Method for installing and updating software modules on control units of motor vehicles
The method allows for secure, wireless installation and updating of software modules on motor vehicle control units without customer intervention, addressing the inconvenience of existing methods by ensuring continuous operation of the target control unit.
Patent Information
- Application Number
- PCT/EP2024/078884
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-11
- Filing Date
- 2024-10-14
- Publication Date
- 2025-06-19
AI Technical Summary
Existing methods for installing and updating software modules on motor vehicle control units require customer intervention and interrupt the operation of the target control unit, making them inconvenient and disruptive.
A method for securely wirelessly transferring and installing software modules on a vehicle-based target control unit without customer intervention, involving the creation and external signing of a script, development and signing of a machine learning model, and wireless transmission and execution on the target control unit.
Enables the secure, wireless installation and updating of software modules on motor vehicle control units without interrupting the target control unit's operation, allowing for seamless updates without customer intervention.
Smart Images

Figure 00000016_0000
Abstract
Description
[0001] PROCEDURE FOR INSTALLING AND UPDATING
[0002] SOFTWARE MODULES ON MOTOR VEHICLE CONTROL UNITS
[0003] TECHNICAL FIELD OF THE INVENTION
[0004] The invention relates to a method for installing and updating software modules on a target control unit of a motor vehicle, wherein the motor vehicle has a control unit that is higher-level than the target control unit.
[0005] BACKGROUND OF THE INVENTION
[0006] Vehicles today have a large number of control units with independent processing units that can carry out a large number of very different assistance functions in order to make driving not only more pleasant and comfortable, but above all also significantly safer, and on the other hand to make maintenance processes more efficient and environmentally friendly, for example by not simply carrying out maintenance after a certain mileage, but only when this seems sensible due to the actual condition of the vehicle, which results from the individual driving behaviour of a user, among other things.
[0007] Control units of the type in question here use software in the form of so-called machine learning models, which can also be referred to as prediction programs due to their function and which are able to evaluate vehicle data on board a vehicle, which is recorded by the vehicle itself using appropriate sensors and typically supplemented by further externally collected data, under certain questions and thus make predictions about certain events, e.g. the degree of wear of a certain component, anomalies in the vehicle or the behavior of a driver, which can be relevant on very different levels, e.g. for driving or maintaining the vehicle.
[0008] Machine learning models are typically created using so-called machine learning algorithms and corresponding training data. They generally perform better, i.e., their predictions are more accurate, the more real vehicle data is available for training. Since modern vehicles typically collect a large amount of vehicle data and transmit it to the vehicle manufacturer wirelessly or wired (e.g., during a workshop visit), depending on customer approval, the manufacturer can collect a large amount of data (so-called fleet data) about the respective vehicle type and the respective individually equipped model and its behavior, which enables the creation of very precise machine learning models.
[0009] Particularly with model changes, there is a dilemma: on the one hand, there is no fleet data – i.e., large data sets on the real-life, everyday behavior of the new vehicles – because only a few vehicles are in test operation, but on the other hand, customers should already be provided with the most comprehensive assistance functions possible. For assistance functions that use software that changes only rarely (such as radio controls), this is generally unproblematic; however, other assistance functions use machine learning models that often improve, especially in the initial phase, and / or are retrained based on new data. In some cases, entirely new functions are developed for control units installed in a vehicle, meaning that the corresponding software on an control unit must not only be updated but also reinstalled.
[0010] DISCLOSURE OF THE INVENTION
[0011] Depending on their type, reliable assistance functions not only contribute to driving safety, but increasingly also to customer satisfaction and brand loyalty. While customers are generally impressed by the reliability of their vehicle, for example, when a precise program prompts them to visit a workshop, which in retrospect actually proves to be worthwhile, they are less than pleased when they have to visit a workshop just for a software update.
[0012] It is known to offer customers the option of a so-called "remote software update," in which the customer initiates a software update for their model by downloading software updates via an application on their mobile phone, via a possibly existing in-vehicle SIM card, or via Wi-Fi and then starting the installation in the vehicle. However, this requires active cooperation from the customer and is also associated with an interruption in the operation of the control unit (hereinafter referred to as the target control unit) whose software is to be updated, so that the customer cannot use the vehicle during the update.
[0013] Based on this, the invention is based on the object of specifying a method for installing and updating software modules on a target control unit of a motor vehicle. This method allows for the secure wireless transfer of software modules to a vehicle-mounted target control unit and the installation and updating of such software modules without customer intervention and, above all, without a complete "flashing" (complete overwriting of the software stored in a ROM of the target control unit). The term "software module" refers to the machine learning model and associated control logic.
[0014] The problem is solved by a method having the features of claim 1. The subordinate claim 10 relates to an arrangement for carrying out the method. Advantageous embodiments and further developments are the subject of the respective subclaims.
[0015] The problem is solved in particular by a method comprising the following steps:
[0016] - creating a script outside the vehicle,
[0017] - signing the script externally,
[0018] - storing the script outside the vehicle in an area that is wirelessly accessible to the higher-level control unit,
[0019] - developing and training a machine learning model for the target control unit outside the vehicle,
[0020] - vehicle-external compilation of the machine learning model,
[0021] - vehicle-external signing of the machine learning model,
[0022] - storing the machine learning model outside the vehicle at a defined address in an area that is wirelessly accessible to the higher-level control unit,
[0023] - entries of the defined address in the script,
[0024] - wireless transmission of the script to the control unit in the vehicle that is superior to the target control unit,
[0025] - Forwarding the script through the higher-level control unit to the target control unit,
[0026] - Verifying the signature of the script by the target control unit,
[0027] - if the signature verification has been completed successfully, execute the script and pass the defined address to the higher-level control unit,
[0028] - Downloading and caching the model by the higher-level control unit,
[0029] - Forwarding the downloaded model to the target control unit,
[0030] - Checking the signature of the model by the target control unit,
[0031] - If the signature verification has been successfully completed, initializing and executing the model on the target control unit. The invention has the advantage that new or updated machine learning models and the associated control logic can be sent "over the air," i.e., wirelessly, to a target control unit in a vehicle equipped with the appropriate means for wireless communication, without customer intervention and without having to interrupt the operation of the target control unit. The corresponding software modules can then be installed and updated when the respective target control unit is not needed, e.g., after the vehicle has been parked.
[0032] In a preferred embodiment of the method, the script is compiled externally of the vehicle, compiled on the target control unit, or interpreted on the target control unit, depending on the scripting language used for the script.
[0033] In a further preferred embodiment of the method, the script comprises control logic, in particular control logic for data preparation, for controlling the machine learning model, for downloading the machine learning model, or merely a configuration, in particular the defined address. If this comprises control logic, the method can advantageously be implemented such that, after the positive completion of the model signature verification, the script initializes the model and executes it on the target control unit.
[0034] Depending on the type and intended use of the model, it can be provided that the script on the target control unit collects data from the control unit or from an on-board network, in particular by means of a programming interface, processes it and passes it on to the model as input.
[0035] The invention advantageously allows the transfer of the script to the higher-level control unit to be triggered in various ways. For example, the transfer can be initiated by a location external to the vehicle, for example, when a software update is completed. Alternatively or additionally, the transfer of the script to the higher-level control unit can be triggered by a vehicle-side request to a location external to the vehicle, i.e., the vehicle actively contacts the vehicle, for example, at certain time intervals (daily, weekly) or at certain mileages (e.g., every 5,000 km), and inquires whether new scripts are available.
[0036] In another preferred embodiment of the method, the download of the model is triggered by the target control unit or the script after the signature of the script has been verified. In a particularly preferred embodiment of the method, the model is downloaded asynchronously by the higher-level control unit, which allows for the transfer of even large amounts of data in a resource-efficient manner.
[0037] To achieve the object, an arrangement for carrying out the method according to the invention is further proposed, which at least comprises:
[0038] - at least one vehicle-external location for creating and signing a script and for developing, training, compiling and signing a machine learning model for the target control unit,
[0039] - at least one memory that is wirelessly accessible to the higher-level control unit for storing the script and the machine learning model,
[0040] - means for wireless communication between the control unit superordinate to the target control unit and the at least one memory,
[0041] - Means for communication, particularly by wire, between the target control unit and its higher-level control unit,
[0042] - wherein the target control device is configured to check the signature of the script and the signature of the model, and
[0043] - wherein the higher-level control unit is designed to download the model, temporarily store it and forward it to the target control unit.
[0044] In an advantageous further development, it can be provided that the target control unit is designed to receive several scripts in parallel, to download several machine learning models in parallel and, if necessary, to execute them in parallel.
[0045] Further details and advantages of the invention will become apparent from the following purely exemplary and non-limiting description of an embodiment in conjunction with the drawing. BRIEF DESCRIPTION OF THE DRAWING
[0046] Fig. 1 shows a diagram of an arrangement for carrying out a method according to the invention and at the same time schematically illustrates certain steps in carrying out the method.
[0047] DESCRIPTION OF PREFERRED EMBODIMENTS
[0048] In the following description, the same reference numbers are used for identical and equivalent parts.
[0049] Fig. 1 shows, in a highly schematic manner, elements of an arrangement, designated as a whole by 10, for installing and updating software modules on a target control unit 12 of a motor vehicle 14, wherein the motor vehicle 14 has a control unit 16 that is higher-level than the target control unit 12. The motor vehicle 14 can be a car, truck, bus, mobile home, motorcycle, rail vehicle, construction vehicle, or the like, which is used in particular for the transport of people and goods, but also for the execution of certain tasks, such as rollers or excavators.
[0050] Both the target control unit 14 and its higher-level control unit 16 form data processing embedded systems, i.e. computers that are integrated into a technical context and perform monitoring, control or regulation functions and / or are responsible for a form of data or signal processing, e.g. encryption or decryption, coding or decoding or filtering. Functionalities that can be mapped with a program on an embedded system of the vehicle include, for example, dynamic data collection. For example, after a vehicle has been delivered, a program is installed over-the-air, i.e. wirelessly, on the control unit in the vehicle. This program either periodically or, for example, event-based, for example when certain vehicle states or error states are detected, forwards certain signals on the control unit either to another control unit via a vehicle's on-board network or to a backend server orsends to the cloud, machine learning on the control unit, e.g., as concrete learning or simply evaluating data with existing neural networks, apps, i.e., applications, also called user programs, that map user functionality, e.g., loading updates for integrating mobile phones into a vehicle's hands-free system that were not yet available on the market when the vehicle was delivered to the customer. A typical target control unit 12 is intended, on the one hand, to execute dynamic program components, but, on the other hand, has so-called system functions and functional properties that, in many cases, also guarantee the functional safety of the motor vehicle and that must not be influenced in an unforeseeable manner under any circumstances.The invention particularly relates to the installation and updating of dynamic program components. Accordingly, the term "software module" refers to both a machine learning model 18 and the associated script 20. In the context of automotive control units, a flexible and isolated execution of loadable program components is realized via various mechanisms. For example, virtual machines based on interpreter technology, such as the Lua VM, also known as the Lua runtime environment, and JIT-compiling (JIT: Just In Time) runtime environments such as node.js are used on larger control units. Preferably, a WebAssembly runtime environment is used. On the other hand, so-called "embedded hypervisors" are used, which are typically hardware-specific and place specific requirements on the respective hardware and software architecture or even on the operating system used.
[0051] Machine Learning Model 18 and Script 20 are developed off-board, for which an off-board environment 22 includes a corresponding development platform 24. The units of the off-board environment, which will be discussed below, can be clustered in a data center, for example, but do not have to be. In particular, the units, provided they exist physically and not merely virtually, can be distributed across completely different locations.
[0052] In addition to the development platform 24 already mentioned, the vehicle-external environment 22 comprises a signature location 26, a memory, here in the form of a so-called campaign management service 28, for storing the script 20 and a memory, here in the form of a so-called upload-download service 30, for storing the machine learning model 18. The term memory here therefore does not only refer to classic memories for storing files, but also to services that have further functions beyond storing files and, in particular, as explained below, can communicate with the control unit 16, as indicated by the arrows 32 and 34.
[0053] The development platform 24 comprises a so-called toolbox 36, in which the so-called tools required for the respective application case are located, for example corresponding compilers, in order to translate, if necessary, the source code of script 20 or model 18 into a form that can be executed by the respective embedded system, i.e. the control units 12 and 16.
[0054] By means of the arrangement 10 shown, a method for installing and updating software modules on the target control unit can then be implemented by performing the following steps:
[0055] First, a script 20 is created on the development platform 24 for a specific use case 38, symbolized by a box. In its simplest form, the script 20 can be just a specific configuration file, which in particular contains a defined address, e.g., a URL, under which the model 18 can later be retrieved via the service 30. Typically, however, the script also contains so-called control logic, for example, relating to data preparation, model control, download logic, etc., and is typically written in a scripting language and then compiled, e.g., in WebAssembly. The script 20 can also be written in a so-called interpreter language so that it can later be interpreted directly on the target control unit 12. If it is written in a high-level scripting language and must be compiled before execution, this can be done on the platform 24 using the tools 36.However, it is also possible to compile the script 20 directly on the target control unit 12.
[0056] The finished script 20 is then signed externally to the vehicle at the signature location 26 and subsequently stored in the service 28, which in turn can be done using tools from the toolbox 36.
[0057] Furthermore, a machine learning model 18 is developed on the development platform 24 for the specific application case 38. This development can be carried out independently of the creation of the script 20, in that the development of the model 18 can occur simultaneously with, before, or after the creation of the script 20. The model 18 is also signed in a conventional manner using the signature location 26. In the illustrated embodiment, however, it is then stored in the upload-download service 30, from which the model 20 can be retrieved using the defined address. This defined address is entered into the script 20.
[0058] As already mentioned, the vehicle 14 can wirelessly contact the service 28. Contact can be initiated both by the vehicle-external environment 22 and by the vehicle 14 itself, for example, by the vehicle 14 regularly querying the service 28, for example, at specific time intervals or after a certain number of kilometers driven, to see if new scripts are available. If this is the case, the higher-level control unit 16 establishes a connection to the service 28 via a so-called script downloader 40 and receives the script 20.
[0059] The received script is then forwarded internally to the vehicle, for example via bus communication such as Ethernet SOME / IP, to the target control unit 12, where a signature check 42 is performed. If this check 42 is successful, the script is installed 44 on the target control unit 12 and executed, which then triggers the downloading and installation 46 of the model 18 by transferring the defined address to the higher-level control unit 16, specifically in this embodiment to an upload / download manager 48, via bus communication such as Ethernet SOME / IP. The upload / download manager 48 then downloads the model 18 from the upload / download service 30, preferably asynchronously. The upload / download manager 48 temporarily stores the model in a file system 50 and notifies the target control unit 12 via bus communication such as Ethernet SOME / IP where the model is stored in the file system 50.The target control unit 12 loads the model 18, for example, via a file transfer protocol such as WebDAV, so that, in programmatic terms, the model 18 is transferred to a memory of the target control unit 12 via a WebDAV server 52 and can then be initialized and executed by the target control unit 12 after a corresponding signature verification. The file system 50 then serves as a WebDAV client.
[0060] A typical example of the use of machine learning models and the application of the invention is the detection of the driver's mental state. For this purpose, various sensors and cameras in the vehicle collect data that can provide information about conditions such as stress, ability to concentrate, etc. This also determines whether the driver is at all receptive to any recommendations from the vehicle or is currently very concentrated, e.g., due to heavy traffic or high speed, and should only be interrupted in an emergency, e.g., to avoid an accident, by a so-called "digital intelligent personal assistant" (a software) in the vehicle. For this purpose, a machine learning model is developed to predict a so-called "interruptibility index" and an emotional state based on vehicle signals, interior camera images, and audio characteristics from interior microphones, etc.A script contains the logic for collecting and preparing (or, in other words, preprocessing) the interior camera images, audio features, and additional data from the vehicle's electrical system, which serve as input to the machine learning model. The data is collected via a data API (Application Programming Interface), which is designed to provide all data available in the target electronic control unit and the vehicle's electrical system. Furthermore, the script contains the logic to run the machine learning model with the preprocessed data and read the model's output.
[0061] The script and the machine learning model are transferred to the ECU as described above. The script contains the logic for deploying and executing the model in the ECU's runtime environment.
[0062] Once the machine learning model is executed, its outputs provide insight into the driver's emotional state, helping in-vehicle personal assistance applications provide the driver with the right information at the right time without distracting them at inopportune times.
[0063] The invention makes it possible to encapsulate the entire software for use case 38 in script 20, which provides enormous flexibility. The machine learning model 18 can be executed directly on a corresponding machine learning hardware accelerator of the target control unit 12, which can minimize its CPU load and further increase efficiency. This can be done by having the script runtime environment also implement the hardware-specific APIs, allowing the machine learning models to be executed directly on dedicated machine learning accelerators of the hardware.
[0064] LIST OF REFERENCE SYMBOLS
[0065] 10 Arrangement for installing and updating software modules
[0066] 12 Target control unit
[0067] 14 Motor vehicle
[0068] 16 higher-level control unit 16
[0069] 18 Machine Learning Model
[0070] 20 script
[0071] 22 external vehicle environment
[0072] 24 Development platform
[0073] 26 Signature location
[0074] 28 Campaign Management Service
[0075] 30 Upload-Download Service
[0076] 32 Data communication
[0077] 34 Data communication
[0078] 36 Toolbox
[0079] 38 Use case
[0080] 40 script downloaders
[0081] 42 Signature verification
[0082] 44 Installing the script
[0083] 46 Downloading and installing the model
[0084] 48 Upload-Download Manager
[0085] 50 File system
[0086] 52 WebDav Server
Claims
Claims 1. A method for installing and updating software modules on a target control unit of a motor vehicle, wherein the motor vehicle has a control unit that is superior to the target control unit, comprising the following steps: - creating a script outside the vehicle, - external signing of the script, - storing the script outside the vehicle in an area that is wirelessly accessible to the higher-level control unit, - developing and training a machine learning model for the target control unit outside the vehicle, - vehicle-external compilation of the machine learning model, - vehicle-external signing of the machine learning model, - storing the machine learning model outside the vehicle at a defined address in an area that is wirelessly accessible to the higher-level control unit, - entries of the defined address in the script, - wireless transmission of the script to the control unit in the vehicle that is superior to the target control unit, - Forwarding the script by the higher-level control unit to the target control unit, - Verification of the script signature by the target control unit, - if the signature verification has been completed successfully, execute the script and pass the defined address to the higher-level control unit, - Downloading and caching the model by the higher-level control unit, - Forwarding the downloaded model to the target control unit, - Checking the signature of the model by the target control unit, - if the signature verification has been completed successfully, initialize and execute the model on the target control unit.
2. Method according to claim 1, characterized in that the script is compiled externally of the vehicle, compiled on the target control unit or interpreted on the target control unit depending on the script language used for the script.
3. The method according to claim 1 or 2, characterized in that the script comprises a control logic, in particular a control logic for data preparation, for controlling the machine learning model, for downloading the machine learning model, or only a configuration, in particular the defined address.
4. The method according to claim 3, comprising a control logic, characterized in that the script, after the positive completion of the verification of the signature of the model, initializes the model and executes it on the target control device.
5. Method according to one of claims 1 to 4, characterized in that the script on the target control unit, in particular by means of a programming interface, collects data from the control unit or from an on-board network, processes it and passes it on as input to the model.
6. Method according to one of claims 1 to 5, characterized in that the transmission of the script to the higher-level control unit is triggered by a vehicle-side request to a location external to the vehicle.
7. Method according to one of claims 1 to 6, characterized in that the transmission of the script to the higher-level control unit is triggered by a location external to the vehicle.
8. Method according to one of claims 1 to 7, characterized in that the downloading of the model is triggered by the target control device or the script after checking the signature of the script.
9. Method according to one of claims 1 to 8, characterized in that the downloading of the model by the higher-level control unit is carried out asynchronously.
10. Arrangement (10) for installing and updating software modules on a target control unit (12) of a motor vehicle (14), wherein the motor vehicle has a control unit (16) superordinate to the target control unit (12), according to a method according to one of claims 1 to 9, comprising: - at least one vehicle-external location (24, 26) for creating and signing a script (20) and for developing, training, compiling and signing a machine learning model (18) for the target control unit, - at least one memory (28, 30) wirelessly accessible to the higher-level control unit (16) for storing the script and the machine learning model, - means for wireless communication between the control unit (16) superordinate to the target control unit (12) and the at least one memory (28, 30), - means for, in particular, wired communication between the target control unit (12) and its higher-level control unit (16), - wherein the target control device (12) is designed to check the signature of the script (20) and the signature of the model (18), and - wherein the higher-level control unit (16) is designed to download the model (20), to temporarily store it and to forward it to the target control unit (12).
11. Arrangement (10) according to claim 10, characterized in that the target control device (12) is designed to receive a plurality of scripts (20) in parallel and / or to download a plurality of machine learning models (18) in parallel and / or to execute a plurality of scripts (20) and / or machine learning models (18) in parallel.
Citation Information
Patent Citations
Updating a vehicle's software based on vehicle field data
DE102022204862A1
Intelligent multifunctional robot and its use
DE202023100163U1
Over-the-air (OTA) mobility services platform
US20190391800A1