A method and apparatus for handling upgrade failure

CN122838149APending Publication Date: 2026-09-29ZHEJIANG GEELY HLDG GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610989178.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-03
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0003]然而,在实际应用过程中,OTA升级并非始终能够顺利完成,由于网络环境不稳定、车辆状态异常、控制器软硬件差异、售后维修或研发换件过程中人为操作不规范等原因,车辆在OTA推送或升级过程中经常会出现升级失败的情况,当OTA升级失败后,通常需要安排用户将车辆送至4S店或维修站点,通过人工方式连接诊断设备,对车辆进行检测、参数补写、例程控制或重新刷写软件,从而恢复车辆状态并完成升级,不仅显著增加用户的时间成本和不便体验,容易引发用户对车辆质量和品牌服务能力的不满,而且频繁的进店维修需要投入大量售后技术人员、人力资源和设备资源,显著提高了车企的运营成本

Benefits of technology

[0016]本发明的升级失败处理方法的有益效果是:通过在车辆升级失败时获取失败信息,并基于失败信息确定诊断修复方案,再将对应诊断修复指令下发至车辆执行诊断修复操作,使车辆在发生升级失败后能够通过远程方式进行自动修复,而无需依赖人工进店检测,也可以将诊断修复指令与升级包组合为联合升级包进行下发,使诊断修复与软件升级能够在同一升级流程中连续执行,减少多次通信交互带来的不稳定因素,从而提高升级失败处理效率,减少人工干预需求,并提升车辆远程升级的可靠性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122838149A_ABST
    Figure CN122838149A_ABST
Patent Text Reader

Abstract

The application provides an upgrade failure processing method and device, and relates to the technical field of vehicles.The upgrade failure processing method provided by the application comprises the following steps: in response to vehicle upgrade failure, failure information corresponding to the vehicle upgrade failure is acquired; a diagnosis repair scheme for repairing the vehicle upgrade failure is determined according to the failure information; diagnosis repair instructions corresponding to the diagnosis repair scheme are sent to the vehicle to perform diagnosis repair operation on the vehicle that has failed to upgrade, and an upgrade package is sent to the vehicle after the diagnosis repair operation is completed; and / or the diagnosis repair instructions corresponding to the diagnosis repair scheme and the upgrade package are combined into a joint upgrade package and sent to the vehicle, so that the vehicle sequentially performs diagnosis repair operation and software upgrade in a preset order.The application can improve the upgrade failure processing efficiency, reduce the need for manual intervention, and improve the reliability of vehicle remote upgrade.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle technology, and more specifically, to a method and apparatus for handling upgrade failures. Background Technology

[0002] With the continuous development of intelligent connected vehicles and vehicle electronic and electrical architecture, the number of vehicle controllers continues to increase, and software functions are highly integrated. During the vehicle's life cycle, the vehicle controller software needs to be remotely upgraded via OTA (Over-The-Air Technology) to achieve function iteration, defect repair, and performance optimization.

[0003] However, in practical applications, OTA upgrades are not always successful. Due to unstable network environments, abnormal vehicle status, differences in controller hardware and software, and improper human operation during after-sales maintenance or R&D parts replacement, vehicles often experience upgrade failures during OTA push or upgrade processes. When an OTA upgrade fails, users usually need to take their vehicles to 4S stores or repair stations to manually connect diagnostic equipment for vehicle testing, parameter rewriting, routine control, or software re-flashing to restore the vehicle's status and complete the upgrade. This not only significantly increases users' time costs and inconvenience, but also easily leads to user dissatisfaction with vehicle quality and brand service capabilities. Furthermore, frequent in-store repairs require a large investment of after-sales technicians, human resources, and equipment resources, significantly increasing the operating costs of car manufacturers. Summary of the Invention

[0004] The problem addressed by this invention is how to efficiently handle OTA upgrade failures.

[0005] To address the above problems, the present invention provides a method and apparatus for handling upgrade failures.

[0006] In a first aspect, the present invention provides an upgrade failure handling method applied in the cloud, the upgrade failure handling method comprising: In response to a vehicle upgrade failure, obtain the corresponding failure information. Based on the failure information, a diagnostic and repair plan is determined to fix the vehicle upgrade failure; The diagnostic repair instructions corresponding to the diagnostic repair scheme are sent to the vehicle to perform diagnostic repair operations on vehicles that have failed to upgrade, and the upgrade package is sent to the vehicle after the diagnostic repair operations are completed; and / or the diagnostic repair instructions corresponding to the diagnostic repair scheme and the upgrade package are combined into a joint upgrade package and sent to the vehicle so that the vehicle performs diagnostic repair operations and software upgrades in a preset order.

[0007] Optionally, the step of obtaining failure information corresponding to the vehicle upgrade failure in response to the vehicle upgrade failure includes: Obtain information about the target object where the upgrade failed, including information about the controller where the upgrade failed; The failure information of the corresponding controller is determined based on the controller information, and the failure information includes at least one of upgrade interruption information and upgrade exception information.

[0008] Optionally, determining the failure information of the corresponding controller based on the controller information includes: Based on the controller information, the execution status of the controller during the upgrade process is detected to determine whether the controller has experienced an upgrade interruption or upgrade anomaly. Based on the detection results, corresponding failure information is generated for the controller.

[0009] Optionally, determining the diagnostic and repair plan for fixing the vehicle upgrade failure based on the failure information includes: Determine the failure type corresponding to the vehicle upgrade failure based on the failure information; The diagnostic and repair plan is determined based on the failure type.

[0010] Optionally, determining the diagnostic and repair plan based on the failure type includes: Based on the failure type, a diagnostic and repair solution corresponding to the failure type is matched from a preset diagnostic and repair solution library, which includes diagnostic and repair solutions provided by different data sources.

[0011] Optionally, after determining the diagnostic and repair plan based on the failure type, the upgrade failure handling method further includes: The diagnostic and repair scheme is analyzed into at least one diagnostic and repair operation step; The diagnostic and repair operation steps generate diagnostic and repair instructions that can be executed by the vehicle.

[0012] Optionally, the upgrade failure handling method further includes: Receive diagnostic information from each controller uploaded by the vehicle, and update the correspondence between the failure information and the diagnostic repair plan based on the diagnostic information.

[0013] Secondly, the present invention provides an upgrade failure handling method, applied to the vehicle end, the upgrade failure handling method comprising: When a vehicle upgrade fails, the corresponding failure information will be sent to the cloud. The system receives diagnostic and repair instructions from the cloud, performs diagnostic and repair operations based on the instructions, and after completing the diagnostic and repair operations, receives an upgrade package from the cloud and performs a software upgrade based on the upgrade package; and / or receives a combined upgrade package from the cloud and performs diagnostic and repair operations and software upgrades sequentially according to a preset order based on the combined upgrade package, wherein the combined upgrade package includes the diagnostic and repair instructions and the upgrade package.

[0014] Thirdly, the present invention provides an upgrade failure handling device applied in the cloud, the upgrade failure handling device comprising: The first module is used to respond to vehicle upgrade failure and obtain the failure information corresponding to the vehicle upgrade failure. The second module is used to determine a diagnostic and repair plan for fixing vehicle upgrade failures based on the failure information. The third module is used to send the diagnostic repair instructions corresponding to the diagnostic repair scheme to the vehicle to perform diagnostic repair operations on the vehicle that has failed to upgrade, and to send the upgrade package to the vehicle after the diagnostic repair operation is completed; and / or to combine the diagnostic repair instructions corresponding to the diagnostic repair scheme and the upgrade package into a joint upgrade package and send it to the vehicle so that the vehicle can perform diagnostic repair operations and software upgrades in a preset order.

[0015] Fourthly, the present invention provides an upgrade failure handling device, applied to a vehicle, the upgrade failure handling device comprising: The fourth module is used to send the failure information corresponding to the vehicle upgrade failure to the cloud when the vehicle upgrade fails. The fifth module is used to receive diagnostic and repair instructions sent from the cloud, perform diagnostic and repair operations based on the diagnostic and repair instructions, and after completing the diagnostic and repair operations, receive an upgrade package sent from the cloud and perform a software upgrade based on the upgrade package; and / or receive a joint upgrade package sent from the cloud and perform diagnostic and repair operations and software upgrades in a preset order based on the joint upgrade package, wherein the joint upgrade package includes the diagnostic and repair instructions and the upgrade package.

[0016] The beneficial effects of the upgrade failure handling method of the present invention are as follows: by obtaining failure information when the vehicle upgrade fails, determining a diagnostic and repair plan based on the failure information, and then sending the corresponding diagnostic and repair instructions to the vehicle to perform the diagnostic and repair operation, the vehicle can be automatically repaired remotely after an upgrade failure, without relying on manual in-store inspection. Alternatively, the diagnostic and repair instructions can be combined with the upgrade package into a joint upgrade package for distribution, so that diagnostic repair and software upgrade can be executed continuously in the same upgrade process, reducing the instability caused by multiple communication interactions, thereby improving the efficiency of upgrade failure handling, reducing the need for manual intervention, and improving the reliability of remote vehicle upgrades. Attached Figure Description

[0017] Figure 1 This is a flowchart illustrating an upgrade failure handling method applied to the cloud according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the process for obtaining failure information according to an embodiment of the present invention; Figure 3 This is a flowchart illustrating the process of determining failure information according to an embodiment of the present invention; Figure 4 This is a schematic diagram of the process for determining a diagnostic and repair solution according to an embodiment of the present invention; Figure 5 This is a schematic diagram of the process for generating diagnostic and repair instructions according to an embodiment of the present invention; Figure 6 This is a flowchart illustrating an upgrade failure handling method applied to a vehicle according to an embodiment of the present invention. Figure 7 This is a system architecture diagram of an upgrade failure handling device applied to the cloud according to an embodiment of the present invention; Figure 8 This is a system architecture diagram of an upgrade failure handling device applied to a vehicle according to an embodiment of the present invention; Figure 9 This is a system architecture diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0018] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Although some embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present invention. It should be understood that the accompanying drawings and embodiments of the present invention are for illustrative purposes only and are not intended to limit the scope of protection of the present invention.

[0019] It should be understood that the various steps described in the method embodiments of the present invention may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this respect.

[0020] The term "comprising" and its variations as used herein are open-ended, meaning "including but not limited to"; the term "based on" means "at least partially based on"; the term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments"; and the term "optionally" means "optional embodiments". Definitions of other terms will be given in the following description. It should be noted that the concepts of "first," "second," etc., mentioned in this invention are used only to distinguish different devices, modules, or units, and are not intended to limit the order of functions performed by these devices, modules, or units or their interdependencies.

[0021] It should be noted that the terms "a" and "a plurality of" used in this invention are illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0022] The names of the messages or information exchanged between the multiple devices in the embodiments of the present invention are for illustrative purposes only and are not intended to limit the scope of these messages or information.

[0023] like Figure 1 As shown in the figure, an upgrade failure handling method provided by an embodiment of the present invention is applied in the cloud, and the upgrade failure handling method includes: S100: In response to a vehicle upgrade failure, obtain the failure information corresponding to the vehicle upgrade failure.

[0024] Specifically, this embodiment uses the application scenario of upgrading the whole vehicle or controller software via OTA as an example. The upgrade failure handling method can be applied to passenger cars, commercial vehicles, or other vehicles with remote upgrade capabilities. Vehicles typically include multiple electronic control units, such as body controllers, power controllers, smart cockpit controllers, and autonomous driving domain controllers. These controllers can be remotely upgraded via OTA. When the upgrade fails during the OTA process due to network fluctuations, controller malfunctions, uninitialized replacement parts, or missing parameters, the upgrade failure handling method in this embodiment can be triggered. For example, when the vehicle is performing an OTA upgrade task, the OTA intelligent diagnostic module on the vehicle side (which can be integrated into the driver information and entertainment host) can monitor the upgrade status of each controller in real time. When any controller is detected to have an upgrade interruption, flashing failure, or verification abnormality, it is determined that the vehicle has experienced an upgrade failure. The vehicle reports the upgrade failure event to the OTA intelligent computing platform (or other cloud platform), and the OTA intelligent computing platform obtains the failure information related to the upgrade failure.

[0025] S200: Determine a diagnostic and repair plan for fixing the vehicle upgrade failure based on the failure information.

[0026] Specifically, the OTA intelligent computing platform determines the diagnostic and repair solutions for vehicle upgrade failures based on the failure information. For example, if the failure information determines that the corresponding failure type is a communication interruption failure, the corresponding diagnostic and repair solution should include resetting the network connection or other diagnostic and repair solutions to resolve the communication interruption.

[0027] S300: Send the diagnostic repair instruction corresponding to the diagnostic repair scheme to the vehicle to perform diagnostic repair operations on the vehicle that has failed to upgrade, and send the upgrade package to the vehicle after the diagnostic repair operation is completed; and / or combine the diagnostic repair instruction corresponding to the diagnostic repair scheme and the upgrade package into a joint upgrade package and send it to the vehicle so that the vehicle performs diagnostic repair operations and software upgrades in a preset order.

[0028] Specifically, for example, if a 4S store replaces a part but does not perform a heavy-duty replacement and does not write the vehicle safety authentication parameters (such as pincodes or other vehicle-level security access codes / matching codes) and controller safety matching parameters (such as PK values ​​or other pairing / authentication key parameters), the OTA intelligent computing platform will convert the diagnostic and repair scheme into diagnostic and repair instructions and send them to the vehicle's intelligent diagnostic module through the vehicle network communication link. The vehicle will then execute the corresponding diagnostic and repair operations, such as performing routine control, parameter writing, or initialization operations, thereby restoring the controller state. After the controller completes the writing, it can also feed the writing results back to the OTA intelligent computing platform and synchronously display the intelligent electrical inspection steps through the human-machine interface. Users receive intuitive feedback. After the repair is completed, the electronic diagnostic platform pushes an OTA upgrade task again, sending the upgrade package to the vehicle. Users can click to complete the upgrade, or the diagnostic repair instructions and the upgrade package can be combined into a joint upgrade package and sent to the vehicle. After completing the diagnostic repair operation according to the joint upgrade package, the software upgrade is performed. This allows the vehicle to automatically restore the upgrade environment (e.g., restore the controller to a communicable, authorizable, and rewritable state) and complete subsequent upgrade tasks after an upgrade failure, reducing the need for manual intervention. In another embodiment, the OTA intelligent computing platform can send the diagnostic repair solution to the vehicle's OTA intelligent diagnostic module, which then automatically retrieves the diagnostic repair instructions based on the failure situation.

[0029] In this embodiment, failure information is obtained when a vehicle upgrade fails, and a diagnostic and repair plan is determined based on the failure information. Then, the corresponding diagnostic and repair instructions are sent to the vehicle to perform the diagnostic and repair operation. This allows the vehicle to be automatically repaired remotely after an upgrade failure, without relying on manual in-store inspection. Alternatively, the diagnostic and repair instructions can be combined with the upgrade package into a joint upgrade package for distribution, allowing diagnostic repair and software upgrade to be executed continuously in the same upgrade process. This reduces the instability caused by multiple communication interactions, thereby improving the efficiency of upgrade failure handling, reducing the need for manual intervention, and enhancing the reliability of remote vehicle upgrades.

[0030] Optionally, the step of obtaining failure information corresponding to the vehicle upgrade failure in response to the vehicle upgrade failure includes: S110: Obtain information about the target object where the upgrade failed, including information about the controller where the upgrade failed.

[0031] Specifically, during the upgrade process, the vehicle continuously collects the upgrade execution status of each controller. When an abnormal termination of the upgrade process, a flash rollback, or a verification failure is detected, the information of the target object where the upgrade failed is recorded, such as the controller number, controller software version number, upgrade package identification information, and current flashing progress.

[0032] S120: Determine the failure information of the corresponding controller based on the controller information, wherein the failure information includes at least one of upgrade interruption information and upgrade exception information.

[0033] Specifically, based on the controller information, the failure information corresponding to each controller is further determined, such as whether it is an upgrade interruption or an upgrade anomaly.

[0034] In this optional embodiment, by obtaining the target object information where the upgrade failed and determining the corresponding controller's failure information based on the controller information, the upgrade failure can be accurately located to the specific controller, thereby avoiding indiscriminate processing of the entire vehicle, improving the accuracy of failure identification, and reducing unnecessary diagnostic operations.

[0035] Optionally, determining the failure information of the corresponding controller based on the controller information includes: S121: Based on the controller information, the execution status of the controller during the upgrade process is detected to determine whether the controller has experienced an upgrade interruption or upgrade anomaly.

[0036] Specifically, the execution status of the controller upgrade process is detected by reading the controller write log, diagnostic fault codes, or upgrade status flags. For example, if the write process is detected to be incomplete and then exits, it is determined to be an upgrade interruption. If the verification is inconsistent or the write fails, it is determined to be an upgrade anomaly.

[0037] S122: Generate failure information corresponding to the controller based on the detection results.

[0038] Specifically, based on the detection results, corresponding failure information is generated for each controller that experiences an anomaly, and a set of failure information is uploaded to the OTA intelligent computing platform.

[0039] In this optional embodiment, by detecting the execution status of the controller during the upgrade process and generating corresponding failure information based on the detection results, the system can distinguish between different failure forms such as upgrade interruption and upgrade anomaly. This facilitates the adoption of differentiated repair measures for different failure types, thereby improving the pertinence and effectiveness of diagnosis and repair.

[0040] Optionally, determining the diagnostic and repair plan for fixing the vehicle upgrade failure based on the failure information includes: S210: Determine the failure type corresponding to the vehicle upgrade failure based on the failure information.

[0041] Specifically, after receiving failure information, the OTA intelligent computing platform can analyze the failure information to determine the failure type. Failure types may include parameter missing failure, component uninitialization failure, communication interruption failure, and software package mismatch failure. S220: Determine the diagnostic and repair plan based on the failure type.

[0042] Specifically, after determining the failure type, the OTA intelligent computing platform can select an appropriate diagnostic and repair solution from the corresponding failure type and repair strategy mapping relationship. For example, the diagnostic and repair solution for parameter missing failure is to write the vehicle safety authentication parameters to the target controller. For example, the diagnostic and repair solution for component replacement failure is to execute the controller initialization routine and write the basic configuration parameters. For example, the diagnostic and repair solution for communication interruption failure is to re-establish the communication session and perform breakpoint resume flashing. For example, the diagnostic and repair solution for software package mismatch failure is to re-match the software version and send an appropriate software package for flashing.

[0043] In this optional embodiment, failure information is analyzed to determine the failure type, and a diagnostic and repair plan is determined based on the failure type. This transforms the failure handling from a single processing mode to a classified processing mode, thereby improving the matching degree of the repair plan and increasing the success rate of upgrade failure repair.

[0044] Optionally, determining the diagnostic and repair plan based on the failure type includes: Based on the failure type, a diagnostic and repair solution corresponding to the failure type is matched from a preset diagnostic and repair solution library, which includes diagnostic and repair solutions provided by different data sources.

[0045] Specifically, the preset diagnostic and repair solution library can be built from various sources, such as historical OTA upgrade failure cases and their successful repair records, or diagnostic definition files and repair strategies provided by various ECU development centers, or repair solutions accumulated by the OTA delivery team in the actual delivery process, or initialization operation templates formed during the R&D phase; after determining the failure type, the preset diagnostic and repair solution library can be matched with the corresponding diagnostic and repair solution based on the failure type.

[0046] Taking the maintenance solutions accumulated by the OTA delivery team as an example, when a vehicle OTA upgrade fails, the OTA delivery team first classifies the failed vehicles and adds them to the corresponding failed vehicle pools according to the failure type, such as parameter anomaly pools, controller replacement pools, and communication anomaly pools. Then, the OTA delivery team analyzes the vehicles in the pools to determine the problematic controller and possible causes. After the analysis, the corresponding diagnostic and repair instructions for the controller are filled into the OTA intelligent computing platform. The OTA intelligent computing platform packages the diagnostic and repair instructions and pushes the package to the OTA intelligent diagnostic module on the vehicle. The diagnostic and repair package can be combined with the OTA software upgrade package for delivery. The diagnostic and repair module upgrade is executed first, followed by the controller software upgrade. Because the diagnostic and repair module on the vehicle side... The diagnostic capability is related to its software version. Different versions support different types of diagnostic services, parameter writing capabilities, and security access policies. By upgrading the diagnostic and repair module, it is made capable of handling new failure types and new controllers, thereby ensuring that diagnostic and repair instructions can be executed correctly, improving the success rate of diagnostic and repair, and reducing repeated upgrade failures caused by insufficient diagnostic capabilities, thus solving the problem in one go. In addition, it also supports silent upgrade mode (user unaware) and user click confirmation upgrade mode. In another embodiment, when the vehicle OTA upgrade fails, the OTA intelligent computing platform classifies the failed vehicles and organizes them into the corresponding failed vehicle pool. The OTA delivery team inputs modular diagnostic instructions based on the batch failure situation and sends them to the vehicle to upgrade, thereby completing the upgrade and repair and realizing batch processing.

[0047] In this optional embodiment, by constructing a solution library containing multi-source diagnostic and repair solutions, the diagnostic and repair solutions can be accumulated and reused based on historical cases, controller diagnostic information, or human experience, thereby reducing redundant development work, improving the efficiency of obtaining repair solutions, and enhancing the system's adaptability to diverse upgrade failure scenarios.

[0048] Optionally, after determining the diagnostic and repair plan based on the failure type, the upgrade failure handling method further includes: S230: The diagnostic and repair scheme is parsed into at least one diagnostic and repair operation step.

[0049] Specifically, after determining the diagnostic and repair plan, the OTA intelligent computing platform can analyze the plan and break it down into multiple diagnostic and repair operation steps, such as establishing a diagnostic session, unlocking secure access, writing execution parameters, and executing routine control. S240: Generate diagnostic and repair instructions that can be executed by the vehicle according to the diagnostic and repair operation steps.

[0050] Specifically, the above operation steps are converted into a standardized diagnostic instruction sequence, such as the UDS diagnostic instruction sequence, thereby generating diagnostic and repair instructions that can be executed by the vehicle. Taking writing safety parameters (Pincode and PK value) to the ECU via the UDS diagnostic protocol as an example, firstly, the SBL (Secondary Bootloader) is flashed without flashing the software, that is, only the boot environment is updated or enabled, without updating the business software, so that the controller enters a boot or maintenance state that supports parameter writing. A diagnostic communication session is established without updating the controller's business software to ensure that the flashing safety operation can be executed. Then, safety authentication parameters are written to the controller via the standard diagnostic protocol, such as writing Pincode to the designated storage area of ​​the ECU and writing the pairing key, so that the target controller completes the matching and binding with the vehicle's safety system, thereby restoring the controller's normal upgrade capability and functional state.

[0051] In this optional embodiment, by parsing the diagnostic and repair scheme into multiple diagnostic and repair operation steps and generating vehicle-executable diagnostic and repair instructions accordingly, the abstract repair scheme can be transformed into standardized execution instructions, thereby improving the consistency and operability of scheme execution and reducing the risks caused by differences in human operation.

[0052] Optionally, the upgrade failure handling method further includes: Receive diagnostic information from each controller uploaded by the vehicle, and update the correspondence between the failure information and the diagnostic repair plan based on the diagnostic information.

[0053] Specifically, the OTA intelligent computing platform has self-learning and updating capabilities. For example, each ECU center can upload newly defined diagnostic information, parameter definitions, or repair strategies to the OTA intelligent computing platform. The OTA intelligent computing platform identifies, organizes, and structures the above information, and updates the mapping relationship between failure information and diagnostic repair solutions. The updated corresponding mapping relationship is stored in the diagnostic repair solution library for subsequent upgrade failure handling. For example, when a new upgrade failure mode appears in the market, the new repair solution can be automatically applied to subsequent vehicles without manual intervention on a vehicle-by-vehicle basis.

[0054] In this optional embodiment, by updating the correspondence between failure information and diagnostic repair solutions based on controller diagnostic information, the system can continuously optimize the solution matching relationship according to the newly added diagnostic data, thereby improving the system's adaptability to new upgrade failure problems and enhancing the system's continuous evolution capability.

[0055] like Figure 6 As shown in the figure, an upgrade failure handling method provided by an embodiment of the present invention is applied to the vehicle end. The upgrade failure handling method includes: S400: When a vehicle upgrade fails, the corresponding failure information will be sent to the cloud.

[0056] Specifically, when an OTA upgrade fails, the vehicle can collect abnormal information during the upgrade process and generate failure information corresponding to the upgrade failure. This information may include upgrade interruption information, upgrade abnormal information, fault code information, controller identification information, upgrade task information, software version information, and controller operating status information. The vehicle then sends the failure information to the cloud via the vehicle network communication link. The cloud analyzes the cause of the upgrade failure and generates a corresponding diagnostic and repair solution.

[0057] S500: Receive the diagnostic repair instruction sent from the cloud, perform diagnostic repair operations based on the diagnostic repair instruction, and after completing the diagnostic repair operations, receive the upgrade package sent from the cloud and perform a software upgrade based on the upgrade package; and / or receive the joint upgrade package sent from the cloud, and perform the diagnostic repair operations and software upgrades sequentially according to a preset order based on the joint upgrade package, wherein the joint upgrade package includes the diagnostic repair instruction and the upgrade package.

[0058] Specifically, the cloud determines the failure type of the vehicle upgrade failure based on the failure information, generates corresponding diagnostic and repair instructions based on the failure type, and sends the diagnostic and repair instructions to the vehicle. Upon receiving the instructions, the vehicle's onboard intelligent diagnostic module parses them and executes the corresponding diagnostic and repair operations. For example, if the cloud determines that the upgrade failure is due to the controller lacking vehicle safety certification parameters, the intelligent diagnostic module can automatically execute the safety certification parameter writing process according to the diagnostic and repair instructions, writing the corresponding vehicle safety certification parameters to the target controller, enabling the target controller to re-match and bind with the vehicle's safety system. Another example is when the upgrade failure is due to the controller not being initialized after component replacement; the intelligent diagnostic module can automatically execute the controller initialization routine according to the diagnostic and repair instructions and write the corresponding initialization parameters or basic configuration parameters to the target controller, thereby restoring the controller to normal working status. After completing the diagnostic and repair operations, the vehicle can report the diagnostic and repair results to the cloud. If the diagnostic and repair is successful, the vehicle receives the upgrade package sent by the cloud and... In one implementation, the upgrade package executes the corresponding software upgrade operation to re-execute failed upgrade tasks. Alternatively, the cloud can combine diagnostic repair instructions with the upgrade package to form a joint upgrade package, which is then sent to the vehicle in one go. Upon receiving the joint upgrade package, the vehicle's intelligent diagnostic module parses it, identifies the diagnostic repair tasks and software upgrade tasks contained within, and executes the corresponding operations sequentially according to a preset order. For example, the vehicle first executes the diagnostic repair task, performing parameter rewriting, initialization configuration, communication restoration, or security authentication restoration for the controller. After the diagnostic repair task is completed, the controller software upgrade process is automatically initiated, performing software flashing on the target controller. This method avoids directly upgrading the software under abnormal conditions, improving the upgrade success rate. After completing the diagnostic repair and software upgrade, the vehicle can also feed back the diagnostic repair results, upgrade results, and controller operating status to the cloud, allowing the cloud to update the mapping relationship between failure types and diagnostic repair solutions, improving the processing efficiency and repair success rate of subsequent upgrade failures of the same type.

[0059] In addition, during the diagnosis and repair process, the vehicle's human-machine interface can be linked with the OTA intelligent diagnostic module to display information on the current diagnostic steps, including the name of the current step, the progress status, whether user cooperation is required, and feedback on the results. For example, when writing controller parameters, the human-machine interface can display "Vehicle safety parameter verification and writing is in progress," allowing the user to understand the current processing progress. When the diagnosis and repair are completed, the human-machine interface can prompt the user with the repair results and subsequent upgrade suggestions. In this way, the user's perception of the remote repair process can be enhanced, reducing the uncertainty caused by upgrade failure.

[0060] In addition, when the diagnostic and repair plan involves controller initialization or replacement matching, the intelligent diagnostic module can automatically write initial parameter information to the target controller according to the diagnostic and repair plan. This includes controller initialization parameters, vehicle configuration parameters, safety certification parameters, and controller matching parameters. For example, when the controller is detected as a newly replaced part that has not been initialized, the initialization process can be automatically executed and the required parameters can be written without manual configuration. By automatically filling in the initial parameters, manual intervention can be reduced, the consistency of parameter writing can be improved, and the risk of human error can be reduced.

[0061] like Figure 7 As shown, an upgrade failure handling device 700 provided in this embodiment of the invention is applied in the cloud. The upgrade failure handling device 700 includes: The first module 710 is used to obtain failure information corresponding to the vehicle upgrade failure in response to the vehicle upgrade failure. The second module 720 is used to determine a diagnostic and repair plan for repairing vehicle upgrade failure based on the failure information. The third module 730 is used to send the diagnostic repair instructions corresponding to the diagnostic repair scheme to the vehicle to perform diagnostic repair operations on the vehicle that has failed to upgrade, and to send the upgrade package to the vehicle after the diagnostic repair operations are completed; and / or to combine the diagnostic repair instructions corresponding to the diagnostic repair scheme and the upgrade package into a joint upgrade package and send it to the vehicle so that the vehicle can perform diagnostic repair operations and software upgrades in a preset order.

[0062] like Figure 8 As shown, an upgrade failure handling device 800 provided in this embodiment of the invention is applied to a vehicle. The upgrade failure handling device 800 includes: The fourth module 840 is used to send the failure information corresponding to the vehicle upgrade failure to the cloud when the vehicle upgrade fails. The fifth module 850 is used to receive diagnostic and repair instructions sent from the cloud, perform diagnostic and repair operations based on the diagnostic and repair instructions, and after completing the diagnostic and repair operations, receive an upgrade package sent from the cloud and perform a software upgrade based on the upgrade package; and / or receive a joint upgrade package sent from the cloud and perform diagnostic and repair operations and software upgrades in a preset order based on the joint upgrade package, wherein the joint upgrade package includes the diagnostic and repair instructions and the upgrade package.

[0063] like Figure 9 As shown, an electronic device 900 provided in this embodiment of the invention includes a memory 920 and a processor 910; the memory 920 is used to store a computer program; the processor 910 is used to implement the upgrade failure handling method described above when the computer program is executed.

[0064] Alternatively, an electronic device 900 includes a memory 920 and a processor 910 coupled to the memory 920; the memory 920 is configured to store a computer program; and the processor 910 is configured to perform the following operations when the computer program is executed: In response to a vehicle upgrade failure, obtain the corresponding failure information. Based on the failure information, a diagnostic and repair plan is determined to fix the vehicle upgrade failure; The diagnostic repair instructions corresponding to the diagnostic repair scheme are sent to the vehicle to perform diagnostic repair operations on vehicles that have failed to upgrade, and the upgrade package is sent to the vehicle after the diagnostic repair operations are completed; and / or the diagnostic repair instructions corresponding to the diagnostic repair scheme and the upgrade package are combined into a joint upgrade package and sent to the vehicle so that the vehicle performs diagnostic repair operations and software upgrades in a preset order.

[0065] This invention provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the upgrade failure handling method described above.

[0066] Alternatively, a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, causes the processor to perform the following operations: In response to a vehicle upgrade failure, obtain the corresponding failure information. Based on the failure information, a diagnostic and repair plan is determined to fix the vehicle upgrade failure; The diagnostic repair instructions corresponding to the diagnostic repair scheme are sent to the vehicle to perform diagnostic repair operations on vehicles that have failed to upgrade, and the upgrade package is sent to the vehicle after the diagnostic repair operations are completed; and / or the diagnostic repair instructions corresponding to the diagnostic repair scheme and the upgrade package are combined into a joint upgrade package and sent to the vehicle so that the vehicle performs diagnostic repair operations and software upgrades in a preset order.

[0067] The present invention will now be described an electronic device 900 that can serve as a server or client of the present invention, which is an example of a hardware device that can be applied to various aspects of the present invention. Electronic device 900 is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. Electronic device 900 can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0068] Electronic device 900 includes a computing unit that can perform various appropriate actions and processes based on a computer program stored in read-only memory (ROM) or a computer program loaded from a storage unit into random access memory (RAM). The RAM may also store various programs and data required for device operation. The computing unit, ROM, and RAM are interconnected via a bus. Input / output (I / O) interfaces are also connected to the bus.

[0069] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc. In this application, the units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiments of the present invention according to actual needs. Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units can be implemented in hardware or as software functional units.

[0070] While the present invention has been disclosed above, its scope of protection is not limited thereto. Those skilled in the art can make various changes and modifications without departing from the spirit and scope of the present invention, and all such changes and modifications will fall within the scope of protection of the present invention.

Claims

1. A method for handling upgrade failures, characterized in that, Applied to the cloud, the upgrade failure handling method includes: In response to a vehicle upgrade failure, obtain the corresponding failure information. Based on the failure information, a diagnostic and repair plan is determined to fix the vehicle upgrade failure; The diagnostic repair instructions corresponding to the diagnostic repair scheme are sent to the vehicle to perform diagnostic repair operations on vehicles that have failed to upgrade, and the upgrade package is sent to the vehicle after the diagnostic repair operations are completed; and / or the diagnostic repair instructions corresponding to the diagnostic repair scheme and the upgrade package are combined into a joint upgrade package and sent to the vehicle so that the vehicle performs diagnostic repair operations and software upgrades in a preset order.

2. The upgrade failure handling method according to claim 1, characterized in that, In response to a vehicle upgrade failure, obtaining the corresponding failure information includes: Obtain information about the target object where the upgrade failed, including information about the controller where the upgrade failed; The failure information of the corresponding controller is determined based on the controller information, and the failure information includes at least one of upgrade interruption information and upgrade exception information.

3. The upgrade failure handling method according to claim 2, characterized in that, The step of determining the failure information of the corresponding controller based on the controller information includes: Based on the controller information, the execution status of the controller during the upgrade process is detected to determine whether the controller has experienced an upgrade interruption or upgrade anomaly. Based on the detection results, corresponding failure information is generated for the controller.

4. The upgrade failure handling method according to claim 1, characterized in that, The diagnostic and repair plan determined based on the failure information includes: Determine the failure type corresponding to the vehicle upgrade failure based on the failure information; The diagnostic and repair plan is determined based on the failure type.

5. The upgrade failure handling method according to claim 4, characterized in that, Determining the diagnostic and repair plan based on the failure type includes: Based on the failure type, a diagnostic and repair solution corresponding to the failure type is matched from a preset diagnostic and repair solution library, which includes diagnostic and repair solutions provided by different data sources.

6. The upgrade failure handling method according to claim 1, characterized in that, After determining the diagnostic and repair plan based on the failure type, the upgrade failure handling method further includes: The diagnostic and repair scheme is analyzed into at least one diagnostic and repair operation step; The diagnostic and repair operation steps generate diagnostic and repair instructions that can be executed by the vehicle.

7. The upgrade failure handling method according to any one of claims 1 to 6, characterized in that, Also includes: Receive diagnostic information from each controller uploaded by the vehicle, and update the correspondence between the failure information and the diagnostic repair plan based on the diagnostic information.

8. A method for handling upgrade failures, characterized in that, When applied to the vehicle side, the upgrade failure handling method includes: When a vehicle upgrade fails, the corresponding failure information will be sent to the cloud. The system receives diagnostic and repair instructions from the cloud, performs diagnostic and repair operations based on the instructions, and after completing the diagnostic and repair operations, receives an upgrade package from the cloud and performs a software upgrade based on the upgrade package; and / or receives a combined upgrade package from the cloud and performs diagnostic and repair operations and software upgrades sequentially according to a preset order based on the combined upgrade package, wherein the combined upgrade package includes the diagnostic and repair instructions and the upgrade package.

9. An upgrade failure handling device, characterized in that, The upgrade failure handling device, applied in the cloud, includes: The first module is used to respond to vehicle upgrade failure and obtain the failure information corresponding to the vehicle upgrade failure. The second module is used to determine a diagnostic and repair plan for fixing vehicle upgrade failures based on the failure information. The third module is used to send the diagnostic repair instructions corresponding to the diagnostic repair scheme to the vehicle to perform diagnostic repair operations on the vehicle that has failed to upgrade, and to send the upgrade package to the vehicle after the diagnostic repair operation is completed; and / or to combine the diagnostic repair instructions corresponding to the diagnostic repair scheme and the upgrade package into a joint upgrade package and send it to the vehicle so that the vehicle can perform diagnostic repair operations and software upgrades in a preset order.

10. An upgrade failure handling device, characterized in that, Applied to the vehicle end, the upgrade failure handling device includes: The fourth module is used to send the failure information corresponding to the vehicle upgrade failure to the cloud when the vehicle upgrade fails. The fifth module is used to receive diagnostic and repair instructions sent from the cloud, perform diagnostic and repair operations based on the diagnostic and repair instructions, and after completing the diagnostic and repair operations, receive an upgrade package sent from the cloud and perform a software upgrade based on the upgrade package; and / or receive a joint upgrade package sent from the cloud and perform diagnostic and repair operations and software upgrades in a preset order based on the joint upgrade package, wherein the joint upgrade package includes the diagnostic and repair instructions and the upgrade package.