Electronic control unit upgrading method and device, and vehicle

By parsing and generating upgrade commands through the in-vehicle intelligent terminal, the problem of poor compatibility of ECU upgrade methods is solved, enabling remote automated upgrades and improving the universality and user experience of ECU upgrades.

CN122173119APending Publication Date: 2026-06-09CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD
Filing Date
2026-03-04
Publication Date
2026-06-09

AI Technical Summary

Technical Problem

In the existing technology, the upgrade methods for electronic control units (ECUs) have poor compatibility and lack universality, resulting in cumbersome operation steps and complex processes, making it difficult to adapt to the differentiated upgrade needs of different ECU manufacturers and versions.

Method used

The system obtains the electronic upgrade package through the in-vehicle intelligent terminal, parses the upgrade configuration file using the main processor, establishes a communication link and generates upgrade instructions, thereby achieving remote automated upgrades. This avoids updating the Tbox program itself, adapts to diverse ECU upgrade needs, and enhances versatility and compatibility.

Benefits of technology

It achieves universality and compatibility for ECU upgrades, reduces the workload of vehicle maintenance and updates, improves user experience, and simplifies the ECU upgrade process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122173119A_ABST
    Figure CN122173119A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of vehicle upgrading, and discloses an electronic control unit upgrading method and device and a vehicle. An electronic upgrading package for an electronic control unit is acquired based on a vehicle-mounted intelligent terminal; the electronic upgrading package is analyzed to determine an upgrading program and an upgrading configuration file of the electronic control unit, the upgrading configuration file including configuration parameters and upgrading flow commands; in a preset communication channel, the upgrading program is forwarded to a target electronic control unit based on the configuration parameters, so that the target electronic control unit executes the upgrading configuration file to generate a response service; in response to the response service, an upgrading instruction is generated based on the upgrading flow commands, so that the target electronic control unit is upgraded according to the upgrading instruction and the upgrading program. The upgrading configuration file is modified to adapt to diversified ECU upgrading requirements, the vehicle software rapid iteration requirement is met, the Tbox does not need to be updated, the ECU upgrading and the newly-added ECU upgrading requirement can be compatible, and the universality and the compatibility are increased.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle upgrade technology, and in particular to an electronic control unit upgrade method, device and vehicle. Background Technology

[0002] With the continuous development of the new energy vehicle field, the number of ECUs (Electronic Control Units) in cars is increasing, and the demand for OTA (Over-the-Air Technology) functions is also growing. Therefore, the BOOT (Bootloader) function, which enables ECUs to perform software self-upgrades, has become an essential function for vehicles.

[0003] However, in related technologies, the firmware upgrade methods and processes of different manufacturers are different, specifically in the differences in upgrade steps. Due to the Tbox (Telematics Box, vehicle remote information terminal) firmware program being locked, it is necessary to upgrade the Tbox first before the ECU program can be upgraded through the Tbox. This makes the operation steps cumbersome and the process complicated. On the other hand, it also leads to poor ECU upgrade compatibility and lack of universality. Summary of the Invention

[0004] This application provides an electronic control unit (ECU) upgrade method, apparatus, and vehicle to address the problems of poor compatibility and lack of universality in ECU upgrade methods in related technologies.

[0005] In a first aspect, embodiments of this application provide an electronic control unit (ECU) upgrade method applied to a vehicle. The method includes: obtaining an ECU upgrade package based on an in-vehicle intelligent terminal; parsing the ECU upgrade package using a main processor in the in-vehicle intelligent terminal to determine an ECU upgrade program and an upgrade configuration file, the upgrade configuration file including configuration parameters and upgrade process commands required for ECU upgrade; forwarding the upgrade program to a target ECU based on the configuration parameters in a preset communication channel, so that the target ECU executes an upgrade configuration file generation response service, wherein the preset communication channel uses an in-vehicle communication processor in the in-vehicle intelligent terminal as middleware to establish a communication link between the main processor and the ECU, and the target ECU is at least one of the ECUs; and generating an upgrade instruction based on the upgrade process commands in response to the received response service, so that the target ECU performs an upgrade according to the upgrade instruction and the upgrade program.

[0006] This application also provides an electronic control unit (ECU) upgrade device applied in a vehicle. The device includes: a download module for acquiring an ECU upgrade package from an in-vehicle smart terminal; a parsing module for parsing the ECU upgrade package using the main processor in the in-vehicle smart terminal to determine the ECU upgrade program and upgrade configuration file, the upgrade configuration file including configuration parameters and upgrade process commands required for customizing the ECU upgrade; a file forwarding module for forwarding the upgrade program to the target ECU based on the configuration parameters via a preset communication channel, enabling the target ECU to execute the upgrade configuration file generation response service, wherein the preset communication channel uses the in-vehicle communication processor in the in-vehicle smart terminal as middleware to establish a communication link between the main processor and the ECU, and the target ECU is at least one of the ECUs; and an upgrade module for generating an upgrade instruction based on the upgrade process commands in response to the received response service, causing the target ECU to upgrade according to the upgrade instruction and upgrade program.

[0007] This application also provides a vehicle that employs the method of any of the above embodiments.

[0008] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method of any of the above embodiments.

[0009] The above-mentioned electronic control unit (ECU) upgrade method, device, and vehicle implementation scheme obtains the ECU upgrade package based on the in-vehicle intelligent terminal; the main processor in the in-vehicle intelligent terminal parses the ECU upgrade package to determine the ECU upgrade program and upgrade configuration file. The in-vehicle intelligent terminal only needs to modify the upgrade configuration file to adapt to diverse ECU upgrade requirements, meeting the needs of rapid vehicle software iteration; the upgrade program and configuration parameters are forwarded to the target ECU through a preset communication channel, so that the target ECU executes the upgrade configuration file generation response service. In response to the received response service, an upgrade instruction is generated based on the upgrade process command, so that the target ECU performs the upgrade according to the upgrade instruction and upgrade program; in this way, remote automated ECU upgrades are achieved through vehicle-side OTA, which can be compatible with ECU upgrade changes and new ECU upgrade requirements without updating the Tbox program itself, increasing versatility and compatibility; it avoids frequent Tbox firmware upgrades due to changes in ECU upgrade requirements, reducing the workload of later vehicle maintenance and updates, reducing the development and testing workload of Tbox adaptation to ECU upgrade processes, and improving user experience. Attached Figure Description

[0010] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application. It is obvious that the drawings described below are merely some embodiments of this application, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.

[0011] In the attached diagram:

[0012] Figure 1 An exemplary architecture diagram of an electronic control unit upgrade device provided in this application embodiment; Figure 2 A flowchart illustrating the electronic control unit upgrade method provided in this application embodiment; Figure 3 This is a schematic diagram of the principle structure of the electronic control unit upgrade device provided in the embodiments of this application; Figure 4 A flowchart of the pre-flash command for the electronic control unit upgrade method provided in this application embodiment; Figure 5 A flowchart of the flashing commands for the electronic control unit upgrade method provided in this application embodiment; Figure 6 A flowchart of the flashing command for the electronic control unit upgrade method provided in this application embodiment; Figure 7 A schematic diagram of the electronic control unit upgrade device provided in the embodiments of this application; Figure 8 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application; Figure 9 This is another structural schematic diagram of an electronic device according to one embodiment of this application. Detailed Implementation

[0013] The following specific examples illustrate the implementation of this application. Those skilled in the art can easily understand other advantages and effects of this application from the content disclosed in this specification. This application can also be implemented or applied through other different specific embodiments. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this application. In the absence of conflict, the following embodiments and features in the embodiments can be combined with each other.

[0014] It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of this application. The drawings only show the components related to this application and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0015] In the following description, numerous details are explored to provide a more thorough explanation of embodiments of the present application. However, it will be apparent to those skilled in the art that embodiments of the present application may be practiced without these specific details. In other embodiments, well-known structures and devices are shown in block diagram form rather than in detail to avoid obscuring embodiments of the present application.

[0016] Please see Figure 1 This application provides an exemplary architecture diagram of an electronic control unit upgrade device. The implementation environment includes a terminal, which may be a vehicle, industrial engineering equipment, agricultural operation equipment, environmental and energy monitoring equipment, or industrial production line equipment. The vehicle 101 includes new energy vehicles and fuel-powered vehicles. The vehicle 101 is connected to the server 102 via a wireless network 100, and the server 102 is a vehicle networking service provider.

[0017] This application provides an electronic control unit (ECU) upgrade device that can run in a vehicle 101 or in software. In some embodiments, the server can be configured as an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, and big data and artificial intelligence platforms. The software can be an ECU upgrade application, but is not limited to the above forms.

[0018] In related technologies, the upgrade process of vehicle internal electronic control units usually relies on diagnostic tools to be operated offline at specific repair sites, which lacks flexibility and timeliness; since firmware is usually fixed on the terminal or server, it is difficult to adapt to the flexible needs of different ECU models or different upgrade strategies.

[0019] To support the differentiated upgrade needs of different ECU manufacturers and versions without modifying the underlying terminal software, thereby improving the flexibility and configurability of the upgrade process, this application provides an electronic control unit upgrade method, device, and vehicle. Please refer to [link to relevant documentation]. Figure 2 This is a flowchart illustrating an electronic control unit upgrade method provided in this application, applied to a vehicle. The method includes: Step S210: Obtain the electronic upgrade package for the electronic control unit based on the vehicle-mounted intelligent terminal; For example, the in-vehicle intelligent terminal establishes a connection with a server, i.e., a vehicle networking service provider, through its built-in wireless communication module, and receives an electronic upgrade package for the target electronic control unit pushed by the server. This electronic upgrade package is a packaged binary file, which typically contains a digital signature to ensure integrity and authenticity. The software package is distributed over the air using remote wireless communication technology as initial data input for the entire upgrade process. The acquisition method of the electronic upgrade package is not limited to wireless networks; alternatively, the upgrade package can also be imported into the in-vehicle intelligent terminal via a wired connection, or relayed to the in-vehicle intelligent terminal via near-field communication technologies such as Bluetooth. This application achieves remote and centralized distribution of the electronic upgrade package, significantly improving the efficiency and coverage of the upgrade operation.

[0020] Step S220: The main processor in the vehicle intelligent terminal is used to parse the electronic upgrade package to determine the upgrade program and upgrade configuration file of the electronic control unit. The upgrade configuration file includes the configuration parameters and upgrade process commands required for the upgrade of the electronic control unit. For example, the main processor of the in-vehicle intelligent terminal runs an operating system. After loading the electronic upgrade package, it parses and obtains a structured upgrade configuration file and upgrade program. The upgrade configuration file uses Extensible Markup Language (EXPLAIN) or a similar format, clearly defining the upgrade process sequence, command parameters, data partitioning information, and dependencies. For example, the upgrade configuration file can use various structured or binary formats, such as JSON and XML. The upgrade program is a standardized execution package and closed-loop update process for version iteration, functional optimization, or defect repair of the embedded software inside the automotive ECU. This application separates the upgrade logic from the upgrade data, externalizing the process control information into a readable and writable configuration file, thus realizing the software-defined upgrade logic. By modifying the configuration file, different ECUs and upgrade strategies can be adapted, greatly enhancing the flexibility and scalability of ECU upgrades and avoiding terminal firmware modifications due to changes in upgrade strategies.

[0021] Step S230: In the preset communication channel, the upgrade program is forwarded to the target electronic control unit based on the configuration parameters, so that the target electronic control unit executes the upgrade configuration file generation response service. The preset communication channel uses the vehicle communication processor in the vehicle intelligent terminal as middleware to establish a communication link between the main processor and the electronic control unit. The target electronic control unit is at least one of the electronic control units. For example, the main processor does not communicate directly with the ECU. Instead, it sends critical upgrade data and UDS instructions to the vehicle communication processor via an inter-core communication mechanism. The vehicle communication processor, acting as middleware, processes vehicle network protocols, receives UDS instructions from the main processor, converts them into frame structures conforming to a specific bus standard, identifies the target electronic control unit based on the uniqueness of configuration parameters, and sends the data to the target electronic control unit through the established communication link. Optionally, communication between the main processor and the vehicle communication processor can utilize various interfaces such as SPI, UART, and Ethernet; this reduces the architectural complexity of the electronic control unit upgrade device and improves stability and portability. Furthermore, this application uses the vehicle communication processor as dedicated middleware, ensuring real-time and reliable communication, allowing the main processor to focus on business logic processing.

[0022] Step S240: In response to the received response service, an upgrade instruction is generated based on the upgrade process command, so that the target electronic control unit can be upgraded according to the upgrade instruction and upgrade procedure.

[0023] For example, the main processor sends specific UDS instructions to the vehicle communication processor step by step according to the parsed upgrade process commands. After each instruction is sent, the main processor waits for and parses the ECU response message (i.e., response service) returned by the vehicle communication processor. By determining whether the response service is a positive or negative response, the main processor decides whether to continue executing the next command in the process, or to retry or terminate the upgrade of the target electronic control unit according to a preset strategy. This achieves intelligent and adaptive control of the upgrade process. On the one hand, it ensures the rigor and high success rate of the upgrade process. On the other hand, through the real-time feedback mechanism, it can quickly identify and respond to abnormal situations that occur during the upgrade process, greatly improving the robustness of the electronic control unit upgrade.

[0024] By using the main processor in the in-vehicle intelligent terminal to parse the electronic upgrade package, the upgrade program and configuration file of the target electronic control unit are determined. The in-vehicle intelligent terminal can adapt to diverse ECU upgrade requirements simply by modifying the upgrade configuration file, meeting the needs of rapid vehicle software iteration. The upgrade program and configuration parameters are forwarded to the target electronic control unit through a preset communication channel, enabling the target electronic control unit to execute the upgrade configuration file generation response service. In response to the received response service, upgrade instructions are generated based on the upgrade process commands, allowing the target electronic control unit to upgrade according to the upgrade instructions and upgrade program. In this way, OTA remote upgrade of ECU software can be performed without updating the Tbox program itself, while being compatible with ECU upgrade changes and new ECU upgrade requirements, increasing versatility and compatibility. It avoids frequent Tbox firmware upgrades due to changes in ECU upgrade requirements, reducing the workload of later vehicle maintenance and updates, reducing the development and testing workload of Tbox adaptation to ECU upgrade processes, and improving the user experience.

[0025] In related technologies, within vehicle electronic systems, the main processor handles high-level application logic, while electronic control units (ECUs) communicate via the vehicle bus. In existing technologies, the main processor often directly processes the bus communication protocol, causing its computing resources to be consumed by lower-level communication tasks, thus reducing system real-time performance and reliability. Furthermore, different bus protocols vary significantly, making it difficult to adapt to various ECUs.

[0026] Optionally, in some embodiments, the method of determining the preset communication channel further includes: Inter-core communication is established between the main processor and the vehicle communication processor, and bus communication based on the transmission protocol is established between the vehicle communication processor and the electronic control unit. By combining inter-core communication and bus communication, a pre-defined communication channel is formed between the main processor and the electronic control unit, with the vehicle communication processor as the middleware.

[0027] For example, the main processor and the vehicle communication processor are integrated as independent hardware units within the vehicle-mounted intelligent terminal. Inter-core communication is achieved through shared memory or a high-speed serial interface, such as SPI or Ethernet. The main processor writes the data to be sent into the shared memory area or sends messages through the interface. The vehicle communication processor reads and processes the data through periodic polling or interrupts. Inter-core communication can employ various methods, such as asynchronous communication based on message queues or using standard protocols like UART or I2C. At the software level, inter-process communication mechanisms provided by the operating system, such as sockets or pipes, can be applied. Furthermore, this achieves efficient data transfer between the main processor and the vehicle communication processor, isolates application logic from communication drivers, reduces the real-time requirements of the main processor, and improves the system's modularity.

[0028] The vehicle communication processor is dedicated to handling vehicle bus protocols, such as the TP protocol on the CAN bus or the DoIP protocol on Ethernet; it initializes the bus interface, configures transmission parameters, and establishes a session with the target electronic control unit (ECU); during data transmission, the vehicle communication processor encapsulates application data into standard frames conforming to the transmission protocol and sends them to the target ECU via the bus, while also handling responses and flow control; it provides a standard communication interface with the target ECU, shielding it from underlying bus differences, enhancing communication reliability and error handling capabilities, and facilitating the integration of various ECUs. Inter-core communication and bus communication are serialized, with the vehicle communication processor acting as middleware, responsible for protocol conversion and data routing; the main processor sends abstract instructions to the vehicle communication processor via inter-core communication; the vehicle communication processor parses the instructions, converts them into specific bus messages, and sends them via bus communication; the target ECU's response returns along the reverse path; this constructs an efficient and reliable end-to-end communication channel, achieving complete decoupling between the main processor and the ECU, improving the architecture's scalability and maintainability, while reducing overall development difficulty.

[0029] By combining inter-core communication and bus communication, and using the vehicle communication processor as middleware, a highly efficient preset communication channel is formed. This achieves loosely coupled communication between the main processor and the electronic control unit, significantly reducing the communication burden on the main processor and improving the real-time performance and reliability of the system.

[0030] In the relevant technologies, the following defects exist in the process of flashing the target electronic control unit of a vehicle: First, the vehicle network topology is complex, and the communication addresses of different ECUs may conflict or change dynamically, which makes it impossible to accurately route the upgrade command to the target ECU; Second, the upgrade process is usually a linear fixed script, which lacks fine-grained management of the flashing process lifecycle and is difficult to deal with specific problems that may occur at different stages, resulting in insufficient fault tolerance and adaptability of the process.

[0031] Optionally, in some embodiments, the configuration parameters include at least one of the name of the electronic control unit, physical request address, functional address and physical response address, and the upgrade process commands are divided into pre-flash commands, flashing commands and post-flash commands according to the flashing timing of the electronic control unit.

[0032] The ECU upgrade configuration file, based on XML (Extensible Markup Language), includes the configuration parameters (i.e., ECU configuration parameters) and upgrade process commands (i.e., ECU upgrade process commands) required for the electronic control unit upgrade. The aforementioned upgrade configuration file allows for the creation of customized electronic control units according to user needs.

[0033] The ECU configuration parameters include at least one of the following: ECU name, ECU physical request address, ECU function address, and ECU physical response address. This allows the target ECU to be identified.

[0034] The ECU upgrade process commands are sent by the Tester (diagnostic instrument) according to the flashing cycle before, during, and after flashing, respectively.

[0035] The following is a template for the XML configuration command for ECU upgrade.

[0036] For example, by fully defining the source and target addresses of both communicating parties (diagnostic tool and ECU), it is ensured that request and response messages can be accurately addressed and routed during point-to-point communication in a multi-ECU network, avoiding communication failures caused by address confusion. This achieves accurate identification and network positioning of the target ECU. In the upgrade configuration file, a set of precise communication identification parameters is defined for the target ECU; among them, the logical identifier named ECU is used for identification and configuration reference; the physical request address is the target physical address used by the diagnostic tool, i.e., the vehicle communication processor in this application, when sending request messages; the functional address is the logical address of the ECU in response to user function requests on the network; and the physical response address is the source physical address used by the ECU when sending response messages. By clearly distinguishing between request and response addresses, address conflicts in bus communication are effectively avoided, significantly improving the determinism and success rate of the upgrade process.

[0037] For example, based on the different impacts of the upgrade process on the ECU state, the complete UDS command sequence is divided into three logical stages. The pre-flash command group is responsible for preparatory work, such as switching diagnostic sessions, secure access, suppressing non-diagnostic communication, and checking preconditions. The mid-flash command group is responsible for core data transmission, such as erasing memory, requesting downloads, transmitting data, and verifying data. The post-flash command group is responsible for cleanup and recovery work, such as ECU reset, checking software version, restoring normal communication, and clearing fault codes. This standardizes and structures the upgrade process, making the process control logic clear and facilitating debugging and maintenance. Through stage division, specific error handling and rollback strategies can be designed for different stages, enhancing the robustness of the upgrade process. Simultaneously, this division facilitates parallel design and testing of the process, improving development efficiency.

[0038] By precisely configuring ECU communication parameters and dividing upgrade commands into stages, the upgrade process is transformed from blind execution to precise control. Precise address configuration ensures that commands accurately reach their targets. Meanwhile, timing-based command segmentation provides a clear roadmap and stage objectives for the upgrade process, making the entire process logically rigorous, with clear steps, traceable errors, and manageable status.

[0039] In related technologies, the system preparation state before flashing and the system recovery operation after flashing are not effectively separated from the core flashing action, resulting in unclear process logic. Once interrupted, it is difficult to accurately locate and recover. There is a lack of state management of the electronic control unit at different flashing times, which can easily lead to flashing failure or abnormal function of the electronic control unit due to insufficient preparation or improper recovery.

[0040] Optionally, in some embodiments, the upgrade instruction includes a pre-flash command, a flashing command, and a post-flash command. In response to receiving a response service, an upgrade instruction is generated based on the upgrade process commands, causing the target electronic control unit to be upgraded according to the upgrade instruction and upgrade procedure, including: In response to upgrade instructions, including pre-flash commands, the target electronic control unit is configured according to the upgrade instructions carried by the pre-flash commands until the pre-upgrade configuration operation is completed; In response to upgrade instructions, including flashing commands, the target electronic control unit is flashed with upgrade instructions carried by the flashing commands until the upgrade program flashing is completed to upgrade the target electronic control unit. In response to upgrade instructions, including post-flash commands, the target electronic control unit is configured according to the upgrade instructions carried by the post-flash commands until the target electronic control unit is restored to the configuration of the preset default mode before flashing.

[0041] For example, if the received response result service meets the upgrade conditions, then the target electronic control unit associated with the configuration parameters is sent to the upgrade process command in sequence, including sending a pre-flash command, a flashing command, and a post-flash command. The main processor, based on the pre-flash command sequence in the upgrade configuration file (containing multiple pre-flash commands), sequentially sends these commands to the target electronic control unit (ECU) via a preset communication channel. These commands include, but are not limited to: switching the target ECU from the default session to the programming session via a diagnostic session control command; completing security authentication and unlocking via a secure access command; suppressing non-diagnostic communication to reduce bus load via a communication control command; and checking programming dependencies via a routine control command. The target ECU is configured according to the upgrade instructions carried by the pre-flash commands until the pre-upgrade configuration is complete. This ensures that the target ECU is in the correct hardware and software environment before receiving new software data, minimizing the risk of interruption or failure during the flashing process due to external interference or poor conditions.

[0042] For example, the main processor executes a flashing command sequence containing multiple flashing commands, sequentially sending pre-flashing commands to the target electronic control unit (ECU) through a preset communication channel. These commands include, but are not limited to, those mentioned above. The process typically begins with an erase memory command to clear the target storage area. Subsequently, a data transmission session is established via a download command. Upgrade program data is sent to the target ECU in blocks via multiple data transmission commands. Data transmission ends with a request to exit transmission command. The target ECU performs writing and storage while receiving data, efficiently and reliably completing the installation of the new software version on the target ECU. The upgrade program is flashed on the target ECU according to the upgrade instructions carried by the flashing commands until the upgrade program flashing is completed and the target ECU is upgraded. Through standardized protocols and processes, the integrity and accuracy of data transmission are ensured.

[0043] For example, the main processor executes a post-flash command sequence containing multiple post-flash commands, which are sequentially sent to the target electronic control unit (ECU) via a preset communication channel. These commands include, but are not limited to: checking the integrity of the flash data via a routine control command; forcing the target ECU to restart and load new software via an ECU reset command; verifying key information such as the software version number via a read data identifier command after the target ECU has been reset and communication has been re-established; re-enabling fault code storage via a control diagnostic fault code setting command; restoring non-diagnostic communication via a communication control command; and configuring the target ECU according to the upgrade instructions carried by the post-flash commands until the target ECU is restored to the preset default configuration before flashing. This ensures that the target ECU can immediately resume normal operation after flashing, avoiding functional limitations or communication anomalies caused by residual programming state.

[0044] By employing the above methods, the impact of the flashing process on vehicle stability is minimized, ensuring the recoverability of the target electronic control unit in abnormal situations. Phased management enables precise control of the upgrade progress, which helps to rationally allocate and release computing and communication resources, thereby improving overall efficiency.

[0045] Please see Figure 3 The schematic diagram of the electronic control unit upgrade device provided in this application embodiment includes: The vehicle remote service provider 3 connects to the vehicle remote information terminal 1 via a wireless network. The main processor 11, i.e., SOC, is located inside the vehicle remote information terminal 1. The main processor 11 contains UDS Services 110. The vehicle communication processor 12 inside the vehicle remote information terminal 1 is connected to the main processor 11 via SPI. The vehicle communication processor 12 is connected to the electronic control unit 3 via CAN bus through TP120.

[0046] For example, the electronic control unit (ECU), upgrade program, and upgrade configuration file are packaged together to form a new electronic upgrade package to solve the compatibility problem of ECU upgrades. The ECU upgrade program format is a hex file.

[0047] The TSP (Automotive Remote Service Provider) server pushes targeted Electronic Control Unit (ECU) upgrade packages to the in-vehicle telematics terminal (Tbox) via a communication network. The onboard telematics terminal's internal main processor (SOC) parses the electronic upgrade package, which includes the ECU upgrade program and the upgrade configuration file for the XML upgrade process. The main processor (SOC) inside the vehicle-mounted remote information terminal parses the electronic upgrade package through the UDS service (Unified Diagnostic Services), determines the relevant ECU information, and sends it to the vehicle communication processor (MCU). The MCU then confirms the target electronic control unit (ECU) transmission protocol (TP) channel based on the relevant information.

[0048] The main processor SOC inside the vehicle telematics terminal Tbox sends a UDS message to the vehicle communication processor MCU via inter-core communication using SPI (Serial Peripheral Interface) according to the XML upgrade process. The TP (Transmission Protocol Layer) in the vehicle communication processor MCU forwards the message to the corresponding CAN bus via the CAN bus and sends it to the corresponding target electronic control unit (ECU). After the target ECU responds to the UDS message, the transmission protocol layer of the vehicle communication processor MCU forwards it to the UDS service of the main processor SOC. The UDS service determines whether to send the next command or interrupt the upgrade based on whether the response is positive or negative.

[0049] Optionally, in some embodiments, the target electronic control unit is configured according to the upgrade instructions carried in the pre-flash command, including at least one of the following: Based on the preset communication channel, a switching command for the extended session is sent to the target electronic control unit so that the target electronic control unit can extend the session; Based on a preset communication channel, a pre-flash check command for the vehicle status is sent to the target electronic control unit, so that the target electronic control unit performs the check and generates a pre-flash check result. Based on a preset communication channel, a pre-flash check command for the vehicle status is sent to the target electronic control unit, so that the target electronic control unit executes the check command and generates a pre-flash check result. A fault masking command is sent to the target electronic control unit based on a preset communication channel, so that the target electronic control unit stops fault detection; Based on a preset communication channel, a communication setting command is sent to the target electronic control unit so that the target electronic control unit only transmits communication messages used for upgrading the electronic control unit.

[0050] For example, the main processor sends diagnostic commands to the target electronic control unit (ECU) via a preset communication channel, using the vehicle communication processor as middleware. These diagnostic commands are typically routine control commands that activate one or more pre-set status check routines within the target ECU. The check commands can specify specific items to be verified, such as the stability of the power supply voltage, the microcontroller core temperature, whether the vehicle speed is zero, and whether the transmission is in parking gear. The target ECU executes the routine, reads the values ​​from relevant sensors or status registers, compares them with internally preset safety thresholds, and generates a check result indicating whether the check passed or failed, returning it via a response message. This implements safety gating for the upgrade operation, preventing forced upgrades under non-safety conditions from the outset. It effectively prevents write interruptions or ECU hardware damage caused by system instability, improving the safety and success rate of the upgrade process.

[0051] For example, the main processor sends a control diagnostic fault code setting command to the target electronic control unit (ECU) via a preset communication channel, specifying corresponding sub-function parameters to instruct the ECU to stop storing all diagnostic fault codes. Upon receiving this instruction, the diagnostic event manager of the target ECU temporarily changes its operating mode, continuing to execute the fault monitoring algorithm but marking the detected events as not stored or only stored in the volatile cache, instead of writing them to the non-volatile fault memory. This effectively avoids misjudging normal but non-routine operations such as mode switching and communication retries during the upgrade process as system faults, ensuring the accuracy and validity of the vehicle's fault history record.

[0052] For example, the main processor sends a communication control command to the target electronic control unit (ECU) through a preset communication channel. This command specifies the message types to be suppressed and their corresponding communication networks. Based on this instruction, the target ECU's communication protocol stack suspends the periodic sending of regular function messages by its application programs while keeping its diagnostic communication service active. This ensures that it only responds to diagnostic request messages related to flashing, significantly reducing the communication load on the relevant bus network. It provides sufficient and real-time communication bandwidth for the large-volume diagnostic messages that need to be transmitted during the flashing process, greatly reducing message delays or loss caused by bus congestion, thereby improving the efficiency and reliability of the upgrade process.

[0053] Please see Figure 4 This is a flowchart of the pre-flash command for the electronic control unit upgrade method provided in this application embodiment; Before flashing, preparation work is carried out. First, to ensure the stability of bus communication during the flashing process; second, to avoid unexpected faults during the flashing process; and third, to read vehicle data to provide some checks before flashing, such as whether the vehicle is in a safe state such as being turned off, parked, and having sufficient battery voltage.

[0054] Among them, Tester is the vehicle communication processor of this application. When interacting with the target ECU to perform pre-flash command, it responds sequentially according to the timing logic. If no positive response is received each time, the instruction is stopped or retried. If no positive response is received after retries of a preset number of times, a fault is reported and a rollback operation is performed. Otherwise, each instruction is executed one by one until the pre-flash command is completed.

[0055] By adopting the above approach, the upgrade process is transformed from an open operation that may be subject to random interference from the external environment into a standardized process carried out in a controlled and isolated environment. This eliminates systemic risks, removes internal interference, and optimizes the transmission channel, creating a safe, static, and efficient working environment for the flashing operation.

[0056] Optionally, in some embodiments, flashing an upgrade program on the target electronic control unit according to the upgrade instructions carried in the flashing command includes: A download command is sent to the target electronic control unit based on a preset communication channel, so that the target electronic control unit responds to the download command by establishing a data transmission channel in the preset communication channel, and transmits data in segments using the data transmission channel until the data transmission is completed. The data includes the upgrade program and configuration parameters. Send a check command to the target electronic control unit so that the target electronic control unit responds to the check command to perform a data integrity check and returns the integrity check result; After the integrity check is passed, a programming test command is sent to the target electronic control unit, so that the target electronic control unit responds to the programming test command to test the programming environment and feeds back the test results; Once the test results are passed, a reset command is sent to the target electronic control unit, causing the target electronic control unit to restart in response to the reset command, load the newly flashed upgrade program, and provide feedback on the loading result.

[0057] For example, the main processor sends a download command to the target electronic control unit (ECU) via a preset communication channel. This command includes parameters such as the total size and format of the data to be transmitted. Upon receiving the command, the target ECU performs resource allocation and initialization, and returns a positive response, typically including the maximum length of a single data block to be received, thus establishing a data transmission channel. Subsequently, the main processor uses a data transmission command to divide the upgrade program and configuration parameters into data blocks of the specified size, and sends them sequentially through the channel. The target ECU receives each data block and caches it or writes it directly to flash memory, achieving efficient and reliable transmission of large-scale upgrade data and ensuring that all necessary data is delivered completely to the target ECU.

[0058] For example, after all data transmission is complete, the main processor sends a routine control command to the target electronic control unit (ECU). This command initiates a pre-set data integrity check routine within the ECU. For instance, it calculates the checksum (such as CRC32 or a hash value) of the received and stored upgrade program data and compares the result with a pre-stored expected value. The comparison result—whether it passes or fails—is fed back to the main processor as the integrity check result via a response message. This effectively prevents ECU programming failures or functional malfunctions due to data errors, greatly improving the reliability and security of the upgrade process.

[0059] For example, after confirming data integrity, the main processor sends another routine control command to initiate a programming environment detection routine; for example, checking whether the current environmental parameters meet the requirements for running the new program, typically including power supply voltage stability, chip operating temperature, memory status, etc. The detection results are fed back to the main processor, ensuring that the new program will run in a compliant hardware environment, avoiding program instability or hardware damage caused by an unsuitable environment. The main processor sends an ECU reset command to the target electronic control unit to perform a hardware reset or software reset operation. The reset includes clearing temporary data, re-initializing the hardware, loading the newly flashed upgrade program from the predetermined boot address, and starting execution; the target electronic control unit performs a hardware or software reset to ensure that all configuration parameters are reloaded from non-volatile memory, the new software version is fully effective, and the target electronic control unit is completely removed from the upgrade state, loading and running the newly flashed software, and entering normal operation with the preset default configuration.

[0060] By employing the above methods, a closed-loop verification and activation process after the upgrade is constructed. Through the triple guarantee mechanism of data integrity check, programming environment detection, and reset loading verification, risks such as data errors, environment incompatibility, and loading failure are eliminated, ensuring that the upgraded target electronic control unit can be put into stable and reliable operation immediately.

[0061] Optionally, in some embodiments, before sending the download command to the target electronic control unit based on a preset communication channel, the method further includes: Send session programming instructions to the target electronic control unit based on a preset communication channel, so that the target electronic control unit switches to a programming session; Send a security access request to the target electronic control unit so that the target electronic control unit responds to the security access request to perform verification and complete the security unlocking. The security access request includes a request seed and a sending key. After the system is securely unlocked, a fingerprint writing request is sent to the target electronic control unit so that the data identifier of the upgrade program stored in the target electronic control unit can complete the fingerprint writing. The data identifier includes the upgrade version number and the upgrade time. After the fingerprint writing is completed, a memory erase request is sent to the target electronic control unit so that the target electronic control unit can erase the storage area that will be covered by the upgrade program.

[0062] For example, the main processor sends a diagnostic session control command to the target electronic control unit (ECU) via a preset communication channel, specifying parameters to require it to switch from the default session to a programming session. After receiving and parsing the command, the ECU's UDS Service switches its internal state from normal operation mode to a mode dedicated to software programming. In this mode, high-privilege diagnostic services such as memory programming and secure access are activated, while some regular application functions may be suppressed, placing the ECU in a specific environment optimized for flashing operations. In this environment, necessary programming services are available, while non-essential functions are restricted. The main processor sends a secure access request seed command, and the ECU generates a random number as a seed and returns it. Subsequently, the main processor uses a pre-shared algorithm to calculate a key using this seed. Finally, the main processor sends a secure access send key command. The ECU uses the same algorithm and its own generated seed to calculate the key and compares it with the received key. If they match, secure unlocking is successful, allowing programming operations; otherwise, unlocking fails. This provides a crucial security barrier, ensuring that only authorized diagnostic tools can update the target ECU's software, effectively preventing malware attacks and unauthorized flashing, and safeguarding the vehicle system's security.

[0063] After the main processor gains secure access, it sends a write data command to the target electronic control unit (ECU). This command points to a specific data identifier, which corresponds to a non-volatile storage area within the ECU used to store upgrade metadata. The written data typically includes key information such as the new software version number for this upgrade, the date and timestamp of the upgrade operation. The target ECU receives this data and stores it permanently, enabling traceability of the upgrade operation and greatly improving the convenience and accuracy of system maintenance and management.

[0064] The main processor sends a routine control command to the target electronic control unit to start a predefined memory erase routine. The command parameters typically specify the starting address and size of the memory block to be erased. For example, it performs an erase operation on a specified area of ​​the internal Flash or other rewritable non-volatile memory, restoring its contents to the initial state. This ensures that the new program can be written into an initialized memory space, avoiding program logic errors or startup failures caused by the mixing of old and new data.

[0065] Please see Figure 5 This is a flowchart of the command process during the flashing of the electronic control unit upgrade method provided in this application embodiment; The system responds sequentially according to the timing logic. If no positive response is received for each response, the instruction is aborted or retried. If no positive response is received after a preset number of retries, a fault is reported and a rollback operation is performed. Otherwise, each instruction is executed one by one until the writing command is completed.

[0066] The above methods not only create a secure sandbox environment for subsequent operations through session switching and secure access, but also establish effective management tracking points through fingerprint writing and physically prepare for data writing through memory erasure.

[0067] Please see Figure 6 The following is a flowchart of the flashing command for the electronic control unit upgrade method provided in this application embodiment: Following the execution logic before and during the flashing process, execute the post-flashing command.

[0068] Optionally, in some embodiments, the target electronic control unit is configured according to the upgrade instructions carried by the flashing command, including at least one of the following: A communication recovery command is sent to the target electronic control unit based on a preset communication channel, so that the target electronic control unit can remove the communication restriction and resume message communication; Based on a preset communication channel, a fault detection command is sent to the target electronic control unit to enable the target electronic control unit to restore the fault detection function. If a fault is detected, fault feedback is provided. A mode switching command is sent to the target electronic control unit via a preset communication channel to restore the target electronic control unit to the preset default mode configuration.

[0069] For example, after confirming the successful flashing of core data, the main processor sends a specific communication recovery command to the target electronic control unit (ECU) through a preset communication channel to restore all message communication or enable specific types of messages. Upon receiving this command, the communication protocol stack of the target ECU will cancel the communication suppression settings it accepted before the flashing and reactivate its application cycle's function message sending task; this enables the target ECU to resume normal data interaction with other vehicle systems, ensuring the integrity and interoperability of its functions.

[0070] For example, the main processor sends a fault detection command to the target electronic control unit through a preset communication channel and sets its parameters to enable the storage of all diagnostic fault codes, restoring the standard behavior of storing the detected fault events into non-volatile memory. This reactivates the target electronic control unit's crucial self-monitoring and safety warning mechanism, ensuring the safety and diagnosability of vehicle operation and ensuring that any real faults that occur after the upgrade can be recorded and reported in a timely manner.

[0071] The main processor sends a mode switching command to the target electronic control unit through a preset communication channel, instructing it to switch back from the programming session to the default session.

[0072] Through the above methods, after undergoing a high-risk flashing operation, the target electronic control unit not only reverse-engineers all temporary restrictions (communication suppression, fault shielding) set for the upgrade, but also prompts the target electronic control unit to complete the final state transition through a proactive mode switching command. This effectively prevents functional abnormalities or system instability that may be caused by the electronic control unit remaining in an unconventional state, ensuring the transparency of the upgrade process to the vehicle's normal operation. In other words, the system can be used normally after the upgrade is completed, achieving a seamless and highly reliable upgrade process.

[0073] In some embodiments, an electronic control unit (ECU) upgrade apparatus is provided, which is used to perform the ECU upgrade method provided in any of the above embodiments. Please refer to... Figure 3 This is a schematic diagram of an electronic control unit upgrade device provided in an embodiment of this application, which can be applied to a vehicle. The electronic control unit upgrade device includes: The upgrade package download module 710 obtains the electronic upgrade package for the electronic control unit based on the in-vehicle intelligent terminal; The upgrade package parsing module 720 uses the main processor in the vehicle intelligent terminal to parse the electronic upgrade package, determine the upgrade program and upgrade configuration file of the electronic control unit, and the upgrade configuration file includes the configuration parameters and upgrade process commands required for the upgrade of the electronic control unit. The file forwarding module 730 is used to forward the upgrade program to the target electronic control unit based on configuration parameters in a preset communication channel, so that the target electronic control unit can execute the upgrade configuration file generation response service. The preset communication channel uses the vehicle communication processor in the vehicle intelligent terminal as middleware to establish a communication link between the main processor and the electronic control unit. The target electronic control unit is at least one of the electronic control units. The upgrade module 740 is used to respond to the received response service, generate upgrade instructions based on the upgrade process command, and enable the target electronic control unit to upgrade according to the upgrade instructions and upgrade program.

[0074] Through the above method, the electronic control unit (ECU) upgrade device of this application obtains an ECU upgrade package based on the vehicle-mounted intelligent terminal; it uses the main processor in the vehicle-mounted intelligent terminal to parse the ECU upgrade package, determine the ECU upgrade program and upgrade configuration file, and the vehicle-mounted intelligent terminal only needs to modify the upgrade configuration file to adapt to diverse ECU upgrade requirements, meeting the needs of rapid vehicle software iteration; it forwards the upgrade program and configuration parameters to the target ECU through a preset communication channel, so that the target ECU executes the upgrade configuration file generation response service, and in response to the received response service, generates upgrade instructions based on the upgrade process commands, so that the target ECU performs upgrades according to the upgrade instructions and upgrade program; in this way, OTA remote upgrade of ECU software can be performed without updating the Tbox program itself, while being compatible with ECU upgrade changes and new ECU upgrade requirements, increasing versatility and compatibility; it avoids frequent Tbox firmware upgrades due to changes in ECU upgrade requirements, reducing the workload of later vehicle maintenance and updates, reducing the development and testing workload of Tbox adaptation to ECU upgrade processes, and improving user experience.

[0075] Specific limitations regarding the electronic control unit (ECU) upgrade device can be found in the above description of the ECU upgrade method, and will not be repeated here. Each module in the aforementioned ECU upgrade device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in the electronic device, or stored in the memory of the electronic device as software, so that the processor can call and execute the corresponding operations of each module.

[0076] In this embodiment, the electronic control unit upgrade device is essentially equipped with multiple modules to execute the electronic control unit upgrade method in any of the above embodiments. The specific functions and technical effects can be referred to in the above embodiments, and will not be repeated here.

[0077] In one embodiment, an electronic device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 8 As shown, the electronic device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with external clients via a network connection. The computer program is executed by the processor to implement the functions or steps of the server-side method described above.

[0078] In one embodiment, an electronic device is provided, which may be a client, and its internal structure diagram may be as follows: Figure 9 As shown, the electronic device includes a processor, memory, network interface, display screen, and input device connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface is used to communicate with an external server via a network connection. The computer program is executed by the processor to implement the functions or steps of the client side of the above method.

[0079] In one embodiment, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method described above.

[0080] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the above-described method.

[0081] It should be noted that the functions or steps that can be implemented by the computer-readable storage medium or electronic device described above can be referred to the relevant descriptions on the server side and client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.

[0082] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), direct memory bus RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0083] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the above-described device or system can be divided into different functional units or modules to complete all or part of the functions described above.

[0084] The above embodiments are merely illustrative of the principles and effects of this application and are not intended to limit this application. Any person skilled in the art can modify or alter the above embodiments without departing from the spirit and scope of this application. Therefore, all equivalent modifications or alterations made by those skilled in the art without departing from the spirit and technical concept disclosed in this application should still be covered by the claims of this application.

Claims

1. A method for upgrading an electronic control unit, characterized in that, Applied to the vehicle end, the method includes: Obtain electronic upgrade packages for electronic control units based on in-vehicle intelligent terminals; The main processor in the vehicle-mounted intelligent terminal is used to parse the electronic upgrade package to determine the upgrade program and upgrade configuration file of the electronic control unit. The upgrade configuration file includes the configuration parameters and upgrade process commands required for the upgrade of the electronic control unit. In a preset communication channel, the upgrade program is forwarded to the target electronic control unit based on the configuration parameters, so that the target electronic control unit executes the upgrade configuration file generation response service. The preset communication channel uses the vehicle communication processor in the vehicle intelligent terminal as middleware to establish a communication link between the main processor and the electronic control unit. The target electronic control unit is at least one of the electronic control units. In response to receiving the response service, an upgrade instruction is generated based on the upgrade process command, causing the target electronic control unit to upgrade according to the upgrade instruction and the upgrade program.

2. The electronic control unit upgrade method as described in claim 1, characterized in that, The methods for determining the preset communication channel include: Inter-core communication is established between the main processor and the vehicle communication processor, and bus communication based on the transmission protocol is established between the vehicle communication processor and the electronic control unit. By combining the inter-core communication and the bus communication, a preset communication channel is formed between the main processor and the electronic control unit, with the vehicle communication processor as an intermediary.

3. The electronic control unit upgrade method as described in claim 1, characterized in that, The configuration parameters include at least one of the electronic control unit's name, physical request address, functional address, and physical response address. The upgrade process commands are divided into pre-flash commands, flashing commands, and post-flash commands based on the timing of flashing the electronic control unit.

4. The electronic control unit upgrade method as described in claim 3, characterized in that, The upgrade instructions include pre-flash commands, flashing commands, and post-flash commands. The response, upon receiving the response service, generates upgrade instructions based on the upgrade process commands, causing the target electronic control unit to upgrade according to the upgrade instructions and the upgrade program, including: In response to the upgrade instruction including a pre-flash command, the target electronic control unit is configured according to the upgrade instruction carried by the pre-flash command until the pre-upgrade configuration operation is completed; In response to the upgrade instruction including the flashing command, the target electronic control unit is flashed according to the upgrade instruction carried by the flashing command until the upgrade program flashing is completed to upgrade the target electronic control unit; In response to the upgrade instruction including the flashing command, the target electronic control unit is configured according to the upgrade instruction carried by the flashing command until the target electronic control unit is restored to the configuration of the preset default mode before flashing.

5. The electronic control unit upgrade method as described in claim 4, characterized in that, The configuration of the target electronic control unit according to the upgrade instruction carried in the pre-flash command includes at least one of the following: Based on the preset communication channel, a switching command for extended sessions is sent to the target electronic control unit so that the target electronic control unit can extend the session; Based on the preset communication channel, a pre-flash check command for the vehicle status is sent to the target electronic control unit, so that the target electronic control unit performs the check and generates a pre-flash check result. Based on the preset communication channel, a fault masking command is sent to the target electronic control unit so that the target electronic control unit stops fault detection; Based on the preset communication channel, a communication setting command is sent to the target electronic control unit so that the target electronic control unit only transmits communication messages for upgrading the target electronic control unit.

6. The electronic control unit upgrade method as described in claim 4, characterized in that, The step of flashing the upgrade program on the target electronic control unit according to the upgrade instruction carried in the flashing command includes: A download command is sent to the target electronic control unit based on the preset communication channel, so that the target electronic control unit establishes a data transmission channel in the preset communication channel, and transmits data in segments using the data transmission channel until the data transmission is completed. The data includes the upgrade program and the configuration parameters. Send a check command to the target electronic control unit so that the target electronic control unit performs an integrity check on the data and returns the integrity check result; After the integrity check is passed, a programming test command is sent to the target electronic control unit so that the target electronic control unit can test the programming environment and return the test results. After the test results are passed, a reset command is sent to the target electronic control unit, causing the target electronic control unit to restart and load the newly flashed upgrade program, and then the loading result is fed back.

7. The electronic control unit upgrade method as described in claim 6, characterized in that, Before sending the download command to the target electronic control unit based on the preset communication channel, the method further includes: Based on the preset communication channel, a session programming command is sent to the target electronic control unit to cause the target electronic control unit to switch to a programming session; A security access request is sent to the target electronic control unit so that the target electronic control unit can verify and complete the security unlocking. The security access request includes a request seed and a sending key. After the system is securely unlocked, a fingerprint writing request is sent to the target electronic control unit so that the target electronic control unit writes the data identifier of the upgrade program into the fingerprint. The data identifier includes the upgrade version number and the upgrade time. After the fingerprint writing is completed, a memory erase request is sent to the target electronic control unit so that the target electronic control unit erases the storage area that will be covered by the upgrade program.

8. The electronic control unit upgrade method as described in claim 4, characterized in that, The configuration of the target electronic control unit according to the upgrade instruction carried by the flashing command includes at least one of the following: Based on the preset communication channel, a communication recovery command is sent to the target electronic control unit to enable the target electronic control unit to remove the communication restriction and resume message communication; Based on the preset communication channel, a fault detection command is sent to the target electronic control unit so that the target electronic control unit can restore the fault detection function. Based on the preset communication channel, a mode switching command is sent to the target electronic control unit so that the target electronic control unit is restored to the preset default mode configuration.

9. An electronic control unit upgrade device, characterized in that, Applied to the vehicle end, the device includes: The download module obtains electronic upgrade packages for the electronic control unit based on the in-vehicle intelligent terminal; The parsing module uses the main processor in the vehicle-mounted intelligent terminal to parse the electronic upgrade package, determine the upgrade program and upgrade configuration file of the electronic control unit, and the upgrade configuration file includes the configuration parameters and upgrade process commands required to customize the upgrade of the electronic control unit; The file forwarding module is used to forward the upgrade program to the target electronic control unit based on the configuration parameters in a preset communication channel, so that the target electronic control unit executes the upgrade configuration file generation response service. The preset communication channel uses the vehicle communication processor in the vehicle intelligent terminal as middleware to establish a communication link between the main processor and the electronic control unit. The target electronic control unit is at least one of the electronic control units. An upgrade module is used to respond to the received response service, generate an upgrade instruction based on the upgrade process command, and cause the target electronic control unit to upgrade according to the upgrade instruction and the upgrade program.

10. A vehicle, characterized in that, The vehicle is described using the method described in any one of claims 1 to 8.