A session coordination recovery method and system for a multi-ecu concurrent diagnosis scenario
Patent Information
- Application Number
- CN202611012762.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-08
- Publication Date
- 2026-09-25
AI Technical Summary
[0018]本发明提供的一种多ECU并发诊断场景的会话协调恢复方法、系统、电子设备及存储介质,通过获取并利用车辆网络中多个电子控制单元之间的依赖关系信息,明确了各ECU在通信路径上的父子层级关系,使得诊断会话中断后能够依据该依赖关系确定合理的恢复顺序,从而确保作为通信路由父节点的ECU优先得到恢复,为其下游子节点ECU的后续恢复提供有效的通信通道,消除了因父节点会话未恢复而导致子节点恢复指令无法送达的死锁现象,同时避免了传统方案中因忽略ECU间路由依赖而对子网ECU盲目发送恢复指令所导致的大量超时失败和无效重试,减少了总线负载占用,并通过对多个ECU依次执行会话状态探测与恢复操作,区分各ECU的实际会话状态,避免对仍处于有效会话状态的ECU执行不必要的重建操作,减少了因安全访问限制导致的通信拒绝,使恢复操作集中于真正需要重建的ECU,从而缩短了整体恢复耗时,提升了恢复过程的顺畅性和可靠性。
Smart Images

Figure CN122816166A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of automotive electronics technology, and more specifically, to a session coordination and recovery method and system for multi-ECU concurrent diagnostic scenarios. Background Technology
[0002] In the field of automotive electronic diagnostics, aftermarket diagnostic tools connect to the vehicle network via a vehicle communication interface to perform parallel diagnostics on multiple electronic control units (ECUs), such as the engine, transmission, and body control, thereby improving diagnostic efficiency. The diagnostic tool maintains communication with each ECU through a diagnostic session. If communication is interrupted due to factors such as a disconnection of the wireless network, a vehicle restart, or a diagnostic tool waking from sleep mode, the diagnostic session needs to be restored.
[0003] However, existing diagnostic session recovery solutions generally suffer from the following technical defects: First, the session hold timer parameters of each ECU are set differently. The typical S3 timer duration may be 3 seconds, 5 seconds, or even longer. However, existing solutions use a uniform timeout judgment logic for all ECUs, which cannot accurately determine the actual session status of each ECU. This leads to repeated sending of session switching commands to still active ECUs, wasting bus resources, or misjudging that a failed ECU is still online, resulting in subsequent communication being denied due to security access restrictions. Second, there are ECUs with routing functions such as gateways and domain controllers in the vehicle network. Any access to its subnet ECUs must be forwarded through them. However, existing parallel recovery strategies send commands to all ECUs to be recovered indiscriminately, causing a large number of commands sent to subnet ECUs to time out and fail before the gateway is recovered, prolonging the recovery time and potentially causing excessive bus load. Third, when some ECU recovery commands fail, existing solutions lack a layered error isolation and degradation handling mechanism. The recovery failure of a single ECU may affect the recovery process of other unrelated ECUs, causing cascading recovery failures.
[0004] In summary, how to overcome the differences in session timers between different ECUs, the routing dependencies between ECUs, and the cascading failures in abnormal recovery scenarios after communication interruption, and achieve efficient, orderly, and fault-tolerant diagnostic session recovery, has become an urgent technical problem to be solved in the field of automotive diagnostic technology. Summary of the Invention
[0005] This invention addresses the technical problems existing in the prior art by providing a session coordination and recovery method and system for multi-ECU concurrent diagnostic scenarios. By acquiring and utilizing the parent-child routing dependency information between ECUs, the session recovery order after interruption is determined, which solves the problem of recovery deadlock and invalid retries caused by ignoring ECU hierarchical dependencies, and improves the efficiency and reliability of session recovery in multi-ECU concurrent diagnostic scenarios.
[0006] According to a first aspect of the present invention, a session coordination and recovery method for a multi-ECU concurrent diagnostic scenario is provided, comprising: Obtain dependency information of multiple electronic control units in the vehicle network, wherein the dependency information is at least used to indicate that the first electronic control unit is the communication routing parent node of the second electronic control unit; In response to a diagnostic session interruption event, the session recovery order of the plurality of electronic control units is determined based on the dependency information; In accordance with the session recovery order, session state detection and recovery operations are performed sequentially on the plurality of electronic control units.
[0007] Based on the above technical solution, the present invention can also be improved as follows.
[0008] Optionally, the dependency information may also include session hold timer parameters for each electronic control unit; The method also includes: Based on the session hold timer parameters, determine the session validity prediction result for each electronic control unit after the interruption event occurs, and adjust the session recovery order based on the session validity prediction result.
[0009] Optionally, the step of sequentially performing session state detection and recovery operations on the plurality of electronic control units according to the session recovery order includes: Send a session activity detection command to the electronic control unit currently awaiting recovery; If a positive response is received, the diagnostic session of the electronic control unit is determined to be still valid, and the recovery operation is skipped; If no positive response is received or a negative response is received, the diagnostic session of the electronic control unit is determined to be invalid, and a session reconstruction operation is performed.
[0010] Optionally, the execution of the session reconstruction operation includes: Send a request to the electronic control unit to enter a non-default session; After successfully entering a non-default session, a secure access authentication process is executed; After secure access authentication is successful, confirm that the diagnostic session of the electronic control unit has been restored.
[0011] Optionally, the step of sequentially performing session state detection and recovery operations on the plurality of electronic control units according to the session recovery order includes: Prioritize performing session state detection and recovery operations on the first electronic control unit, which serves as the parent node of the communication routing; After the session of the first electronic control unit is restored, the session state detection and restoration operation is then performed on the second electronic control unit.
[0012] Optionally, the method also includes: When a session recovery operation fails to be performed on the target electronic control unit, the downstream electronic control units that have a dependency relationship with the target electronic control unit are marked as unrecoverable based on the dependency information, and the session recovery operation continues to be performed on the electronic control units of other independent branches.
[0013] Optionally, obtaining the dependency information of multiple electronic control units in the vehicle network includes: The physical address, functional address, network segment, parent-child routing dependency, and session persistence timer parameters of each electronic control unit are parsed from the vehicle configuration file or network topology description file. Based on the parsing results, a directed acyclic dependency topology graph is constructed, where nodes represent electronic control units, edges represent parent-child routing dependencies, and node attributes include at least session hold timer parameters.
[0014] Optionally, the step of sequentially performing session state detection and recovery operations on the plurality of electronic control units according to the session recovery order includes: Among multiple electronic control units at the same level, a time-division polling method is used to perform session state detection and recovery operations one by one in order to control the bus load.
[0015] According to a second aspect of the present invention, a session coordination and recovery system for multi-ECU concurrent diagnostic scenarios is provided, comprising: The topology acquisition module is used to acquire dependency information of multiple electronic control units in the vehicle network. The dependency information is used at least to indicate that the first electronic control unit is the communication route parent node of the second electronic control unit. A recovery order determination module is used to determine the session recovery order of the plurality of electronic control units based on the dependency information in response to an interruption event of a diagnostic session. The session recovery execution module is used to perform session state detection and recovery operations on the plurality of electronic control units in sequence according to the session recovery order.
[0016] According to a third aspect of the present invention, an electronic device is provided, including a memory and a processor, wherein the processor is configured to implement the steps of the above-described session coordination and recovery method for concurrent diagnostic scenarios of multiple ECUs when executing a computer management program stored in the memory.
[0017] According to a fourth aspect of the present invention, a computer-readable storage medium is provided, on which a computer management class program is stored, wherein when the computer management class program is executed by a processor, the steps of the session coordination and recovery method for the above-described multi-ECU concurrent diagnostic scenario are implemented.
[0018] This invention provides a session coordination and recovery method, system, electronic device, and storage medium for multi-ECU concurrent diagnostic scenarios. By acquiring and utilizing the dependency information between multiple electronic control units in the vehicle network, the parent-child hierarchical relationship of each ECU on the communication path is clarified. This allows for the determination of a reasonable recovery order based on this dependency relationship after a diagnostic session is interrupted, ensuring that the ECU acting as the parent node of the communication route is recovered first, providing an effective communication channel for the subsequent recovery of its downstream child node ECUs. This eliminates the deadlock phenomenon where child node recovery commands cannot be delivered due to the parent node's session not being recovered. At the same time, it avoids the large number of timeout failures and invalid retries caused by blindly sending recovery commands to subnet ECUs due to ignoring the routing dependencies between ECUs in traditional solutions, reducing bus load. By sequentially performing session state detection and recovery operations on multiple ECUs, the actual session state of each ECU is distinguished, avoiding unnecessary reconstruction operations on ECUs that are still in a valid session state. This reduces communication denials caused by security access restrictions, allowing recovery operations to focus on the ECUs that truly need reconstruction, thereby shortening the overall recovery time and improving the smoothness and reliability of the recovery process. Attached Figure Description
[0019] Figure 1 This is a schematic diagram illustrating the technical architecture of the diagnostic instrument and the vehicle network. Figure 2 A flowchart of a session coordination and recovery method for a multi-ECU concurrent diagnostic scenario provided in one embodiment; Figure 3 A flowchart of a session coordination and recovery method for a multi-ECU concurrent diagnostic scenario is provided as another embodiment; Figure 4 A flowchart illustrating the session coordination and recovery method for a multi-ECU concurrent diagnostic scenario in a specific implementation context; Figure 5 A block diagram of a session coordination and recovery system for a multi-ECU concurrent diagnostic scenario provided by the present invention; Figure 6 A schematic diagram of the hardware structure of a possible electronic device provided by the present invention; Figure 7 This is a schematic diagram of the hardware structure of a possible computer-readable storage medium provided by the present invention. Detailed Implementation
[0020] The specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples. The following examples are for illustrative purposes only and are not intended to limit the scope of the invention.
[0021] In this embodiment of the invention, when collecting, processing, and storing user personal information (such as images, behavioral characteristics, etc.), the implementation of the technical solution strictly adheres to the principles of legality, legitimacy, and necessity, as well as the core rule of "notification-consent." Specifically, before information collection, the system clearly informs the user of the purpose, method, scope, and usage rules of information collection through an interactive interface, and requires the user's active authorization and consent. The entire information processing process employs data encryption, access control, and other technical measures to ensure information security, and establishes mechanisms to facilitate users' exercise of their rights (such as querying, correcting, withdrawing consent, and deleting information). For exceptions stipulated by law (such as those necessary for fulfilling statutory duties or responding to public health emergencies), their application is strictly limited to the scope and limits authorized by law, ensuring that the technical solution does not contain any content that violates the law, social morality, or harms the public interest.
[0022] Figure 1 This is a schematic diagram of the communication architecture between the diagnostic instrument and the vehicle network involved in this invention. Figure 1 As shown, the architecture comprises three main parts: a diagnostic tool, a Vehicle Communication Interface (VCI), and an in-vehicle network. Within the diagnostic tool, the diagnostic application acts as the top-level module, working in conjunction with the underlying dependency topology construction module, session state detection module, and hierarchical recovery scheduling module. Specifically, the dependency topology construction module generates and stores the network topology structure (e.g., a directed dependency topology graph), the session state detection module initiates state detection on each ECU during network interruption recovery, and the hierarchical recovery scheduling module schedules the recovery process in an orderly manner based on the aforementioned network topology information and detection results. The hierarchical recovery scheduling module establishes a bidirectional communication link with the VCI. The VCI, acting as the physical connection hub, enables data interaction between the diagnostic tool and the in-vehicle network through the vehicle bus protocol stack. The in-vehicle network adopts a hybrid backbone and subnet topology. Gateway ECUs, serving as communication routing parent nodes, are deployed on the backbone bus, connecting downwards to several subnet buses. These subnet buses host terminal electronic control units such as the transmission ECU (also known as the TCU, transmission control unit), body control ECU (also known as the BCM, body control module), and engine ECU (also known as the EMS, engine management system). The gateway ECU serves as the sole routing node in the subnet, and the EMS, TCU, and BCM all communicate with the diagnostic tool through the gateway. Figure 1 The architecture design shown clearly defines the parent-child dependency relationship between each ECU, enabling diagnostic commands to be routed between subnets through the gateway ECU, thereby effectively supporting session coordination and hierarchical recovery functions in multi-ECU concurrent diagnostic scenarios.
[0023] Figure 2 This invention provides a flowchart of a session coordination and recovery method for multi-ECU concurrent diagnostic scenarios, combined with... Figure 1 and Figure 2As shown, the method provided in this embodiment mainly includes steps S1 to S3.
[0024] S1, Obtain dependency information of multiple ECUs in the vehicle network, wherein the dependency information is at least used to indicate that the first electronic control unit is the communication routing parent node of the second electronic control unit.
[0025] The purpose of this step is to understand the communication path dependencies between various ECUs in advance, and to identify which ECUs need to be routed through other ECUs, thus providing a basis for determining the recovery order later. For example, any diagnostic communication from the engine ECU and transmission ECU connected to the private CAN subnet via the gateway ECU must be forwarded through the gateway ECU; therefore, the gateway ECU is the communication routing parent node for these subnet ECUs.
[0026] S2, in response to an interruption event of the diagnostic session, determines the session recovery order of the plurality of ECUs based on the dependency information.
[0027] This step initiates after a communication interruption, using the acquired dependency information to determine the recovery order of each ECU. Since recovery commands from subnet ECUs must be forwarded by the parent ECU before being delivered, the parent ECU's session must be restored first; otherwise, recovery commands sent to subnet ECUs will time out due to unroutable routing. This step avoids the problems of invalid retries and excessive bus load caused by indiscriminately sending recovery commands to all ECUs in parallel, as in traditional solutions.
[0028] S3, according to the session recovery order, perform session state detection and recovery operations on the multiple ECUs in sequence.
[0029] This step processes each ECU one by one in the order determined in step S2. For each ECU, it first detects whether its current session state is still valid, and then decides whether to perform the recovery operation based on the detection result. By executing the operation sequentially rather than in parallel, it avoids the load impact caused by a large number of recovery commands flooding the bus at the same time. At the same time, it ensures that the session of the parent node ECU is available before the child node ECU begins recovery, eliminating the deadlock situation where the child node recovery operation fails due to the parent node not recovering.
[0030] Understandably, based on the deficiencies in the background technology, this invention proposes a session coordination and recovery method for multi-ECU concurrent diagnostic scenarios. This method acquires and utilizes parent-child routing dependency information among multiple ECUs in the vehicle network. After a diagnostic session is interrupted, it determines the recovery order based on this dependency, thereby ensuring that the ECU acting as the parent node of the communication route is recovered first. This eliminates the deadlock phenomenon where child node recovery commands cannot be delivered due to the parent node's session not being recovered. It also avoids the large number of timeout failures and invalid retries caused by indiscriminately issuing recovery commands to all ECUs in parallel, as in traditional solutions, significantly reducing bus load. Simultaneously, by executing session state detection and recovery operations sequentially according to a determined order, it can distinguish the actual session state of each ECU, skipping unnecessary reconstructions of ECUs still in valid session states, reducing communication denials caused by security access restrictions, and concentrating recovery operations on ECUs that truly need reconstruction. This shortens the overall recovery time and improves the efficiency and reliability of session recovery in multi-ECU concurrent diagnostic scenarios.
[0031] Based on the above technical solutions, the embodiments of the present invention can be further improved as follows.
[0032] Example 1: This embodiment provides a session coordination and recovery method for multi-ECU concurrent diagnostic scenarios. This method is based on, for example, Figure 1 The diagnostic tool, vehicle communication interface (VCI), and in-vehicle network shown are implemented. The in-vehicle network includes a gateway ECU deployed on the main bus and multiple subnet ECUs (such as engine ECU, transmission ECU, body control ECU, etc.) connected to the private network bus.
[0033] like Figure 3 and Figure 4 The diagram shows a flowchart of a session coordination and recovery method for a multi-ECU concurrent diagnostic scenario provided in this embodiment. Combined with... Figure 3 and Figure 4 As shown, the method provided in this embodiment achieves efficient coordination and recovery of sessions through the following steps S1 to S3.
[0034] S1, Obtain dependency information and session persistence parameters In response to the establishment or update of a diagnostic session, the diagnostic tool actively acquires dependency information of multiple electronic control units (ECUs) in the vehicle network, as well as session maintenance timer parameters for each ECU.
[0035] Specifically, this step involves the interaction between the diagnostic tool and the vehicle communication interface (VCI) to collect information on multi-ECU dependencies and the session maintenance timer parameters of each ECU, providing basic data for subsequent session recovery. This step specifically includes sub-steps S101~S104: S101, triggers parameter acquisition process Combination Figure 4 As shown, in response to the establishment of a diagnostic session, network topology changes (such as adding / removing an ECU, updating gateway configuration), or timed synchronization events, the diagnostic tool sends a parameter acquisition command to the Vehicle Communication Interface (VCI) to request the dependency information of all concurrent diagnostic ECUs in the vehicle network and the session maintenance timer parameters.
[0036] S102, Issue a probe command and receive a response. After receiving the acquisition command, the Vehicle Communication Interface (VCI) transmits it to all electronic control units (ECUs) in the vehicle network (including CAN / LIN / K-Line protocol stacks) via its internal bus protocol stack (such as CAN / LIN / K-Line protocol stack). Figure 1 It can send session status detection commands or custom status query commands in parallel to the gateway ECU on the main bus, the engine ECU on the private network bus, the transmission ECU, the body control ECU, etc.
[0037] After receiving the instruction, each ECU returns the current session status (valid / invalid), session maintenance timer parameters (such as timer timeout threshold and current remaining time), and communication route parent node identifier (if it is a subnet ECU, it returns the ID of its parent node ECU; if it is a gateway ECU or an independent ECU, it returns its own ID to indicate that it has no parent node).
[0038] S103, Filter ECUs to be restored and initialize the set. The diagnostic tool analyzes the response data from each ECU transmitted back by the VCI and filters out the ECUs that need to be included in the recovery scope according to preset response judgment rules, for example: (1) If the ECU returns a positive response, indicating that the session is valid or the timer has not expired, the session is marked as valid and removed directly from the set R to be restored, without the need for subsequent restoration; (2) If the ECU returns a timeout response, a negative response, or a timer timeout, it is marked as session failure and kept in the set R to be recovered.
[0039] Simultaneously, the diagnostic tool parses and extracts the physical addresses, functional addresses, bus segments, parent-child routing dependency information, and session persistence timer parameters of all ECUs, including those in the vehicle configuration file or network topology description file, containing information on both the state to be restored and the active state. This information serves as the basis for subsequent topology construction and sequence adjustment. This dependency information is used to indicate at least one ECU as the communication routing parent node for another ECU.
[0040] S104, Construct and store the directed acyclic dependency topology graph. The diagnostic tool constructs a directed acyclic dependency topology graph (DAG) between ECUs based on the parent node identifiers of their communication routes. Each node in the constructed DAG topology graph represents an ECU and includes attributes such as: ECU identifier, session hold timer parameters, bus segment, and parent node reference. Edges in the DAG topology graph represent parent-child routing dependencies, with the edge direction pointing from the parent node to the child node. This indicates that communication between the child ECU and the child ECU must be routed through the parent node, with the logical relationship being: parent ECU → child ECU, for example: gateway ECU → engine ECU, gateway ECU → transmission ECU, gateway ECU → body control ECU.
[0041] The diagnostic instrument stores the directed acyclic topology graph to Figure 1 The topology graph storage unit is shown, and the session maintenance timer parameters (such as timeout threshold and current remaining time) of each ECU are marked in the topology graph to form parameterized dependency information.
[0042] Understandably, step S1, through operations such as detection, filtering, and topology construction, clarifies the gateway ECU routing paths that each subnet ECU must pass through for external communication, and establishes the parent-child hierarchical relationship of each ECU in the communication topology. Simultaneously, it collects and records the session maintenance timer timeout threshold and current countdown status of each ECU, providing a precise logical basis for subsequent steps of session validity prediction and recovery according to dependency order.
[0043] S2, Determine the session resumption order When the diagnostic tool detects an interruption event in the diagnostic session (e.g., abnormal termination of the session due to communication timeout, vehicle sleep-wake-up, or network topology change), the diagnostic tool comprehensively evaluates the session maintenance timer parameters of each ECU based on the dependency information obtained in step S1, and determines the session recovery order of multiple ECUs.
[0044] The diagnostic tool prioritizes parent nodes in routing, placing parent ECUs before child ECUs to ensure that the parent node has normal routing and forwarding capabilities before child node communication is restored.
[0045] In addition, the diagnostic tool estimates the remaining valid time after the interruption event based on the session maintenance timer parameters of each ECU, predicts the session validity status of each ECU, and dynamically adjusts the initially determined recovery order based on the prediction results, prioritizing the recovery of sessions that are about to time out to ensure the continuity of diagnostics.
[0046] Understandably, this step determines the session recovery order by comprehensively considering dependency information and session persistence timer parameters. This ensures that the ECU acting as the parent node of the communication route is recovered before its child ECUs, eliminating deadlock situations where child node recovery commands cannot be delivered due to the parent node's session not being recovered. At the same time, the recovery order is dynamically adjusted based on the session persistence timer parameters of each ECU, so that sessions about to time out can be processed first. This avoids misjudgments caused by a unified timeout judgment logic, reduces communication rejections caused by security access restrictions, thereby improving the targeting and success rate of the recovery operation and reducing the consumption of bus resources by invalid retries.
[0047] S3, sequentially perform state probing and hierarchical recovery based on dependency topology. Following the session recovery sequence determined in step S2, the diagnostic tool sequentially sends commands to multiple target ECUs via the Vehicle Communication Interface (VCI), in conjunction with... Figure 4 As shown, this step specifically includes sub-steps S301 to S305.
[0048] S301, Load the recovery order and determine the current level. The diagnostic tool reads the set R to be restored generated in the preceding steps and its corresponding session restoration order list. This list divides multiple ECUs into multiple levels according to dependency information. The first level contains the gateway ECU, which acts as the parent node for communication routing, and subsequent levels contain its downstream child node ECUs. The diagnostic tool processes the electronic control units within each level sequentially, starting from the first level.
[0049] S302, Perform time-division polling detection on the electronic control units within the current level. When multiple ECUs exist at the current level, the diagnostic tool uses a time-division polling approach to process them one by one to avoid excessive load caused by sending a large number of commands to the bus simultaneously. For the target ECU selected in the current round, the diagnostic tool sends a session activity probe command to it via VCI. This command is used to query whether the ECU is still in a valid non-default session state. The diagnostic tool starts a timer and waits for the ECU to return a response.
[0050] S303, Perform differentiated operations based on the detection response results. The diagnostic tool receives and parses the response message from the target ECU, and performs the following operations based on the response content: (1) If a positive response is received, it indicates that the diagnostic session of the ECU is still valid and does not need to be rebuilt. The diagnostic tool marks it as successfully restored and removes it from the set to be restored R without executing any additional session switching instructions.
[0051] (2) If no positive response is received or a negative response is received, it indicates that the diagnostic session for the ECU has failed and needs to be rebuilt. The diagnostic tool performs a session rebuild operation on the electronic control unit, specifically including: Send a request to the ECU to enter a non-default session, such as a diagnostic session control command in the UDS service, requesting a switch to an extended session or programming session; After successfully entering a non-default session, a secure access authentication process is executed, including operations such as sending a seed request, receiving a seed, calculating a key, and sending the key, in order to pass the secure access restrictions. After secure access authentication is successful, the diagnostic session recovery of the ECU is confirmed to be complete, and it is marked as successfully recovered and removed from the set R to be recovered.
[0052] S304, Hierarchical advancement and parent node priority protection After all ECUs in the current level have been processed, the diagnostic machine checks if a next level exists. If it does, before proceeding to the next level, it confirms that all parent node ECUs in the current level have been successfully restored. If the parent node restoration fails, based on the dependency information, all downstream child node ECUs that depend on this parent node are marked as unrecoverable and removed from the set to be restored R, while recording the reason for the failure. If the parent node restoration is successful, the machine proceeds to the next level and repeats sub-steps S302 to S304 until all levels have been processed.
[0053] S305, Summary of Recovery Results and End of Process The diagnostic tool determines whether the set R to be recovered is empty. If it is not empty, it continues to call the next ECU.
[0054] Repeat steps S301 to S305 until the set R to be restored is empty, which indicates that the status detection and restoration operations for all ECUs have been completed. At this point, the diagnostic tool summarizes the restoration results of all ECUs and generates a restoration report.
[0055] Understandably, this step is based on a hierarchical division of the dependency topology, prioritizing the recovery of gateway ECUs to ensure communication channel availability, thus eliminating deadlock issues caused by child node recovery commands failing to reach due to parent node session failure. A time-division polling approach is used to process multiple ECUs within the same level one by one, avoiding excessive load caused by sending a large number of commands to the bus simultaneously. Differentiated session state detection is used to perform reconstruction operations only on ECUs whose sessions have failed, skipping recovery for ECUs still in valid sessions, reducing unnecessary session switching commands and security access authentication processes, and lowering bus resource consumption. When a parent node fails to recover, all downstream child nodes dependent on that parent node are marked as unrecoverable and removed from the recovery set, preventing the failure of a single node from cascading and affecting the recovery process of other independent branches. Finally, through hierarchical advancement and cyclic control, until all ECUs at all levels have been processed, orderly, efficient, and fault-tolerant recovery of multi-ECU diagnostic sessions is achieved.
[0056] Figure 5 This invention provides a structural diagram of a session coordination and recovery system for a multi-ECU concurrent diagnostic scenario, as shown in the embodiment of the invention. Figure 5 As shown, a session coordination and recovery system for multi-ECU concurrent diagnostic scenarios includes a topology acquisition module, a recovery order determination module, and a session recovery execution module, wherein: The topology acquisition module is used to acquire dependency information of multiple electronic control units in the vehicle network. The dependency information is used at least to indicate that the first electronic control unit is the communication route parent node of the second electronic control unit. A recovery order determination module is used to determine the session recovery order of the plurality of electronic control units based on the dependency information in response to an interruption event of a diagnostic session. The session recovery execution module is used to perform session state detection and recovery operations on the plurality of electronic control units in sequence according to the session recovery order.
[0057] It is understood that the session coordination and recovery system for multi-ECU concurrent diagnostic scenarios provided by the present invention corresponds to the session coordination and recovery method for multi-ECU concurrent diagnostic scenarios provided in the foregoing embodiments. The relevant technical features of the session coordination and recovery system for multi-ECU concurrent diagnostic scenarios can be referred to the relevant technical features of the session coordination and recovery method for multi-ECU concurrent diagnostic scenarios, and will not be repeated here.
[0058] Please see Figure 6 , Figure 6 This is a schematic diagram illustrating an embodiment of the electronic device provided in this invention. For example... Figure 6As shown, this embodiment of the invention provides an electronic device 600, including a memory 610, a processor 620, and a computer program 611 stored in the memory 610 and executable on the processor 620. When the processor 620 executes the computer program 611, it performs the following steps: S1, Obtain dependency information of multiple electronic control units in the vehicle network. The dependency information is at least used to indicate that the first electronic control unit is the communication routing parent node of the second electronic control unit. The dependency information also includes session hold timer parameters of each electronic control unit. S2, in response to an interruption event of the diagnostic session, determine the session recovery order of the plurality of electronic control units based on the dependency information; Based on the session hold timer parameters, determine the session validity prediction result for each electronic control unit after the interruption event occurs, and adjust the session recovery order based on the session validity prediction result; S3, according to the session recovery order, perform session state detection and recovery operations on the plurality of electronic control units in sequence.
[0059] Please see Figure 7 , Figure 7 This is a schematic diagram illustrating an embodiment of a computer-readable storage medium provided by the present invention. (See diagram below.) Figure 7 As shown, this embodiment provides a computer-readable storage medium 700, on which a computer program 611 is stored. When the computer program 611 is executed by a processor, it performs the following steps: S1, Obtain dependency information of multiple electronic control units in the vehicle network. The dependency information is at least used to indicate that the first electronic control unit is the communication routing parent node of the second electronic control unit. The dependency information also includes session hold timer parameters of each electronic control unit. S2, in response to an interruption event of the diagnostic session, determine the session recovery order of the plurality of electronic control units based on the dependency information; Based on the session hold timer parameters, determine the session validity prediction result for each electronic control unit after the interruption event occurs, and adjust the session recovery order based on the session validity prediction result; S3, according to the session recovery order, perform session state detection and recovery operations on the plurality of electronic control units in sequence.
[0060] This invention provides a session coordination and recovery method, system, electronic device, and storage medium for concurrent diagnostic scenarios involving multiple ECUs. By acquiring the parent-child routing dependencies between multiple electronic control units in the vehicle network, the recovery order of each electronic control unit is determined based on this dependency information after a diagnostic session is interrupted. This ensures that the electronic control unit acting as the parent node of the communication route is recovered first, thereby providing an effective communication channel for the subsequent recovery of its downstream child node electronic control units. This eliminates the deadlock situation where the child node's recovery command cannot be delivered due to the parent node's session not being recovered. Simultaneously, by performing session state detection and recovery operations in a determined order, the actual session state of each electronic control unit can be distinguished. Unnecessary reconstruction of electronic control units that are still in a valid session state is skipped, reducing communication rejection and invalid occupation of bus resources caused by security access restrictions. This allows the recovery operation to focus on the electronic control units that truly need reconstruction, shortening the overall recovery time and improving the efficiency and reliability of session recovery in concurrent diagnostic scenarios involving multiple electronic control units.
[0061] It should be noted that the descriptions of each embodiment in the above embodiments have different focuses. For parts that are not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.
[0062] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0063] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0064] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0065] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0066] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention.
[0067] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. A session coordination and recovery method for multi-ECU concurrent diagnostic scenarios, characterized in that, include: Obtain dependency information of multiple electronic control units in the vehicle network, wherein the dependency information is at least used to indicate that the first electronic control unit is the communication routing parent node of the second electronic control unit; In response to a diagnostic session interruption event, the session recovery order of the plurality of electronic control units is determined based on the dependency information; In accordance with the session recovery order, session state detection and recovery operations are performed sequentially on the plurality of electronic control units.
2. The session coordination and recovery method for a multi-ECU concurrent diagnostic scenario according to claim 1, characterized in that, The dependency information also includes session hold timer parameters for each electronic control unit; The method also includes: Based on the session hold timer parameters, determine the session validity prediction result for each electronic control unit after the interruption event occurs, and adjust the session recovery order based on the session validity prediction result.
3. A session coordination and recovery method for a multi-ECU concurrent diagnostic scenario according to claim 1 or 2, characterized in that, The step of sequentially performing session state detection and recovery operations on the plurality of electronic control units according to the session recovery order includes: Send a session activity detection command to the electronic control unit currently awaiting recovery; If a positive response is received, the diagnostic session of the electronic control unit is determined to be still valid, and the recovery operation is skipped; If no positive response is received or a negative response is received, the diagnostic session of the electronic control unit is determined to be invalid, and a session reconstruction operation is performed.
4. The session coordination and recovery method for a multi-ECU concurrent diagnostic scenario according to claim 3, characterized in that, The execution of the session reconstruction operation includes: Send a request to the electronic control unit to enter a non-default session; After successfully entering a non-default session, a secure access authentication process is executed; After secure access authentication is successful, confirm that the diagnostic session of the electronic control unit has been restored.
5. A session coordination and recovery method for a multi-ECU concurrent diagnostic scenario according to claim 1 or 2, characterized in that, The step of sequentially performing session state detection and recovery operations on the plurality of electronic control units according to the session recovery order includes: Prioritize performing session state detection and recovery operations on the first electronic control unit, which serves as the parent node of the communication routing; After the session of the first electronic control unit is restored, the session state detection and restoration operation is then performed on the second electronic control unit.
6. A session coordination and recovery method for a multi-ECU concurrent diagnostic scenario according to claim 1 or 2, characterized in that, The method also includes: When a session recovery operation fails to be performed on the target electronic control unit, the downstream electronic control units that have a dependency relationship with the target electronic control unit are marked as unrecoverable based on the dependency information, and the session recovery operation continues to be performed on the electronic control units of other independent branches.
7. The session coordination and recovery method for a multi-ECU concurrent diagnostic scenario according to claim 1, characterized in that, The acquisition of dependency information among multiple electronic control units in the vehicle network includes: The physical address, functional address, network segment, parent-child routing dependency, and session persistence timer parameters of each electronic control unit are parsed from the vehicle configuration file or network topology description file. Based on the parsing results, a directed acyclic dependency topology graph is constructed, where nodes represent electronic control units, edges represent parent-child routing dependencies, and node attributes include at least session hold timer parameters.
8. The session coordination and recovery method for a multi-ECU concurrent diagnostic scenario according to claim 1, characterized in that, The step of sequentially performing session state detection and recovery operations on the plurality of electronic control units according to the session recovery order includes: Among multiple electronic control units at the same level, a time-division polling method is used to perform session state detection and recovery operations one by one in order to control the bus load.
9. A session coordination and recovery system for multi-ECU concurrent diagnostic scenarios, characterized in that, include: The topology acquisition module is used to acquire dependency information of multiple electronic control units in the vehicle network. The dependency information is used at least to indicate that the first electronic control unit is the communication route parent node of the second electronic control unit. A recovery order determination module is used to determine the session recovery order of the plurality of electronic control units based on the dependency information in response to an interruption event of a diagnostic session. The session recovery execution module is used to perform session state detection and recovery operations on the plurality of electronic control units in sequence according to the session recovery order.
10. An electronic device, characterized in that, The system includes a memory and a processor, wherein the processor is used to execute computer management programs stored in the memory to implement the steps of the session coordination and recovery method for a multi-ECU concurrent diagnostic scenario as described in any one of claims 1-8.