "software-defined vehicles," rapid software updates and management have become essential. Although OTA (Over-The-Air) upgrades offer the convenience of wireless ECU flashing, they are limited by traditional serial scheduling mechanisms and static protocol stack architectures, failing to meet the needs of parallel flashing of multiple ECUs and expansion to automaker-specific protocols. Furthermore, manual parameter configuration has a high error rate, and data conflicts may occur during parallel flashing of multiple ECUs, leading to upgrade failures. Therefore, a new method is urgently needed to improve the efficiency and scalability of ECU flashing.
[0144] To address the aforementioned technical issues, this embodiment proposes a dynamic protocol extension and parallel writing system based on the AUTOSAR architecture, as shown in the architecture diagram below. Figure 3 As shown, it includes a dynamic protocol extension layer 302, a parallel write layer 304, and a security control layer 306.
[0145] Optionally, in this embodiment, the dynamic protocol extension layer 302 defines a protocol descriptor structure, allowing the system to dynamically load physical layer parameters and callback functions of DoIP / DoCAN and vehicle manufacturer-specific protocols. It achieves multi-protocol adaptive message conversion through a unified service access point, enabling hot deployment of protocols with zero compilation. The parallel flashing layer 304 integrates a parallel flashing coordinator, employing a dynamic time window scheduling algorithm to allocate bus resources in real time. It drives the incremental differential engine to transmit only firmware difference blocks, reducing data transmission by 70%. Based on a distributed transaction protocol, it ensures the atomicity of multi-ECU flashing and automatically triggers a safe rollback in case of an anomaly. The security control layer 306 embeds diagnostic probes to verify the flashing process in real time, supports hot updates of encryption algorithms, and ensures the security and integrity of the flashing operation.
[0146] Optionally, in this embodiment, a unified service node (such as Jenkins) issues a flashing task, obtains the corresponding diagnostic configuration file (including communication protocol, baud rate, sampling points, diagnostic request response ID, etc.) and flashing process configuration file from the server based on the ECU serial number, and dynamically establishes a diagnostic connection.
[0147] The target encryption function is obtained using the ECU serial number and security level to generate a first key. After the transmission channel is established, the ECU generates a random seed and a second key. The first key and the second key are compared to ensure that the transmission channel passes the first security check. At the same time, the flashing verification data associated with the flashing package is obtained to confirm that the first file identification information is consistent with the second file identification information in the second configuration information, so as to pass the second security check.
[0148] After ensuring channel security and flashing package integrity, the first target flashing protocol is determined from multiple first candidate flashing protocols based on global selection parameters, a transmission channel is established, and the first electronic control unit is flashed in parallel. The dynamic time window scheduling algorithm optimizes bus resource allocation to ensure parallel flashing of 12+ ECUs.
[0149] Multiple flashing results are integrated to form a detailed flashing report, including flashing efficiency, data transmission volume, and error messages under each protocol, to assist in subsequent flashing decisions. At the same time, test results are sent to a designated email address.
[0150] This embodiment also proposes a dynamic protocol extension and parallel writing method based on the AUTOSAR architecture, as shown in the flowchart below. Figure 4 As shown, the system is divided into four layers: scheduling layer, control layer, execution layer, and operation and maintenance layer. The steps proceed in a logical order. The following is a detailed explanation of each step:
[0151] I. The scheduling layer method steps include:
[0152] S402, Unified Service Node: As the starting node of the entire distributed diagnostic and flashing process, it integrates and schedules various service resources of the platform, providing a unified service entry point for subsequent steps.
[0153] S404, Flash Configuration Descriptor: Writes and generates configuration description information for diagnostic flashing, providing a configuration basis for obtaining topology and version mapping relationships.
[0154] S406, Obtain ECU Topology: Read the connection topology between vehicle electronic control units (ECUs) to clarify the networking and association relationships of each ECU.
[0155] S410, obtain firmware version mapping relationship: retrieve the matching mapping data between ECU and corresponding firmware version to determine the firmware version information that needs to be flashed for different ECUs.
[0156] II. The steps of the control layer method include:
[0157] S408, Load Protocol Descriptor: Loads the communication protocol description information required for distributed diagnostic writing, providing protocol rules for subsequent generation of diagnostic sequences.
[0158] S412, Load Security Policy Descriptor: Import security policy configuration information during the flashing process and define security rules such as authentication and encryption.
[0159] S414, Calculate the security key: Based on the loaded security policy, calculate and generate a security key used for authentication and data encryption during the flashing process.
[0160] S416, Generate Diagnostic Sequence: Combine the protocol descriptor and security key to generate a diagnostic execution sequence that conforms to the communication protocol and security requirements.
[0161] S418, Generate Diagnostic Request Sequence: Based on the diagnostic sequence, further generate a specific diagnostic request instruction sequence for the target ECU.
[0162] III. The steps of the execution layer method include:
[0163] S422, Distributed Transaction Protocol Response Diagnostic Request Sequence:
[0164] A distributed transaction protocol is used to parse and respond to diagnostic request sequences, ensuring the effective execution of requests in distributed scenarios.
[0165] S424, Send diagnostic request to target ECU: Send the parsed diagnostic request command to the target ECU device that needs to be flashed.
[0166] S426, Verify Embedded Probe: Verify the status, identity, or data integrity of the target ECU using an embedded probe to confirm whether the preconditions for flashing are met.
[0167] S428, if the verification is successful, submit the version: If the embedded probe verification is successful, submit the corresponding firmware version to the target ECU and perform the flashing operation.
[0168] S430, in the event of a failed verification, a rollback is triggered: if the embedded probe verification fails, the process rollback mechanism is triggered to undo the executed operations and restore the ECU to its original state.
[0169] IV. The operation and maintenance layer methods and steps include:
[0170] S432, Generate full-link log: Regardless of whether the verification is successful or not, a full-link operation log is recorded from the scheduling layer to the execution layer, including information such as step execution status and data interaction.
[0171] S434, Push Report: Generates a diagnostic write result report based on the full-link logs and pushes it to the specified operation and maintenance terminal or platform.
[0172] S436, Send Email / Message: Notify relevant maintenance personnel of the flashing result report via email, instant message, etc., to complete the process loop.
[0173] Optionally, in this embodiment, by dynamically loading protocol descriptors, parallel scheduling algorithms and distributed transaction protocols, the limitations of traditional static protocol stacks and serial scheduling are broken, significantly improving the writing efficiency, reducing the whole vehicle writing time from 2 hours to 12 minutes, adapting to production line cycle times of ≤6 minutes, and realizing full-process parameter self-configuration.
[0174] Optionally, in this embodiment, by using multiple ECUs to flash in parallel, an incremental differential engine to reduce data transmission, dynamic time window allocation of bus resources, and closed-loop management and real-time probe verification, the efficiency, safety, and accuracy of the flashing operation are ensured.
[0175] To illustrate further, suppose a smart car needs a software upgrade for its powertrain ECU. To ensure the safety and efficiency of the operation, the system would proceed as follows:
[0176] 1. Task Trigger: The unified service node (automated scheduling platform) issues a flashing task, which includes the powertrain ECU serial number and firmware package information.
[0177] 2. Connection Establishment and Security Verification: The system obtains the diagnostic configuration information of the powertrain ECU based on the serial number and establishes a diagnostic connection. Simultaneously, the system uses the ECU serial number and security level to determine the encryption function and generate a first key. The ECU generates a random seed and a second key, passing the first security verification. Furthermore, the system verifies that the file identifier information of the flashing package matches the file identifier information indicated in the configuration information, ensuring the flashing package passes the second security verification.
[0178] 3. Parallel Flashing: The system determines DoIP as the primary flashing protocol based on global selection parameters, establishes a transmission channel, and uses a dynamic time window scheduling algorithm to allocate bus resources for parallel flashing. The incremental differential engine only transmits firmware difference blocks, reducing data transmission volume and improving flashing efficiency by 80%.
[0179] 4. Results Integration and Reporting: The system integrates the flashing results to generate a flashing report, including detailed information such as flashing efficiency, data transmission volume, and error messages under the DoIP protocol, and sends the report to the designated email address.
[0180] It should be noted that, in this embodiment, a Pluggable Protocol Stack Framework (PPSF) can be used to define a protocol descriptor structure for loading protocols, allowing DOIP / DOCAN and proprietary protocols to be plug-and-play. A unified service accessor issues protocol identifiers to trigger the flushing task, thereby achieving adaptive message conversion across multiple protocols; a parallel flushing coordinator is integrated synchronously. The encryption algorithm has high adaptability, using embedded diagnostic probes for real-time CRC verification, and a distributed transaction protocol ensures atomicity. The protocol extension cycle is shortened from one month to two hours, eliminating manual configuration and significantly reducing costs.
[0181] During the diagnostic request for a secure unlock session, the corresponding encryption algorithm is invoked based on the ECU's serial number. The corresponding key is calculated using the seed obtained from the ECU, and the complete diagnostic request is sent to the MCU to complete the secure unlock. Before triggering the flashing task, the CRC data or verification data of the flashing package is calculated and stored in a variable. The calculated CRC data or verification data is embedded according to the corresponding file identifier, and then the complete diagnostic request is sent to the MCU to complete the CRC verification.
[0182] By using a coordinator's dynamic time window scheduling, parallel flashing of 12+ ECUs is achieved, reducing data transmission volume by 70% with the incremental differential engine. Efficiency is improved by 80%, and the entire vehicle flashing time is reduced to 12 minutes (meeting a production line cycle time of ≤6 minutes), saving costs. Flashing multiple ECUs only requires distributing the serial numbers of multiple ECUs when the flashing task is triggered. Then, the corresponding flashing configuration file and flashing file are retrieved based on the corresponding ECU serial number. Diagnostic configuration information (finding the corresponding hardware physical channel and obtaining parameters such as the current ECU's communication protocol, baud rate, sampling point, and diagnostic request response ID) is obtained from the flashing configuration file to establish a diagnostic connection.
[0183] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0184] According to another aspect of the embodiments of this application, a writing apparatus for an electronic control unit for implementing the above-described writing method for an electronic control unit is also provided. For example... Figure 5 As shown, the device includes:
[0185] The acquisition unit 502 is configured to acquire the serial numbers associated with at least two electronic control units in response to a flashing request from at least two electronic control units, wherein the at least two electronic control units include a first electronic control unit and a second electronic control unit.
[0186] The matching unit 504 is used to match a first configuration information set corresponding to a first serial number associated with a first electronic control unit from the configuration information set library, and to match a second configuration information set corresponding to a second serial number associated with a second electronic control unit from the configuration information set library. The configuration information set library is used to store the configuration information set corresponding to each serial number. A configuration information set includes configuration information indicating multiple candidate flashing protocols corresponding to an electronic control unit and configuration information for determining the target flashing protocol from multiple candidate flashing protocols.
[0187] The flashing unit 506 is used to perform a first flashing operation on the first electronic control unit according to a first target flashing protocol determined based on a first configuration information set, and to perform a second flashing operation on the second electronic control unit according to a second target flashing protocol determined based on a second configuration information set, wherein the first flashing operation and the second flashing operation are executed in parallel.
[0188] As an optional solution, the device further includes: a first determining module, configured to determine a plurality of first candidate flashing protocols corresponding to the first electronic control unit from the first configuration information in the first configuration information set before performing a first flashing operation on the first electronic control unit according to a first target flashing protocol determined based on the first configuration information set; a second determining module, configured to determine a first target flashing protocol from the plurality of first candidate flashing protocols based on a first selection parameter stored in the second configuration information in the first configuration information set before performing a first flashing operation on the first electronic control unit according to the first target flashing protocol determined based on the first configuration information set; the device further includes: a third determining module, configured to determine a plurality of second candidate flashing protocols corresponding to the second electronic control unit from the third configuration information in the second configuration information set before performing a second flashing operation on the second electronic control unit according to a second target flashing protocol determined based on the second configuration information set; and a fourth determining module, configured to determine a second target flashing protocol from the plurality of second candidate flashing protocols based on a second selection parameter stored in the fourth configuration information in the second configuration information set before performing a second flashing operation on the second electronic control unit according to the second target flashing protocol determined based on the second configuration information set.
[0189] As an optional solution, the device further includes: a first acquisition module, configured to, after performing a first flashing operation on the first electronic control unit according to a first target flashing protocol determined based on a first configuration information set, acquire a third target flashing protocol indicated by the first flashing request in response to a third flashing request triggered on the first electronic control unit, wherein the third flashing request is used to request to perform a flashing operation on the first electronic control unit according to the third target flashing protocol; and an adjustment module, configured to, after performing a first flashing operation on the first electronic control unit according to the first target flashing protocol determined based on the first configuration information set, modify a first selection parameter stored in the second configuration information to a third selection parameter when multiple first candidate flashing protocols include the third target flashing protocol, wherein the third selection parameter is a parameter used to indicate the matching of the third target flashing protocol from multiple first candidate flashing protocols.
[0190] As an optional solution, the device further includes: an establishment module, used to determine a first target flashing protocol from multiple first candidate flashing protocols based on first selection parameters stored in the second configuration information in the first configuration information set, and then establish a transmission channel between the first electronic control unit and a flashing package matching the first serial number according to the first target flashing protocol and the channel configuration information indicated by the first configuration information, wherein the transmission channel is used to transmit the target flashing file matching the first serial number in the flashing package to the first electronic control unit; and a first flashing module, used to perform a flashing operation on the first electronic control unit using the target flashing file after determining the first target flashing protocol from multiple first candidate flashing protocols based on the first selection parameters stored in the second configuration information in the first configuration information set, provided that the transmission channel passes the first security check and the flashing package passes the second security check.
[0191] As an optional solution, the device further includes: a second acquisition module, used to acquire a target encryption function corresponding to the first electronic control unit based on the first serial number and the security level of the first electronic control unit before performing a flashing operation on the first electronic control unit using the target flashing file and before establishing the transmission channel, wherein the target encryption function is the encryption function corresponding to the security level among multiple encryption functions corresponding to the sequence range of the first serial number; a first generation module, used to generate a first key for the first electronic control unit using the target encryption function before performing a flashing operation on the first electronic control unit using the target flashing file; a second generation module, used to generate a second key based on a random seed generated by the first electronic control unit after establishing the transmission channel, before performing a flashing operation on the first electronic control unit using the target flashing file; and a fifth determination module, used to determine that the transmission channel passes the first security check if the first key and the second key are consistent before performing a flashing operation on the first electronic control unit using the target flashing file.
[0192] As an optional solution, the device further includes: a third acquisition module, used to acquire flash verification data associated with the flash package before flashing the first electronic control unit using the target flash file, wherein the flash verification data embeds the first file identification information of the target flash file; a fourth acquisition module, used to acquire the second file identification information stored in the second configuration information before flashing the first electronic control unit using the target flash file, wherein the second file identification information is used to indicate the file to be flashed on the first electronic control unit; and a sixth determination module, used to determine that the flash package passes the second security check if the first file identification information and the second file identification information are consistent before flashing the first electronic control unit using the target flash file.
[0193] As an optional solution, the flashing unit 506 includes: a seventh determining module, used to determine multiple first candidate flashing protocols corresponding to the first electronic control unit from the first configuration information in the first configuration information set; a second flashing module, used to perform flashing operations on the first electronic control unit sequentially according to each flashing protocol in the multiple first candidate flashing protocols when the second configuration information in the first configuration information set stores global selection parameters, to obtain multiple flashing results; and an integration module, used to integrate the multiple flashing results to obtain a flashing report of the first electronic control unit.
[0194] Optionally, in this embodiment, the implementation of each of the above-mentioned unit modules can be referred to the above-mentioned method embodiments, which will not be repeated here.
[0195] According to another aspect of the embodiments of this application, an electronic device for implementing the above-described electronic control unit flashing method is also provided. This electronic device may be... Figure 6 The terminal device or server shown. This embodiment uses this electronic device as an example for illustration. Figure 6 As shown, the electronic device includes a memory 602 and a processor 604. The memory 602 stores a computer program, and the processor 604 is configured to execute the steps in any of the above method embodiments via the computer program.
[0196] Optionally, in this embodiment, the aforementioned electronic device may be located in at least one of a plurality of network devices in a computer network.
[0197] Optionally, in this embodiment, the processor can be configured to perform the following steps via a computer program:
[0198] S1, in response to the flashing request of at least two electronic control units, obtain the serial numbers associated with at least two electronic control units, wherein the at least two electronic control units include a first electronic control unit and a second electronic control unit;
[0199] S2, based on the first serial number associated with the first electronic control unit, a first configuration information set corresponding to the first serial number is matched from the configuration information set library, and based on the second serial number associated with the second electronic control unit, a second configuration information set corresponding to the second serial number is matched from the configuration information set library. The configuration information set library is used to store the configuration information set corresponding to each serial number. A configuration information set includes configuration information indicating multiple candidate flashing protocols corresponding to an electronic control unit and configuration information used to determine the target flashing protocol from multiple candidate flashing protocols.
[0200] S3, according to the first target flashing protocol determined based on the first configuration information set, a first flashing operation is performed on the first electronic control unit, and according to the second target flashing protocol determined based on the second configuration information set, a second flashing operation is performed on the second electronic control unit, wherein the first flashing operation and the second flashing operation are performed in parallel.
[0201] Alternatively, as those skilled in the art will understand, Figure 6 The structure shown is for illustrative purposes only. Electronic devices can also be smartphones (such as Android phones, iOS phones, etc.), tablets, PDAs, mobile internet devices (MIDs), PADs, and other terminal devices. Figure 6 This does not limit the structure of the aforementioned electronic devices or electronic equipment. For example, electronic devices or electronic equipment may also include components that are more... Figure 6 The more or fewer components shown (such as network interfaces, etc.), or having the same Figure 6 The different configurations shown.
[0202] The memory 602 can be used to store software programs and modules, such as the program instructions / modules corresponding to the electronic control unit flashing method and device in this embodiment. The processor 604 executes various functional applications and data processing by running the software programs and modules stored in the memory 602, thereby realizing the aforementioned electronic control unit flashing method. The memory 602 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 602 may further include memory remotely located relative to the processor 604, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof. Specifically, the memory 602 may be used, but is not limited to, to store information such as a first target flashing protocol and a second target flashing protocol. As an example, such as... Figure 6 As shown, the memory 602 may include, but is not limited to, the acquisition unit 502, matching unit 504, and writing unit 506 in the electronic control unit's writing device. Furthermore, it may include, but is not limited to, other module units in the electronic control unit's writing device, which will not be elaborated upon in this example.
[0203] Optionally, the transmission device 606 described above is used to receive or send data via a network. Specific examples of the network described above may include wired networks and wireless networks. In one example, the transmission device 806 includes a Network Interface Controller (NIC), which can be connected to other network devices and a router via a network cable to communicate with the Internet or a local area network. In one example, the transmission device 606 is a radio frequency (RF) module, used for wireless communication with the Internet.
[0204] In addition, the above-mentioned electronic device also includes: a display 608 for displaying the first target flashing protocol and the second target flashing protocol; and a connection bus 610 for connecting the various module components in the above-mentioned electronic device.
[0205] In other embodiments, the aforementioned terminal device or server can be a node in a distributed system, wherein the distributed system can be a blockchain system, which is a distributed system formed by connecting multiple nodes through network communication. The nodes can form a peer-to-peer (P2P) network, and any form of computing device, such as a server, terminal, or other electronic device, can become a node in the blockchain system by joining this peer-to-peer network.
[0206] According to one aspect of this application, a computer program product is provided, comprising a computer program / instructions containing program code for performing the methods shown in the flowchart. In such embodiments, the computer program can be downloaded and installed from a network via a communication component, and / or installed from a removable medium. When the computer program is executed by a central processing unit, it performs various functions provided in embodiments of this application.
[0207] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0208] According to one aspect of this application, a computer-readable storage medium is provided, wherein a processor of a computer device reads computer instructions from the computer-readable storage medium, and executes the computer instructions to cause the computer device to perform the above-described electronic control unit flashing method.
[0209] Optionally, in this embodiment, the computer-readable storage medium may be configured to store a computer program for performing the following steps:
[0210] S1, in response to the flashing request of at least two electronic control units, obtain the serial numbers associated with at least two electronic control units, wherein the at least two electronic control units include a first electronic control unit and a second electronic control unit;
[0211] S2, based on the first serial number associated with the first electronic control unit, a first configuration information set corresponding to the first serial number is matched from the configuration information set library, and based on the second serial number associated with the second electronic control unit, a second configuration information set corresponding to the second serial number is matched from the configuration information set library. The configuration information set library is used to store the configuration information set corresponding to each serial number. A configuration information set includes configuration information indicating multiple candidate flashing protocols corresponding to an electronic control unit and configuration information used to determine the target flashing protocol from multiple candidate flashing protocols.
[0212] S3, according to the first target flashing protocol determined based on the first configuration information set, a first flashing operation is performed on the first electronic control unit, and according to the second target flashing protocol determined based on the second configuration information set, a second flashing operation is performed on the second electronic control unit, wherein the first flashing operation and the second flashing operation are performed in parallel.
[0213] Optionally, in this embodiment, those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0214] If the integrated units in the above embodiments are implemented as software functional units and sold or used as independent products, they can be stored in the aforementioned computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause one or more computer devices (which may be personal computers, servers, or network devices, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application.
[0215] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0216] In the several embodiments provided in this application, it should be understood that the disclosed client can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between units or modules, and may be electrical or other forms.
[0217] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0218] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0219] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A method of flashing an electronic control unit, characterized by, include: In response to a flashing request from at least two electronic control units, the serial numbers associated with the at least two electronic control units are obtained, wherein the at least two electronic control units include a first electronic control unit and a second electronic control unit; Based on the first serial number associated with the first electronic control unit, a first configuration information set corresponding to the first serial number is matched from the configuration information set library, and based on the second serial number associated with the second electronic control unit, a second configuration information set corresponding to the second serial number is matched from the configuration information set library. The configuration information set library is used to store the configuration information set corresponding to each serial number. A configuration information set includes configuration information indicating multiple candidate flashing protocols corresponding to an electronic control unit and configuration information for determining the target flashing protocol from the multiple candidate flashing protocols. According to the first target flashing protocol determined based on the first configuration information set, a first flashing operation is performed on the first electronic control unit, and according to the second target flashing protocol determined based on the second configuration information set, a second flashing operation is performed on the second electronic control unit, wherein the first flashing operation and the second flashing operation are performed in parallel.
2. The method according to claim 1, characterized in that, Before performing the first flashing operation on the first electronic control unit according to the first target flashing protocol determined based on the first configuration information set, the method further includes: Multiple first candidate flashing protocols corresponding to the first electronic control unit are determined from the first configuration information in the first configuration information set; Based on the first selection parameter stored in the second configuration information in the first configuration information set, the first target flashing protocol is determined from the plurality of first candidate flashing protocols; Before performing the second flashing operation on the second electronic control unit according to the second target flashing protocol determined based on the second configuration information set, the method further includes: Multiple second candidate flashing protocols corresponding to the second electronic control unit are determined from the third configuration information in the second configuration information set; Based on the second selection parameter stored in the fourth configuration information in the second configuration information set, the second target flashing protocol is determined from the plurality of second candidate flashing protocols.
3. The method of claim 2, wherein, After performing a first flashing operation on the first electronic control unit according to a first target flashing protocol determined based on the first configuration information set, the method further includes: In response to a third flash request triggered on the first electronic control unit, a third target flash protocol indicated by the first flash request is obtained, wherein the third flash request is used to request that a flash operation be performed on the first electronic control unit in accordance with the third target flash protocol; When the plurality of first candidate flashing protocols includes the third target flashing protocol, the first selection parameter stored in the second configuration information is modified to a third selection parameter, wherein the third selection parameter is a parameter used to indicate the matching of the third target flashing protocol from the plurality of first candidate flashing protocols.
4. The method according to claim 2, characterized in that, After determining the first target flashing protocol from the plurality of first candidate flashing protocols based on the first selection parameters stored in the second configuration information in the first configuration information set, the method further includes: According to the first target refresh protocol and the channel configuration information indicated by the first configuration information, a transmission channel is established between the first electronic control unit and the flashing package matching the first serial number, wherein the transmission channel is used to transmit the target flashing file matching the first serial number in the flashing package to the first electronic control unit. If the transmission channel passes the first security check and the flashing package passes the second security check, the first electronic control unit is flashed using the target flashing file.
5. The method according to claim 4, characterized in that, Before performing the flashing operation on the first electronic control unit using the target flashing file, the method further includes: Before the transmission channel is established, a target encryption function corresponding to the first electronic control unit is obtained based on the first serial number and the security level of the first electronic control unit. The target encryption function is the encryption function corresponding to the security level among multiple encryption functions corresponding to the sequence range of the first serial number. The first key of the first electronic control unit is generated using the target encryption function; After the transmission channel is established, a second key is generated based on the random seed generated by the first electronic control unit; If the first key matches the second key, the transmission channel is determined to have passed the first security check.
6. The method according to claim 4, characterized in that, Before performing the flashing operation on the first electronic control unit using the target flashing file, the method further includes: Obtain the flash verification data associated with the flash package, wherein the flash verification data embeds the first file identification information of the target flash file; Obtain the second file identification information stored in the second configuration information, wherein the second file identification information is used to indicate the file to be flashed by the first electronic control unit; If the first file identification information and the second file identification information are consistent, it is determined that the flashing package has passed the second security verification.
7. The method according to any one of claims 1 to 6, characterized in that, The step of performing a first flashing operation on the first electronic control unit according to a first target flashing protocol determined based on the first configuration information set includes: Multiple first candidate flashing protocols corresponding to the first electronic control unit are determined from the first configuration information in the first configuration information set; When the second configuration information in the first configuration information set stores global selection parameters, the first electronic control unit is flashed according to each of the multiple first candidate flashing protocols in turn, and multiple flashing results are obtained. The multiple flashing results are integrated to obtain the flashing report of the first electronic control unit.
8. A writing device for an electronic control unit, characterized in that, include: The acquisition unit is configured to acquire the serial numbers associated with at least two electronic control units in response to a flashing request from at least two electronic control units, wherein the at least two electronic control units include a first electronic control unit and a second electronic control unit. The matching unit is used to match a first configuration information set corresponding to a first serial number associated with a first electronic control unit from the configuration information set library, and to match a second configuration information set corresponding to a second serial number associated with a second electronic control unit from the configuration information set library. The configuration information set library is used to store the configuration information set corresponding to each serial number. A configuration information set includes configuration information indicating multiple candidate flashing protocols corresponding to an electronic control unit and configuration information for determining the target flashing protocol from multiple candidate flashing protocols. The flashing unit is used to perform a first flashing operation on the first electronic control unit according to a first target flashing protocol determined based on a first configuration information set, and to perform a second flashing operation on the second electronic control unit according to a second target flashing protocol determined based on a second configuration information set, wherein the first flashing operation and the second flashing operation are executed in parallel.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein the program, when executed, performs the method described in any one of claims 1 to 7.
10. An electronic device comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is configured to execute the method described in any one of claims 1 to 7 through the computer program.