Update system, method for rolling out wireless updates, computer program product and computer-readable storage medium

The update system optimizes wireless updates in vehicle fleets by managing a constant number of vehicles and monitoring error rates to reduce execution time and failure risks, addressing the inefficiencies of traditional group-based distributions.

DE102024001701B4Active Publication Date: 2026-06-18MERCEDES BENZ GROUP AG
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
MERCEDES BENZ GROUP AG
Filing Date
2024-05-25
Publication Date
2026-06-18

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Update system (1) for rolling out wireless updates to vehicles (2), comprising a vehicle fleet (3) with a plurality of vehicles (2) and a central computing unit (4), wherein the central computing unit (4) is configured to distribute a wireless update to the vehicles (2) using a wireless communication channel, and the vehicles (2) are configured to receive the wireless update from the central computing unit (4) and to implement a respective wireless update in a vehicle-internal computing unit (5), wherein the central computing facility (4) is further equipped to: - to specify or receive a distribution set (6) and an installation set (7), the distribution set (6) defining a selection of vehicles (2) of the vehicle fleet (3) to which the wireless update is to be rolled out, and the installation set (7) defining a subset of the vehicles (2) assigned to the distribution set (6) that are to implement the wireless update simultaneously; - to distribute and implement the wireless update to the vehicles (2) assigned to the installation set (7), wherein the respective vehicles (2) are configured to transmit status information to the central computing unit (4), including at least information on whether the respective wireless update was successfully implemented on the respective vehicle-internal computing unit (5) or whether the update failed; and - taking into account the respective status information, to keep the installation quantity (7) constant so that as soon as the implementation of the wireless update in one vehicle (2) has been completed, the distribution and implementation in the next vehicle (2) of the distribution quantity (6) is started, characterized by the fact that the central computing facility (4) is further equipped to: - to determine an error rate, describing a ratio of the vehicles (2) of the distribution set (6) where the implementation of the wireless update has failed to a total set of vehicles (2) of the distribution set (6) on which a wireless update implementation has already taken place; and - to compare the error rate with a defined error rate threshold, stopping the rollout of the wireless update as soon as the error rate reaches the error rate threshold.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to an update system for rolling out wireless updates for vehicles of the type defined in more detail in the preamble of claim 1, a method for rolling out wireless updates with such an update system, as well as a computer program product and a computer-readable storage medium.

[0002] Vehicles, such as cars, are increasingly becoming mobile computer systems. Providing driver assistance functions to enhance comfort and driving safety requires processing a wide variety of sensor signals and controlling various actuators within the vehicle. Vehicles can incorporate extensive environmental sensors, such as one or more cameras, ultrasonic sensors, radar sensors, microphones, and / or LiDARE. With the help of such sensor systems, vehicles can perceive their surroundings, enabling at least semi-automated or even autonomous driving. Furthermore, modern vehicles are typically connected to a central computing unit, also known as a backend, for example, via a wireless communication channel. For this purpose, the vehicles may include a telecommunications unit that allows for a mobile internet connection.

[0003] To provide a wide range of functions, the implementation of appropriate hardware in the vehicle is just as important as the implementation of software running on that hardware. Over the vehicle's lifespan, it may be necessary to update the vehicle's software. This allows security vulnerabilities to be closed, errors (also known as bugs) to be fixed, and new functionalities to be added. Such an update can include, for example, adapting the firmware of a control unit, modifying the program code of an application, or introducing new constants or characteristic curves on a processing unit within the vehicle.

[0004] Data packages can be delivered to the respective computing units in the vehicle in a variety of ways. Traditionally, data can be delivered locally within the vehicle, for example, via cable or a physical storage medium such as an SD card or USB stick. However, this involves increased effort for the user, as the corresponding data packages must first be downloaded to a separate computer system, such as a desktop computer, transferred to the storage medium, and then manually inserted into the vehicle. For this reason, the delivery of updates to vehicles via wireless updates, also known as over-the-air (OTA) updates, has become established. With this method, vehicles can receive the corresponding update packages from a server via the internet and install them in the vehicle after optional user confirmation.

[0005] For vehicle manufacturers, it is desirable to carry out such update campaigns as quickly as possible so that the affected computer systems are available again promptly. Due to a variety of reasons, errors can occur during the installation of an update package. Update campaigns are therefore typically carried out in a group-based or wave-like manner. This means that the computer systems to be updated are divided into different groups, which are supplied with the respective update sequentially. This allows the vehicle manufacturer to track the installation success of each update and, if necessary, for example, if too many installation attempts fail, to adjust or stop the update campaign.While this can improve the reliability of the vehicles' operational readiness, it slows down the rollout rate of the corresponding update packages.

[0006] It is therefore desirable to provide procedures and resources that can accelerate the execution of update campaigns, thereby minimizing the risk of failure of the computer systems to be updated or of the vehicles comprising the corresponding computer systems.

[0007] Means for executing corresponding wireless update campaigns in a vehicle context are known from DE 10 2022 101 072 A1. This document describes a central hub for mediating between an OTA master and a fault server, where the OTA master is a device installed in a vehicle of a fleet for managing the implementation of updates in the vehicle. Vehicles can transmit fault information to the fault server, which is then queried by the hub. The OTA master can send a request to the hub to install an update. The hub then checks whether a fault exists for the corresponding vehicle. If no fault exists, the installation of the update in the vehicle can be enabled. If, however, a fault exists, the installation of the update in the vehicle is restricted.

[0008] Furthermore, DE 10 2017 217 668 A1 discloses a method and a central data processing device for updating software in a large number of vehicles. The method allows software to be rolled out successively to the vehicles in a fleet in order to ensure an even distribution of the load on the central data processing device.

[0009] Furthermore, DE 10 2014 219 322 A1 discloses the updating of a vehicle control system via Car2X. An update message is sent via a vehicle ad-hoc network. To ensure that a sufficient number of vehicles are always available, not all vehicles in a larger fleet receive the update simultaneously.

[0010] Furthermore, DE 11 2019 004 030 T5 discloses a central device. This central device serves to distribute a wireless update to the vehicles in a fleet. An error rate can be determined, describing the ratio of the number of vehicles that reported an error during the update to the number of target vehicles.

[0011] Furthermore, DE 10 2022 004 038 A1 discloses a method for the optimal rollout of software updates.

[0012] The present invention is based on the objective of providing an improved update system for rolling out wireless updates for vehicles, with the help of which the execution time of an update campaign can be reduced, while simultaneously reducing the failure risk of the hardware or software components intended for the update campaign.

[0013] According to the invention, this problem is solved by an update system with the features of claim 1. Advantageous embodiments and further developments, as well as a method for rolling out wireless updates with such an update system, a computer program product, and a computer-readable storage medium are set forth in the dependent claims.

[0014] A generic update system for rolling out wireless updates to vehicles, comprising a vehicle fleet with a large number of vehicles and a central computing unit, wherein the central computing unit is configured to distribute a wireless update to the vehicles using a wireless communication channel, and the vehicles are configured to receive the wireless update from the central computing unit and each implement a respective wireless update in an in-vehicle computing unit, further provides that the central computing unit is also configured to: - to define or receive a distribution set and an installation set, the distribution set defining a selection of vehicles in the vehicle fleet to which the wireless update is to be rolled out, and the installation set defining a subset of the vehicles assigned to the distribution set that are to implement the wireless update simultaneously; - to distribute and implement the wireless update to the vehicles assigned to the installation set, with the respective vehicles being configured to transmit status information to the central computing unit, including at least information on whether the respective wireless update was successfully implemented on the respective vehicle-internal computing unit or whether the update failed; and - taking into account respective status information, to keep the installation quantity constant so that, as soon as the implementation of the wireless update in one vehicle has been completed, the distribution and implementation in the next vehicle of the distribution quantity is started, wherein, according to the invention, the central computing device is further configured to: - to determine an error rate, describing a ratio of the vehicles in the distribution set where the implementation of the wireless update has failed, to the total number of vehicles in the distribution set on which a wireless update implementation has already taken place; and - to compare the error rate with a defined error rate threshold, stopping the rollout of the wireless update as soon as the error rate reaches the error rate threshold.

[0015] The update system according to the invention is therefore able to roll out update campaigns for the vehicles in a fleet not in groups or waves, but to provide a constant number of vehicles with the corresponding updates simultaneously from the start to the end of the update campaign. Since it is no longer necessary to wait until a corresponding group or wave of vehicles has been updated before the next group or wave of vehicles can be updated, the time required to carry out the update campaign can be reduced. Because not all vehicles or computing units of the fleet are updated simultaneously, but only a number of vehicles corresponding to the number of installations, the risk of failure can be reduced to a minimum.The number of installations can vary depending on a wide range of boundary conditions.

[0016] Wireless updates can also be referred to as over-the-air updates. These can be any type of update, such as modifying existing software in the vehicle or installing entirely new software. In its simplest form, a wireless update involves adding or modifying data on a computing unit located within the vehicle. The vehicle fleet can include various types of vehicles, such as cars, trucks, vans, buses, and the like. The central computing unit can also be referred to as a backend or cloud server. The vehicles can communicate with the central computing unit, for example, via the internet. The vehicles themselves can be connected to the internet via cellular network or, if a hotspot is within range, via Wi-Fi.

[0017] The distribution set refers to the number of vehicles in the fleet affected by the respective update campaign. The distribution set is therefore determined by which computing units or software components are to be updated by the respective update campaign.

[0018] The installation quantity corresponds to a subset of the distribution quantity and can, for example, be manually specified by the vehicle manufacturer. For instance, a fixed number can be specified for the installation quantity, such as 1000 systems to be updated, or a percentage of the distribution quantity, such as 2%, 5%, 10%, or even fractions or multiples thereof.

[0019] Based on the status information, the central computer system can determine whether a wireless update has been successfully implemented in a given vehicle. This status information thus allows the system to determine the completion of the implementation process within the vehicle. This enables the central computer system to decide when the wireless update should be sent to the next vehicle in the distribution group and implemented there, in order to keep the number of installed vehicles—that is, the number of vehicles currently performing an update—constant throughout the update campaign. Optionally, it is also conceivable that individual vehicles could transmit corresponding status information during the implementation of a wireless update, for example, to provide updates on the installation progress.In this case, the status information could, for example, include the installation progress as a percentage.

[0020] As already described, the central computing facility is also set up to: - to determine an error rate, describing a ratio of the vehicles in the distribution set where the implementation of the wireless update has failed, to the total number of vehicles in the distribution set on which a wireless update implementation has already taken place; and - to compare the error rate with a defined error rate threshold, stopping the rollout of the wireless update as soon as the error rate reaches the error rate threshold.

[0021] By determining the error rate and comparing it to the error rate threshold, the central computing unit is provided with a tool to stop problematic update campaigns early on. As mentioned earlier, there are various reasons why updates might not be successfully implemented in certain vehicles. For example, a wireless update might contain bugs, the external conditions for enabling the update implementation in the vehicle might not be met, a computing unit involved in the update process in the vehicle might be overloaded, resulting in an insufficient installation speed, and so on.Other obstacles to implementing corresponding wireless updates may include limited internet connectivity, infrequent use of the vehicle's computing components involved in the update process, and / or the need for manual user interaction to start a download of a corresponding update package and / or to start the installation of a downloaded update package in the vehicle.

[0022] The central computing unit can first update a minimum number of vehicles before checking the error rate to prevent the update campaign from being aborted if the wireless update fails with the first vehicles supplied with the respective wireless update.

[0023] To minimize the risk of failure of the hardware and / or software components installed in the vehicle, or of the vehicles themselves, previous update campaigns involved rolling out the wireless update in groups or waves. According to the invention, however, the number of vehicles in the distribution set on which the wireless update is implemented is kept constant. If a successful installation of the wireless update cannot be achieved on too many vehicles, the invention prevents the rollout of the wireless update. This prevents the vehicles in the distribution set that are not yet equipped with the wireless update from receiving the corresponding wireless update, or from the implementation process being initiated in the respective vehicles. The reliable operation of these vehicles can thus be ensured.The error rate threshold used in this process can be set variably depending on the specific update campaign. For example, the error rate threshold can be a value such as 5%, 10%, 15%, or fractions or multiples thereof.

[0024] Furthermore, a time threshold can be defined for implementing wireless updates in each vehicle. If an update of the respective component in the vehicle is not possible within the time period specified by the time threshold, this can be interpreted as a trigger for detecting a failed implementation. If an affected in-vehicle processing unit freezes, it may not be possible to detect the update failure. This could ultimately lead to all vehicles in the installed batch being stuck in a corresponding update process in the worst-case scenario. As a result, the central processing unit would no longer be able to distribute further wireless updates to the remaining vehicles in the distribution batch.Accordingly, by considering the time threshold, a failed implementation can be detected, allowing the central computing unit to jump to the next vehicle. The central computing unit is preferably responsible for verifying compliance with the time threshold.

[0025] According to an advantageous embodiment of the update system according to the invention, the central computing unit is further configured to receive a failure risk value, describing the ratio of the expected number of vehicles on which the implementation of the wireless update will fail to the distribution quantity, and to determine the installation quantity depending on the failure risk value. The failure risk value can, for example, be estimated by the vehicle manufacturer. During the development of a corresponding wireless update or update package, the installation process can be tested in various test environments. This makes it possible to determine a corresponding failure rate for a wide variety of operating conditions. This failure rate can then be transferred from the test environment to the actual vehicle fleet.For example, if the update campaign tests in relevant test environments and exhibits a particularly low error rate, a higher number of installations can be selected compared to a high error rate. This is because it can be expected that the wireless update will be reliably implemented on the vehicles in the fleet, allowing more vehicles to be updated simultaneously due to a lower risk of failure. This further reduces the time required to execute the update campaign. Conversely, if a high failure rate is detected, the number of installations is reduced, thus minimizing the risk of failure.

[0026] According to the invention, a method for rolling out wireless updates using an update system described above involves performing the following process steps: - Determining or receiving the distribution quantity and the installation quantity by the central computing unit; and - Distributing and implementing the wireless update on the vehicles specified by the installation quantity, by the central computing unit; wherein - the central computing facility keeps the installation quantity constant, taking into account the status information.

[0027] The invention therefore relates not only to the update system itself, but also to the process carried out by the update system.

[0028] A computer program product according to the invention comprises machine-interpretable instructions which, when executed by a processor of a central computing unit of an update system described above, cause the latter to provide such a method.

[0029] A computer-readable storage medium according to the invention stores such a computer program product according to the invention. For the provision of the method according to the invention, the central computing unit of the update system according to the invention has at least read access to said computer-readable storage medium.

[0030] Further advantageous embodiments of the update system and the method for rolling out wireless updates according to the invention also result from the exemplary embodiments, which are described in more detail below with reference to the figures.

[0031] This shows: Fig. 1 a schematic representation of an update system according to the invention; Fig. 2 a schematic representation of a wave-based rollout of wireless updates to the vehicles of a vehicle fleet; Fig. 3 a schematic representation of a rollout according to the invention of wireless updates to the vehicles of the vehicle fleet; and Fig. 4 a flowchart of a method according to the invention for rolling out wireless updates with the in Fig. 1. Update system shown.

[0032] Fig. Figure 1 shows an update system 1 according to the invention, comprising a central computing unit 4 and a plurality of vehicles 2 belonging to a vehicle fleet 3.

[0033] Each vehicle 2 comprises at least one in-vehicle computing unit 5, which is wirelessly connected to the central computing unit 4 via a telecommunications unit 8. This enables the distribution of wireless updates from the central computing unit 4 to the respective vehicles 2 via the internet.

[0034] The vehicle manufacturer of vehicles 2 in fleet 3 can execute an update campaign. Such an update campaign involves installing update packages or the aforementioned wireless update on a selection of computing units 5 of selected vehicles 2 in fleet 3. For example, the firmware of a specific control unit might need to be updated to close a security vulnerability. In this case, all vehicles 2 in which the aforementioned control unit with the aforementioned firmware is installed are affected by the update campaign. All of these vehicles 2, or computing units 5, are located in the Fig. 2 and Fig. 3 represented as distribution set 6.

[0035] Fig. Figure 2 shows the previously standard procedure for rolling out the wireless update to the aforementioned vehicles 2. For this purpose, the distribution set 6 is divided into several groups 9, which are supplied with the wireless update sequentially. All vehicles 2 assigned to a specific group 9 receive said wireless update as simultaneously as possible.

[0036] In Fig. Group 9.1 has already received the wireless update. Group 9.2 is currently receiving the wireless update, which will then be implemented in the respective vehicles. Groups 9.3 and 9.4 are still awaiting the wireless update. Group 9.3 will only receive the wireless update once the rollout to Group 9.2 is complete.

[0037] The in Fig. The scheme shown in Figure 2 for distributing the wireless update to vehicles 2 of fleet 3 allows for a reduction in the failure risk for vehicles 2 of fleet 3 due to a faulty implementation of wireless updates. This enables the identification of errors in the implementation process during the rollout of the wireless update to groups 9.1 and 9.2, and the distribution to groups 9.3 and 9.4 to be adjusted depending on the success of the rollout. However, due to the sequential distribution of the wireless update to groups 9.1 to 9.4, a comparatively long time is required to execute the update campaign.

[0038] Fig. Figure 3 shows a scheme according to the invention for rolling out the wireless update to the vehicles 2. Fig. Figure 3 again shows a distribution of the vehicles 2 of the vehicle fleet 3 across the distribution set 6. According to the invention, the central computing unit 4 defines or receives an installation set 7, for example, through manual input from a developer, wherein those vehicles 2 of the vehicle fleet 3 receive and implement the wireless updates that are assigned to the installation set 7. The installation set 7 remains constant. This means that a Fig. The first batch 10.1 of vehicles 2 shown in Figure 3 has already been supplied with the wireless update, and a second batch 10.2 of distribution batch 6 is still pending. As indicated by an arrow, the installation batch 7 moves continuously towards the second batch 10.2, causing the second batch 10.2 to shrink and the first batch 10.1 to grow.

[0039] Using the scheme according to the invention for rolling out wireless updates, the time required to execute the update campaign can be reduced. However, the failure risk of the vehicles 2 or the respective computing units 5 remains within acceptable limits. Thus, the rollout of the wireless update to the vehicles 2 assigned to the second batch 10.2 is adapted depending on the implementation success of the first batch 10.1.

[0040] For this purpose, the central computing unit 4 determines an error rate, describing the ratio of the vehicles 2 in the distribution set 6 where the implementation of the wireless update failed to the total number of vehicles 2 in the distribution set 6 on which the implementation of the wireless update has already taken place. This error rate is then compared with a defined error rate threshold, and the rollout of the wireless update is stopped if the error rate reaches the error rate threshold.

[0041] The size of the installation set 7, i.e., the number of vehicles 2 that are to receive the wireless update and simultaneously implement said wireless update, can be chosen to be different depending on various boundary conditions. In particular, the central computing unit 4 can receive a failure risk value, which represents a measure of the likelihood of a successful implementation of the wireless update. The lower the risk of the implementation of a wireless update failing in a vehicle 2, the larger the installation set 7 can be.

[0042] The exact procedure for rolling out the wireless update will be explained again using the following examples: Fig. Figure 4 illustrates this. The process starts in step 400. In step 401, a sequential counter is set to 0. This can be expressed, for example, as "i = 0".

[0043] In step 402, it is checked whether the continuous counter is at most as large as the installation quantity 7. This can be expressed as “i ≤= N”.

[0044] If this is the case, in step 403 the wireless update is distributed to a new vehicle 2 or to an internal computing unit 5 encompassed by the respective vehicle 2.

[0045] Then, in step 404, the continuous counter is incremented, equivalent to "i + 1".

[0046] Once the number of vehicles 2 receiving wireless updates equals the total number of installations (7), step 405 checks whether at least one vehicle 2 has completed the wireless update implementation. For this purpose, the respective vehicles 2 can transmit status information to the central computer 4. Based on this status information, the central computer 4 can verify the successful implementation of the wireless update.

[0047] In step 406, the central computing unit 4 checks whether a particular implementation in vehicle 2 or on the computing unit 5 was successful. If so, in step 407 the serial counter is decremented, indicated by "i - 1". This triggers the re-execution of steps 403 and 404, so that the wireless update is distributed to the next vehicle 2 in the distribution set 6.

[0048] If, however, a successful implementation of the wireless update was not possible, the central computing unit 4 checks in step 408 whether the error rate has reached the defined error rate threshold. If this is the case, the rollout of the wireless update to the vehicles 2 is interrupted or terminated in step 409. If, however, this is not the case, step 407 is executed again, and the serial counter is decremented by 1 so that the distribution of the wireless update to the next vehicle 2 can take place.

[0049] With the aid of the update system 1 according to the invention and the method according to the invention for rolling out wireless updates, the time required to execute the update campaign can be shortened, thereby minimizing the failure risk of the individual vehicles 2 of the vehicle fleet 3.

Claims

[1] Update system (1) for rolling out wireless updates to vehicles (2), comprising a fleet of vehicles (3) with a plurality of vehicles (2) and a central computing unit (4), wherein the central computing unit (4) is configured to distribute a wireless update to the vehicles (2) using a wireless communication channel and the vehicles (2) are configured to receive the wireless update from the central computing unit (4) and each implement a respective wireless update in an in-vehicle computing unit (5), wherein the central computing facility (4) is further equipped to: - to specify or receive a distribution set (6) and an installation set (7), the distribution set (6) defining a selection of vehicles (2) of the vehicle fleet (3) to which the wireless update is to be rolled out, and the installation set (7) defining a subset of the vehicles (2) assigned to the distribution set (6) that are to implement the wireless update simultaneously; - to distribute and implement the wireless update to the vehicles (2) assigned to the installation set (7), wherein the respective vehicles (2) are configured to transmit status information to the central computing unit (4), including at least information on whether the respective wireless update was successfully implemented on the respective vehicle-internal computing unit (5) or whether the update failed; and - taking into account the respective status information, to keep the installation quantity (7) constant so that as soon as the implementation of the wireless update in one vehicle (2) has been completed, the distribution and implementation in the next vehicle (2) of the distribution quantity (6) is started, characterized by , that the central computing facility (4) is further equipped to: - to determine an error rate, describing a ratio of the vehicles (2) of the distribution set (6) where the implementation of the wireless update has failed to a total set of vehicles (2) of the distribution set (6) on which a wireless update implementation has already taken place; and - to compare the error rate with a defined error rate threshold, stopping the rollout of the wireless update as soon as the error rate reaches the error rate threshold. [2] Update system (1) according to claim 1, characterized by , that the central computing unit (4) is further configured to receive a failure risk value describing a ratio of an expected quantity of vehicles (2) on which the implementation of the wireless update will fail to the distribution quantity (6), and to determine the installation quantity (7) depending on the failure risk value. [3] Method for rolling out wireless updates using an update system (1) according to claim 1 or 2, characterized by the following procedural steps: - Determining or receiving the distribution quantity (6) and the installation quantity (7) by the central computing unit (4); and - Distributing and implementing the wireless update on the vehicles (2) specified by the installation quantity (7), by the central computing unit (4); wherein - the central computing facility(4) keeps the installation quantity (7) constant, taking into account the status information. [4] Computer program product, characterized by machine-interpretable instructions which, when executed by a processor of a central computing unit (4) of an update system (1) according to claim 1 or 2, cause the latter to provide a method according to claim 3. [5] Computer-readable storage medium, characterized by a computer program product according to claim 4.

Citation Information

Patent Citations

  • Update of a vehicle control via Car2X

    DE102014219322A1

  • Method and central data processing device for updating software in a large number of vehicles

    DE102017217668A1

  • Methods for optimized rollout of software updates

    DE102022004038A1

  • CENTER, UPDATE CONTROL PROCEDURE, NON-TRANSITORY STORAGE MEDIUM, OTA MASTER AND SOFTWARE UPDATE SYSTEM

    DE102022101072A1

  • CENTRAL DEVICE

    DE112019004030T5