Brushing risk management and control method and device of electronic control unit, electronic equipment and storage medium
By using a centralized gateway to monitor and trigger circuit breakers in real time during the ECU flashing process, the problem of vehicle communication paralysis caused by ECU flashing anomalies was solved, ensuring the safe operation of critical systems and the stability of the flashing process.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NANCHANG XINGWEI SOFTWARE DEVELOPMENT CO LTD
- Filing Date
- 2025-12-31
- Publication Date
- 2026-05-12
AI Technical Summary
An abnormal handling mechanism in the existing electronic control unit (ECU) flashing process can cause the vehicle's communication network to fail, posing a risk to the functional safety of critical systems.
The ECU flashing process is monitored in real time through a centralized gateway, the risk level of flashing is assessed, and circuit breaker measures are implemented, including cutting off external diagnostic connections and sending safe exit commands, to prevent ECU reset or bus shutdown.
It effectively prevented the vehicle's communication bus from failing, ensuring the continuous normal operation of critical systems such as power and braking, and improving the safety and stability of the flashing process.
Smart Images

Figure CN122019253A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of risk management technology for flashing electronic control units, and in particular to a method, apparatus, electronic device, and storage medium for risk management of flashing electronic control units. Background Technology
[0002] With the development of vehicle intelligence, ECU (Electronic Control Unit) software rewriting is becoming increasingly frequent. Existing fault handling mechanisms in the rewriting process have serious flaws: when a rewriting failure occurs, the system typically can only rely on the target ECU to perform a hardware reset or put it into a bus-off state to interrupt communication. This simplistic and crude approach can paralyze the bus segment where the ECU resides and even the entire communication network, causing the normal message transmission of critical systems such as power and braking to be blocked, leading to vehicle-wide functional safety risks. Summary of the Invention
[0003] Therefore, it is necessary to address the existing problem of risk management for flashing electronic control units by proposing a method, device, electronic equipment, and storage medium for risk management of flashing electronic control units.
[0004] Firstly, this application provides a method for controlling the risk of flashing an electronic control unit, the method comprising: After the flashing session of the electronic control unit is established, the flashing process is monitored in real time. Based on the aforementioned real-time monitoring, it is determined whether there is a risk of data rewriting. If there is a risk of flashing, the flashing process will be circuit-broken through a centralized gateway.
[0005] Furthermore, the step of real-time monitoring of the writing process includes: The centralized gateway periodically sends status read requests to the electronic control unit to obtain at least one of its hardware temperature parameters; wherein, the hardware temperature parameter includes at least one of chip junction temperature, circuit board temperature, or ambient temperature; The result of the status read request is used as the monitoring data for the real-time monitoring.
[0006] Furthermore, the step of real-time monitoring of the writing process includes: The centralized gateway performs a validity check on the target address in the data writing request; wherein, the validity check includes determining whether the target address is within a preset valid address range of the electronic control unit memory to be written. The result of the legality verification is used as the monitoring data for real-time monitoring.
[0007] Furthermore, the step of circuit breaking during the flashing process if a risk of rewriting exists includes: Assess the risk level of the aforementioned write risk; The corresponding circuit breaker mechanism is determined based on the risk level: The circuit breaker mechanism controls the corresponding data processing unit to perform circuit breaker processing.
[0008] Furthermore, the step of assessing the risk level of the write risk includes: Determine whether an illegal target address is detected, or the hardware temperature parameter exceeds the first temperature threshold, or the communication connection with the diagnostic device is abnormal; If so, it is classified as a high-risk level; If not, then it is detected whether the hardware temperature parameter exceeds the second temperature threshold; wherein the second temperature threshold is less than the first temperature threshold; If so, it is classified as a medium-risk level.
[0009] Furthermore, the step of obtaining the corresponding circuit breaker mechanism based on the risk level includes: When the risk level is determined to be high risk, the corresponding first circuit breaker mechanism is obtained; wherein, the first circuit breaker mechanism includes: the centralized gateway disconnecting the current communication connection with the external diagnostic device and sending an instruction to the electronic control unit being flashed to safely exit the flashing session; When the risk level is determined to be medium risk, the corresponding second circuit breaker mechanism is obtained, wherein the second circuit breaker mechanism includes: the centralized gateway suspending the forwarding of data and generating alarm information.
[0010] Furthermore, after the step of controlling the corresponding data processing unit to perform circuit breaker processing according to the circuit breaker mechanism, the method further includes: Continuously monitor whether the conditions for triggering the medium-risk level have been eliminated; If the determination condition is eliminated, the centralized gateway is controlled to resume forwarding and writing data; wherein, the resumed forwarding and writing data means resuming the interrupted transmission from the position where forwarding and writing data was paused.
[0011] Secondly, this application provides a device for controlling the risk of rewriting electronic control units, the device comprising: The monitoring module is used to monitor the flashing process in real time after the flashing session of the electronic control unit is established. The judgment module is used to determine whether there is a risk of flashing or rewriting based on the real-time monitoring. The circuit breaker module is used to interrupt the flashing process through a centralized gateway if there is a risk of flashing.
[0012] Thirdly, this application provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor performs the following steps: After the flashing session of the electronic control unit is established, the flashing process is monitored in real time. Based on the aforementioned real-time monitoring, it is determined whether there is a risk of data rewriting. If there is a risk of flashing, the flashing process will be circuit-broken through a centralized gateway.
[0013] Fourthly, this application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform the following steps: After the flashing session of the electronic control unit is established, the flashing process is monitored in real time. Based on the aforementioned real-time monitoring, it is determined whether there is a risk of data rewriting. If there is a risk of flashing, the flashing process will be circuit-broken through a centralized gateway.
[0014] The beneficial effects of this invention are as follows: the authority to handle flashing anomalies is moved from a single electronic control unit to a centralized gateway. When a risk is detected, the gateway can implement partial circuit breaking by precisely cutting off external diagnostic connections and sending a safe exit command without triggering the target electronic control unit to reset or enter a bus shutdown state. This avoids the risk of paralysis of the entire vehicle communication bus caused by traditional methods and effectively ensures the continuous normal operation of critical systems such as power and braking. Attached Figure Description
[0015] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0016] in: Figure 1 This is an application environment diagram of the electronic control unit flashing risk control method in one embodiment; Figure 2 This is a flowchart of a method for controlling the risk of flashing an electronic control unit in one embodiment; Figure 3 This is a structural block diagram of the electronic control unit's flashing risk control device in one embodiment; Figure 4 This is a structural block diagram of an electronic device in one embodiment. Detailed Implementation
[0017] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0018] Figure 1 This is a diagram illustrating the application environment for risk management of electronic control unit (ECU) flashing in one embodiment. (Refer to...) Figure 1 The method for controlling the flashing risk of an electronic control unit (ECU) is applied to an ECU flashing risk control system. This system includes a terminal 110 and a server 120. The terminal 110 and server 120 are connected via a network. The terminal 110 can be a desktop terminal or a mobile terminal; the mobile terminal can be at least one of a mobile phone, tablet, or laptop. The server 120 can be a standalone server or a server cluster consisting of multiple servers.
[0019] like Figure 2 As shown, in one embodiment, a method for managing the risk of flashing an electronic control unit (ECU) is provided. This method is executed through an in-vehicle network architecture with a centralized gateway deployed. The specific steps of this method for managing the risk of flashing an ECU include: S1: After the flashing session of the electronic control unit is established, the flashing process is monitored in real time. S2: Determine whether there is a risk of flashing / writing based on the real-time monitoring; S3: If there is a risk of flashing, the flashing process will be circuit-broken through a centralized gateway.
[0020] As described in step S1 above, after the electronic control unit (ECU) flashing session is established, the external device establishes a physical connection with the vehicle's Ethernet via the OBD interface or wireless connection, and then sends a route activation request (DoIPRouting Activation Request) to the vehicle's DoIP gateway. This request carries the external device's logical address (e.g., 0x0E80) and authentication credentials (such as a digital certificate or token) for authentication. After verifying the credentials, the vehicle's DoIP (Diagnostic over Internet Protocol) gateway successfully establishes a TCP (Transmission Control Protocol) connection with the external device on port 13400, thus entering the flashing session. Specifically, this refers to a special, high-privilege diagnostic operation mode that the ECU enters to receive and write new software / firmware data, allowing diagnostic message forwarding. This state is considered the completion of the flashing session. After the flashing session begins, through the vehicle network architecture with a centralized gateway deployed, the centralized gateway plays a monitoring role throughout the flashing process, responsible for monitoring and managing all diagnostic data packets flowing through its interface. The monitoring content mainly includes the legality of the data being flashed, the integrity of the data transmission, and the communication status with the target ECU (Electronic Control Unit).
[0021] Specifically, real-time monitoring includes verifying the legitimacy of the target address and data content in the flashing request. This typically involves reading and verifying the memory mapping of the target ECU. Furthermore, the centralized gateway can monitor information such as the target ECU's temperature, receiving status, and bus status through its built-in monitoring module. This multi-dimensional monitoring mechanism can not only promptly detect potential problems, such as whether the target address is out of range or whether data integrity is compromised, but also detect anomalies such as overheating during the flashing process. Through real-time monitoring, the centralized gateway instantly aggregates data and generates visualized status updates, enabling accurate judgments during subsequent risk assessments.
[0022] As described in step S2 above, based on the real-time monitoring, a comprehensive analysis is performed on the monitoring results to determine whether there is a risk in the current flashing process. Specific risk factors include: whether the target address of the flashing data is legal, whether the ECU's operating status is normal, and whether its temperature exceeds a safety threshold. Specifically, the risk assessment module evaluates this monitoring data according to set logical rules. First, the module checks the address information in the flashing request to confirm whether the target address is within the legal address range of the target ECU. If the target address is found to be outside the range, the system immediately marks the flashing request as high-risk. Furthermore, if the real-time monitoring shows that the core temperature of the ECU exceeds a set safety threshold, it will also be assessed as high-risk.
[0023] As described in step S3 above, if a flashing risk exists, the flashing process is interrupted via a centralized gateway. The main purpose of the circuit breaker is to safely interrupt the risky flashing process without affecting the normal operation of the electronic control unit, thus preventing functional safety hazards caused by data errors or hardware failures. The specific implementation steps of the circuit breaker include: First, the centralized gateway disconnects the communication connection with external diagnostic equipment, thereby preventing any continued flashing requests or data from affecting the current flashing session. Simultaneously, the system sends a safety command conforming to the Unified Diagnostic Services (UDS) protocol to the target ECU, requiring it to safely exit the current programming session. Although the flashing process is interrupted, the ECU remains in a stable state, preventing a Bus-Off state caused by unexpected restarts or failures. After the circuit breaker is completed, the system records a detailed log of the event, including the time, type, and temperature reading of the risk, for subsequent analysis and tracking.
[0024] In one embodiment, step S1, which involves real-time monitoring of the writing process, includes: S101: Through the centralized gateway, periodically send status read requests to the electronic control unit to obtain at least one of its hardware temperature parameters; wherein, the hardware temperature parameter includes at least one of chip junction temperature, circuit board temperature or ambient temperature; S102: Use the result of the status read request as the monitoring data for the real-time monitoring.
[0025] As described in step S101 above, the centralized gateway periodically sends status read requests to the electronic control unit (ECU) to obtain at least one hardware temperature parameter. This hardware temperature parameter includes at least one of the following: chip junction temperature, circuit board temperature, or ambient temperature. The centralized gateway periodically sends status read requests to the target ECU to monitor its hardware temperature parameters in real time, ensuring the safety of the flashing process. Specifically, the periodic sending of status read requests can be set to a fixed time interval, such as every 2 seconds or 5 seconds. For each request, the ECU returns its current temperature parameters, and the centralized gateway integrates this data into the monitoring system. The obtained hardware temperature parameters include, but are not limited to, chip junction temperature, circuit board temperature, and ambient temperature. Chip junction temperature typically refers to the operating temperature of the chip inside the ECU, while circuit board temperature reflects the thermal state of the entire circuit board, and ambient temperature is the temperature within the space where the ECU is located. By monitoring these temperature parameters, the system can identify overheating risks early, thereby avoiding hardware damage or functional failure due to abnormal temperatures during the flashing process and ensuring the overall safety of the vehicle.
[0026] As described in step S102 above, the results of the status read requests are used as the monitoring data for real-time monitoring. The centralized gateway processes the results of all status read requests received in step S101 and records them as the monitoring data required by the real-time monitoring system. First, after receiving the results of the status read requests, the centralized gateway parses these results, extracts temperature parameters, and converts them into a meaningful data format. Each temperature parameter may include the current value, unit (e.g., Celsius or Fahrenheit), and timestamp information to accurately reflect status changes in subsequent data processing and monitoring analysis. Second, this monitoring data is updated in real-time to the monitoring system's database or data cache to ensure absolute real-time information. By comparing temperature change trends, the system can achieve more intelligent risk assessment to determine whether the current operating status is within the normal range.
[0027] In one embodiment, step S1, which involves real-time monitoring of the writing process, includes: S111: The centralized gateway performs a validity check on the target address in the data writing request; wherein, the validity check includes determining whether the target address is within the preset valid address range of the electronic control unit memory to be written; S112: Use the result of the legality verification as the monitoring data for the real-time monitoring.
[0028] As described in step S111 above, the centralized gateway performs a validity check on the target address in the flashing data write request. This validity check includes determining whether the target address is within a preset valid address range of the electronic control unit (ECU) memory being flashed. When the ECU performs a flashing operation, the first step is to verify the validity of the target address to be written. This is a crucial step to ensure normal system operation and data accuracy, aiming to prevent potential risks and damage to the ECU from erroneous data writing. Specifically, the centralized gateway verifies the target address of the flashing data according to a preset address range. This address range is typically defined as the valid address area within the ECU memory, including all valid writable addresses and their corresponding storage functions. During the verification process, if the target address is within the valid address range, the system will continue with subsequent operations; if the target address exceeds the valid range, the system will determine the request as invalid and generate a warning promptly. This validity verification mechanism not only effectively prevents data write failures caused by address errors, but also avoids interference and damage to critical ECU functions. Furthermore, this process provides fundamental support for subsequent data monitoring, helping to comprehensively assess the risks of the entire flashing process, promptly detect and handle illegal address requests, significantly reducing operational risks and improving the success rate and system security of flashing. Specifically, each microcontroller (MCU) datasheet specifies the physical address mapping of its on-chip Flash, RAM, and other memories. For example, if the main program Flash of a certain MCU model starts at 0x0800 0000 and is 1MB in size, then its valid physical address range is [0x0800 0000, 0x080F FFFF]. Any address request outside this range cannot be executed at the hardware level.
[0029] After the flashing process begins, the cloud sends a series of 0x36 (transfer data) requests to the BDCU through the gateway.
[0030] Example of a valid request: A request contains address 0x0800 A110 and the corresponding data. Gateway verification: 0x0800 4000 <= 0x0800 A110 <= 0x0807 FFFF, the result is valid, and the request is forwarded normally.
[0031] Example of an illegal request (risk trigger): Due to a cloud packaging error or communication tampering, a request contains the address 0x0800 0100. Gateway verification: This address is less than 0x0800 4000, falls within the Bootloader region, and is not within the legitimate scope of this application flashing. The monitoring module immediately assesses this event as high risk (because it may damage the Bootloader and brick the ECU). Subsequently, the circuit breaker execution module activates the first circuit breaker mechanism: immediately severing the TCP connection with the cloud and sending a 0x10 01 instruction to the BDCU, causing it to safely exit the programming session, thereby protecting the Bootloader from being overwritten.
[0032] As described in step S112 above, the result of the legality verification is used as the monitoring data for real-time monitoring. The centralized gateway processes the results of the legality verification and records these results as real-time monitoring data. Specifically, after the centralized gateway completes the legality verification of the target address, it needs to incorporate the verification result ("legal" or "illegal") into the real-time monitoring data. For example, the result can be stored in a monitoring database or memory, along with a timestamp and corresponding write request information, to facilitate subsequent data tracking and processing. By recording this monitoring data, the system can quickly locate the source of the problem when a risk occurs and provide technical support personnel with detailed event logs. This process not only enhances the traceability of the write operation but also enables effective analysis while ensuring data integrity in the event of a fault or anomaly, further improving the stability and security of the overall write process.
[0033] In one embodiment, step S3, which involves circuit breaking the flashing process if there is a risk of flashing, includes: S301: Assess the risk level of the aforementioned write risk; S302: Obtain the corresponding circuit breaker mechanism based on the risk level: S303: Control the corresponding data processing unit to perform circuit breaking processing according to the circuit breaking mechanism.
[0034] As described in step S301 above, the risk level of the flashing process is assessed. The centralized gateway or domain controller assesses the risk level detected during the flashing process based on real-time monitoring results. The risk level is typically assessed comprehensively based on multiple factors, including the legality of the flashing data, the status of the target ECU, and the monitored hardware temperature. Each risk level can be assigned specific risks by relevant personnel. Specifically, the risk level determination mechanism usually involves comparing different monitoring parameters with preset thresholds. For example, if monitoring reveals that the target address of the flashing request is not within a legal range, the system may immediately assess the risk as "high risk." Similarly, if the temperature of the target ECU exceeds a set safety threshold, it will also be assessed as "high risk." Conversely, if all parameters are within acceptable ranges, but the temperature is close to a preset upper limit or there are other minor anomalies, it can be assessed as "medium risk." In a specific embodiment, during implementation, the risk decision module built into the vehicle Ethernet diagnostic gateway (or domain controller) makes judgments based on a configurable security policy library. This policy library defines multi-dimensional risk detection items, precise trigger thresholds, corresponding risk levels, and circuit breaker actions. For high-risk events that directly jeopardize ECU functional safety or successful flashing, the first circuit breaker mechanism is immediately executed (severing external connections and sending a safe exit command). Examples include: 1) Illegal address writing: The target address in the diagnostic write request exceeds the preset legal address range of the target ECU; 2) Diagnostic device IP address jump: The source IP of the current communication device is inconsistent with the authorized IP recorded during route activation; 3) Abnormal communication continuity: Continuous request timeouts or communication stagnation without any response occur; 4) Data integrity corruption: The checksum (e.g., CRC32) of the transmitted data block is incorrect; 5) Hardware overheating risk: The ECU chip junction temperature or circuit board temperature exceeds the set safety limit (e.g., core temperature ≥115°C or board temperature ≥105°C). For medium-risk states that indicate potential risks but have not yet reached an emergency level, the system executes a more flexible second circuit breaker mechanism (pausing flashing, initiating mitigation measures, and issuing an alarm). For example: Excessively high ambient temperature (e.g., ≥75°C) may affect the long-term stability of the ECU. In this case, the data stream will be paused, and the cooling system will be automatically activated and the user will be notified. Resumption of transmission after the risk conditions are eliminated is supported.
[0035] As described in step S302 above, the corresponding circuit breaker mechanism is obtained based on the risk level. After identifying the risk level, the corresponding circuit breaker mechanism is selected and obtained according to this level. The core function of this mechanism is to take a series of actions to ensure the safety and stability of the electronic control unit (ECU) during the flashing process, based on the specific situation where the risk has been assessed. Specifically, the system has multiple preset circuit breaker mechanisms to adapt to different levels of risk response strategies. For example, when the risk is assessed as "high risk", the required circuit breaker mechanism may include immediately cutting off communication with external diagnostic equipment and sending a command to the target ECU to safely exit the flashing session. Conversely, for "medium risk" situations, the circuit breaker mechanism may not perform such extreme operations, but instead choose to suspend the flashing operation and issue an alarm message to facilitate manual intervention by technicians. By flexibly selecting different circuit breaker mechanisms, the system can comprehensively consider the risk handling related to vehicle functional safety while protecting performance, thereby improving overall safety and reliability.
[0036] As described in step S303 above, the corresponding data processing unit is controlled to perform circuit breaking according to the circuit breaking mechanism. The centralized gateway performs actual circuit breaking on the corresponding data processing unit according to the selected circuit breaking mechanism. If the risk is determined to be "high risk", the centralized gateway will cut off all communication connections with external diagnostic equipment. This cutting-off process ensures that any further flashing data or commands cannot affect the target ECU, preventing system failures caused by erroneous data or commands. At the same time, the gateway will also send an appropriate instruction to the target ECU according to the UDS (Unified Diagnostic Service) specification, instructing it to safely exit the current flashing session. This control can be achieved by directly sending instructions or by multiplexing data channels. If the risk is "medium risk", the centralized gateway may suspend data transmission according to the circuit breaking mechanism and notify the operator of the risk status by generating an alarm. This not only helps operators to assess and adjust the problem in a timely manner, but also maintains the normal operation of the target ECU to a certain extent, avoiding affecting the function of the entire vehicle. By implementing the circuit breaker mechanism, the system can effectively control the risks to a minimum, greatly improving the safety, stability and controllability of the entire flashing process, thereby ensuring the vehicle's functional safety when the electronic control unit is flashed.
[0037] In one embodiment, step S301 of assessing the risk level of the write risk includes: S3011: Determine whether an illegal target address is detected, or the hardware temperature parameter exceeds the first temperature threshold, or the communication connection with the diagnostic device is abnormal; S3012: If so, it is determined to be a high-risk level; S3013: If not, then it is detected whether the hardware temperature parameter exceeds the second temperature threshold; wherein the second temperature threshold is less than the first temperature threshold. S3014: If so, it is determined to be a medium-risk level.
[0038] As described in step S3011 above, the system determines whether an illegal target address, hardware temperature parameters exceeding a first temperature threshold, or abnormal communication with the diagnostic device is detected. The centralized gateway first needs to comprehensively evaluate the real-time monitoring data to determine if the current flashing process poses a risk. The key lies in several monitored parameters. First, the system checks whether the target address of the flashing data is legal. By comparing it with the preset legal address range of the ECU memory, it checks whether the target address is within the valid read / write range. If the target address is found to be illegal, the flashing process will be immediately deemed high-risk, as this could lead to data corruption or control unit malfunction. Then, the system monitors the hardware temperature parameters, especially checking whether the chip junction temperature and circuit board temperature exceed the first temperature threshold. If the temperature parameters exceed this threshold, this will also lead to a high-risk assessment of the flashing process, as excessively high temperatures can threaten the normal operation of electronic components and may even cause hardware damage. In addition, the system also needs to check the communication connection status with the external diagnostic device. If abnormal communication occurs during the flashing process, such as continuous timeouts or no response, this will also be considered a high-risk indicator.
[0039] As described in step S3012 above, if any of the following conditions are detected: illegal target address, hardware temperature parameters exceeding the first temperature threshold, or abnormal communication connection, the system will immediately determine the flashing process as "high-risk." When the system determines it to be high-risk, the centralized gateway will take corresponding actions, such as proactively issuing an alarm to inform the operator of the current risk status. Furthermore, based on the high-risk determination, the system will initiate a circuit breaker procedure to disconnect from external diagnostic tools, ensuring the flashing operation terminates immediately and preventing further damage to the ECU. Effective assessment and response to high-risk conditions not only protects the target ECU from damage caused by data errors but also ensures the safety of other critical vehicle functions (such as power and braking). The setting of the first temperature threshold is related to the corresponding hardware. For example, if detecting the PCB board temperature, the corresponding first temperature threshold can be set to 105℃; if it is the ECU core temperature, the corresponding first temperature threshold can be set to 115℃. Specifically, both the first and second temperature thresholds are values set by relevant personnel based on the temperature values of the corresponding hardware.
[0040] As described in step S3013 above, if the judgment result indicates that the current flashing process is not assessed as high-risk, the system will continue to monitor hardware temperature parameters to determine if a second temperature threshold is exceeded. The second temperature threshold must be set lower than the previously defined first temperature threshold. This setting allows for more precise risk quantification. When the hardware temperature exceeds the second threshold, the system classifies this state as "medium-risk." The significance of this setting is that, through a tight monitoring and access mechanism, operators can be promptly notified to prevent unexpected escalation situations, such as hardware damage caused by high temperatures. The setting of the second temperature threshold is related to the corresponding hardware; for example, it can be set to 100°C. In some embodiments, it can also be determined by detecting the ambient temperature; for example, an ambient temperature greater than 75°C is considered medium-risk. Medium-risk means that the system is on the edge of normal operation, and there is a risk of failure. If not handled promptly, this medium-risk state may escalate to high-risk in the future, leading to flashing failure or device damage. At this stage, the system needs to prepare countermeasures for medium-risk situations, typically including alarm registration and data stream suspension, so that technicians can intervene in a timely manner to ensure the smooth completion of the flashing process.
[0041] As described in step S3014 above, if it is determined that the monitored hardware temperature parameter does indeed exceed the set second temperature threshold, the system will assess the flashing process as a "medium-risk level." This assessment is to ensure the safety of the ECU during flashing and to avoid equipment damage or functional failure due to overheating. By promptly determining the resulting medium-risk level, the system can provide operators with sufficient information so that they can assess the situation in a timely manner and take appropriate remedial measures. Identifying intermediate states also helps to prevent the risk from escalating, ensuring the safe operation of the entire vehicle system.
[0042] In one embodiment, step S302 of obtaining the corresponding circuit breaker mechanism based on the risk level includes: S3021: When the risk level is determined to be high risk, the corresponding first circuit breaker mechanism is obtained; wherein, the first circuit breaker mechanism includes: the centralized gateway disconnecting the current communication connection with the external diagnostic device and sending an instruction to the electronic control unit being flashed to safely exit the flashing session; S3022: When the risk level is determined to be medium risk, the corresponding second circuit breaker mechanism is obtained, wherein the second circuit breaker mechanism includes: the centralized gateway suspending the forwarding of data and generating alarm information.
[0043] As described in step S3021 above, when the risk level is determined to be high risk, the corresponding first circuit breaker mechanism is activated. This first circuit breaker mechanism includes: the centralized gateway disconnecting the current communication connection with the external diagnostic device and sending a command to the ECU being flashed to safely exit the flashing session. When the flashing process risk level is determined to be "high risk" through the preceding evaluation steps, the system immediately activates the corresponding first circuit breaker mechanism. The specific implementation of the first circuit breaker mechanism includes two main operations: First, the centralized gateway disconnects the current communication connection with the external diagnostic device. This disconnection ensures that no further data requests or commands can be transmitted, thereby avoiding any data errors or system failures caused by continued flashing. This proactive disconnection strategy reflects the system's forward-looking management of potential risks, aiming to ensure the stable operation of the system. Second, the centralized gateway also sends a safe exit command conforming to the Unified Diagnostic Service (UDS) protocol to the ECU being flashed. This command aims to notify the target ECU to safely exit the flashing session, ensuring it returns to normal operating mode rather than remaining in a state that could cause failure during the process. Through this precise control, the entire process not only avoids hardware damage caused by flashing failures, but also prevents functional failures caused by high temperatures or data errors, providing important protection for the functional safety of the vehicle.
[0044] As described in step S3022 above, when the risk level is determined to be medium risk, a corresponding second circuit breaker mechanism is activated. This second circuit breaker mechanism includes: the centralized gateway suspending the forwarding of flashing data and generating an alarm message. When the assessment finds the risk level to be "medium risk," the system will activate the corresponding second circuit breaker mechanism. The purpose of this mechanism is to prevent potential future failures by taking appropriate measures before the risk deteriorates to high risk. Specifically, the centralized gateway first suspends all ongoing flashing data forwarding, actively stopping any data flow to the target ECU, ensuring the integrity and security of the flashing process without complete interruption. Then, an alarm message is generated to alert the operator to the current medium risk status. This alarm message not only helps operators become aware of potential problems but also provides necessary contextual information to help them make appropriate decisions or take further measures. This medium-risk circuit breaker mechanism achieves flexible and gradual risk control, without affecting the normal operation of the ECU, while providing operators with information for decision-making, thereby enabling them to take measures to prevent risk escalation. This emphasis on flexibility ensures that equipment remains operational in low-risk situations while guaranteeing the functional safety of the entire vehicle system. Effective monitoring and management improve the success rate of flashing operations and reduce malfunctions that may result from unaddressed risks.
[0045] In one embodiment, after step S303, which involves controlling the corresponding data processing unit to perform circuit breaker processing according to the circuit breaker mechanism, the method further includes: S3041: Continuously monitor whether the conditions for triggering the medium-risk level have been eliminated; S3042: If the determination condition is eliminated, control the centralized gateway to resume forwarding and writing data; wherein, the resumed forwarding and writing data is a breakpoint resumption transmission that continues forwarding from the position where forwarding and writing data was paused.
[0046] As described in step S3041 above, continuous monitoring of the conditions that previously led to the flashing process being assessed as medium risk is crucial for ensuring that system risks can be effectively controlled and ultimately eliminated. The key is to confirm whether the medium-risk status can be resolved through continuous data collection and analysis. Specifically, the centralized gateway periodically accesses relevant monitoring data and checks previously set monitoring parameters, such as whether the previously monitored hardware temperature has dropped below a safe threshold or whether communication with external diagnostic devices has returned to normal. In this way, the system can obtain the current status in real time and flexibly respond to changes in risk. Specifically, monitoring needs to be performed based on the corresponding risk. If it's a communication anomaly, and no timeout is detected for 10 consecutive seconds, the Tester re-initiates a legitimate connection. If it's a temperature exceeding the limit, and the ECU core temperature is detected as <105℃ and the PCB board temperature as <95℃ for 30 seconds, it's considered back to normal. If it's an illegal operation, and a legitimate device is detected (IP + certificate matching), it's considered back to normal, and a reconnection is initiated. If it's a network anomaly, and the abnormal traffic disappears and the IP stabilizes, it's considered back to normal. This process can also include intelligent analysis of monitoring data, and even the introduction of machine learning algorithms to improve the accuracy of judgments. For example, if the temperature is detected to have dropped to a safe value, and then the monitored data is compared with historical data to form a trend analysis, the system can use this information to infer whether the risk has been eliminated. Continuous monitoring not only ensures that operators can understand the dynamics of the risk in a timely manner, but also provides data support for the smooth execution of subsequent recovery operations, thereby ensuring the safety and stability of the write process.
[0047] As described in step S3042 above, if the judgment condition is eliminated, the centralized gateway is controlled to resume forwarding the flashing data. The resumed forwarding of flashing data refers to resuming the transmission from the point where forwarding was paused. If monitoring confirms that the judgment condition indicating a risk has been eliminated, the centralized gateway will control the continued forwarding of flashing data, restarting the flashing process to ensure the ECU continues to receive the latest program updates. Specifically, the resumed forwarding data will be based on the data status recorded by the system during the pause, allowing the flashing to continue from the "breakpoint" upon resumption. This design completely avoids the time and resource waste caused by starting the data flashing process from scratch, improving efficiency. During the resumed forwarding, the system strictly adheres to the UDS (Unified Diagnostic Service) protocol to ensure all operations are legal and secure. Furthermore, during resumed forwarding, the system will alternately perform status checks to ensure the flashing process can proceed smoothly under the specified state, guaranteeing the reliability of the final flashing result. This recovery mechanism reflects the intelligence of the entire system, enabling flexible responses to various risk states under safe conditions, achieving efficient control of the flashing process, and laying a solid foundation for subsequent fault handling. Intelligent monitoring and recovery ensure the proper functioning of the electronic control unit, thereby guaranteeing the overall safety of the vehicle.
[0048] After the flashing operation is successfully completed, the following standard closing procedure is executed: First, a routine compliant with the UDS protocol is called to perform a programming integrity verification; then, an ECU reset command is sent to cause the electronic control unit to perform a soft reboot to activate the newly flashed software; finally, the system will disable the previously enabled fuse monitoring function module and release the computing and storage resources it occupies.
[0049] In a specific embodiment, let's take "remote OTA (Over-The-Air) upgrade of a certain ECU (Electronic Control Unit)" as an example: S10: The vehicle establishes a secure connection with the cloud server via cellular network and other communication modules, and begins downloading the new software data package for the target ECU. The DoIP gateway, as the central hub of the in-vehicle network, establishes and maintains the diagnostic communication link (DoIP session based on TCP connection) with the cloud server, and is also responsible for routing the received flashing data and instructions to the target ECU.
[0050] S20: During data transmission and flashing, the global monitoring module built into the DoIP gateway continues to operate. In addition to verifying data packet integrity, this module periodically (e.g., once per second) sends a diagnostic request (UDS service 0x22) to the target ECU via the vehicle's CAN bus to read key hardware status parameters such as its chip junction temperature. In this embodiment, it is assumed that the vehicle was previously parked under direct sunlight for an extended period, resulting in a high initial ECU temperature. The monitoring module continuously reads that the target ECU's chip junction temperature continues to rise, reaching 116°C.
[0051] S30: The risk decision module compares the read temperature value of 116°C with a preset risk threshold library. According to the preset strategy, a chip junction temperature exceeding 115°C is defined as the first temperature threshold, and the triggered risk event is classified as "high risk". This determination is based on the fact that excessively high temperatures may directly lead to chip operation errors, memory write failures, or permanent hardware damage.
[0052] S40: When a high-risk condition is identified, the circuit breaker execution module immediately activates the first circuit breaker mechanism. Cut off external connection: The DoIP gateway actively disconnects the current TCP / IP socket connection with the cloud server, immediately stopping the inflow of all subsequent data at the network level.
[0053] Securely terminate the flashing session: Simultaneously, the gateway sends a UDS-compliant safety command (0x10 01) to the target ECU via the internal network (such as CAN FD), commanding it to securely exit the programming session and switch to the extended diagnostic session or the default session. This operation only exits the target ECU from flashing mode without triggering a hardware reset or bus shutdown.
[0054] Log and Alarm: The system generates a detailed safety log containing event time, temperature data, and actions taken, and stores it in non-volatile memory. Simultaneously, a notification is pushed to the user via the vehicle's human-machine interface (HMI): "Component temperature detected as too high; upgrade paused to ensure safety." S50: After the user moves the vehicle to a shady place or waits for a period of time, the ECU temperature gradually decreases due to natural cooling or the cooling system working. The DoIP gateway's monitoring module continuously monitors the temperature and finds that it has dropped to 100°C, which is below the preset second temperature threshold (e.g., 105°C, as a condition for removing "medium risk"). At this point, the user receives a prompt on the HMI indicating that the upgrade can continue, and clicks the "Continue Upgrade" button.
[0055] S60: After receiving the continue command: The gateway first verifies whether the current target ECU's status parameters, such as temperature, remain within a safe range.
[0056] After successful verification, the gateway re-establishes a secure DoIP connection with the cloud server.
[0057] By utilizing the breakpoint resume function supported by the flashing protocol itself, the gateway requests the server to continue transmission from the precise data packet position where the last data stream was interrupted, rather than restarting the entire upgrade process.
[0058] S70: The remaining data was successfully transmitted and written under secure monitoring. Finally, the gateway guided the entire process to complete the final integrity verification (0x31 service) and ECU soft reset (0x11 01 service) to activate the new software. Throughout the process, network communication of the vehicle's drive system, braking system, and other critical functional domains was not interfered with, and the vehicle remained in a normal driving state.
[0059] Reference Figure 3 The present invention also provides a device for controlling the risk of rewriting electronic control units, the device comprising: The monitoring module 902 is used to monitor the flashing process in real time after the flashing session of the electronic control unit is established. The judgment module 904 is used to determine whether there is a risk of flashing or rewriting based on the real-time monitoring. The circuit breaker module 906 is used to interrupt the flashing process through a centralized gateway if there is a risk of flashing.
[0060] In one embodiment, the monitoring module 902 includes: The status read request sending submodule is used to periodically send status read requests to the electronic control unit through the centralized gateway to obtain at least one of its hardware temperature parameters; wherein, the hardware temperature parameter includes at least one of chip junction temperature, circuit board temperature or ambient temperature; The monitoring data first tagging submodule is used to take the result of the status read request as the monitoring data of the real-time monitoring.
[0061] In one embodiment, the monitoring module 902 includes: The legality verification submodule is used to verify the legality of the target address in the write request for flashing data through the centralized gateway; wherein, the legality verification includes determining whether the target address is within the preset legal address range of the electronic control unit memory to be flashed; The monitoring data second tagging submodule is used to use the result of the legality verification as the monitoring data of the real-time monitoring.
[0062] In one embodiment, the fuse module 906 includes: The risk level assessment submodule is used to assess the risk level of the write / flash risk; The circuit breaker mechanism acquisition submodule is used to acquire the corresponding circuit breaker mechanism based on the risk level. The circuit breaker processing submodule is used to control the corresponding data processing unit to perform circuit breaker processing according to the circuit breaker mechanism.
[0063] In one embodiment, the risk level assessment submodule includes: The first risk assessment unit determines whether the target address is illegal, the hardware temperature parameter exceeds the first temperature threshold, or the communication connection with the diagnostic device is abnormal. If the first judgment unit detects that the target address is illegal, the hardware temperature parameter exceeds the first temperature threshold, or the communication connection with the diagnostic device is abnormal, it will determine it as a high-risk level. The second risk assessment unit, if it does not detect an illegal target address, or if the hardware temperature parameter exceeds the first temperature threshold, or if the communication connection with the diagnostic device is abnormal, then it detects whether the hardware temperature parameter exceeds the second temperature threshold; wherein, the second temperature threshold is less than the first temperature threshold. The second determination unit determines the risk level as medium if it detects that the hardware temperature parameter exceeds the second temperature threshold.
[0064] In one embodiment, the circuit breaker mechanism acquisition submodule includes: The first circuit breaker mechanism acquisition unit is used to acquire the corresponding first circuit breaker mechanism when the risk level is determined to be high risk; wherein, the first circuit breaker mechanism includes: the centralized gateway cutting off the current communication connection with the external diagnostic device and sending an instruction to the electronic control unit being flashed to safely exit the flashing session; The second circuit breaker mechanism acquisition unit is used to acquire the corresponding second circuit breaker mechanism when the risk level is determined to be medium risk. The second circuit breaker mechanism includes: the centralized gateway suspending the forwarding of data and generating alarm information.
[0065] In one embodiment, the fuse module 906 further includes: The monitoring submodule is used to continuously monitor whether the conditions that trigger the medium-risk level have been eliminated; The recovery submodule is used to control the centralized gateway to resume forwarding and writing data if the determination condition is eliminated; wherein, the resumed forwarding and writing data is a breakpoint resumption of forwarding from the position where forwarding and writing data was paused.
[0066] Figure 4 An internal structural diagram of an electronic device in one embodiment is shown. This electronic device can specifically be a terminal or a server, and more specifically, a computer device. Figure 4As shown, the electronic device includes a processor, a memory, and a network interface connected via a system bus. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and may also store a computer program. When executed by the processor, this computer program enables the processor to implement a method for managing the risk of flashing the electronic control unit. The internal memory may also store a computer program, which, when executed by the processor, enables the processor to implement the method for managing the risk of flashing the electronic control unit. Those skilled in the art will understand that... Figure 4 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the electronic device to which the present application is applied. The specific electronic device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.
[0067] In one embodiment, an electronic device is provided, including a memory and a processor, the memory storing a computer program that, when executed by the processor, causes the processor to perform the following steps: After the flashing session of the electronic control unit is established, the flashing process is monitored in real time. Based on the aforementioned real-time monitoring, it is determined whether there is a risk of data rewriting. If there is a risk of flashing, the flashing process will be circuit-broken through a centralized gateway.
[0068] By moving the authority to handle flashing anomalies from individual electronic control units to a centralized gateway, the gateway can implement partial circuit breaking without triggering the target electronic control unit to reset or enter a bus shutdown state. This is achieved by precisely disconnecting external diagnostic connections and sending a safe exit command, thus avoiding the risk of paralyzing the entire vehicle communication bus caused by traditional methods and effectively ensuring the continuous normal operation of critical systems such as power and braking.
[0069] In one embodiment, a computer-readable storage medium is provided storing a computer program that, when executed by a processor, causes the processor to perform the following steps: After the flashing session of the electronic control unit is established, the flashing process is monitored in real time. Based on the aforementioned real-time monitoring, it is determined whether there is a risk of data rewriting. If there is a risk of flashing, the flashing process will be circuit-broken through a centralized gateway.
[0070] By moving the authority to handle flashing anomalies from individual electronic control units to a centralized gateway, the gateway can implement partial circuit breaking without triggering the target electronic control unit to reset or enter a bus shutdown state. This is achieved by precisely disconnecting external diagnostic connections and sending a safe exit command, thus avoiding the risk of paralyzing the entire vehicle communication bus caused by traditional methods and effectively ensuring the continuous normal operation of critical systems such as power and braking.
[0071] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments described above. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM), etc.
[0072] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0073] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.
Claims
1. A method for controlling the risk of rewriting electronic control units, characterized in that, The method includes: After the flashing session of the electronic control unit is established, the flashing process is monitored in real time. Based on the aforementioned real-time monitoring, it is determined whether there is a risk of data rewriting. If there is a risk of flashing, the flashing process will be circuit-broken through a centralized gateway.
2. The method for controlling the risk of flashing electronic control units according to claim 1, characterized in that, The steps for real-time monitoring of the writing process include: The centralized gateway periodically sends status read requests to the electronic control unit to obtain at least one of its hardware temperature parameters; wherein, the hardware temperature parameter includes at least one of chip junction temperature, circuit board temperature, or ambient temperature; The result of the status read request is used as the monitoring data for the real-time monitoring.
3. The method for controlling the risk of flashing / writing electronic control units according to claim 1, characterized in that, The steps for real-time monitoring of the writing process include: The centralized gateway performs a validity check on the target address in the data writing request; wherein, the validity check includes determining whether the target address is within a preset valid address range of the electronic control unit memory to be written. The result of the legality verification is used as the monitoring data for real-time monitoring.
4. The method for controlling the risk of rewriting electronic control units according to claim 1, characterized in that, The step of circuit breaking the flashing process if there is a risk of flashing includes: Assess the risk level of the aforementioned write risk; The corresponding circuit breaker mechanism is determined based on the risk level: The circuit breaker mechanism controls the corresponding data processing unit to perform circuit breaker processing.
5. The method for controlling the risk of rewriting electronic control units according to claim 4, characterized in that, The steps for assessing the risk level of the write risk include: Determine whether an illegal target address is detected, or the hardware temperature parameter exceeds the first temperature threshold, or the communication connection with the diagnostic device is abnormal; If so, it is classified as a high-risk level; If not, then it is detected whether the hardware temperature parameter exceeds the second temperature threshold; wherein the second temperature threshold is less than the first temperature threshold; If so, it is classified as a medium-risk level.
6. The method for controlling the risk of rewriting electronic control units according to claim 5, characterized in that, The step of obtaining the corresponding circuit breaker mechanism based on the risk level includes: When the risk level is determined to be high risk, the corresponding first circuit breaker mechanism is obtained; wherein, the first circuit breaker mechanism includes: the centralized gateway disconnecting the current communication connection with the external diagnostic device and sending an instruction to the electronic control unit being flashed to safely exit the flashing session; When the risk level is determined to be medium risk, the corresponding second circuit breaker mechanism is obtained, wherein the second circuit breaker mechanism includes: the centralized gateway suspending the forwarding of data and generating alarm information.
7. The method for controlling the risk of rewriting electronic control units according to claim 6, characterized in that, After the step of controlling the corresponding data processing unit to perform circuit breaking processing according to the circuit breaking mechanism, the method further includes: Continuously monitor whether the conditions for triggering the medium-risk level have been eliminated; If the determination condition is eliminated, the centralized gateway is controlled to resume forwarding and writing data; wherein, the resumed forwarding and writing data means resuming the interrupted transmission from the position where forwarding and writing data was paused.
8. A risk control device for flashing electronic control units, characterized in that, The device includes: The monitoring module is used to monitor the flashing process in real time after the flashing session of the electronic control unit is established. The judgment module is used to determine whether there is a risk of flashing or rewriting based on the real-time monitoring. The circuit breaker module is used to interrupt the flashing process through a centralized gateway if there is a risk of flashing.
9. A computer-readable storage medium, characterized in that, The device contains a computer program that, when executed by a processor, causes the processor to perform the steps of the flashing risk control method for the electronic control unit as described in any one of claims 1 to 7.
10. An electronic device, characterized in that, The device includes a memory and a processor, the memory storing a computer program that, when executed by the processor, causes the processor to perform the steps of the electronic control unit flashing risk control method as described in any one of claims 1 to 7.