Doip transmission upgrade package-based verification field generation method and system
In the technology of DoIP transmission upgrade packets, the upgrade packet verification field is generated based on the upgrade packet integrity detection and message information detection, which solves the problem of inconsistency of the upgrade packet and the increase in system load, and realizes the effective checksum content integrity guarantee for the upgrade packet.
Patent Information
- Application Number
- PCT/CN2024/111086
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-13
- Filing Date
- 2024-08-09
- Publication Date
- 2025-06-19
AI Technical Summary
The existing technology based on DoIP transmission upgrade packets has the risk of inconsistency in upgrading packets and the problem of increasing system load, and it is impossible to effectively use specific invalid fields for upgrade packet verification.
In response to the upgrade download request, the first fixed value and the first check value are obtained based on the integrity detection of the upgrade packet, and whether the first address of the upgrade packet is stored in the request message information meets the preset conditions, and the first fixed value is filled in the area to be filled to obtain the second check value, encapsulating the first check value and the second check value to generate the upgrade packet verification field.
Double verification of the upgrade package size and content is achieved, ensuring that the upgrade package is not tampered with, and the risk of additional verification instructions increasing the system load is avoided.
Smart Images

Figure CN2024111086_19062025_PF_FP_ABST
Abstract
Description
A method and system for generating check field based on DoIP transmission upgrade package Technical Field
[0001] The present invention relates to the field of vehicle diagnosis and upgrade control, and in particular to a method and system for generating a check field of an upgrade package based on DoIP transmission, and a method and device for checking and upgrading the check field. Background Art
[0002] The existing DoIP (Diagnostic Communication Protocol over Internet Protocol) upgrade package transmission process can refer to the ISO 13400-1 standard. In this standard, there is no verification of the upgrade package before, during, or after the upgrade package transmission. Although a new DID (Data Identification) or RID (Routine Control Identification) can be added after the step to verify the upgrade package, there will be the following technical problems.
[0003] 1. There is a risk of inconsistent upgrade packages: The 0x34 service request for the vehicle to download the upgrade package is inconsistent with the actual transmission of the upgrade package through 0x36. The current verification method only performs a simple integrity check on the received data packet, such as whether it can be fully compressed and whether the upgrade service can be decompressed normally. For example, the OTA upgrade system and method for an in-vehicle infotainment system based on the DoIP protocol disclosed in 202210670170.5. Because the contents of the upgrade package cannot be verified, there is a risk of tampering with the system or bricking the system during installation.
[0004] 2. Increase system load and number of operations: Subsequent additions such as DID or RID to verify the upgrade package also increase the DoIP load and the number of operations, requiring additional commands and failing to implement active verification of the upgrade package.
[0005] When deploying diagnostic upgrades based on DoIP, certain fields in the upgrade package request message are wasted under certain circumstances. For example, when deploying the Autosar diagnostic module on an Android platform, Android lacks a memory address (memoryAddress). The upgrade package is placed directly in a specific Android path. Therefore, for the 0x34 service, the memoryAddress field is wasted and serves no purpose, allowing it to be used with any value and meaningless.
[0006] Therefore, there is still a great need to improve the DoIP upgrade package transmission technology, effectively utilize specific invalid fields without increasing the system load, and improve the upgrade package verification field generation and verification method.
[0007] Summary of the Invention
[0008] The purpose of the present invention is to provide a method, system, verification upgrade method and device for generating a check field based on DoIP transmission upgrade package. The present invention solves the problem that the poor correlation between check field generation and upgrade package content affects the accuracy of the upgrade package, and additional verification instructions increase the load of the upgrade system.
[0009] The present invention provides the following solutions
[0010] In the first aspect, the present invention describes a method for generating a check field based on a DoIP transmission upgrade package, comprising the following steps:
[0011] S1: In response to an upgrade download request, obtaining a first fixed value based on an integrity check of the upgrade package, and obtaining a first checksum based on a size check of the upgrade package;
[0012] S2: Detect whether the first address of the upgrade package stored in the request message meets a preset condition. If so, set the storage area corresponding to the first address as a to-be-filled area;
[0013] S3: After verifying the first fixed value, fill the first fixed value into the to-be-filled area to obtain a second verification value;
[0014] S4: Encapsulate the first verification value and the second verification value to obtain the upgrade package verification field.
[0015] Obtaining the first fixed value based on performing integrity detection on the upgrade package includes performing integrity detection on the upgrade package using a preset algorithm to obtain a first fixed value having a first byte length.
[0016] The detection request message information stores whether the first address of the upgrade package meets the preset conditions. If so, the first address is set as the area to be filled; including responding to the diagnostic service command, detecting whether the corresponding operating platform has a storage area corresponding to the first address of the upgrade package. If not, confirming that the storage area corresponding to the first address meets the second byte length, and setting the storage area as the area to be filled.
[0017] After verifying the first fixed value, filling the first fixed value into the to-be-filled area to obtain a second verification value includes verifying the first fixed value using a cyclic redundancy check so that the verified first fixed value has a third byte length, and the third byte length is less than the first byte length;
[0018] When the third byte length does not exceed the second byte length, the first fixed value is filled into the to-be-filled area to obtain a second check value.
[0019] In the second aspect, the present invention describes a check field generation system based on DoIP transmission upgrade package, the generation system includes
[0020] an upgrade package detection module, configured to detect the upgrade package to be upgraded, so as to obtain a first fixed value corresponding to the integrity of the upgrade package and a first check value corresponding to the size of the upgrade package;
[0021] A message detection module is used to detect whether the request message information meets the preset conditions and identify the storage area corresponding to the first address in the request message information as the area to be filled;
[0022] A verification module, configured to verify the first fixed value so that the byte length of the verified first fixed value does not exceed the length of the area to be filled;
[0023] A filling module is used to fill the first fixed value into the to-be-filled area to obtain a second verification value.
[0024] The check field generation system also includes
[0025] The encapsulation and sending module is used to encapsulate the first verification value and the second verification value to obtain the upgrade package verification field, and send the upgrade package verification field to the upgrade verification end.
[0026] In the third aspect, the present invention records a verification and upgrade method based on DoIP transmission upgrade package, comprising the following steps:
[0027] S1: connect to the host computer and stop status update and other operations;
[0028] S2: Enter bootloader mode (programming session), after security unlocking, send upgrade download request to the host computer;
[0029] S3: Receive the upgrade package checksum sent by the host computer through the upgrade download service;
[0030] S4: Receive the upgrade package sent by the host computer through the data transmission service;
[0031] S5: Use the upgrade package verification field to verify the received upgrade package, and install the upgrade package after the verification is complete;
[0032] The upgrade package check field is generated using the above-mentioned check field generation method.
[0033] The receiving host computer sends the upgrade package through the data transmission service, including
[0034] S41: receiving the upgrade package size sent by the host computer through the upgrade download service;
[0035] S42: Determine the maximum amount of data to be transmitted each time by the data transmission service based on the size of the upgrade package, and feed it back to the host computer;
[0036] S43: Receive the upgrade package data that is continuously sent by the host computer through the data transmission service until the sending is completed.
[0037] The upgrade package verification field is used to verify the received upgrade package, and the upgrade package is installed after the verification is completed, including
[0038] After the transmission is completed, the upgrade package transmission completion is fed back by requesting to exit the transmission service, and the received upgrade package is verified using the upgrade package verification field.
[0039] In a fourth aspect, the present invention describes a verification and upgrade device based on DoIP transmission upgrade package, comprising:
[0040] The upgrade verification terminal receives the upgrade download request sent by the host computer and verifies the upgrade package through the upgrade package verification field after receiving the complete upgrade package;
[0041] Verification field generation system, used to generate upgrade package verification fields;
[0042] The data link module, in response to the upgrade download service and the data transmission service, enables the upgrade verification terminal and the host computer to be in a data link open state during the upgrade package verification field and the upgrade package data transmission;
[0043] The check field generation system is based on the check field generation system of the DoIP transmission upgrade package.
[0044] Compared with the prior art, the present invention has the following advantages: the upgrade package verification field generated by the present invention is derived from the upgrade package content information, and the upgrade package verification field contained therein can not only verify the size but also the content, and part of the verification field is filled in the message information. No additional instructions are required, and the upgrade verification end actively verifies the received upgrade package, which not only eliminates the risk of the upgrade package not being able to be decompressed normally or the installation error causing the vehicle system to become bricked, but also does not increase the load on the upgrade system. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0046] FIG1 is a flow chart of an embodiment of a method for generating a check field according to the present invention.
[0047] FIG2 is a structural block diagram of an embodiment of a check field generation system of the present invention.
[0048] FIG3 is a flow chart of an embodiment of a verification and upgrading method according to the present invention.
[0049] FIG4 is a structural block diagram of an embodiment of a verification and upgrading device according to the present invention. DETAILED DESCRIPTION
[0050] To make the objectives, technical solutions, and advantages of this application more clear, this application will be further described in detail below with reference to the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this application.
[0051] The terms used in the examples of this application are for the purpose of describing specific embodiments only and are not intended to limit this application. The singular forms "a," "the," and "the" used in the examples of this application and the appended claims are also intended to include plural forms, and unless the context clearly indicates otherwise, "a plurality" generally includes at least two.
[0052] It should be understood that the term "and / or" as used herein is merely a description of the relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document generally indicates that the associated objects are in an "or" relationship.
[0053] It should be understood that although the terms first, second, third, etc. may be used to describe in the embodiments of the present application, these descriptions should not be limited to these terms. These terms are only used to distinguish the descriptions. For example, without departing from the scope of the embodiments of the present application, the first may also be referred to as the second, and similarly, the second may also be referred to as the first.
[0054] As used herein, the words "if" and "if" may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to the determination" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)," depending on the context.
[0055] It should also be noted that the terms "include," "comprises," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a product or device comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such product or device. In the absence of further limitations, an element defined by the phrase "comprises a..." does not exclude the presence of other identical elements in the product or device comprising the element.
[0056] It should be noted in particular that any symbols and / or numbers in the specification that are not marked in the accompanying drawings are not drawing marks.
[0057] Example 1
[0058] As shown in Figure 1, this application discloses a method for generating a check field based on a DoIP transmission upgrade package, comprising the following steps:
[0059] S1: In response to an upgrade download request, obtaining a first fixed value based on an integrity check of the upgrade package, and obtaining a first checksum based on a size check of the upgrade package;
[0060] S2: Detect whether the first address of the upgrade package stored in the request message meets a preset condition. If so, set the storage area corresponding to the first address as a to-be-filled area;
[0061] S3: After verifying the first fixed value, fill the first fixed value into the to-be-filled area to obtain a second verification value;
[0062] S4: Encapsulate the first verification value and the second verification value to obtain the upgrade package verification field.
[0063] When diagnosing a vehicle based on the DoIP protocol, a diagnostic tool or host computer is used to perform the upgrade. The UDS commands used to transmit the upgrade package are 0x34, 0x36, and 0x37. The process involves using service 0x34 to inform the vehicle of the upgrade package size, then using service 0x36 to send the package data until transmission is complete. Once transmission is complete, service 0x37 notifies the vehicle of the package's completion. The vehicle system begins installing the upgrade package, which may involve a vehicle restart, temporarily disconnecting the diagnostic tool or host computer from the vehicle system. Once the vehicle system reconnects to the diagnostic tool or host computer, it must resume updating the DTC status bits. This completes the DoIP flash process. It can be seen that no verification of the upgrade package is performed before, during, or after transmission.
[0064] To address this issue, the upgrade package checksum field generation method of the present application includes at least the generation of a first checksum value representing the upgrade package size, which is used to verify that the upgrade package transmission size is within a preset size; and the generation of a second checksum value to mark the uniqueness and integrity of the upgrade package content. This upgrade package checksum field generation method thus enables dual verification of both the upgrade package size and the content integrity, ensuring that the upgrade package has not been tampered with.
[0065] The generation of the second checksum relies on a fixed value obtained through an integrity check of the upgrade package. This integrity check can be data representing a specific storage location or content in the upgrade package. Changes to the upgrade package content will result in changes to this data. This fixed value is then added to the storage area corresponding to the first address. The resulting second checksum is then used to verify the contents of the upgrade package after it is delivered to the vehicle, eliminating the need for additional verification commands.
[0066] The fixed value obtained by performing integrity check on the upgrade package may be the upgrade package message content, an extract of the upgrade package content itself, or a combination of the message content and the upgrade package content.
[0067] Example 2
[0068] Obtaining the first fixed value based on integrity testing of the upgrade package includes performing integrity testing on the upgrade package using a preset algorithm to obtain a first fixed value having a first byte length. The first fixed value has a fixed byte length that varies depending on different testing methods, and includes one or more markers representing the integrity of the contents of the upgrade package.
[0069] Take the request message format of service 0x34 in the UDS protocol as an example;
[0070] The memoryAddress field in the 0x34 service can be used as the first fixed value to complete the upgrade package inspection. The upgrade package is then integrity checked using algorithms such as md5sum or sha256sum. A fixed-length digest or hash value is obtained, such as 16 bytes for md5sum and 32 bytes for sha256sum.
[0071] The detection request message information stores the first address of the upgrade package, and if so, sets the first address as a to-be-filled area. The method includes responding to a diagnostic service command to detect whether the corresponding operating platform has a storage area corresponding to the first address of the upgrade package. If not, confirming that the storage area corresponding to the first address meets the second byte length and setting the storage area as a to-be-filled area. An example of detecting that the memoryAddress meets the preset condition is when the Autosar diagnostic module is deployed on an Android platform. Android does not have a storage area first address memoryAddress, and the upgrade package is directly placed in a certain path on Android. Therefore, for the 0x34 service, the memoryAddress field is wasted and serves no purpose. In this case, the memoryAddress can be used as a to-be-filled area.
[0072] Furthermore, for other environments, corresponding storage areas that are meaningless relative to the deployment platform are detected in the request message format and can be used as areas to be filled.
[0073] After verifying the first fixed value, filling the first fixed value into the to-be-filled area to obtain a second verification value, including verifying the first fixed value through a cyclic redundancy check method so that the verified first fixed value has a third byte length, and the third byte length is less than the first byte length. Preferably, the third byte length is one-third to one-fifth of the first byte length; for example, after obtaining a 16-byte digest or a 32-byte hashing value, this value can be verified through a verification method such as CRC32 (4 bytes) or CRC64 (8 bytes); filling the digest or hashing value that has passed the CRC check into the memoryAddress field of the 0x34 service; before filling, it is also necessary to extract the length of the storage field of the memoryAddress, which can be confirmed by the lower 4 bits of the ALFID (addressAndLengthFormatIdentifier), which is at most 16 bytes, and generally 4 bytes.
[0074] When the third byte length does not exceed the second byte length, the first fixed value is filled into the to-be-filled area to obtain a second check value. In the above example, if the second byte length is detected to be 16 bytes, the corresponding 4-byte or 8-byte parameter obtained after the first fixed value is verified by CRC or other means can be filled into the to-be-filled area to obtain the second check value.
[0075] The upgrade package verification field obtained in this solution contains the total size of the upgrade package and the digest or hash value of the upgrade package content. This can be sent to the vehicle system via service 0x34. Once the vehicle system obtains the size and digest or hash value of the upgrade package to be transmitted, it can perform integrity verification against the upgrade package subsequently obtained via service 0x36. No additional DID or RID is required to passively verify the upgrade package.
[0076] Example 3
[0077] In the second aspect, the present invention discloses a check field generation system based on DoIP transmission upgrade package, as shown in FIG2, the generation system includes
[0078] an upgrade package detection module, configured to detect the upgrade package to be upgraded, so as to obtain a first fixed value corresponding to the integrity of the upgrade package and a first check value corresponding to the size of the upgrade package;
[0079] A message detection module is used to detect whether the request message information meets the preset conditions and identify the storage area corresponding to the first address in the request message information as the area to be filled;
[0080] A verification module, configured to verify the first fixed value so that the byte length of the verified first fixed value does not exceed the length of the area to be filled;
[0081] A filling module is used to fill the first fixed value into the to-be-filled area to obtain a second verification value.
[0082] The verification field generation system further includes an encapsulation and sending module, which is used to encapsulate the first verification value and the second verification value to obtain the upgrade package verification field, and send the upgrade package verification field to the upgrade verification terminal.
[0083] The upgrade package detection module is linked to the cloud to detect in real time whether there is an installation package to be updated in the cloud. After obtaining an update response, it starts to detect the upgrade package, including the size of the upgrade package and the integrity of the upgrade package and its content. The upgrade package detection module can also be set to detect the upgrade package version and the compatibility of the upgrade package version with the vehicle to be upgraded.
[0084] The message detection module and the upgrade package detection module can operate in parallel. When an upgrade download request is obtained, while the upgrade package is being detected, the message detection module identifies the preset area in the request message information. If the storage area corresponding to the first address is a meaningless storage area, the area is set as the area to be filled.
[0085] The verification module obtains the first fixed value obtained from the upgrade package detection module, verifies the first fixed value, and ensures that the verified first fixed value meets a preset length.
[0086] The filling module selects a first fixed value of appropriate length and completed verification to fill into the filling area, and the parameter that can be filled into the corresponding position of the detection request message information is the second verification value.
[0087] Finally, the first check value and the second check value are encapsulated and sent to the vehicle system together with the request message information.
[0088] Example 4
[0089] Based on Example 3, the present invention discloses a verification field generation system for an upgrade package based on DoIP transmission, which also includes an upgrade package encryption module for obtaining an upgrade package encryption key, and pre-encapsulating the encryption key outside the upgrade package verification field, and sending it to the vehicle system together with the upgrade package verification field. Only when the vehicle system successfully decompresses the upgrade package through the encryption key, the upgrade package verification field will further start the subsequent upgrade package verification program.
[0090] Example 5
[0091] As shown in FIG3 , the present invention records a verification and upgrade method based on DoIP transmission upgrade package, including the following steps:
[0092] S1: connect to the host computer and stop status update and other operations;
[0093] S2: Enter bootloader mode, and after security unlocking, send an upgrade download request to the host computer;
[0094] S3: Receive the upgrade package checksum sent by the host computer through the upgrade download service;
[0095] S4: Receive the upgrade package sent by the host computer through the data transmission service;
[0096] S5: Use the upgrade package verification field to verify the received upgrade package, and install the upgrade package after the verification is complete;
[0097] The upgrade package check field is generated using the above-mentioned check field generation method.
[0098] The specific process is
[0099] (1) Establish a DoIP connection between the diagnostic instrument or host computer and the vehicle;
[0100] (2) Before upgrading, stop updating the DTC status bit, etc., enter the programming session to perform security unlocking, etc.; in response to the upgrade service request, start generating the upgrade package checksum field;
[0101] (3) The diagnostic instrument or host computer uses the 0x34 service to inform the vehicle of the upgrade package's upgrade package checksum field, decompression key and other information; the vehicle returns the maximum amount of data to be transmitted each time through the subsequent 0x36 service;
[0102] (4) The diagnostic instrument or host computer continuously sends the data of the upgrade package through the 0x36 service until the sending is completed;
[0103] (5) After the transmission is completed, the 0x37 service is used to inform the vehicle that the upgrade package has been transmitted.
[0104] (6) The vehicle system starts installing the upgrade package, which may involve restarting the vehicle. In this case, the diagnostic instrument or host computer will be temporarily disconnected from the vehicle system.
[0105] (7) After the vehicle system re-establishes a connection with the diagnostic instrument or host computer, it is necessary to restore the update of the DTC status bit, etc.
[0106] The receiving host computer sends the upgrade package through the data transmission service, including
[0107] S41: receiving the upgrade package size sent by the host computer through the upgrade download service;
[0108] S42: Determine the maximum amount of data to be transmitted each time by the data transmission service based on the size of the upgrade package, and feed it back to the host computer;
[0109] S43: Receive the upgrade package data that is continuously sent by the host computer through the data transmission service until the sending is completed.
[0110] Referring to the above example, the diagnostic instrument or host computer uses the 0x34 service to inform the vehicle of the size of the upgrade package. The vehicle returns the maximum amount of data to be transmitted each time in the subsequent 0x36 service to improve data transmission efficiency.
[0111] Example 6
[0112] As shown in FIG4 , the present invention describes a verification and upgrade device based on DoIP transmission upgrade package, including
[0113] The upgrade verification terminal receives the upgrade download request sent by the host computer and verifies the upgrade package through the upgrade package verification field after receiving the complete upgrade package;
[0114] Verification field generation system, used to generate upgrade package verification fields;
[0115] The data link module, in response to the upgrade download service and the data transmission service, enables the upgrade verification terminal and the host computer to be in a data link open state during the upgrade package verification field and the upgrade package data transmission;
[0116] The check field generation system is based on the check field generation system of the DoIP transmission upgrade package.
[0117] The solution of the present invention fully utilizes the memoryAddress field in the UDS 0x34 service as an integrity check for the upgrade package; it avoids the additional operation of adding DID or RID to the integrity check in the prior art, realizes active verification of vehicle upgrades, and avoids the risk of tampering with the upgrade package.
[0118] Finally, it should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. References to the common and similar parts between the various embodiments will be sufficient. For the systems or devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, their descriptions are relatively simple; for relevant details, refer to the descriptions of the methods.
[0119] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for generating a check field based on a DoIP transmission upgrade package, characterized in that: The following steps are included S1: In response to an upgrade download request, obtaining a first fixed value based on integrity detection of the upgrade package, and obtaining a first check value based on detection of the size of the upgrade package; S2: Detect whether the first address of the upgrade package stored in the request message information meets the preset condition. If so, set the storage area corresponding to the first address as the area to be filled; S3: after verifying the first fixed value, fill the first fixed value into the to-be-filled area to obtain a second verification value; S4: Encapsulate the first verification value and the second verification value to obtain the upgrade package verification field.
2. The method for generating a check field based on a DoIP transmission upgrade package as claimed in claim 1, characterized in that: The method of obtaining the first fixed value based on integrity detection of the upgrade package includes the following steps The upgrade package is integrity checked using a preset algorithm to obtain a first fixed value having a first byte length.
3. The method for generating a check field based on a DoIP transmission upgrade package as claimed in claim 2, characterized in that: Whether the first address of the upgrade package stored in the detection request message information meets a preset condition, and if so, setting the first address as a to-be-filled area; include In response to the diagnostic service command, it is detected whether the corresponding operating platform has a storage area corresponding to the first address of the upgrade package. If not, it is confirmed that the storage area corresponding to the first address meets the second byte length, and the storage area is set as the area to be filled.
4. The method for generating a check field based on a DoIP transmission upgrade package as claimed in claim 3, characterized in that: After verifying the first fixed value, the first fixed value is filled into the to-be-filled area to obtain a second verification value, including Verify the first fixed value by a cyclic redundancy check, so that the verified first fixed value has a third byte length, and the third byte length is less than the first byte length; When the third byte length does not exceed the second byte length, the first fixed value is filled into the area to be filled to obtain a second check value.
5. A verification field generation system based on DoIP transmission upgrade package, characterized in that: The generating system comprises An upgrade package detection module, used to detect the package to be upgraded to obtain a first fixed value corresponding to the integrity of the upgrade package and a first check value corresponding to the size of the upgrade package; A message detection module, used to detect whether the request message information meets the preset conditions, and identify the storage area corresponding to the first address in the request message information as the area to be filled; A verification module, used for verifying the first fixed value so that the byte length of the verified first fixed value does not exceed the length of the area to be filled; A filling module is used to fill the first fixed value into the to-be-filled area to obtain a second verification value.
6. The verification field generation system based on DoIP transmission upgrade package as claimed in claim 5, characterized in that: Also includes The encapsulation and sending module is used to encapsulate the first verification value and the second verification value to obtain the upgrade package verification field, and send the upgrade package verification field to the upgrade verification end.
7. A verification and upgrade method based on DoIP transmission upgrade package, characterized in that: The following steps are included S1: Link with the host computer and stop status update; S2: Enter bootloader mode, and after security unlocking, send an upgrade download request to the host computer; S3: receiving the upgrade package verification field sent by the host computer through the upgrade download service; S4: receiving the upgrade package sent by the host computer through the data transmission service; S5: Use the upgrade package verification field to verify the received upgrade package, and install the upgrade package after the verification is completed; The upgrade package check field is generated by the check field generation method for the upgrade package based on DoIP transmission as described in any one of claims 1-4.
8. The verification and upgrade method based on DoIP transmission upgrade package as claimed in claim 7, characterized in that: The receiving host computer sends the upgrade package through the data transmission service, including S41: receiving the upgrade package size sent by the host computer through the upgrade download service; S42: Determine the maximum amount of data transmitted by the data transmission service each time according to the size of the upgrade package, and feed it back to the host computer; S43: receiving the upgrade package data continuously and cyclically sent by the host computer through the data transmission service until the sending is completed.
9. The verification and upgrade method based on DoIP transmission upgrade package as claimed in claim 8, characterized in that: The upgrade package verification field is used to verify the received upgrade package, and after the verification is completed, the upgrade package is installed, including After the transmission is completed, the upgrade package transmission completion is fed back by requesting to exit the transmission service, and the received upgrade package is verified using the upgrade package verification field.
10. A verification and upgrade device based on DoIP transmission upgrade package, characterized in that: include The upgrade verification end receives the upgrade download request sent by the host computer, and after receiving the complete upgrade package, verifies the upgrade package through the upgrade package verification field; Verification field generation system, used to generate upgrade package verification fields; The data link module, in response to the upgrade download service and the data transmission service, enables the upgrade verification terminal and the host computer to be in a data link open state during the upgrade package verification field and the upgrade package data transmission; The check field generation system is the check field generation system based on DoIP transmission upgrade package as described in claim 5 or 6.
Citation Information
Patent Citations
OTA upgrading system and method of vehicle-mounted information entertainment system based on DoIP protocol
CN114924770A
Driving platform OTA upgrading process control method, system and device and medium
CN116382739A
Check field generation method and system based on DoIP transmission upgrade package
CN117914529A
Vehicle-Mounted Device Upgrade Method and Related Apparatus
US20210311720A1