Program flashing method and related apparatus
By setting the vehicle controller's diagnostic session mode to programming session mode, security authentication and program checks are performed, resolving the issue of abnormal ECU applications in new energy light trucks and improving the security of application repair and flashing.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- BEIJING SINGAUTO TECH CO LTD
- Filing Date
- 2025-11-12
- Publication Date
- 2026-05-21
AI Technical Summary
An ECU application malfunction in a new energy light truck renders the vehicle unusable. How can the application be effectively repaired and the security of the flashing process improved?
If the application is invalid, set the vehicle controller's diagnostic session mode to programming session mode, perform security authentication, delete the invalid application, download and check the integrity and dependencies of the application to be flashed, and perform a reset operation to flash it into the vehicle controller after passing the check.
It achieved the goal of repairing the application, improved the security of vehicle flashing programs, protected the information of OEMs and vehicle owners, and enhanced the standardization and management convenience of software flashing.
Smart Images

Figure CN2025134532_21052026_PF_FP_ABST
Abstract
Description
A method for flashing a program and related devices
[0001] Cross-references to related applications
[0002] This disclosure is based on and claims priority to Chinese Patent Application No. 2024116203550, filed on November 13, 2024, the entire contents of which are incorporated herein by reference. Technical Field
[0003] This disclosure relates to the field of program flashing technology, and in particular to a program flashing method and related apparatus. Background Technology
[0004] In certain scenarios, a malfunction in the ECU (Electronic Control Unit) of a new energy light truck can cause an abnormal application, rendering the vehicle unusable. Therefore, how to re-flash the repaired application into the ECU is a pressing issue that needs to be addressed. Summary of the Invention
[0005] In view of the above problems, this disclosure provides a program flashing method and related apparatus to achieve the purpose of repairing application programs. The specific solution is as follows:
[0006] The first aspect of this disclosure provides a method for flashing a program, including:
[0007] If the application is invalid, set the vehicle controller's diagnostic session mode to programming session mode;
[0008] After the security authentication is passed, the invalid application is deleted, the application to be flashed is downloaded, and the integrity of the application to be flashed is checked.
[0009] If the application to be flashed is complete, then perform a program dependency check on the application to be flashed.
[0010] If the program dependency check passes, the vehicle controller is reset so that the application to be flashed is written to the vehicle controller.
[0011] In some embodiments, setting the vehicle controller's diagnostic session mode to programming session mode when the application is invalid includes:
[0012] If the application is invalid, the diagnostic session mode is switched from the default session mode to the extended session mode, and security authentication is performed.
[0013] After security authentication is passed, diagnostic fault codes and non-diagnostic communication are disabled, and then the extended session mode is switched to the programming session mode.
[0014] In some embodiments, after the vehicle controller is reset, the method further includes:
[0015] Switch the diagnostic session mode from the programming session mode to the default session mode, and then switch the default session mode to the extended session mode;
[0016] In the extended session mode, the non-diagnostic communication and the diagnostic fault codes are enabled, and then the extended session mode is switched back to the default session mode.
[0017] In some embodiments, it also includes:
[0018] In the event of an application upgrade, the diagnostic session mode of the vehicle controller is set to the programming session mode;
[0019] Download the application to be updated and replace the backup application stored in the backup area of the vehicle controller with the application to be updated;
[0020] Perform a legality check on the application to be updated;
[0021] If the check fails, the application to be updated will be deleted from the backup area, and the backup application will be stored in the backup area.
[0022] If the check passes, the application to be updated will be backed up in the operating area of the vehicle controller.
[0023] In some embodiments, after setting the vehicle controller's diagnostic session mode to programming session mode, the method further includes:
[0024] Request a seed from the vehicle controller;
[0025] The system receives a seed sent by the vehicle controller, generates a key based on the seed, and sends the key to the vehicle controller for security authentication.
[0026] In some embodiments, switching the diagnostic session mode from the default session mode to the extended session mode includes:
[0027] In the default session mode, the hardware version number and software version number of the vehicle controller are obtained, and then the default session mode is switched to the extended session mode.
[0028] The second aspect of this disclosure provides a program flashing system, comprising:
[0029] The mode switching module is used to switch the vehicle controller's diagnostic session mode to programming session mode when the application is invalid.
[0030] The download module is used to delete invalid applications, download the application to be flashed, and check whether the application to be flashed is complete after the security authentication is passed.
[0031] The inspection module is used to perform program dependency checks on the application to be flashed when the application to be flashed is complete.
[0032] The flashing module is used to reset the vehicle controller if the program dependency check passes, so that the application to be flashed is flashed into the vehicle controller.
[0033] This disclosure provides a computer program product including computer-readable instructions that, when executed on an electronic device, cause the electronic device to implement the program flashing method of the first aspect or any implementation thereof.
[0034] A fourth aspect of this disclosure provides an electronic device including at least one processor and a memory connected to the processor, wherein:
[0035] The memory is used to store computer programs;
[0036] The processor is used to execute the computer program so that the electronic device can implement the program flashing method of the first aspect or any implementation thereof.
[0037] The fifth aspect of this disclosure provides a computer storage medium carrying one or more computer programs, which, when executed by an electronic device, enable the electronic device to perform a program flashing method according to the first aspect or any implementation thereof.
[0038] By employing the above technical solutions, the program flashing method and related apparatus provided in this disclosure, when the application is invalid, set the diagnostic session mode of the vehicle controller to the programming session mode, download the application to be flashed in this mode, check the integrity and dependencies of the application, and reset the vehicle controller if the check passes, so that the application to be flashed is flashed into the vehicle controller, thereby achieving the purpose of repairing the application; in addition, performing security authentication after setting the diagnostic session mode of the vehicle controller to the programming session mode can improve the security of vehicle program flashing. Attached Figure Description
[0039] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.
[0040] Figure 1 is a flowchart of a program flashing method provided in this disclosure;
[0041] Figure 2 is a schematic diagram of a diagnostic session mode switching provided in this disclosure;
[0042] Figure 3 is a schematic diagram of a brushing process provided in this disclosure;
[0043] Figure 4 is another schematic diagram of the flashing process provided in this disclosure;
[0044] Figure 5 is a structural diagram of a program flashing system provided in this disclosure;
[0045] Figure 6 is a schematic diagram of the structure of an electronic device provided in this disclosure. Detailed Implementation
[0046] The embodiments of this disclosure are described below with reference to the accompanying drawings. The terminology used in the Description of Embodiments section of this disclosure is for illustrative purposes only and is not intended to limit the scope of this disclosure.
[0047] The embodiments of this disclosure will now be described with reference to the accompanying drawings. Those skilled in the art will recognize that, with technological advancements and the emergence of new scenarios, the technical solutions provided in the embodiments of this disclosure are equally applicable to similar technical problems.
[0048] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such terms are interchangeable where appropriate; this is merely a way of distinguishing objects with the same properties in the description of embodiments of this disclosure. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion, so that a process, method, system, product, or apparatus that comprises a series of elements is not necessarily limited to those elements but may include other elements not expressly listed or inherent to those processes, methods, products, or apparatuses.
[0049] This disclosure provides a method for flashing a program. The method for flashing a program according to this disclosure will be described in detail below with reference to the accompanying drawings.
[0050] Referring to Figure 1, which is a flowchart of a program flashing method provided by an embodiment of the present disclosure, as shown in Figure 1, the program flashing method provided by the present disclosure is applied to a diagnostic instrument. The method may include steps 101 to 104, which will be described in detail below.
[0051] Step 101: If the application is invalid, set the vehicle controller's diagnostic session mode to programming session mode.
[0052] The vehicle controller can be an ECU. After the vehicle rolls off the production line, the bootloader is permanently stored in a designated memory area of the ECU, allowing the ECU to support the reprogramming of application programs and application data (including network configuration data and calibration data). During normal operation, the application programs and application data are executed. In certain scenarios, if a fault occurs in a new energy light truck, causing an abnormality in the ECU's application programs, and the application programs or application data become invalid, the bootloader will be activated, requiring one or more application software programs or application data to be downloaded to the ECU's memory for reprogramming.
[0053] In some embodiments, when the application is invalid, setting the vehicle controller's diagnostic session mode to programming session mode includes:
[0054] If the application is invalid, switch the diagnostic session mode from the default session mode to the extended session mode and perform security authentication;
[0055] After security authentication is passed, diagnostic fault codes and non-diagnostic communication are disabled, and then the extended session mode is switched to the programming session mode.
[0056] In Bootloader mode, the vehicle controller's diagnostic session modes include three types: default session mode, extended session mode, and programming session mode. Upon power-up, it first enters the default session mode. To enter the programming session mode, it is necessary to switch from the default session mode to the extended session mode, and then from the extended session mode to the programming session mode.
[0057] Figure 2 is a schematic diagram of the diagnostic session mode switching provided in this embodiment of the present disclosure. Figure 2 shows the bootloader mode and the application mode. The bootloader mode uses three different diagnostic session modes: default session mode, extended session mode, and programming session mode. The application mode uses two diagnostic session modes: default session mode and extended session mode. When the application is valid, it is in application mode, first in default session mode, then switches to extended session mode after receiving message 1003, then switches back to default session mode after receiving message 1001 in extended session mode, and finally resets the ECU after receiving message 1002. When the application is invalid, it is in bootloader mode, first in default session mode, then switches to extended session mode after receiving message 1003, then enters programming session mode after receiving message 1002 in extended session mode, and switches back to default session mode after receiving message 1001 in extended session mode. In bootloader mode, if there is an external programming request, the vehicle controller's diagnostic session mode is the default session mode; otherwise, it determines whether the application is valid. In the default session mode, the ECU resets upon receiving a 1101 reset message; in the extended session mode, the ECU resets upon receiving a 1101 reset message or an S3 timer timeout message; in the programming session mode, the ECU resets upon receiving a 1101 reset message, a 1001 message, or an S3 timer timeout message. The ECU enters the default session mode upon power-up.
[0058] In some embodiments, switching the diagnostic session mode from the default session mode to the extended session mode includes:
[0059] In the default session mode, the hardware version number and software version number of the vehicle controller are obtained, and then the default session mode is switched to the extended session mode.
[0060] When the diagnostic tool obtains the ECU's hardware version number, the Diagnostic Service Identifier (SID) is 22 and the Diagnostic Address (DID) is 0xF193. The ECU responds positively or negatively to this information; a positive response message is 62h. Then, the diagnostic tool obtains the ECU's software version number, with the Diagnostic Service Identifier (SID) being 0x22 and the Diagnostic Address (DID) being 0xF195. The ECU responds positively or negatively to this information; a positive response message is 62h. Finally, the tool switches from the default session mode to the extended session mode.
[0061] Optionally, the diagnostic session mode can be switched from the default session mode to the extended session mode, and security authentication can be performed, including:
[0062] After switching to extended session mode, the ECU responds positively and sends timing parameters P2CAN and P2*CAN. The positive response message is 50h, and then security authentication is performed.
[0063] During security authentication, the diagnostic tool requests a seed from the ECU (Signal ID 0x27h01h). The ECU responds positively with a message of 67h. The diagnostic tool receives the seed from the ECU, generates a key based on the seed, and sends the key to the ECU (Signal ID 0x27h02h). The ECU responds positively with a message of 67h, and security authentication is successful.
[0064] After successful safety authentication, the diagnostic tool checks the pre-programming conditions: SID 31h, DID 0xF002, ECU responds positively with a message of 71h. Then, the diagnostic tool disables Diagnostic Trouble Codes (DTCs): SID 0x85,02h, ECU responds positively with a message of C5h. Next, the diagnostic tool disables non-diagnostic communication: SID 0x85,03h, ECU responds positively with a message of 68h. This message request uses either physical addressing or functional addressing, requiring CAN (FD) network preparation before programming, as well as preparation to improve download capabilities.
[0065] After disabling diagnostic fault codes and non-diagnostic communication, the extended session mode is switched to the programming session mode with SID 10. The ECU responds positively with a message of 50h and sends timing parameters P2CAN and P2*CAN.
[0066] In some embodiments, after setting the diagnostic session mode of the vehicle controller to the programming session mode, the method further includes:
[0067] Request a seed from the vehicle controller;
[0068] Receive the seed sent by the vehicle controller, generate a key based on the seed, and send the key to the vehicle controller for security authentication.
[0069] The diagnostic tool requests a seed from the ECU (Signal ID: 0x27,03h). The ECU responds positively with a message of 67h. The diagnostic tool receives the seed from the ECU, generates a key based on it, and sends the key to the ECU (Signal ID: 0x27,04h). The ECU responds positively with a message of 67h. The diagnostic tool writes fingerprint information (Signal ID: 0x2E, DID: 0xF184). The ECU responds positively with a message of 6Eh, indicating successful security authentication.
[0070] Step 102: After the security authentication is passed, delete the invalid application, download the application to be flashed, and check whether the application to be flashed is complete.
[0071] Before deleting the invalid application, the diagnostic tool downloads the driver, checks its integrity (SID 31h, DID 0xF1A0), and the ECU responds positively with a message of 71h. Then, the invalid application is deleted (SID 31h, DID 0xFF00). The ECU responds either positively or negatively (71h message for a positive response, 7FH message for a negative response), and the response key is 78h. The diagnostic tool then downloads the application to be flashed and checks its integrity (SID 31h, DID 0xF1A0), with the ECU responding positively with a message of 71h.
[0072] Optionally, the diagnostic tool determines whether more data needs to be downloaded. If so, the downloaded application is deleted; otherwise, step 103 is executed.
[0073] Step 103: If the application to be flashed is complete, then perform a program dependency check on the application to be flashed.
[0074] If the application to be flashed is complete, a program dependency check is performed on the application to be flashed. The SID is 31h and the DID is 0xFF01. The ECU will definitely respond, and the message for a positive response is 71h.
[0075] Step 104: If the program dependency check passes, reset the vehicle controller to allow the application to be flashed to be written into the vehicle controller.
[0076] The vehicle controller was reset. The SID was 11h and the DID was 0x01. The ECU responded positively, and the positive response message was 51h.
[0077] In some embodiments, after resetting the vehicle controller, the method further includes:
[0078] Switch the diagnostic session mode from programming session mode to default session mode, and then switch the default session mode to extended session mode;
[0079] In extended session mode, enable non-diagnostic communication and diagnostic fault codes, and then switch extended session mode back to the default session mode.
[0080] After resetting the vehicle controller and flashing the application to it, first switch the diagnostic session mode from programming session mode to default session mode, then switch the default session mode to extended session mode (SID 0x10). The ECU responds positively with a message of 50h (SID 0x50) and timing parameters of P2CAN and P2*CAN. The diagnostic tool enables non-diagnostic communication (SID 0x28,00h), and the ECU responds positively with a message of 68h. The diagnostic tool enables diagnostic fault codes (DTCs) (SID 0x85,01h), and the ECU responds positively with a message of C5h. Then, switch the extended session mode back to the default session mode (SID 0x10), and the ECU responds positively with a message of 50h (SID 0x50) and timing parameters of P2CAN and P2*CAN. The diagnostic tool cleared the diagnostic information; SID was 0x14, DID was 0Xffff, and the ECU responded positively with a 54h message. The CAN (FD) network was then resynchronized after programming.
[0081] In some embodiments, the ECU downloads a data block, the diagnostic tool requests download with a message of 34h, the ECU responds affirmatively with a message of 74h, the diagnostic tool transmits application data with a message of 36h, the ECU responds negatively with a message of 7Fh, the response code is 78h, the ECU responds affirmatively with a message of 76h, the diagnostic tool determines whether there is still application data to be transmitted, if so, it continues to transmit application data, if not, it requests to exit with a message of 37h, the ECU responds negatively with a message of 7Fh, the response code is 78h, the ECU responds affirmatively with a message of 77h.
[0082] In some embodiments, the program flashing method provided in this disclosure further includes:
[0083] In the event of an application upgrade, the vehicle controller's diagnostic session mode will be switched to programming session mode.
[0084] Download the application to be updated and replace the backup application stored in the backup area of the vehicle controller with the application to be updated;
[0085] Perform a legality check on the application to be updated;
[0086] If the check fails, the application to be updated will be removed from the backup area, and the backup application will be stored in the backup area.
[0087] If the check passes, the application to be updated will be backed up in the running area of the vehicle controller.
[0088] If a program upgrade is performed, the vehicle controller's diagnostic session mode will be set to programming session mode. To prevent the ECU from malfunctioning due to software flashing, for ECUs supporting A / B side flashing, both A and B area flashing must be supported, with one area serving as the operating area and the other as the backup area. Download the application to be updated, replace the backup application stored in the vehicle controller's backup area with the application to be updated, perform a validity check on the application to be updated, and check if the application to be updated is corrupted. If the check fails, the application to be updated can be deleted, and the original backup application stored in the backup area can be rolled back to the backup area. This means that even if the software update fails, the program can still run normally as before the update. If the check passes, the application to be updated will be backed up in the vehicle controller's operating area.
[0089] As shown in Figure 3, the ECU includes an MCU (Microcontroller Unit). The MCU's FLASH memory is divided into two areas, A and B. Area A serves as the normal operating area for the application, storing the first application, APP1. Area B serves as the backup area, storing a backup of APP1. When downloading an application to be updated, APP1 in the backup area is erased first. Then, the application to be updated, APP2, is flashed into the backup area B. If the flash is successful, the backup of APP2 can be stored in area A. As shown in Figure 4, if APP2 is invalid or corrupted when flashing it into area B, APP2 is erased from area B, and the backup of APP1 is rolled back to area B. At this time, area B becomes the running area, ensuring that the original version of the program can continue to run even after a flashing failure. Optionally, after an upgrade failure, area A or B is not fixed as the running area. If the upgrade in area A fails, the bootloader can change the backup area in area B into the running area, and then back up area B back to area A. If the next upgrade in area B fails, it will switch back to area A as the running area.
[0090] The program flashing method disclosed herein can improve the security of new energy vehicles, such as new energy light trucks, when flashing software. By using a bootloader before flashing the ECU, the information of the OEM and vehicle owner can be more effectively protected, preventing information leakage. Applying this bootloader process to the software flashing process improves the standardization of software flashing by OEMs, making OEM management more convenient and saving time and effort for vehicle users.
[0091] The above describes a program flashing method provided by the embodiments of this disclosure. The following will describe a system for performing the above program flashing method.
[0092] Please refer to Figure 5, which is a schematic diagram of a program flashing system provided in an embodiment of this disclosure. As shown in Figure 5, the program flashing system includes:
[0093] The mode conversion module 501 is used to switch the diagnostic session mode of the vehicle controller to the programming session mode when the application is invalid.
[0094] Download module 502 is used to delete invalid applications, download the application to be flashed, and check whether the application to be flashed is complete after the security authentication is passed.
[0095] The inspection module 503 is used to perform program dependency checks on the application to be flashed when the application to be flashed is complete.
[0096] The flashing module 504 is used to reset the vehicle controller after the program dependency check passes, so that the application to be flashed can be flashed into the vehicle controller.
[0097] Mode conversion module 501 is specifically used for:
[0098] If the application is invalid, switch the diagnostic session mode from the default session mode to the extended session mode and perform security authentication;
[0099] After security authentication is passed, diagnostic fault codes and non-diagnostic communication are disabled, and then the extended session mode is switched to the programming session mode.
[0100] The system flashing program also includes:
[0101] The switching module is used to switch the diagnostic session mode from programming session mode to the default session mode, and then switch the default session mode to extended session mode.
[0102] The enable module enables non-diagnostic communication and diagnostic fault codes in extended session mode, and then switches extended session mode back to the default session mode.
[0103] The system flashing program also includes:
[0104] The upgrade module is used to set the vehicle controller's diagnostic session mode to programming session mode in the event of an application upgrade; download the application to be updated and replace the backup application stored in the vehicle controller's backup area with the application to be updated; perform a validity check on the application to be updated; if the check fails, the application to be updated is deleted from the backup area and the backup application is stored in the backup area; if the check passes, the application to be updated is backed up in the vehicle controller's operating area.
[0105] The system flashing program also includes:
[0106] The security authentication module is used to request a seed from the vehicle controller after setting the diagnostic session mode of the vehicle controller to the programming session mode; receive the seed sent by the vehicle controller, generate a key based on the seed, and send the key to the vehicle controller for security authentication.
[0107] The mode conversion module 501 is also used for:
[0108] In the default session mode, the hardware version number and software version number of the vehicle controller are obtained, and then the default session mode is switched to the extended session mode.
[0109] This disclosure also provides an electronic device. Referring to FIG6, a schematic diagram of a structure suitable for implementing the electronic device in this disclosure is shown. The electronic device in this disclosure may include, but is not limited to, fixed terminals such as mobile phones, laptops, PDAs (personal digital assistants), PADs (tablet computers), desktop computers, etc. The electronic device shown in FIG6 is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this disclosure.
[0110] As shown in Figure 6, the electronic device may include a processing unit (e.g., a central processing unit, a graphics processing unit, etc.) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage device 608 into a random access memory (RAM) 603. When the electronic device is powered on, the RAM 603 also stores various programs and data required for the operation of the electronic device. The processing unit 601, ROM 602, and RAM 603 are interconnected via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0111] Typically, the following devices can be connected to I / O interface 605: input devices 606 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 607 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 608 including, for example, memory cards, hard drives, etc.; and communication devices 609. Communication device 609 allows the electronic device to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 6 shows an electronic device with various devices, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.
[0112] This disclosure also provides a computer program product including computer-readable instructions, which, when executed on an electronic device, cause the electronic device to implement any of the program flashing methods provided in this disclosure.
[0113] This disclosure also provides a computer-readable storage medium carrying one or more computer programs. When the one or more computer programs are executed by an electronic device, the electronic device can implement any of the program flashing methods provided in this disclosure.
[0114] It should also be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. In addition, in the accompanying drawings of the device embodiments provided in this disclosure, the connection relationship between modules indicates that they have a communication connection, which can be implemented as one or more communication buses or signal lines.
[0115] Through the above description of the embodiments, those skilled in the art can clearly understand that this disclosure can be implemented by means of software plus necessary general-purpose hardware, and of course, it can also be implemented by special-purpose hardware including application-specific integrated circuits, special-purpose CPUs, special-purpose memory, special-purpose components, etc. Generally, any function performed by a computer program can be easily implemented by corresponding hardware, and the specific hardware structure used to implement the same function can also be diverse, such as analog circuits, digital circuits, or special-purpose circuits. However, for this disclosure, software program implementation is more often a better implementation method. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium, such as a computer floppy disk, USB flash drive, mobile hard disk, ROM, RAM, magnetic disk, or optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, training equipment, or network device, etc.) to execute the methods described in the various embodiments of this disclosure.
[0116] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product.
[0117] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this disclosure are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, training device, or data center to another website, computer, training device, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a training device or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state drives (SSDs)).
Claims
1. A method for flashing a program, comprising: If the application is invalid, set the vehicle controller's diagnostic session mode to programming session mode; After the security authentication is passed, the invalid application is deleted, the application to be flashed is downloaded, and the integrity of the application to be flashed is checked. If the application to be flashed is complete, then perform a program dependency check on the application to be flashed. If the program dependency check passes, the vehicle controller is reset so that the application to be flashed is written to the vehicle controller.
2. The program flashing method according to claim 1, wherein, The step of setting the vehicle controller's diagnostic session mode to programming session mode when the application is invalid includes: If the application is invalid, the diagnostic session mode is switched from the default session mode to the extended session mode, and security authentication is performed. After security authentication is passed, diagnostic fault codes and non-diagnostic communication are disabled, and then the extended session mode is switched to the programming session mode.
3. The program flashing method according to claim 2, wherein, After resetting the vehicle controller, the method further includes: Switch the diagnostic session mode from the programming session mode to the default session mode, and then switch the default session mode to the extended session mode; In the extended session mode, the non-diagnostic communication and the diagnostic fault codes are enabled, and then the extended session mode is switched back to the default session mode.
4. The program flashing method according to any one of claims 1-3 further includes: In the event of an application upgrade, the diagnostic session mode of the vehicle controller is set to the programming session mode; Download the application to be updated and replace the backup application stored in the backup area of the vehicle controller with the application to be updated; Perform a legality check on the application to be updated; If the check fails, the application to be updated will be deleted from the backup area, and the backup application will be stored in the backup area. If the check passes, the application to be updated will be backed up in the operating area of the vehicle controller.
5. The program flashing method according to any one of claims 1-3, wherein, After setting the vehicle controller's diagnostic session mode to programming session mode, the method further includes: Request a seed from the vehicle controller; The system receives a seed sent by the vehicle controller, generates a key based on the seed, and sends the key to the vehicle controller for security authentication.
6. The program flashing method according to claim 2, wherein, Switching the diagnostic session mode from the default session mode to the extended session mode includes: In the default session mode, the hardware version number and software version number of the vehicle controller are obtained, and then the default session mode is switched to the extended session mode.
7. A program flashing system, comprising: The mode switching module is used to switch the vehicle controller's diagnostic session mode to programming session mode when the application is invalid. The download module is used to delete invalid applications, download the application to be flashed, and check whether the application to be flashed is complete after the security authentication is passed. The inspection module is used to perform program dependency checks on the application to be flashed when the application to be flashed is complete. The flashing module is used to reset the vehicle controller if the program dependency check passes, so that the application to be flashed is flashed into the vehicle controller.
8. A computer program product comprising computer-readable instructions that, when executed on an electronic device, cause the electronic device to implement the program flashing method as described in any one of claims 1 to 6.
9. An electronic device comprising at least one processor and a memory connected to said processor, wherein: The memory is used to store computer programs; The processor is used to execute the computer program to enable the electronic device to implement the program flashing method as described in any one of claims 1 to 6.
10. A computer storage medium, wherein, The storage medium carries one or more computer programs, which, when executed by an electronic device, enable the electronic device to implement the program flashing method as described in any one of claims 1 to 6.