Method for upgrading agricultural machinery system, upgrading device and intelligent driving system of agricultural machinery
By adopting a user-authorized configurable security upgrade strategy, combined with silent upgrade and boot push strategies, the security risks and compliance issues in agricultural machinery system upgrades have been resolved, enabling safe and compliant firmware updates and improving user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZOOMLION HEAVY MASCH CO LTD
- Filing Date
- 2026-02-03
- Publication Date
- 2026-06-05
AI Technical Summary
The existing agricultural machinery system upgrade logic fails to establish differentiated safety protection mechanisms for high-risk operation characteristics, posing safety hazards. Furthermore, the lack of user informed consent mechanisms leads to compliance disputes.
This paper provides a method for upgrading agricultural machinery systems. By using a user-authorized configurable and secure upgrade electronic control program strategy, adopting silent upgrade and power-on push strategies, and combining multi-terminal collaborative management, the upgrade is ensured to be carried out in a secure environment.
It improves the security and compliance of firmware updates in agricultural operation scenarios, enhances user experience, complies with functional safety standards in multiple countries, and implements a user-understandable security upgrade mechanism.
Smart Images

Figure CN122152592A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle-mounted online upgrade technology, specifically to an upgrade method and device for agricultural machinery systems, as well as an intelligent driving system for agricultural machinery. Background Technology
[0002] Currently, most mainstream agricultural machinery manufacturers' remote upgrade systems adopt a default silent mode. Once the system detects an available firmware update, it automatically triggers the download and installation process, typically without user confirmation or permission intervention before the upgrade. While this "system-driven" upgrade mechanism improves update efficiency, it has raised significant compliance controversies in the context of increasingly stringent regulations emphasizing "user informed consent" and "operational autonomy" in many countries worldwide. Especially in markets where some countries have introduced stricter standards with explicit requirements for the transparency and controllability of software changes, such default behavior may constitute a potential infringement on user rights.
[0003] Meanwhile, the operating environment of agricultural machinery is far more complex than that of passenger cars. Its system consists of multi-layered heterogeneous components, including vehicle-side control units, implement-side actuators (such as suspension controllers and power take-off shafts), and high-precision sensors. These components operate independently yet are interconnected. Even when the vehicle is stationary, the power take-off shaft may retain energy due to inertia or hydraulic residue, the engine may be idling, or the autopilot function may not be disengaged. Performing firmware updates under such unsafe conditions could lead to resource contention, communication interruptions, or control command conflicts, resulting in drift in operating accuracy, abnormal power output, or even mechanical damage, posing serious safety hazards.
[0004] Existing technical solutions mostly follow the upgrade logic of passenger cars and fail to establish differentiated safety protection mechanisms for the high-risk operation characteristics of agricultural machinery. There is an urgent need to build a more rigorous and refined upgrade control framework. Summary of the Invention
[0005] In view of this, and to address the shortcomings of the existing technology, the present invention provides an upgrade method, an upgrade device, and an intelligent driving system for agricultural machinery, which can significantly improve the security, compliance, and user experience of firmware updates in agricultural operation scenarios based on a user-authorized, configurable, and secure upgrade strategy for electronic control programs.
[0006] To achieve the above objectives, the present invention provides an upgrade method for an agricultural machinery system, the upgrade method comprising: issuing a silent upgrade authorization request when the agricultural machinery system is activated; enabling a configurable silent upgrade strategy in response to an authorization consent instruction; and enabling a power-on push upgrade strategy in response to an authorization rejection instruction.
[0007] Optionally, the silent upgrade strategy includes: in the startup state, automatically detecting whether an upgrade package for a specified module exists, wherein the specified module is system-recommended and / or autonomously configured, and includes at least two independently running storage areas; if the existence of the upgrade package for the specified module is detected and the current environment conforms to the security policy corresponding to the specified module, silently downloading the upgrade package to the non-running first storage area of the specified module, wherein the security policy is system-recommended and / or autonomously configured; silently installing and verifying the upgrade package in the first storage area to generate an update program; and automatically loading the update program from the first storage area when the specified module restarts.
[0008] Optionally, the security strategy includes one or more of the following judgment conditions: current network status, power-on operation time, autonomous driving usage, RTK positioning service usage status, breakpoint resume function, driver on-site status, whether the shift gear is in neutral (N), whether the vehicle is parked, working status, suspension position, cutter position, handrail position, seed insert position, engine speed, PTO speed, vehicle speed, and power supply.
[0009] Optionally, the setting module includes programs and / or firmware for the following components: vehicle infotainment system, controller, and sensors.
[0010] Optionally, the vehicle system includes one or more of the following: a multimodal communication management module, a multi-sensor fusion perception module, a steering control module, a configuration management module, a vehicle electronic control system management module, a human-machine interaction module, a safety strategy management module, a driving speed and steering control module, a tool task control module, and a vehicle electronic control system diagnostic center. The controller includes one or more of the following: a vehicle controller, a power management system controller, a braking system controller, an automatic tire pressure controller, a multi-channel auxiliary output valve controller, a transmission control system controller, an electric steering controller, a hydraulic steering controller, a vehicle suspension controller, a suspension controller, a screening system controller, and a conveying system controller. The sensors include one or more of the following: a satellite positioning receiver, a pressure sensor, a tension sensor, a multi-channel vision sensor, a flow sensor, a flow velocity sensor, a driver presence fusion monitoring system, a temperature and humidity comprehensive detection system, an attitude sensor, an angle sensor, a speed sensor, a lidar, a millimeter-wave radar, a pressure sensor, and a production monitoring system.
[0011] Optionally, the power-on upgrade push strategy includes: automatically detecting whether there is an upgrade package for any module each time the agricultural machinery system is powered on; issuing an upgrade prompt message if an upgrade package for a target module is detected; performing an upgrade operation on the target module in response to an acceptance of the upgrade command; and issuing a skip upgrade prompt or a non-skip prompt in response to a rejection of the upgrade command, depending on the type of the target module or the type of the upgrade package for the target module.
[0012] Optionally, the upgrade operation includes: determining whether the current environment conforms to the security policy corresponding to the target module, wherein the security policy is system-recommended and / or user-defined; if the condition is met, downloading and installing the upgrade package for the target module; and if the condition is not met, issuing an error message and terminating the upgrade process.
[0013] Optionally, the error message includes: content that does not comply with the security policy and rectification suggestions. After the upgrade process is suspended, the power-on push upgrade policy further includes: enabling the upgrade operation after a set time; or enabling the upgrade operation in response to an active upgrade command.
[0014] On the other hand, the present invention provides an upgrade device for an agricultural machinery system, the upgrade device comprising: an authorization request module for issuing a silent upgrade authorization request when the agricultural machinery system is activated; a silent upgrade module for enabling a configurable silent upgrade strategy in response to an authorization consent instruction; and a push upgrade module for enabling a power-on push upgrade strategy in response to an authorization rejection instruction.
[0015] On the other hand, the present invention provides an intelligent driving system for agricultural machinery, including the agricultural machinery system upgrade device described above; or for performing the agricultural machinery system upgrade method described above.
[0016] Through the above technical solutions, the present invention provides an upgrade method, upgrade device, and intelligent driving system for agricultural machinery systems, which can construct a user-understandable safety strategy mechanism and achieve compliant upgrades that meet the functional safety standards of multiple countries. Based on a user-authorized configurable safety upgrade electronic control program strategy, the present invention significantly improves the security, compliance, and user experience of firmware updates in agricultural operation scenarios.
[0017] Other features and advantages of the present invention will be described in detail in the following detailed description section. Attached Figure Description
[0018] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings: Figure 1 A flowchart of the agricultural machinery system upgrade method provided by the present invention; Figure 2 A schematic diagram of the technical route for the agricultural machinery system upgrade method provided by the present invention; Figure 3 A schematic diagram of an upgrade device for an agricultural machinery system provided by the present invention; Figure 4 This is a diagram illustrating the architecture of an intelligent driving system for agricultural machinery provided by the present invention. Detailed Implementation
[0019] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.
[0020] This invention first provides an upgrade method 100 for agricultural machinery systems, the core of which lies in building an intelligent upgrade system based on user authorization, security policies, and multi-terminal collaboration, which significantly improves the security, compliance, and user experience of firmware updates in agricultural operation scenarios.
[0021] like Figure 1 As shown, the upgrade method 100 of the present invention may include the following steps S110-S130.
[0022] Step S110: When the agricultural machinery system is activated, a silent upgrade authorization request is issued.
[0023] First, you can refer to Figure 2 The technical roadmap outlines a step where, upon system startup, a silent upgrade authorization request is sent to the user, who can then choose to authorize or decline. This decision serves as a compliance and security prerequisite for all subsequent upgrades. It ensures that upgrade decision-making power remains entirely with the operator, aligning with the core principle in existing standards that "human factors are a critical variable for system safety." Furthermore, it guarantees compliance with informed consent requirements in major global markets, fundamentally transferring upgrade control from the system to the user.
[0024] Specifically, users who purchase agricultural machinery can choose to authorize or not authorize silent remote upgrades of the programs and firmware of various components (such as vehicle systems, controllers, and sensors) in the agricultural machinery system. If silent remote upgrades are authorized, users can further select and configure the programs and firmware of various components that are allowed to be silently upgraded, as described in step S120. If no authorization is granted, the user will need to actively confirm the subsequent upgrade and installation process each time the machine is turned on, as described in step S130.
[0025] Step S120: In response to the authorization consent instruction, enable the configurable silent upgrade strategy.
[0026] In this step, a configurable silent upgrade strategy can be enabled in response to user authorization. This strategy can automatically determine whether to support the upgrade based on the external operating environment and the operating status of the agricultural machinery system as dynamic conditions.
[0027] Specifically, after the user explicitly authorizes a silent remote upgrade, the system will automatically activate a highly configurable, environment-aware silent upgrade strategy. This strategy integrates the operational characteristics and safety redundancy design of the agricultural intelligent driving system to ensure the smooth evolution of system modules without interrupting field operations. For example, the silent upgrade strategy in step S120 may also include the following steps S121-S124: Step S121: In the startup state, automatically detect whether there is an upgrade package for the specified module.
[0028] First, when the user clicks "Authorize Silent Remote Upgrade," the silent upgrade configuration management menu will automatically open. The user can then select the modules for which silent upgrades are allowed through the intelligent driving system's human-machine interface. These modules are system-recommended and / or user-defined, specifically including the programs and / or firmware for the following components: vehicle infotainment system, controllers, and sensors.
[0029] For example, an in-vehicle infotainment system may include one or more of the following: a multimodal communication management module, a multi-sensor fusion perception module, a steering control module, a configuration management module, a vehicle electronic control system management module, a human-machine interaction module, a safety strategy management module, a driving speed and steering control module, a tool task control module, and a vehicle electronic control system diagnostic center. A controller may include one or more of the following: a vehicle controller, a powertrain management system controller, a braking system controller, an automatic tire pressure controller, a multi-channel auxiliary output valve controller, a transmission control system controller, an electric steering controller, a hydraulic steering controller, a vehicle suspension controller, a suspension controller, a screening system controller, and a conveying system controller. Sensors may include one or more of the following: a satellite positioning receiver, a pressure sensor, a tension sensor, a multi-channel vision sensor, a flow sensor, a velocity sensor, a driver presence fusion monitoring system, a temperature and humidity integrated detection system, an attitude sensor, an angle sensor, a speed sensor, a lidar, a millimeter-wave radar, a pressure sensor, and a production monitoring system.
[0030] Additionally, it's important to note that this invention also requires intelligent identification and automatic exclusion of devices that do not support dual-partition (AB partition) storage, ensuring that only components with secure upgrade capabilities are included in the policy scope, forming a precise and controllable list of upgrade targets. Since some controllers / sensors that do not support AB partitions cannot be selected for silent upgrades, the module configuration must include at least two independently operating storage areas. In other words, this invention also requires the constraint that only system modules, controllers, or sensors supporting dual-partition storage are allowed to perform silent downloads and installations on non-operating partitions, ensuring the main system's operating partition continues to operate stably, while upgrades are performed on non-operating partitions, with neither interfering with the other.
[0031] Step S122: If an upgrade package for a setting module is detected and the current environment meets the security policy corresponding to the setting module, the upgrade package is silently downloaded to the first storage area of the setting module that is not running.
[0032] Specifically, when a user selects to use the system's recommended secure download and installation strategy, the system will automatically connect to the network to detect whether there are upgrade pushes for the specified system modules / controllers / sensors. If the upgrade complies with the recommended security strategy, it will be downloaded silently. To ensure differentiation, the upgrade package needs to be downloaded to the first non-running storage area of the available AB partition of the storage medium.
[0033] The safety policies are system-recommended and / or user-defined. Users can choose between two modes: one is the system's intelligently recommended safety policy, generated based on massive amounts of field operation data, comprehensively evaluating network stability, equipment load, and operational continuity; the other is a custom policy, allowing flexible adjustment of trigger conditions within the system's preset parameter range. In other words, users can choose whether to use the system-recommended silent upgrade safety download and installation policy for each selected system module / controller / sensor. If they choose not to use it, they can customize the settings according to the system's recommended configuration policy range. For example, if upgrading a power controller, the safety requirements could include key-on power + controller start + no high-voltage power supply + vehicle speed zero.
[0034] In addition, taking the steering control module as an example, the safety strategy includes one or more of the following judgment conditions: current network status, power-on operation time, autonomous driving usage, RTK (Real-Time Kinematic) positioning service usage status, breakpoint resume function, driver on-site status, whether the reversing gear is in N gear, whether the vehicle is parked, working status, suspension position, cutter position, handrail position, seed insert position, engine speed, PTO speed, vehicle speed, power supply, etc. For example, when the system detects that any set module has an upgrade package, it will automatically judge the environmental conditions according to the safety strategy corresponding to the module. Users can customize five priority conditions for silent download: (1) the current network signal strength is higher than -85dBm; (2) the equipment has accumulated power-on operation time of more than 30 minutes, ensuring that the system has entered a stable operating state; (3) the autonomous driving function has not been activated in the past 10 minutes; (4) the network RTK has not been used for high-precision automatic steering in the past 10 minutes; (5) the breakpoint resume function has passed the self-test, ensuring the reliability of the upgrade under network fluctuations.
[0035] If it is a suspension controller program update package, it can be judged in the following ascending order: (1) the whole vehicle ACC is in the On position; (2) the driver detection is in place; (3) the vehicle is in parking gear or neutral gear; (4) the engine speed is 0; (5) the PTO speed is 0; (6) the suspension position is at the lower limit (currently 0%); (7) confirm that the surrounding environment is safe.
[0036] All the above conditions are verified one by one in a preset order. If any condition is not met, the download is stopped to ensure that the upgrade is always triggered in a safe operating environment. When all safety conditions are met, the upgrade package is silently downloaded to the non-running first storage area of the designated module. This area is a backup partition in the dual-partition architecture, physically isolated from the currently running system. The download process does not interrupt the operation, does not occupy the main system resources, and ensures the continuous and stable operation of the agricultural machinery.
[0037] As can be seen, users can choose to adopt the system's preset recommended security policies, or, within the system's defined parameter range, independently adjust and prioritize the upgrade trigger conditions for each module. Policy configurations can be saved as personalized templates independently for each module, enabling flexible "one machine, multiple policies" management to meet the differentiated needs of different operating scenarios and user habits. Furthermore, once all the above-mentioned custom policies are confirmed, they will be persistently stored as the upgrade template specific to that module, and subsequent upgrades can support automatic invocation. That is to say, when the custom policy conditions are met, the system will silently download the upgrade package to the first, non-running storage area in the background, and can also perform subsequent integrity checks and signature verifications to ensure the firmware's trustworthiness.
[0038] Step S123: Silently install and verify the upgrade package in the first storage area to generate the update program.
[0039] After downloading, the system can automatically perform silent installation and verification of specified system modules / controllers / sensors. It's important to note that this installation process needs to be performed in the non-running area (first storage area) of the available AB partitions on the storage medium. That is, the system automatically completes the silent installation and verification in the non-running partition, generating an update program as a new bootable program image. The entire process requires no user intervention and does not consume resources on the main running partition. If verification fails, the process is immediately terminated and logged. After successful installation, the system marks the partition as pending activation, and the main running system continues to operate until the next startup.
[0040] Step S124: When the setting module restarts, the update program is automatically loaded from the first storage area.
[0041] Upon the next boot, the new program can be automatically loaded from the updated, non-running primary storage area. This allows for seamless firmware version switching while ensuring complete transparency to the user during the upgrade process, maintaining operational continuity and guaranteeing the continuity and reliability of agricultural machinery during critical farming seasons. Simultaneously, this asynchronous upgrade strategy preserves the original stable version for abnormal rollbacks, creating dual safety redundancy. Therefore, this mechanism not only continues the intent of the user's historical authorization decisions but also achieves the industrial-grade security goal of "zero-aware upgrades" through dynamic strategies and dual-partition isolation.
[0042] Step S130: In response to the authorization denial instruction, enable the boot-up push upgrade policy.
[0043] If the user chooses not to authorize silent download and installation, the system will not proactively download and push upgrades. Instead, it will remind the user of available program / configuration update packages each time the device is booted. The user can choose to agree to or reject the upgrade. The system will decide whether to allow skipping based on the module type (e.g., steering control, suspension control) or the nature of the upgrade package (e.g., safety-critical, feature optimization). It is worth noting that major security upgrades are mandatory and cannot be skipped.
[0044] Therefore, this invention can respond to user refusal of authorization by prompting for available upgrade packages each time the system starts, and only execute the corresponding firmware upgrade operation after the user explicitly confirms. Furthermore, the upgrade process must meet the same security conditions as silent upgrades, ensuring that security remains the primary principle regardless of the mode.
[0045] The boot-up upgrade strategy in step S130 may also include the following steps S131-S134: Step S131: Automatically detect whether there is an upgrade package for any module each time the agricultural machinery system is turned on.
[0046] Each time the agricultural machinery system is powered on, the system will automatically execute the power-on upgrade push strategy, first scanning all key modules (including the vehicle system, controller and sensors) to see if there are available upgrade packages.
[0047] Step S132: If an upgrade package for a target module is detected, an upgrade prompt message is issued.
[0048] Once an upgrade version of the target module is detected, the system will display a clear and structured upgrade prompt through the human-computer interaction interface, clearly showing the upgrade content, version number, fixes, and potential impacts for the user to make a decision.
[0049] Step S133: In response to the agreed upgrade instruction, perform the upgrade operation on the target module.
[0050] If the user chooses to agree to the upgrade, the system will dynamically assess whether the current operating environment meets the security requirements based on the module's preset or user-defined proactive security download and installation strategy, and will make conditional judgments based on the proactive security download and installation strategy of the selected system module / controller / sensor. Specifically, this may include multi-dimensional parameters such as network stability, device operating time, autonomous driving usage status, RTK service activity, and the integrity of the breakpoint resume function.
[0051] The upgrade process may include: 1) Determine whether the current environment meets the security policy corresponding to the target module. The security policy is either system-recommended or manually set.
[0052] All of the above strategies allow users to flexibly adjust priorities within the system's recommended range. For example, users can set a custom rule for the steering control module to "allow downloads only after 30 minutes of operation and when autopilot is not in use."
[0053] 2) If the conditions are met, download and install the upgrade package for the target module.
[0054] Once all conditions are verified, the system will automatically initiate the upgrade process and sequentially execute the program download and installation operations, as detailed in the upgrade process described above. Simultaneously, the upgrade package can be securely downloaded to a temporary storage area. The download and installation progress, estimated remaining time, and a security warning will pop up, clearly stating that "the device cannot be operated during the upgrade; interruption or cancellation is supported."
[0055] 3) If the condition is not met, issue an error message and abort the upgrade process.
[0056] If the conditions are not met, a pop-up error message will appear on the human-computer interaction interface, and the upgrade process will be aborted. Specifically, a structured error message can appear, clearly indicating the non-compliant items, and the upgrade process will be stopped to ensure operational safety. The error message may include: content deemed non-compliant with security policies and rectification suggestions. In other words, the system can specifically indicate which aspects do not meet security requirements, and after the user adjusts according to the security requirements, they can proactively re-attempt the upgrade process.
[0057] For example, the system will accurately report specific failures (such as "The current RTK signal is weak; it is recommended to wait for the positioning to stabilize") and provide rectification suggestions. After making corrections, users can manually restart the upgrade at any time or schedule a restart. After a successful upgrade, the system will automatically complete program verification and installation. Some updates will take effect without a restart, and the system will prompt "You can continue working." If core modules (such as HCU) are involved, the system will prompt "It is recommended to restart to activate the update." Users can restart the system according to the prompts and continue with subsequent operations.
[0058] Step S134: In response to the upgrade rejection instruction, issue a skip upgrade prompt or a non-skip prompt based on the type of the target module or the upgrade package type of the target module.
[0059] If a user refuses to upgrade, the system will intelligently determine the upgrade package type: for major security patches or core function updates, a "cannot be skipped" message will be displayed and a rejection log will be recorded; for ordinary function updates, skipping is allowed and a reminder will be sent again upon the next boot.
[0060] After the upgrade process is aborted, the boot-up upgrade strategy in step S130 may also include: Step S135: After a set time, initiate the upgrade operation; or Step S136: In response to the active upgrade command, initiate the upgrade operation.
[0061] For example, if the upgrade is aborted, the system will automatically retry at a set time (e.g., after 2 hours) or restart the process in response to an upgrade command triggered by the user, ensuring that critical updates are finally implemented and balancing work continuity and system security.
[0062] As can be seen, after the upgrade is suspended, the present invention can continuously monitor environmental changes, automatically reassess the upgrade conditions after a set time, or respond to the upgrade command actively triggered by the user, restart the download and installation process until the conditions are met and the upgrade is completed, forming a closed-loop security upgrade mechanism of "prompt-block-guide-retry".
[0063] As can be seen, the agricultural machinery system upgrade method provided by this invention strictly follows the core architecture of "user-authorized drive, environmental perception decision-making, zoned secure execution, and multi-terminal collaborative management," with each step forming a complete and closed-loop logical chain. The key technical points of this invention are: the recommended experience-based secure upgrade strategy and an appropriately editable secure upgrade strategy.
[0064] Specifically, the beneficial effects that this application can achieve include: 1. Construct a user-understandable safety strategy mechanism: Based on industry experience, this invention pre-sets a safety upgrade strategy, provides a user-understandable experience-based safety upgrade strategy, and provides an interactive interface that can be configured independently within a limited parameter range. This allows users to dynamically adjust the upgrade trigger conditions according to the actual working environment, significantly reducing system risks caused by misoperation or environmental mismatch, enhancing users' trust and sense of control over the intelligent driving system, and allowing users to use the intelligent driving system with greater peace of mind. 2. Achieve compliant upgrades that meet international expected functional safety standards: By giving users the option to actively authorize silent upgrades, the upgrade decision-making power is returned to the operator, fundamentally avoiding unauthorized firmware changes. Compared with the active silent upgrades of some OEMs, it is more in line with the stringent compliance requirements of many countries. 3. All upgrades are performed on components that support dual-partition storage, with the non-running area isolated for updates. This ensures both continuous operation of the main system and safe rollback, providing a reusable and highly reliable technical architecture for intelligent driving of agricultural machinery.
[0065] In addition, the present invention also provides an upgrade device 200 for an agricultural machinery system, such as... Figure 3As shown, the upgrade device 200 includes: an authorization request module 210, used to issue a silent upgrade authorization request when the agricultural machinery system is activated; a silent upgrade module 220, used to enable a configurable silent upgrade strategy in response to an authorization consent instruction; and a push upgrade module 230, used to enable a power-on push upgrade strategy in response to an authorization rejection instruction.
[0066] In addition, the present invention also provides an intelligent driving system for agricultural machinery, including the agricultural machinery system upgrade device 200 described above; or the system is upgraded by the agricultural machinery system upgrade method 100 described above.
[0067] The intelligent driving system architecture of the agricultural machinery of the present invention can be referred to as follows. Figure 4 As shown, the management framework includes the following three-terminal collaboration: 1. Cloud, including the following components: (1) The IoT device management center is the only platform that allows communication with various terminal devices. It can parse and store various types of data uploaded by the devices, such as operating condition data, high frequency data, diagnostic data, operation data, and collection data, and provide API interfaces for various service / application platforms to call. It also supports the transmission of data and files to terminal devices, such as configuration files, setting parameters, program installation packages, task files, planning and design files, etc. (2) The big data analysis and management platform can configure the range and frequency of data collection fields for specified terminal devices and can generate comparative analysis charts of custom combined data; (3) The technical support management platform provides work order flow management and diagnostic analysis support to technical support personnel, and collaborates with the big data analysis management platform to predict faults in various terminal devices; (4) API integration with third-party platforms refers to the integration with platforms of other companies, which can share working condition data, task data, work record data, diagnostic data, etc. (5) The OTA management service platform formulates upgrade strategies and tasks for various terminal devices, manages various baseline package programs and configuration files, and can remotely upgrade the vehicle-side intelligent driving system modules / controllers / sensors of various agricultural machinery. (6) The FMIS customer application platform is provided to the machine purchaser to realize digital management of the farm plots, fleet, personnel, crops and operation process; 2. Vehicle end, including the following components: (1) The vehicle network management terminal integrates a variety of standard or optional communication modules, including but not limited to WIFI / Bluetooth / Radio / LoRa / 4G / 5G / Starlink, etc., and connects to the vehicle display and control center via Ethernet to realize communication between the vehicle and the cloud, and supports various data upload and download; (2) The vehicle display and control center is the carrier of the intelligent driving control system. Depending on the type of agricultural machinery it carries, it includes, but is not limited to, a multimodal communication management module, a multi-sensor fusion perception module, a steering control module, a configuration management module for various working devices, a vehicle electronic control system management module, a human-machine interaction module, a safety strategy management module, a driving speed and reversing control module, an ISOBUS implement task control module, and a vehicle electronic control system diagnostic center. Through various control algorithms, it realizes assisted driving operations and unmanned driving operations of agricultural machinery. (3) The display and control center extends the interactive screen and connects to the vehicle network management terminal and the vehicle display and control center via Ethernet. Multiple screens can be configured as optional accessories and undertake some of the human-machine interaction functions and computing power of the vehicle display and control center. (4) Vehicle-mounted sensors refer to various sensor devices mounted on the vehicle end. Depending on the type of agricultural machinery mounted, they include, but are not limited to, high-precision satellite positioning receivers, pressure / tension sensors, multi-channel vision sensors, flow / velocity sensors, driver presence fusion monitoring systems, temperature and humidity integrated detection systems, attitude / angle sensors, speed sensors, laser / millimeter-wave radar, pressure sensors, production monitoring systems, etc. Some sensors are connected to the vehicle network management terminal and transmit sensor data to the vehicle display and control center via Ethernet. Some sensors transmit sensor data to the vehicle display and control center and the underlying electronic control system via CAN network. (5) The underlying electronic control system refers to the controllers of various component assemblies and the integrated control execution program. Each controller communicates through the underlying CAN network. Depending on the type of agricultural machinery it is equipped with, it includes, but is not limited to, multi-functional vehicle controller, power management system controller, braking system controller, automatic tire pressure controller, multi-way auxiliary output valve controller, transmission control system controller, electric / hydraulic steering controller, vehicle suspension controller, suspension controller, screening system controller (harvester), and conveying system controller (harvester). 3. The tool end includes the following components: (1) The machine ISOBUS controller is connected to the vehicle display and control center via CAN network, receives task data sent by the ISOBUS task control module, and performs high-precision execution control through the segment control module and the rate control module to accurately complete the work task.
[0068] Other beneficial effects of the agricultural machinery system and its upgrading device 200 of the present invention can be found in the above description of the agricultural machinery system upgrading method 100, and will not be repeated here.
[0069] The above-described specific embodiments are used to explain and illustrate the present invention, and are merely preferred embodiments of the present invention, not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made to the present invention within the spirit and scope of the claims fall within the protection scope of the present invention. The preferred embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the present invention is not limited to the specific details of the above embodiments. Within the scope of the technical concept of the present invention, various simple modifications can be made to the technical solution of the present invention, and these simple modifications all fall within the protection scope of the present invention.
[0070] It should also be noted that the various specific technical features described in the above specific embodiments can be combined in any suitable manner without contradiction. In order to avoid unnecessary repetition, the present invention will not describe the various possible combinations separately.
[0071] Furthermore, various different embodiments of the present invention can be combined in any way, as long as they do not violate the spirit of the present invention, they should also be regarded as the content disclosed by the present invention.
[0072] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
Claims
1. A method for upgrading an agricultural machinery system, characterized in that, The upgrade method includes: When the agricultural machinery system is activated, a silent upgrade authorization request is issued; In response to the consent authorization command, enable a configurable silent upgrade policy; and In response to the authorization denial command, the system will enable the power-on push upgrade policy.
2. The upgrade method according to claim 1, characterized in that, The silent upgrade strategy includes: In the startup state, the system automatically detects whether there is an upgrade package for a specified module, wherein the specified module is recommended by the system and / or set by the user, and includes at least two independently operating storage areas; If an upgrade package for the specified module is detected and the current environment conforms to the security policy corresponding to the specified module, the upgrade package is silently downloaded to the first storage area of the specified module that is not running. The security policy is system recommended and / or set by the user. The upgrade package is silently installed and verified in the first storage area, generating an update program; and When the setting module restarts, the update program is automatically loaded from the first storage area.
3. The upgrade method according to claim 2, characterized in that, The safety strategy includes one or more of the following judgment conditions: current network status, startup time, autonomous driving usage, RTK positioning service usage status, breakpoint resume function, driver presence status, whether the shift gear is in neutral (N), whether the vehicle is parked, working status, suspension position, cutter position, handrail position, seed insert position, engine speed, PTO speed, vehicle speed, and power supply.
4. The upgrade method according to claim 2, characterized in that, The setting module includes programs and / or firmware for the following components: vehicle infotainment system, controller, and sensors.
5. The upgrade method according to claim 4, characterized in that, The vehicle infotainment system includes one or more of the following: a multimodal communication management module, a multi-sensor fusion perception module, a steering control module, a configuration management module, a vehicle electronic control system management module, a human-machine interaction module, a safety strategy management module, a driving speed and steering control module, a tool task control module, and a vehicle electronic control system diagnostic center. The controller includes one or more of the following: vehicle controller, power management system controller, braking system controller, automatic tire pressure controller, multi-way auxiliary output valve controller, transmission control system controller, electric steering controller, hydraulic steering controller, vehicle suspension controller, suspension controller, screening system controller, and conveying system controller. The sensors include one or more of the following: satellite positioning receiver, pressure sensor, tension sensor, multi-channel vision sensor, flow sensor, velocity sensor, driver presence fusion monitoring system, temperature and humidity integrated detection system, attitude sensor, angle sensor, speed sensor, lidar, millimeter-wave radar, pressure sensor, and production monitoring system.
6. The upgrade method according to claim 1, characterized in that, The boot-up push upgrade strategy includes: Each time the agricultural machinery system is powered on, it automatically checks whether there is an upgrade package for any module. If an upgrade package for a target module is detected, an upgrade prompt message is issued; In response to the agreed upgrade instruction, an upgrade operation is performed on the target module; and In response to an upgrade rejection command, a prompt to skip the upgrade or a prompt that the upgrade cannot be skipped is issued, depending on the type of the target module or the upgrade package type of the target module.
7. The upgrade method according to claim 6, characterized in that, The upgrade operation includes: The system performs a conditional judgment on whether the current environment conforms to the security policy corresponding to the target module, wherein the security policy is system-recommended and / or set autonomously; If the conditions are met, the upgrade package for the target module is downloaded and installed; and If the conditions are not met, an error message will be issued and the upgrade process will be aborted.
8. The upgrade method according to claim 7, characterized in that, The error message includes: content that is determined to be inconsistent with the security policy and rectification suggestions. After the upgrade process is aborted, the boot-up upgrade push strategy also includes: The upgrade operation will be initiated after a set time; or In response to the proactive upgrade command, the upgrade operation is initiated.
9. An upgrade device for an agricultural machinery system, characterized in that, The upgrade device includes: The authorization request module is used to issue a silent upgrade authorization request when the agricultural machinery system is activated; A silent upgrade module is used to enable a configurable silent upgrade strategy in response to an authorization consent command; and The push upgrade module is used to respond to authorization denial commands and enable the boot push upgrade policy.
10. An intelligent driving system for agricultural machinery, characterized in that, It includes the agricultural machinery system upgrade device as described in claim 9; or the system upgrade is performed by the agricultural machinery system upgrade method as described in any one of claims 1-8.