OVER-THE-AIR TRIGGER FOR VEHICLE QUERY UPDATES
The system allows for efficient wireless software updates for vehicles by using a publish/subscribe model to send query protocols and retrieve update manifests, addressing the inefficiencies of traditional update methods.
Patent Information
- Application Number
- DE102017101491
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2016-03-09
- Filing Date
- 2017-01-26
- Publication Date
- 2025-06-12
- Estimated Expiration
- 2037-01-26
AI Technical Summary
Current methods for updating vehicle software require vehicles to be physically taken to a dealer, where technicians manually apply updates, which is inefficient and resource-intensive.
A system and method for wirelessly updating vehicle software using a publish/subscribe model, where a vehicle sends a query protocol to a service delivery network server in response to a trigger message, and retrieves a manifest indicating network addresses of updates, allowing for over-the-air software updates.
Enables efficient and automated software updates for vehicles without the need for physical dealer visits, reducing resource usage and improving update frequency and reliability.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
TECHNICAL FIELDThe illustrative embodiments generally relate to a method and apparatus for executing over-the-air software updates to execute a vehicle query in response to a published over-the-air trigger.GENERAL STATE OF THE ARTTo update a software version of a component of a vehicle, the vehicle may be driven to a dealer and maintained by a technician. The technician may employ a system that tracks the individual software levels of each component in the vehicle as well as available software updates. The technician can manually apply the software updates displayed by the system and can record any changes in the system again.Over-the-air (OTA) software updates are a technique by which a vehicle's software can be updated over a wireless link. Using an embedded modem or other wireless data connection to the vehicle, OTA updates enable software changes in vehicle electronic control devices (ECUs) without dealer searching.WO 2016 / 007563 A1 describes apparatuses, methods and systems for platforms for remotely updating embedded facilities.US 2015 / 0100955 A1 discloses a method, a system and a computer-readable storage medium for updating software.SUMMARYIt is an object of the invention to provide a system and a method for wirelessly updating software of a vehicle.This object is achieved by a system having the features of claim 1 and a method having the features of claim 8.In a first illustrative embodiment, a system includes a vehicle logged on to a theme managed by a message broker and connected to the vehicle, at least one controller programmed to send query protocol specification configuration information of the vehicle to a service delivery network server in response to a trigger message published to the theme by the server, and retrieve a manifest indicating network addresses of updates determined using the query protocol.In a second illustrative embodiment, a method includes receiving, by a vehicle processor, a message published by a service delivery network on a theme managed by a message broker and associated with a vehicle indicative of vehicle update availability; generating a query protocol that specifies vehicle equipment information in response to receiving the message; sending the query protocol to the service delivery network; and retrieving a manifest indicative of network addresses of updates determined using the query protocol.In a third illustrative embodiment, a non-transitory computer readable medium includes instructions that, when executed by a computer system of a vehicle, cause the vehicle to retrieve a manifest of service delivery network addresses for updates served by a web server, the updates selected based on a protocol with vehicle equipment information compiled by the vehicle computer system in response to receiving a message published to a vehicle logged-on theme managed by a message broker indicating vehicle update availability.BRIEF DESCRIPTION OF THE DRAWINGSFIG. 1 illustrates an example block topology for a vehicle-based computing platform; FIG. 2 illustrates an example service delivery network in communication with a vehicle having a configurable module via the network;FIGS. 3A and 3B illustrate exemplary communication message flows between the vehicle and the service delivery network via the message broker; FIG. 4 illustrates an example topic tree for use with a vehicle-based computing platform for service delivery network communication; and FIG. 5 illustrates an example process for updating computer platform software.DETAILED DESCRIPTIONAs required, detailed embodiments of the present invention are disclosed herein; however, it is to be understood that the disclosed embodiments are merely exemplary of the invention that may be embodied in various and alternative forms. The figures are not necessarily to scale; some features may be exaggerated or minimized to show details of particular components. Therefore, specific structural and functional details disclosed herein are not to be interpreted as limiting, but merely as a representative basis for teaching one skilled in the art to variously employ the present invention.A software update system may use a publish / subscribe model to publish messages to and from vehicles. The publish / subscribe model may use topics, also known as logical channels, through which publishers may send messages and participants may receive messages. In some cases, a vehicle may be a publisher and may send vehicle notifications to a service delivery network, may respond to commands from the service delivery network, or may notify the service delivery network of a vehicle connectivity status. In other cases, a vehicle may be a subscriber and may receive control messages or indications of available software updates from a service delivery network.A topic tree structure may be used to define a structure of the topics and sub-topics used in sending messages between the vehicles and the service delivery network. A vehicle computing platform may log in to nodes of the topic tree corresponding to the installed software / firmware version of one or more modules included within the vehicle. These modules may include a telematics unit (TCU), as an example.A service delivery network may receive a notification of a software update from a publisher. The notification may result in the service delivery network publishing a trigger notification in a topic node corresponding to a vehicle to be updated or a version of the software to be updated. The service delivery network may further publish the software update binary to a web server at a web address specific to the update. The publisher may be a remote original manufacturer (OEM) server or a third party software provider.The vehicle may generate a query log indicating updates are available based on receipt of the trigger message notification in the topic tree. The challenge protocol may include version information from at least one hardware or software module installed in the vehicle and may be used to determine which modules to update. The query log may include information compiled according to a data identifier list that defines which information to include in the query log and where that information is in the active software installation.The vehicle may be configured to send the challenge protocol to the service delivery network. In one example, the vehicle may send the query protocol to an address of the service delivery network via a secure HyperText Transport Protocol (HTTPS) connection. The service delivery network may receive the challenge protocol and respond to the vehicle with a manifest based on the information included in the provided challenge protocol. The manifest may indicate web server locations of at least one software update to be installed by the vehicle and may be provided back to the vehicle via HTTPS.Based on the manifest, the vehicle may be configured to install updated bins and / or configurations retrieved from the specified web server locations. Because the updates are made available by the web server, the vehicles may be able to download the updates using resume functionality available from web server downloads. Further, since the challenge log generation and the upload are performed in response to a service notification that updates are available, periodically inquiring for updates by the vehicle is avoided, thereby avoiding the resource use of the periodic generation and upload of challenge logs. Further aspects of the system are described in detail below.FIG. 1 illustrates an example diagram of a system 100 that may be used to provide telematics services to a vehicle 102. The vehicle 102 may be various types of passenger vehicles, such as crossover utility vehicle (CUV), sport utility vehicle (SUV), truck, camping vehicle (RV), boat, plane, or other mobile machines for transporting people or goods. Telematics services may include, as some non-limiting possibilities, navigation, directions, vehicle maintenance status reports, local business search, accident report, and hands-free calling. In one example, system 100 may include the SYNC system manufactured by Ford Motor Company of Dearborne, Michigan. It should be appreciated that the illustrated system 100 is merely an example and more, fewer, and / or differently arranged elements may be used.The computing platform 104 may include one or more processors 106 coupled to both a memory 108 and a computer readable storage medium 112 and configured to execute instructions, instructions, and other routines to support the processes described herein. For example, the computing platform 104 may be configured to execute commands from vehicle applications 110 to provide features such as navigation, accident reporting, satellite radio decoding, and hands-free calling. These instructions and other data may be stored in a non-transitory manner using a variety of types of computer readable storage medium 112. The computer readable medium 112 (also referred to as a processor readable medium or memory) includes any non-transitory (e.g., tangible) medium that participates in providing instructions or other data that may be read by the processor 106 of the computing platform 104. Computer-executable instructions may be compiled or interpreted from computer programs created using a variety of programming languages and / or technologies, including, without limitation, and either alone or in combination, Java, C, C++, C#, Objective C, Fortran, Pascal, Java script, Python, Perl, and PL / SQL.The computing platform 104 may be equipped with various features that allow vehicle occupants to connect to the computing platform 104. For example, the computing platform 104 may include an audio input 114 configured to receive spoken commands from vehicle occupants through a connected microphone 116 and an auxiliary audio input 118 to receive audio signals from connected devices. The auxiliary audio input 118 may be a wired jack, such as a stereo input, or a wireless input, such as a BLUETOOTH (R) audio connection. In some examples, audio input 114 may be configured to provide audio processing capabilities such as preamplification of low-level signals and conversion of analog inputs to digital data for processing by processor 106.The computing platform 104 may also provide one or more audio outputs 120 to an input of the audio playback functionality of the audio module 122. In other examples, the computing platform 104 may provide audio output to the occupants using one or more associated speakers (not illustrated). The audio module 122 may include an input selector 124 configured to provide audio content from a selected audio source 126 to an audio amplifier 128 for playback by vehicle speakers 130. The audio sources 126 may include, for example, decoded amplitude modulated (AM) or frequency modulated (FM) radio signals and compact disc (CD) or digital versatile disc (DVD) audio playback. The audio sources 126 may also include audio received from the computing platform 104, such as audio content generated by the computing platform 104, audio content decoded from flash memories connected to a universal serial bus (USB) subsystem 132 of the computing platform 104, and audio content forwarded by the computing platform 104 from the auxiliary audio input 118.Computing platform 104 may use a voice interface 134 to provide a hands-free interface to computing platform 104. The voice interface 134 may support voice recognition of audio received via the microphone 116 according to a grammar of available commands and voice output generation for output via the audio module 122. In some cases, the system may be configured to mute, cross-fade, or otherwise override the audio source specified by the input selector 124 when one audio signal is ready for presentation by the computing platform 104 and another audio source 126 is selected for playback.The computing platform 104 may also receive input from human machine interface (HMI) controls 136 configured to provide occupant interaction with the vehicle 102. For example, the computing platform 104 may be connected to one or more buttons or other HMI controls configured to invoke functions of the computing platform 104 (e.g., steering wheel audio buttons, a talk button, dashboard controls, etc.). The computing platform 104 may also drive or otherwise communicate with one or more displays 138 to provide visual output to vehicle occupants via a video controller 140. In some cases, the display 138 may be a touch screen further configured to receive user touch inputs via the video controller 140, while in other cases, the display 138 may be only a display without touch input capabilities.The computing platform 104 may be further configured to communicate with other components of the vehicle 102 via one or more vehicle networks 142. The vehicle networks 142 may include one or more of a vehicle controller area network (CAN), an Ethernet network, or a media oriented system transfer (MOST), among others. The vehicle networks 142 may enable the computing platform 104 to communicate with other vehicle 102 systems, such as a vehicle modem 144 (which may not be present in some configurations), a global positioning system (GPS) module 146 configured to provide current location and control information of the vehicle 102, and various vehicle electronic control devices (ECUs) 148 configured to provide other types of information regarding the systems of the vehicle 102. As some non-limiting possibilities, the vehicle ECUs 148 may include a powertrain controller configured to control engine operating components (e.g., idle control components, fuel delivery components, emissions control components, etc.) and monitor engine operating components (e.g., status of engine diagnostic codes); a central controller configured to communicate various power control functions such as exterior lighting, interior lighting, keyless entry, remote starting and entry state checking (e.g., closure state of the hood, doors and / or trunk of the vehicle 102); a radio device configured to communicate with fobs or other local vehicle 102 devices; and a management controller configured to provide control and monitoring of heating and cooling system components (e.g., compressor clutch and heating fan control, temperature sensor information, etc.).As shown, the audio module 122 and the HMI controls 136 may communicate with the computing platform 104 via a first vehicle network 142A, and the vehicle modem 144, GPS module 146, and vehicle ECUs 148 may communicate with the computing platform 104 via a second vehicle network 142B. In other examples, the computing platform 104 may be connected to more or fewer vehicle networks 142. Additionally or alternatively, one or more HMI controls 136 or other components may be connected to the computing platform 104 via different vehicle networks 142 than shown or directly without connection to a vehicle network 142.The computing platform 104 may also be configured to communicate with mobile devices 152 of the vehicle occupants. The mobile devices 152 may include any of various types of portable computing device they, such as cellular phones, tablet computers, smart watches, laptop computers, portable music players, or other devices capable of communication with the computing platform 104. In many examples, the computing platform 104 may include a wireless transceiver 150 (e.g., a BLUETOOTH (R) module, a ZIGBEE (R) transceiver, a Wi-Fi transceiver, etc.) configured to communicate with a compatible wireless transceiver 154 of the mobile device 152. Additionally or alternatively, the computing platform 104 may communicate with the mobile device 152 via a wired connection, such as via a USB port, between the mobile device 152 and the USB subsystem 132.The wide area network 156 may provide communication services such as packet switched network services (e.g., Internet access, VoIP communication services) to devices connected to the wide area network 156. An example of a wide area network 156 may include a cellular telephone network. Mobile devices 152 may provide network connectivity to wide area network 156 via a device modem 158 of mobile device 152. To facilitate communications over the wide area network 156, mobile devices 152 may be associated with unique device identifiers (e.g., Media Access Control (MAC) addresses, mobile device numbers (MDNs), Internet Protocol (IP) addresses, Mobile Station International Subscriber Directory Numbers (MSISDNs), International Mobile Subscriber Identifier (IMSI), etc.) to identify communications of the mobile devices 152 over the wide area network 156. In some cases, occupants of the vehicle 102 or devices with permission to connect to the computing platform 104 may be identified by the computing platform 104 according to paired device 160 data stored in the storage medium 112. Paired device data 160 may indicate, for example, the unique device identifiers of mobile devices 152 previously paired with computing platform 104 of vehicle 102, secret information shared between paired mobile device 152 and computing platform 104, such as connection keys, and / or personal identification numbers (PIN), and most recently used or device priority information, such that computing platform 104 may automatically re-connect to matching mobile device data 152 in paired device data 160 without user intervention. In some cases, the paired device data 160 may also display additional information or options associated with the permissions or functionality of the computing platform 104 for which the paired mobile device 152 is authorized to access when connected.When a paired mobile device 152 that supports network connectivity is automatically or manually connected to the computing platform 104, the mobile device 152 may allow the computing platform 104 to use the network connectivity of the device modem 158 to communicate over the wide area network 156. In an example, the computing platform 104 may use a dataover voice connection over a voice call or data connection of the mobile device 152 to communicate information between the computing platform 104 and the wide area network 156. Additionally or alternatively, the computing platform 104 may use the vehicle modem 144 to communicate information between the computing platform 104 and the wide area network 156, without using the communication facilities of the mobile device 152.Similar to the computing platform 104, the mobile device 152 may include one or more processors 164 configured to execute instructions of mobile applications 170 loaded into a memory 166 of the mobile device 152 from the storage medium 168 of the mobile device 152. In some examples, the mobile applications 170 may be configured to communicate with the computing platform 104 or other locally networked devices and with the wide area network 156.The computing platform 104 may also include a device connection interface 172 to facilitate integration of the functionality of the mobile applications 170 into the grammar of commands available via the voice interface 134. The device connection interface 172 may also provide the mobile applications 170 with access to vehicle features, such as information available to the computing platform 104 via the vehicle networks 142, or access to the display 138. An example of a device connection interface 172 may be the SYNC APPLINK component of the SYNC system provided by Ford Motor Company of Dearborn, MI.FIG. 2 illustrates an example diagram 200 of a service delivery network 202 in communication over the network 156 with a vehicle 102 via a message broker 204. The vehicle 102 may be in wireless communication with the network 156 via the computing platform 104 of the vehicle 102. When a vehicle 102 is assembled, the vehicle 102 may include various hardware and software components. Upon or after assembly, a computing platform 104 of the vehicle 102 may be configured to query the existence and version information for at least a portion of these hardware and software components of the vehicle 102. Using the retrieved information and additional information identifying the specific vehicle 102 (e.g., vehicle identification number (VIN) information stored on the car area network (CAN) bus, subscriber identity module (SIM) information of the vehicle modem 144, such as international mobile device identifier (IMEI), etc.), the computing platform 104 may communicate via the network 156 and message broker 204 to establish an account with the service delivery network 202. The service delivery network 202 may receive these communications from the vehicles 102 and manage storage of the hardware configurations and software (e.g., firmware, etc.) versions associated with identifiers of the vehicles 102.The message broker 204 may additionally provide publish / subscribe messaging functionality for communication between the service delivery network 202 and the vehicles 102. The publish / subscribe model may use one or more topics 206, where topics 206 are called logical channels through which publishers may send messages 208 and participants may receive messages 208. Rather than receiving all messages 208, participants of the topics 206 receive messages 208 for the topics 206 to which they are logged on, and all participants on a topic 206 receive substantially the same topic messages 208.FIGS. 3A and 3B illustrate example communication message flows 208 between the vehicle 102 and the service delivery network 202 via the message broker 204. Messages 208 may be of various categories, such as commands 302, command responses 304, and notifications 306.As shown in FIG. 3A, a command 302 may be published by the service delivery network 202 to a theme of the message broker 204 for which the vehicle 102 is logged. A command 302 is a message type 208 that prompts a recipient of the command 302 to perform an action specified by the command 302. A command response 304 is a message 208 provided back to a transmitter in response to receiving a command 302. The response 304 to the command 302 may be published by the vehicle 102 to a theme 206 for which it is logged to the service delivery network 202.As shown in FIG. 3B, a notification 306 may be published by the vehicle 102 to a theme of the message broker 204 for which it is logged to the service delivery network 202. A notification 306 is a type of message that provides information from a sender to a recipient 208 without requesting execution of a particular action. In response to the notification 306, the message broker 204 may publish a notification response 308 to the vehicle 102 because the service delivery network 202 does not need to provide a response to the notification 306.A publisher of messages 208 may be responsible for providing messages 208 to the themes 206 that match the theme 206. For example, the publisher may include, for the instructions 302, an OEM or other entity responsible for managing and / or updating vehicle software / firmware. In some cases, a vehicle 102 may be a publisher and may send vehicle notifications 306 to a theme 206 for which it is logged to the service delivery network 202, may use notifications 306 to notify the service delivery network 202 of the vehicle 102 connectivity status to the network 156, or may respond to messages 208 from the service delivery network 202 with command responses 304. In other cases, a vehicle 102 may be a subscriber and may receive commands 302 or other information from a service delivery network 202 via the message broker 204.The messages 208 may use a name / value pair model that allows data items of the messages 208 to be defined and referenced by name by the vehicles 102 and the service delivery network 202. Each message 208 may include certain base fields that are present in all messages 208. Furthermore, each message category 208 may include a particular minimum set of data items that are present in all messages 208 of that category. For example, notifications 306 or other messages 208 from vehicle 102 to service delivery network 202 may include a first set of common information useful for recipients of messages 208 from vehicles, and commands 302 or other messages 208 from service delivery network 202 to vehicle 102 may include a second set of common information useful for recipients of messages 208 from service delivery network 202.Depending on the type of message 208 (e.g., command type 302), message 208 may further include additional fields relevant to that specific message type 208. To do so, the name / value pair model may enable subsets of data to be defined (e.g., information to be included in messages 208 of vehicles 102, information to be included in messages 208 from the service delivery network 202, information describing the status of the vehicle 102, etc.) which may then be included in definitions of the message 208 without requiring redundant redefinition for each message type 208 that requires the common information. Because the fields of the message 208 may be referenced by the vehicles 102 and the service delivery network 202 by name or identifiers (rather than by a raw byte offset in the message 208), the system may allow data elements to be added to the definitions of the message 208 (or to the common information definitions) without undesirably affecting vehicles 102 implementing communication with the service delivery network 202 using a parent version of the definitions of the message 208.With respect to processing the various categories of messages 208 published to the topics 206, the vehicle 102 may be configured to execute commands 302 it received from the service delivery network 202 in the order in which the commands 302 were received. To do so, the vehicle 102 may be configured to manage a command queue of received commands 302 to enable the vehicle 102 to execute the received commands 302 from the queue in a first-in-first-out (FIFO) manner. The vehicle 102 may also be configured to execute the notifications 306 in the order in which they occur on the vehicle 102 side. To do so, the vehicle 102 may be configured to manage a notification queue so that it may execute the notifications 306 from the queue in a last-in-first-out (LIFO) manner. In the event of a conflict between a command 302 and a notification 306, the vehicle 102 may be configured to execute the messages 208 in the order in which they were received from the service delivery network 202 or occurred in the vehicle 102 based on time stamps of the messages 208.The topics 206 may be used to enable the messages 208 to be published to or from the appropriate vehicles 102 and in the appropriate message category 208. To facilitate publishing messages 208 to suitable topics 206, the topics 206 may be arranged into a topic tree 210. The topic tree 210 may be defined by the service delivery network 202 to provide a structure of the topics 206 and sub-topics 206 used in sending messages 208 between the vehicles 102 and the service delivery network 202.FIG. 4 illustrates an example topic tree 210 for use in the vehicle 102 for communication to the service delivery network 202. A computing platform 104, such as a telematics unit of a vehicle 102, may log in to nodes of the topic tree 210 corresponding to the installed region, software / firmware version, features, configuration file version of the vehicle 102, etc. It should be appreciated that the particular layout of the example topic tree 210 is for purposes of illustration only and other layouts of the topic tree 210 may be used. For example, other topic trees 210 may be used by the service delivery network 202 that have more, fewer, or different levels of categorization.Referring to the topic tree 210 of FIG. 4, a region node 400 of the topic tree 210 may indicate a region to which the sub-topic 206 nodes may refer below the region node 400. In some cases, the region nodes 400 may represent different regional market areas in which vehicles 102 may be sold, such as North America, Europe, and Asia Pacific. In other examples, region nodes 400 may refer to other geographic spaces, such as countries, states, zip codes, and telephone prefixes. Accordingly, by segmenting the topic tree 210 by region, the service delivery network 202 may publish different information to vehicles 102 associated with different regions.Under each region node 400, the topic tree 210 may include one or more vehicle-specific nodes 402, where each vehicle-specific node 402 pertains to a vehicle 102 connected to the parent region node 400. As one possibility, the service delivery network 202 may create vehicle-specific nodes 402 for vehicles 102 according to the VIN or other unique identifier of vehicles 102 registering with the service delivery network 202 as belonging to a particular region. Sub-nodes to the vehicle-specific nodes 402 may be used to further organize topics 206 configured for communication to and from the individual vehicles 102.For example, the topic tree 210 among the vehicle-specific nodes 402 may further include one or more vehicle topic nodes 404 for communication to the specific vehicles 102. A vehicle 102 may log in to the vehicle topic node 404 corresponding to the VIN or other unique identifier of the vehicle 102, such that the vehicle 102 may be able to receive messages 208 in topics 206 that are specifically related to the vehicle 102 itself.For example, a vehicle 102 may log in to a time critical update vehicle topic node 404-A to receive messages 208 (such as time critical commands 302 described in more detail below) for the particular vehicle 102 having a time critical type. Because of their time critical nature, messages 208 posted to the update vehicle time critical topic node 404-A may run and be removed from the topic 206 if they are not received by the vehicle 102 within a duration of time (e.g., a duration of time specified by the message 208, a duration of time common to all time critical messages 208, etc.). As another example, a vehicle 102 may log in to a non-time critical vehicle topic node 404-B to receive messages 208 for the particular vehicle 102 that are not of a time critical type (e.g., non-time critical commands 302, also described in more detail below).Updates such as calendar updates may be posted to the non-time critical vehicle topic node 404-B and may remain on the topic 206 until received from the logged-on vehicle 102. As another example, a vehicle 102 may log in to a feature update vehicle topic node 404-C to receive messages 208 in a topic 206 that is directed to particular vehicles 102 and is related to updates regarding the features of the vehicle 102. In this content, a feature may refer to grouping configuration parameters applicable to the specified vehicle 102 and included in the topic tree 210. For example, a feature may represent settings to implement an available connected service (e.g., MY FORD MOBILE (R)) or a customized collection of settings (e.g., a series of features to be enabled and / or disabled for use by a particular fleet server). As yet another example, a vehicle 102 may log in to a firmware update vehicle topic node 404-D to receive messages 208 in a topic 206 directed to particular vehicles 102 and associated with updates to the firmware of the vehicle 102.The vehicle-specific nodes 402 of the topic tree 210 may further include one or more vehicle topic nodes 406 for communication from the specific vehicles 102 (e.g., to the service delivery network 202). For example, a general notification topic node 406-A may be used by a vehicle 102 to publish messages 208 (e.g., notifications 306) such as low fuel level indications, erratic driving of the vehicle 102, or periodic current GPS locations of the vehicle 102. As another example, a connection status topic node 406-B may be used by a vehicle 102 to publish messages 208 such as the connection status of the vehicle 102 (e.g., notifications 306 indicating whether the vehicle 102 was disconnected from the network 156 and then reconnected). As yet another example, a command response notification topic node 406-C may be used by a vehicle 102 to publish messages 208 such as notifications 306 indicating the success or failure of the command 302 requested by the service delivery network 202.Further, the topic tree 210 under each region node 400 may include one or more hardware version topic nodes 408, where each hardware version topic node 408 pertains to a hardware version of an installed vehicle 102 that may be shared by multiple vehicles 102 (e.g., a version of the hardware of computing platform 104). These hardware version topic nodes 408 and sub-topic nodes may accordingly be used to reference the vehicles 102 according to the hardware version and not according to the individual vehicle 102.Under each hardware version topic node 408, the topic tree 210 may include one or more firmware version nodes 410. Each firmware version node 410 may organize nodes of the topic tree 210 associated with a firmware version that may be installed in the hardware of the parent tree relationship vehicle 102 for a particular region.The firmware version node 410 may further include feature nodes 412 that organize nodes of the topic tree 210 associated with a particular feature. As mentioned above, a feature may represent settings to implement an available connected service or customized collection of settings. Thus, a firmware version may support multiple different features where different portions of functionality of the firmware are engaged or disengaged for the different features.The feature nodes 412 may further include configuration version nodes 414, each of which represents a topic 206 associated with a version of a configuration file for the associated feature, firmware version, hardware version, and region. The configuration files may include settings and other information associated with the parent features that configure them (e.g., for the version of the firmware installed on the version of the hardware for the particular region). As settings and other options may change from version to version, the configuration files may also include a version number of the firmware for which they are compatible.A vehicle 102 may log in to themes 206 of the topic tree 210 that relate to the configuration of the vehicle 102. As an example, a vehicle may log in to a vehicle topic node 404 corresponding to the VIN of the vehicle 102 to receive any updates that address the specific vehicle 102. As another example, a vehicle 102 computing platform 104 may log in to a configuration version node 414 of the topic tree 210 to receive configuration updates or other updates corresponding to the installed region, hardware version, firmware version, feature, and global configuration version of the vehicle 102. The subscribed vehicle 102 may review or otherwise be informed of messages 208 published to the subscribed topics 206.The service delivery network 202 may publish messages 208 to the topics 206 of the topic tree 210 for which updates are to be performed. As one possibility, service delivery network 202 may publish a command 302 to a vehicle topic node 404 to cause a particular vehicle 102 to be informed that an update should be performed for vehicle 102. As another possibility, the service delivery network 202 may publish a command 302 to a configuration version node 414 to cause any subscribed vehicles 102 having a particular region, hardware version, firmware version, feature, and global configuration version to execute an update.Referring again to FIG. 2, a user of the vehicle 102 may register with software updates executed by the vehicle 102. To facilitate the login process, in some examples, the computing platform 104 may provide a prompt to the user via the display 138 and / or the audio module 122 requesting the user's authorization. An example prompt may prompt the user to agree on over-the-air updates to be performed via the vehicle modem 144 (or via WiFi or through a connected mobile device 152 data connection). Approval may be requested once, but used over multiple update cycles. As another possibility, the user may log in over-the-air updates using a mobile device 152 paired or otherwise connected to the vehicle 102 (e.g., by providing approval via a mobile application executed by the mobile device 152, by sending a short message service (SMS) message from the mobile device 152 to a particular number, using an authorization webpage accessible by the mobile device 152, etc.).Once authorized (e.g., by receiving keystrokes or spoken dialog from the user), the computing platform 104 may be configured to query software updates of the vehicle ECUs 148. This polling can be performed silently without requiring user input.The computing platform 104 may be configured to acquire information associated with the modules of the vehicle 102. The process of collecting data may be referred to as a query and the data collection may be referred to as a query log 212. The information to be queried may include, as some non-limiting examples, module name, module serial number, VIN, hardware part number, MAC address, part numbers of software applications, languages and service packs available on the module, storage space on the module, and status information regarding the installation of previous updates.The computing platform 104 may be further configured to determine which information to acquire by using an optimized data identifier list (ODL) file 214 that defines the specific information to be queried and where such information may be located. In particular, the information to be captured may include data items from the vehicle ECUs 148 or other controllers of the vehicle 102, and may be retrieved via the controller area network (CAN) or other vehicle 102 communication architecture that supports communication between controllers. The information may also include diagnostic codes and other vehicle state information that may be detected by a dealer during maintenance of the vehicle 102. The information may also include analytics data including usage and logging data that includes insight into the use of various vehicle features. In some cases, the ODL file 214 may be installed on the computing platform 104 as part of installing the software, while in other cases, the ODL file 214 may have been previously received according to previously performed updates (described in more detail below). As yet another example, the computing platform 104 may be configured to publish an ODL request to a vehicle-specific topic 206 of the message broker 204 (e.g., the general notification topic 406-A) and receive an ODL 214 file that has been published in response and defines what information to query for the particular VIN.The computing platform 104 may be configured to send the challenge protocol 212 to the service delivery network 202. In an example, the computing platform 104 may send the query protocol 212 to the service delivery network 202 via HTTPS (e.g., by connecting the computing platform 104 to a predefined web address of the service delivery network 202 known to the computing platform 104). Variations in sending the challenge protocol 212 to the service delivery network 202 are possible. As another example, the computing platform 104 may be configured to publish the challenge protocol 212 to a topic 206 of the message broker 204 specific to the vehicle 102 to be invoked by the service delivery network 202.The service delivery network 202 may review the topics 206 to which the vehicle 102 is logged. When the vehicle 102 has published the challenge protocol 212, the service delivery network 202 may check the current module configuration and current version of the computing platform 104 and determine whether any software updates should be installed in the vehicle 102. Based on the determination, the service delivery network 202 may identify bins that should be installed in the vehicle 102 to execute the identified updates. These bins may be identified in a manifest 216. Furthermore, manifest 216 may specify network addresses at which each of the specified update binary files may be retrieved. As an example, the manifest 216 may specify the network addresses as URLs served by a web server 218 of the service delivery network 202. In some cases, the bins may include new versions of files to be installed, while in other cases, the bins may include stepwise updates to be applied to currently installed bins to update the currently installed bins from one version to a next version.To identify the software updates, the service delivery network 202 may be configured to compare the current versions of modules displayed in the query log 212 with the latest version of the modules compatible with the computing platform 104. The service delivery network 202 may be further configured to identify any components that should be updated, any additional dependencies that these updated versions may require. These additional dependencies may be further added to the manifest 216.Once completed, the service delivery network 202 may send the manifest 216 to the computing platform 104. In an example, the service delivery network 202 may send the manifest 216 to the vehicle 102 via HTTPS (e.g., via the HTTP connection to which the computing platform 104 sent the challenge protocol 212 to the computing platform 104, via a different connection to the same or a different predefined web address of the service delivery network 202 known to the computing platform 104, etc.). Variations in sending the manifest 216 to the vehicle 102 are possible. For example, the service delivery network 202 may publish the manifest 216 to a theme 206 of the message broker 204 to be called by the vehicle 102. The computing platform 104 may review the topics 206 to which the vehicle 102 is logged.Regardless of the approach, the computing platform 104 may be configured to install the updates indicated by the manifest 216 once they are received. Based on the manifest 216, the computing platform 104 may be configured to download the updated bins and / or configurations retrieved from the web server policies specified by the manifest 216. As an example, the manifest 216 may specify the network addresses as URLs of the service delivery network 202 served by a web server 218, and the computing platform 104 may download the updated URLs from the URLs specified by the manifest 216. Because the updates may be made available from the web server 218 via HTTPS, the computing platform 104 may be able to download the updates using resume functionality available for download from web servers 218.In some examples, the computing platform 104 may be configured to execute installation of a second installation of the computing platform 104 other than the currently active installation from which the computing platform 104 was booted to avoid interrupting the current version of the software installed on the computing platform 104. The installation of the updates to the second installation can be performed quietly without requiring input from the user.Upon completion of installation of the software updates specified by the manifest 216, the computing platform 104 may be configured to execute an additional query of the modules of the vehicle 102 to generate a new query log 212. Similar to the above, computing platform 104 may generate query log 212, but this time using the received ODL 214, which provides an updated definition of which information to query for the currently executing software update. Similar to the above, computing platform 104 may also be configured to publish challenge protocol 212 to message broker 204 to be received by service delivery network 202. Accordingly, the service delivery network 202 may be automatically updated from the installation status of the vehicle 102 without requiring HMI user interaction.FIG. 5 illustrates an example process 500 for updating software of the computing platform 104. The process 500 may be executed, for example, by a computing platform 104 of a vehicle 102 in communication with a service delivery network 202 via a network 156.At operation 502, the computing platform 104 reports to topics 206 of a topic tree 210 in which instructions 302 are published to update the software version or configuration of one or more modules of the vehicle 102. These modules may include, for example, the computing platform 104 itself and / or other vehicle ECUs 148. For example, the computing platform 104 may log into a desired feature node 404-C of the topic tree 210 in which vehicle-specific updates for a software component of a module of the vehicle 102 may be published through the service delivery network 202. As another example, the computing platform 104 may log in to a configuration version node 414 that represents a topic 206 of the topic tree 210 served by the service delivery network 202 and associated with the installed version, features, and region of the component or module of the vehicle 102.At operation 504, the computing platform 104 determines whether a trigger notification 208 is received in one of the logged-on topics 206. As an example, the service delivery network 202 may publish a trigger notification 208 to the desired feature node 404-C to address an update to the vehicle 102. As another example, the service delivery network 202 may publish a trigger notification 208 to the configuration version node 414 to address vehicles 102 having a particular configuration. The vehicle 102 may be notified or otherwise receive the topics 206 of the topic tree 210 via the notification 208 due to its registration with the topics 206. The trigger notification 208 may indicate to the vehicle 102 that software updates are available. If a notification 208 is received, control passes to operation 506. Otherwise, control remains at operation 504.At operation 506, the vehicle 102 generates a query log 212. The challenge protocol 212 may include version information from at least one software module installed in the vehicle 102. The information to be queried may include, as some non-limiting examples, module name, module serial number, VIN, hardware part number, MAC address, part numbers of software applications, languages and service packs available on the module, storage space on the module, and status information regarding the installation of previous updates. The computing platform 104 may be configured to generate the interrogation protocol 212 according to an ODL 214 that defines which information to interrogate and where that information may be located. The information to be queried may include, for example, requested identifiers from the computing platform 104 and other vehicle ECUs 148 within the vehicle 102. The information may be captured via the CAN bus or other vehicle network 142 and included in the interrogation protocol 212. In some cases, the ODL 214 may be received as part of an installation of the software in the vehicle 102, while in other cases, the ODL 214 may have been previously received according to previously performed updates.At operation 508, the vehicle 102 sends the challenge protocol 212 to the service delivery network 202. In an example, the computing platform 104 may send the query protocol 212 to the service delivery network 202 via HTTPS (e.g., by connecting the computing platform 104 to a predefined web address of the service delivery network 202 known to the computing platform 104). Variations in sending the challenge protocol 212 to the service delivery network 202 are possible. As another example, the computing platform 104 may publish the challenge protocol 212 to a theme 206 of the message broker 204 specific to the vehicle 102 and to be called by the service delivery network 202.At operation 510, the vehicle 102 receives a manifest 216 from the message broker 204. The manifest 216 may display one or more bins to be downloaded and installed by the vehicle 102, as well as other information to be used in performing the update, such as updated ODL 214 and / or keys to decrypt the bins to be downloaded and installed. In an example, the service delivery network 202 may send the manifest 216 to the vehicle 102 via HTTPS (e.g., via the HTTP connection to which the computing platform 104 sent the challenge protocol 212 to the computing platform 104, via a different connection to the same or a different predefined web address of the service delivery network 202 known to the computing platform 104, etc.). Variations in sending the manifest 216 to the vehicle 102 are possible. For example, the service delivery network 202 may publish the manifest 216 to a theme 206 of the message broker 204 to be called by the vehicle 102. The computing platform 104 may review the topics 206 to which the vehicle 102 is logged.At operation 512, the vehicle 102 downloads the bins specified by the manifest 216. The computing platform 104 of the vehicle 102 may download the bins from, for example, the web server 218 of the service delivery network 202 at network addresses specified by the manifest 216. The computing platform 104 may also decrypt the bins into decrypted bins according to the received keys.At operation 514, the computing platform 104 installs the software update. For example, the computing platform 104 may execute or otherwise apply the firmware update to the installed firmware version to update the firmware version. In some cases, the computing platform 104 may be further configured to publish a message 208 to a command response notification topic node 406-C of the vehicle 102 to notify the service delivery network 202 of success or failure of the software update. Upon receiving a message 208 indicating success of the software update, the service delivery network 202 may update its records of the installed configuration status of the vehicle 102. As another possibility, the computing platform 104 may publish an error message 208 to the command response notification topic node 406-C, and the process 600 may end or possibly proceed to operation 512 to retry downloading and installing.At operation 516, the computing platform 104 updates the theme 206 applications of the vehicle 102. For example, the computing platform 104 may offload the vehicle 102 from the configuration version node 414 of the topic tree 210 and the firmware version node 410 for the old version and log it to the configuration version node 414 of the topic tree 210 associated with the new installed version of the firmware. Therefore, the vehicle 102 may be able to receive further trigger notifications 208 corresponding to the updated configuration of the vehicle 102. After operation 516, control passes to operation 504.Thus, a service delivery network 202 may use a topic tree 210 to selectively provide updates to vehicles 102 according to the installed software version, such as firmware version of a module of the vehicle 102 or a software version of an application installed on the computing platform 104, without affecting the vehicle 102 installations of software versions on vehicles 102 having different versions. Furthermore, these updates may be provided to the vehicles 102 in a stepwise and automatic manner via the ether without causing manufacturer or dealer technician costs. Because the updates are made available by the web server 218, the vehicles 102 may be able to download the updates using resume functionality available from web server 218 downloads. Further, because the challenge log generation 212 and the upload are performed in response to a service notification that updates are available, periodic challenge for updates by the vehicle 102 is avoided, thereby avoiding the resource use of the periodic generation and upload of challenge logs 212.Computing devices described herein, such as computing platform 104, mobile devices 152, service delivery network 202, and message broker 204, generally include computer-executable instructions, which instructions may be executable by one or more computing devices such as those listed above. Computer-executable instructions may be compiled or interpreted from computer programs created using a variety of programming languages and / or technologies, including, without limitation, and either alone or in combination, Java, C, C++, C#, Visual Basic, Java Script, Perl, etc. Generally, a processor (e.g., a microprocessor) receives instructions from, for example, a memory, a computer readable medium, etc., and executes these instructions, thereby executing one or more processes that include one or more of the processes described herein. These instructions and other data may be stored and transmitted using a plurality of computer readable media.With respect to the processes, systems, methods, heuristics, etc. described herein, it should be understood that these processes may be practiced with the described steps in an order different from the order described herein, although the steps of these processes, etc. were described as occurring according to a particular ordered sequence. It should be further understood that certain steps could be performed simultaneously, that other steps could be added, or that certain steps described herein could be omitted. In other words, the descriptions of processes herein are provided for the purpose of illustrating certain embodiments, and should not be construed in any way as limiting the claims.While exemplary embodiments have been described above, it is not intended that these embodiments describe all possible forms of the invention. Rather, the words used in the specification are words of description rather than limitation. In addition, the features of various implementing embodiments may be combined to form further embodiments of the invention.It is further described: A. System comprising:a vehicle logged on to a theme managed by a message broker and connected to the vehicle comprising at least one controller programmedsending a query protocol to a service delivery network server that specifies configuration information of the vehicle that is generated in response to a trigger message published on the theme by the server; andretrieving a manifest indicative of network addresses of updates determined using the query protocol.The B. system of A, wherein the at least one controller is further programmed to include, in the interrogation protocol, at least one of (i) current state information of at least one software component installed in the vehicle, and (ii) diagnostic codes of at least one software component installed in the vehicle. The C. system of A, wherein the at least one controller is further programmed to generate the interrogation log based on a data identifier list defining the configuration information to be included in the interrogation log and on which of a plurality of vehicle electronic control devices (ECUs) the information is located. D. The system of A, wherein the theme is associated with a vehicle identification number (VIN) of the vehicle. E. The system of A, wherein the at least one controller is further programmed:download the updates from the network addresses;installing the updates in the vehicle; generating a second query log in response to completing installing the updates; andsending the second query protocol to the server.F. The system of E, wherein the at least one controller is further programmed to download the updates from the network addresses via one or more secure HyperText Transport Protocol (HTTPS) connections. The G. system of A, wherein the at least one controller is further programmed:sending the query protocol to the service delivery network server over a secure HyperText Transport Protocol (HTTPS) connection; andretrieving the manifest from the service delivery network server via the HTTPS connection.H. Method comprising:receiving, by a vehicle processor, a message published from a service delivery network on a theme managed by a message broker and associated with a vehicle indicative of vehicle update availability; generating a query protocol that specifies vehicle equipment information in response to receiving the message;sending the challenge protocol to the service delivery network; andretrieving from the service delivery network a manifest indicating network addresses of updates determined using the query protocol.I. The method of H, further comprising including, in the interrogation protocol, at least one of (i) current state information of at least one software component installed in the vehicle and (ii) diagnostic codes of at least one software component installed in the vehicle. J. The method of H, further comprising generating the interrogation log based on a data identifier list defining the configuration information to be included in the interrogation log and on which of a plurality of vehicle electronic control devices (ECUs) the information resides. K. The method of H, wherein the theme is associated with a vehicle identification number (VIN) of the vehicle. L. The method of H, further comprising:downloading the updates from the network addresses;installing the updates in the vehicle;generating a second query protocol in response to completing installing the updates; andsending the second query protocol to the service delivery network.The M. method of L, wherein the network addresses comprise at least one Universal Resource Locator (URL) served by a web server of the service delivery network. N. A non-transitory computer readable medium comprising instructions that, when executed by a computer system of a vehicle, cause the vehicle to: retrieve a manifest of service delivery network addresses for updates served by a web server, the updates selected based on a protocol including vehicle equipment information compiled by the vehicle computer system in response to receiving a message published to a vehicle logged-on topic managed by a message broker indicating vehicle update availability. The O. medium of N, wherein the protocol comprises at least one of (i) current state information of at least one software component installed in the vehicle and (ii) diagnostic codes of at least one software component installed in the vehicle. The P. medium of N, wherein the log is generated based on a data identifier list defining the configuration information to be included in the log and on which of a plurality of vehicle electronic control devices (ECUs) the information is located. Q. The medium of N, wherein the theme is associated with a vehicle identification number (VIN) of the vehicle. The R. medium of N, further comprising instructions that, when executed by the vehicle computer system, cause the vehicle to:download the updates from the network addresses;installing the updates in the vehicle;generating a second protocol after installation; andpublish the second protocol to the theme.The S. medium of R, wherein the network addresses comprise at least one Universal Resource Locator (URL) served by a web server of the service delivery network.
Claims
A system comprising: a vehicle (102) logged on to a theme managed by a message broker (204) and connected to the vehicle (102), comprising at least one controller programmed to send a challenge protocol (212) to a service delivery network server (218) that specifies configuration information of the vehicle (102) generated in response to a trigger message (208) published to the theme by the server (218) and to retrieve a manifest (216) that indicates network addresses of updates determined using the challenge protocol (212).The system of claim 1, wherein the at least one controller is further programmed to include, in the interrogation protocol (212), (i) current state information of at least one software component installed in the vehicle (102), and (ii) diagnostic codes of at least one software component installed in the vehicle (102).The system of claim 1, wherein the at least one controller is further programmed to generate the interrogation protocol (212) based on a data identifier list defining the configuration information to be included in the interrogation protocol (212) and on which of a plurality of vehicle electronic control devices (ECUs) (148) the information resides.The system of claim 1, wherein the theme is associated with a vehicle identification number (VIN) of the vehicle (102).The system of claim 1, wherein the at least one controller is further programmed to: download the updates from the network addresses; install the updates in the vehicle (102); generate a second query protocol (212) in response to completing the installing of the updates; and send the second query protocol (212) to the server (218).The system of claim 5, wherein the at least one controller is further programmed to download the updates from the network addresses via one or more secure HyperText Transport Protocol (HTTPS) connections.The system of claim 1, wherein the at least one controller is further programmed to: send the challenge protocol (212) to the service delivery network server (218) over a secure HyperText Transport Protocol (HTTPS) connection; and retrieve the manifest (216) from the service delivery network server (218) over the HTTPS connection.A method comprising: receiving, by a vehicle processor (106), a message published from a service delivery network (202) on a theme managed by a message broker (204) and connected to a vehicle (102) indicating vehicle update availability; generating a query protocol (212) that specifies vehicle equipment information in response to receiving the message; sending the query protocol (212) to the service delivery network (202); and retrieving, from the service delivery network (202), a manifest (216) indicating network addresses of updates determined using the query protocol (212).The method of claim 8, further comprising, in the interrogation protocol (212), (i) including current state information of at least one software component installed in the vehicle (102) and (ii) diagnostic codes of at least one software component installed in the vehicle (102).The method of claim 8, further comprising generating the query log (212) based on a data identifier list defining the configuration information to be included in the query log (212) and on which of a plurality of vehicle electronic control devices (ECUs) (148) the information is located.The method of claim 8, wherein the theme is associated with a vehicle identification number (VIN) of the vehicle (102).The method of claim 8, further comprising: downloading the updates from the network addresses; installing the updates in the vehicle (102); generating a second challenge protocol (212) in response to completing the installing of the updates; and sending the second challenge protocol (212) to the service delivery network (202).The method of claim 12, wherein the network addresses comprise at least one Universal Resource Locator (URL) served by a web server (218) of the service delivery network (202).
Citation Information
Patent Citations
Method and System for Updating Software
US20150100955A1
Remote Embedded Device Update Platform Apparatuses, Methods and Systems
WO2016007563A1