Vehicle ECU Delta Updates for Vulnerability Repair Without Downtime

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern vehicles face challenges in managing software updates for Electronic Control Units (ECUs) due to complexity, vulnerabilities, and limited storage, with current methods being inefficient, inconvenient, and prone to introducing bugs, and there is a need for solutions that allow differential software updates over-the-air without significant memory usage or downtime.

Innovation Solution

A system and method for automatically providing updates to vehicles by receiving ECU activity data, determining software vulnerabilities, and sending delta files to update ECU software, allowing for efficient software updates without requiring entire software module replacements or reprogramming, and enabling rollback to prior versions without re-downloading.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If entire ECU software is replaced through recalls or over-the-air updates, then software vulnerabilities are fixed, but storage space is consumed and downtime is required

Engineering Contradiction:
Improvesoftware vulnerability fixVSAvoidstorage space
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the ECU software update process into two distinct parts: (1) a read-only memory containing the complete ECU software, and (2) a separate reconfigurable logic device that can be updated independently through JTAG interfaces. This segmentation allows the main software to remain intact in read-only memory while only the reconfigurable logic portion is updated, thereby fixing vulnerabilities without consuming additional storage space or requiring system downtime.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the updateable portion of the ECU software from the main read-only memory and places it in a separate reconfigurable logic device. This extraction enables independent updating of the logic portion through JTAG interfaces without affecting the main software or requiring consumption of storage space in the read-only memory, thus resolving the contradiction between fixing vulnerabilities and preserving storage space.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If entire ECU software is replaced through recalls or over-the-air updates, then software vulnerabilities are fixed, but downtime is required

Engineering Contradiction:
Improvesoftware vulnerability fixVSAvoiddowntime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the ECU software update process into two distinct parts: (1) a read-only memory containing the complete ECU software, and (2) a separate reconfigurable logic device that can be updated independently through JTAG interfaces. This segmentation allows the main software to remain intact in read-only memory while only the reconfigurable logic portion is updated, thereby fixing vulnerabilities without requiring system downtime since the update process does not interrupt the execution of the main software.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the updateable portion of the ECU software from the main read-only memory and places it in a separate reconfigurable logic device. This extraction enables independent updating of the logic portion through JTAG interfaces without affecting the main software or requiring system downtime, thus resolving the contradiction between fixing vulnerabilities and maintaining continuous operation.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If ECU software is updated through OBD ports or over-the-air, then updates are provided to vehicles, but the process is inefficient and prone to introducing bugs

Engineering Contradiction:
Improveupdate deliveryVSAvoidupdate process stability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a standardized JTAG interface as an intermediary between the update source and the reconfigurable logic device. This JTAG intermediary provides a controlled, deterministic update path that is less prone to errors compared to over-the-air updates. The JTAG interface enables reliable bit-by-bit programming of the logic device while maintaining system stability, thus resolving the contradiction between update delivery efficiency and update process reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If ECU complexity increases with more features, then functionality is enhanced, but managing software performance and bug fixes becomes more difficult

Engineering Contradiction:
ImproveECU functionalityVSAvoidsoftware management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the ECU into a stable read-only memory containing the core software and a separate reconfigurable logic device. This segmentation allows the core software to remain simple and unchanged while the reconfigurable logic portion can be independently updated to add new features or fix bugs, thereby enhancing functionality without increasing overall software management complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic reconfigurability to the ECU through the reconfigurable logic device that can be programmed and updated independently via JTAG interfaces. This dynamic capability allows the ECU to adapt its functionality without modifying the core software in read-only memory, thus enhancing versatility while keeping software management complexity contained to the reconfigurable portion only.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11900103B2Self-healing learning system for one or more controllers
Publication Date: 2024.02.13 AURORA LABS LTD
  • US11900103B2 patent drawing
  • US11900103B2 patent drawing
  • US11900103B2 patent drawing

AI summary

Disclosed embodiments relate to automatically providing updates to at least one vehicle. Operations may include receiving, at a server remote from the at least one vehicle, Electronic Control Unit (ECU) activity data from the at least one vehicle, the ECU activity data corresponding to actual operation of the ECU in the at least one vehicle; determining, at the server and based on the ECU activity data, a software vulnerability affecting the at least one vehicle, the software vulnerability being determined based on a deviation between the received ECU activity data and expected ECU activity data; identifying, at the server, an ECU software update based on the determined software vulnerability; and sending, from the server, a delta file configured to update software on the ECU with a software update corresponding to the identified ECU software update.