Method, computer program and data carrier for documenting a type configuration for a computing device
A blockchain-based method for documenting type configurations addresses the need for tamper-proof and transparent software update documentation, ensuring integrity and regulatory compliance in vehicle software updates.
Patent Information
- Application Number
- JP2024552131
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-03-09
- Filing Date
- 2023-02-20
- Publication Date
- 2026-02-13
- Estimated Expiration
- 2043-02-20
AI Technical Summary
Existing software update management systems lack tamper-proof and transparent documentation, especially for vehicles, which is crucial for ensuring software integrity and compliance with regulatory requirements.
A method utilizing a distributed ledger technology, such as a blockchain, to store identification values of type configurations, allowing for tamper-proof documentation and decentralized development ecosystems, ensuring integrity and traceability of software updates.
Ensures secure, transparent, and traceable documentation of software updates, maintaining software integrity and compliance with regulatory standards, while reducing memory costs and enabling efficient distribution and execution of updates.
Smart Images

Figure 0007813904000001 
Figure 0007813904000002
Abstract
Description
[Technical Field]
[0001] The invention relates to a method for documentation of type configurations generated on the basis of a provided type library, in particular for a computing device of a motor vehicle, as defined in claim 1. Furthermore, the invention relates to a computer program as defined in claim 9. Finally, the invention relates to an electronically readable data carrier as defined in claim 10. [Background technology]
[0002] Future legislation may require vehicle manufacturers to operate so-called software update management systems (SUMS), which allow, for example, over-the-air software updates for vehicles without the need to bring the vehicle into the factory, and thus directly to the end user. Furthermore, it would be desirable to make software updates more plannable and, above all, more transparent. A particular challenge here is the tamper-proof documentation of the planning results. Furthermore, it would be desirable for the documentation to be traceable even after many years. Patent Document 1 shows a product line based content management system and a corresponding method. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] DE10 2010 050 379 A1 Summary of the Invention [Problem to be solved by the invention]
[0004] The object of the invention is to provide a method, a computer program and a data carrier, which can enable the safety or integrity of software updates, in particular in motor vehicles, in a particularly advantageous manner. [Means for solving the problem]
[0005] This problem is solved according to the invention by the subject matter of the independent claims. Advantages and preferred embodiments of the invention are set out in the dependent claims, the description and the drawings.
[0006] A first aspect of the present invention relates to a method for documenting a type configuration generated for at least one computing device, the first computing device and / or at least one other computing device, based on a provided type library. For example, the first computing device may be one of a complex of computing devices for product line development. The at least one other computing device may be, in particular, an automotive computing device. Each computing device is, in particular, an electronic computing device, in particular including a processor. Preferably, each computing device is thus configured as a computer and / or for electronic data processing.
[0007] A type library is, for example, an interface description for accessing particularly publicly accessible data structures and / or a subprogram for an external service program, which may, for example, be configured as a server that can be shared by several subprograms. Based on the type library, partial and / or complete type configurations can be created, which, for example, form the basis of a distributed development ecosystem.
[0008] The documenting method of the present invention comprises the following steps: The first step involves providing a first version of a type library by a first computing device.
[0009] A second step involves storing the identification values of the first version of the type library in a distributed data bank.
[0010] In a third step, the first computing device and / or another computing device, for example a computing device in a motor vehicle, generates a first at least partial and / or in particular complete type configuration based on the first version of the type library.
[0011] A fourth step involves storing the identification values of the first type configuration in a distributed data bank.
[0012] A distributed data bank is particularly a distributed ledger, similar to a distributed ledger, which is preferably suitable for documenting type libraries and / or type configurations. Such a distributed ledger may, for example, include a type of consensus scheme, which makes it possible to preclude or make particularly difficult manipulation of the identification values that can be uniquely assigned to a type configuration or type library, respectively. For example, the identification value of a first version of a type library is a hash value, which makes it possible to uniquely identify the first version of the type library and, in particular, to recognize changes to the type library that lead to new versions. For example, changes to the type library result in a different identification value. The respective identification values of the respective versions of a type configuration are formed in a similar manner.
[0013] The first computing device may for example be a computing device of an authoring system for type libraries (English: Type Library Authoring System), and the other computing device may for example be a control device of a motor vehicle.
[0014] Thus, for example, one advantage of the present invention is the specific, automated, and irreversible creation and / or update of a specific first type library and of partial and / or complete type configurations derived therefrom. In this way, the use of a distributed data bank, particularly configured as a distributed ledger, allows, on the one hand, tamper-proof documentation and, on the other hand, lays the foundation for a decentralized development ecosystem, whereby data protection and intellectual property protection considerations can be taken into account in a particularly advantageous manner. For example, the method according to the present invention is also suitable for managing type configurations as a method for defining type configurations, as a method for checking the integrity of type libraries, as a method for creating consistent type configurations applicable, for example, for over-the-air updates, and as a method for authenticating type configurations.
[0015] The insight underlying the present invention is that distributed ledger technology may be particularly suitable for the documentation of a distributed development ecosystem. Type configurations may provide a concrete realization of previous general development results, for example during the development of a type library. From the perspective of the end user of the vehicle, this may preferably include a large number of configuration options or ordering options that must be covered in the development process and taken into account in the production / manufacturing process.
[0016] For example, it is known that type libraries can be constructed that take into account numerous configuration options and ordering options, and that partial type configurations as well as ultimately complete or full type configurations can be derived from the type library.
[0017] The method of the present invention allows type library and / or type configuration requirements to be met and made operational in a distributed development ecosystem.
[0018] In other words, the method of the present invention creates the possibility of using a central type library, in particular on the basis of a distributed database, to create particularly consistent partial and / or complete type configurations, and thus to provide a basis for a distributed development ecosystem. For example, there is the advantage that only references, which can be expressed in particular by identification values, to the respective type library or type configuration can be stored in the distributed database, for example as hash values or in addition to the hash. The actual source data of the type library and / or type configuration, and therefore the source code, can be stored, for example, in separate databases.
[0019] In a preferred embodiment of the present invention, the distributed databank is operated by a consensus scheme. In other words, the databank is configured as a distributed ledger, and in particular as a blockchain. The consensus scheme may be, for example, a proof-of-work scheme, which can be implemented by solving a cryptographic puzzle. Additionally or alternatively, a proof-of-holding scheme, for example, a proof-of-stack scheme, can be implemented, whereby the computing devices participating in the distributed databank, such as the first computing device and at least one other computing device, each have the possibility to implement a proof-of-holding and / or a proof-of-work scheme and thus agree on a universally valid, unambiguous version of the respective identification value. Alternatively, for example, a so-called proof-of-time and / or a proof-of-space scheme can also be implemented. The adoption of a consensus scheme allows the tamper-proofness of the documentation to be guaranteed in a particularly preferred manner.
[0020] In another preferred embodiment of the present invention, each type library and / or each type configuration is stored in at least one separate database. In other words, for example, at least one of the computing devices reserves memory space, in which, for example, source code of the type library and / or type configuration is stored, particularly in a database structure. This provides the possibility that the distributed database, in which, for example, the identification values are stored, can be kept as lean as possible, which allows, for example, the method to be implemented particularly efficiently. Additionally or alternatively, this can reduce, for example, memory costs.
[0021] In another preferred embodiment of the present invention, at least one of the data banks and / or at least one of the computing devices are synchronized via a distributed data bank, in particular, where at least one of the computing devices is part of a product line development (Software Product Line (SPL) Engineering). In other words, file exchange occurs between the individual computing devices and / or data banks, and the distributed data bank controls data collation, so that the data banks or computing devices are each, in particular jointly, up-to-date and thus have access to the latest version of the type library or type configuration at any given time. For example, Software Product Line (SPL) Engineering data banks can be preferably synchronized via a distributed ledger or blockchain to obtain the transparency or verifiability required for authentication and / or to improve distributed software development. A further advantage is that software built on the basis of the type library and / or type configuration can be instantly kept up-to-date on each computing instance or computing device, and thus, for example, in a vehicle.
[0022] In another preferred embodiment of the present invention, additional method steps are performed. For example, in another step, a second version of the type library derived from the first version is provided by the first computing device and / or another computing device. In a subsequent step, an identification value of the second version of the type library is stored in a distributed data bank. In other words, a new version of the type library is provided that has been or will be further developed based on the first type library, e.g., based on its source code. An identification value that uniquely identifies the second version of the type library is then stored in the distributed data bank. If the distributed data bank is a blockchain, for example, a new block is added to the data bank with the associated identification value. This provides the advantage that the method allows for documentation of changes to the type library in a particularly preferred manner.
[0023] In another preferred embodiment, the following additional steps are performed: generating, by the first computing device and / or the second computing device, at least one second type configuration at least partially and / or completely based on the second version of the type library, and storing identification values of the second type configuration in a distributed data bank.
[0024] For example, if a type library is constantly further developed in terms of content, it may be updated and re-versioned on a regular basis, e.g. daily, and the method then has the advantage that a corresponding release process can be advantageously configured so that existing content of the type library is not deleted, but only new content is added.
[0025] In a distributed development ecosystem or for software updates in a car that add new components, the process of erasing a type library should only be allowed if it does not affect the elements of the partial and / or complete type configuration derived from it and thus the concrete product instance of, say, a car at the end consumer. An additional step makes this at least traceable.
[0026] In line with the deletion of a type library, elements of partial and / or complete type configurations can or should also be deleted only if they are not relevant to a concrete product instance, e.g., a car. As soon as a complete type configuration is used by a concrete product instance, all elements of the product line development to which the complete type configuration is associated become documentation-relevant and thus silicon-relevant, if they are to become future software updates for the car. Preferably, this method allows any changes in the type configuration to be particularly advantageously documented and therefore particularly permanently preserved.
[0027] This can be made possible, in particular, by the use of identification values. Thus, in a preferred embodiment of the present invention, each identification value is a reference value and / or a cryptographic hash value, and / or each type library or type configuration is stored as at least part of the respective cryptographic value. In other words, each identification value includes a reference value and / or a hash value and / or a type library or type configuration. This provides the advantage that, for example, if a source file is deleted, the corresponding reference continues to exist in the distributed ledger, even if it is no longer known where it points. Even if the reference's location is no longer known, this is not important, in particular, since, as explained above, the end user's concrete product instance does not have any dependencies on the deleted elements, which may, for example, be part of the type configuration. This provides a particularly advantageous application of the method for documentation purposes.
[0028] In a preferred embodiment of the present invention, at least one of the computing devices provides a runtime environment, which allows the execution of the respective type libraries and / or type configurations. In other words, at least one of the computing devices, which has access to the distributed database and is part of, for example, a car, is configured to be able to directly use, for example, product line software, which is built based on one of the type configurations, when the method is applied in product line development. This provides the advantage that software can be not only rapidly distributed, but also executed.
[0029] A second aspect of the invention relates to a computer program directly readable in a storage device of a computing device so as to perform the steps of the method according to the first aspect of the invention when the program is run on the computing device.
[0030] Advantages and advantageous features of the first aspect of the invention may be considered advantages and advantageous features of the second aspect of the invention, and vice versa.
[0031] A third aspect of the present invention relates to an electronically readable data carrier having electronically readable control information stored thereon, the control information comprising at least one computer program according to the second aspect of the invention and configured to carry out a method according to the first aspect of the invention when the data carrier and a computing device are used.
[0032] Advantages and advantageous embodiments of the first and second aspects of the invention may be regarded as advantages and advantageous embodiments of the third aspect of the invention, and vice versa.
[0033] Further advantages, features and details of the present invention will become apparent from the following description of preferred embodiments and from the drawings. The features and combinations of features mentioned in the above description and in the following description of the figures and / or shown only in the figures can be used not only in the respective combinations presented, but also in other combinations or alone without departing from the scope of the present invention. [Brief explanation of the drawings]
[0034] [Figure 1] 1 is a schematic flow chart of a method for documenting a type configuration; [Figure 2] 2 is a schematic diagram of an embodiment of the method shown in FIG. 1. DETAILED DESCRIPTION OF THE INVENTION
[0035] FIG. 1 shows a schematic flow chart of a method for documenting a type configuration generated based on a provided type library, in particular for a computing device in an automobile.
[0036] Preferably, an electronic computing device in a motor vehicle, configured for example as a control unit, will be able to provide in the future software updates that can be documented and furthermore authenticated, and therefore as difficult as possible to tamper with.
[0037] This is achieved by the proposed method, which allows for the management of type configuration in addition to documentation, so that the method can be implemented for the definition of type configuration, and is also suitable for checking the integrity of type libraries and preventing tampering.
[0038] To this end, the method comprises several steps. In a first step S1, a first version N of a type library TB(N) is provided by a first computing device, for example configured as an authoring system AS.
[0039] A second step S2 involves storing the identification values of the first version N of the type library TB(N) in a distributed data bank VD.
[0040] In a third step S3, a first at least partial type configuration pTK(X) or a complete type configuration vTK(X) is generated by the first computing device, the authoring system AS and / or at least one other computing device, exemplarily a partial type configuration service pTKS (partial Type Configuration Service) and a complete type configuration service vTKS (complete Type Configuration Service).
[0041] Finally, in a fourth step S4, the identification values of the first type configurations pTK(X) or vTK(X) are stored in the distributed data bank VD.
[0042] Figure 2 shows in a schematic diagram an embodiment of the method presented in Figure 1, in which the authoring system AS releases in one step a new version N of the type library TB(N), which is documented according to step S2 in the distributed data bank VD.
[0043] Then, by means of another computing device, for example a partial type configuration service pTKS, a partial type configuration pTK(X) is created on the basis of the type library, and its identifying values are documented in the data bank VD according to step S3. Additionally or alternatively, by means of a complete type configuration service vTKS, a complete type configuration vTK(X) is created according to step S3. The corresponding identifying values are then saved according to step S4.
[0044] In this way, complete documentation of the type library, including traceability to each version, is already guaranteed.
[0045] 2, the partial library TB(N) can then be further developed in content and released in a new version N+1 as partial library TB(N+1), the type library service TBS (English: Type Library Service) then using, from this point on, the new version N1 of the type library TB N+1, for example in a readable form. In other words, the provision of the second version N+1 of the type library TB, derived from the first version N, is carried out by the first computing device (AS) and / or by a further computing device (pTKS). Additionally, the storage of the identification values of the second version N+1 of the type library TB is carried out in a distributed data bank VD.
[0046] In a subsequent step, a computing device configured as a partial type configuration service pTKS can create a new partial type configuration pTK(Y) based on the type library TB(N+1) and document its identification value in a distributed data bank VD.
[0047] Additionally or alternatively, if a complete type configuration vTK(Y) is created based on the type library TB(N+1), this too is documented in the equally distributed data bank VD.
[0048] In addition to versioning the entire type library TB(N) / TB(N+1), the method also allows versioning of individual components of each type library TB(N) / TB(N+1) itself, with unambiguous reference.
[0049] Preferably, in the method, a runtime environment is provided by at least one of the computing devices, for example by the AS and / or the TKS, and in particular by the type library service TBS, whereby the respective type library TB(N), TB(N+1) and / or the respective type configuration TK(X), TK(Y) can be executed. For example, the type library service TBS can provide a runtime environment whereby versions N and / or N+1 of the type library TB can be used, at least in a readable manner.
[0050] Thus, each type configuration vTK(X), vTK(Y), pTK(X), pTK(Y) always targets exactly the unambiguous version N or N+1 of the type library TB(N) / TB(N+1) from which it is derived. For full type configurations vTK(X), vTK(Y), they may also target unambiguous versions of partial type configurations pTK(X), pTK(Y).
[0051] The method presented here provides the possibility of preserving all provided information, including type libraries TB(N), TB(N+1) and type configurations vTK(X), vTK(Y), pTK(X), pTK(Y), in particular through a central data bank VD having a consensus mechanism and additionally structured as a distributed ledger or blockchain, so that subsequent manipulation of this information is impossible.
[0052] Each identification value stored in the distributed data bank VD comprises, for example, a reference and / or a cryptographic hash value and / or the respective type library TB(N), TB(N+1) or the respective type configuration vTK(X), vTK(Y), pTK(X), pTK(Y) itself. Additionally or alternatively, the type library TB(N), TB(N+1) and / or the respective type configuration vTK(X), vTK(Y), pTK(X), pTK(Y) can each be stored in at least one further data bank.
[0053] In order to map a corresponding development ecosystem, such as a development project, within the framework of a collaboration or to restrict collaboration to specific suppliers, the method allows the provision of corresponding layers for each sub-area of a type library or a partial and / or complete type configuration, which extract only the desired elements of the respective database and accordingly fade out the rest.
[0054] The functionality of this layer may be advantageously realized directly through the mechanisms of the applied distributed ledger technology, for example by applying smart contracts or self-sovereign or decentralized identity mechanisms.
[0055] This embodiment is preferably designed for automotive applications in the automotive industry, however the method can be applied to the development of any complex, multivariate, mass-produced product, including, by way of example, aircraft, trucks, buses, agricultural machinery, ships, trains, drones, robots, motorcycles, autonomous vehicles, machines, and equipment, both in the consumer goods industry and in the information and communications technology industry.
[0056] Furthermore, the presented methodology allows for the type-based product line development concept to be concretized in the context of a distributed homogeneous development ecosystem, thus fulfilling the requirements imposed, for example, pursuant to UNECE regulation UN-R 156.
[0057] The methods described herein may be in the form of a computer program which, when executed, implements the method on one of an electronic computing device. Similarly, there may be an electronically readable data carrier having stored thereon electronically readable control information which contains at least one such computer program and is configured to be able to carry out the methods when the data carrier is used in an electronic computing device.
Claims
1. 1. A method for documenting a type configuration (TK) generated based on a provided type library (TB), the method being executed on at least one computing device, the method comprising: providing (S1) a first version of said type library (TB) by a first computing device; a step (S2) of storing the identification values of the first version of said type library (TB) in a distributed data bank (VB); generating (S3) by said first computing device and / or at least one other computing device a first at least partial type configuration (pTK) and / or a complete type configuration (vTK) based on a first version of said type library (TB); a step (S4) of storing in said distributed data bank (VB) an identification value of said first type configuration (TK); The method comprising:
2. 2. The method of claim 1, wherein the distributed data bank (VD) operates in a consensus manner.
3. 3. A method according to claim 1 or 2, characterized in that each said type library (TB) and / or each said type configuration (pTK / vTK) is stored in at least one separate data bank.
4. 3. The method according to claim 1 or 2, characterized in that at least one of the data banks and / or at least one of the computing devices are synchronized through the distributed data bank (VD), in particular at least one of the computing devices is part of a product line development.
5. The following additional steps: providing, by said first computing device and / or said other computing device, a second version of a type library (TB) derived from said first version; storing the identification values of the second version of the type library (TB) in the distributed data bank; 3. The method according to claim 1 or 2, characterized by:
6. The following additional steps: generating, by said first computing device and / or said further computing device, at least one second at least partial type configuration (pTK / vTK) based on a second version of said type library (TB); storing the identification values of said second type configurations (pTK / vTK) in said distributed data bank (VB); The method of claim 5, characterized by:
7. 3. A method according to claim 1 or 2, characterized in that each said identification value comprises a reference value and / or a cryptographic hash value and / or the respective said type library (TB) or the respective said type configuration (TK).
8. 3. The method according to claim 1 or 2, characterized in that at least one of the computing devices provides a runtime environment by means of which a respective type library (TB) and / or type configuration (TK) can be executed.
9. A computer program directly loadable into a storage device of a computing device, said computer program being for carrying out the steps of the method according to claim 1 or 2 when said program is run on said computing device.
10. 10. An electronically readable data carrier having electronically readable control information stored thereon, said control information comprising at least one computer program as claimed in claim 9, said data carrier being configured to carry out the method of claim 1 or 2 when said computer program is executed.
Citation Information
Patent Citations
Product line managing module for product line based content management system, produces bill of materials of product and auto code for several modules based on data dictionary entries and interface information
DE102010050379A1
Management method, management apparatus, and, program
JP2019220146A
Announcement smart contracts to announce software release
US20190305959A1
Software library access and usage management
US20210311926A1