Vehicle ECU Delta Updates for Vulnerability Repair Without Downtime
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern vehicles face challenges in managing software updates for Electronic Control Units (ECUs) due to complexity, vulnerabilities, and limited storage, with current methods being inefficient, inconvenient, and prone to introducing bugs, and there is a need for solutions that allow differential software updates over-the-air without significant memory usage or downtime.
Innovation Solution
A system and method for automatically providing updates to vehicles by receiving ECU activity data, determining software vulnerabilities, and sending delta files to update ECU software, allowing for efficient software updates without requiring entire software module replacements or reprogramming, and enabling rollback to prior versions without re-downloading.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If entire ECU software is replaced through recalls or over-the-air updates, then software vulnerabilities are fixed, but storage space is consumed and downtime is required
Solution Approach 1:
The patent segments the ECU software update process into two distinct parts: (1) a read-only memory containing the complete ECU software, and (2) a separate reconfigurable logic device that can be updated independently through JTAG interfaces. This segmentation allows the main software to remain intact in read-only memory while only the reconfigurable logic portion is updated, thereby fixing vulnerabilities without consuming additional storage space or requiring system downtime.
Solution Approach 2:
The patent extracts the updateable portion of the ECU software from the main read-only memory and places it in a separate reconfigurable logic device. This extraction enables independent updating of the logic portion through JTAG interfaces without affecting the main software or requiring consumption of storage space in the read-only memory, thus resolving the contradiction between fixing vulnerabilities and preserving storage space.
2Reliability
If entire ECU software is replaced through recalls or over-the-air updates, then software vulnerabilities are fixed, but downtime is required
Solution Approach 1:
The patent segments the ECU software update process into two distinct parts: (1) a read-only memory containing the complete ECU software, and (2) a separate reconfigurable logic device that can be updated independently through JTAG interfaces. This segmentation allows the main software to remain intact in read-only memory while only the reconfigurable logic portion is updated, thereby fixing vulnerabilities without requiring system downtime since the update process does not interrupt the execution of the main software.
Solution Approach 2:
The patent extracts the updateable portion of the ECU software from the main read-only memory and places it in a separate reconfigurable logic device. This extraction enables independent updating of the logic portion through JTAG interfaces without affecting the main software or requiring system downtime, thus resolving the contradiction between fixing vulnerabilities and maintaining continuous operation.
3Productivity
If ECU software is updated through OBD ports or over-the-air, then updates are provided to vehicles, but the process is inefficient and prone to introducing bugs
Solution Approach 1:
The patent introduces a standardized JTAG interface as an intermediary between the update source and the reconfigurable logic device. This JTAG intermediary provides a controlled, deterministic update path that is less prone to errors compared to over-the-air updates. The JTAG interface enables reliable bit-by-bit programming of the logic device while maintaining system stability, thus resolving the contradiction between update delivery efficiency and update process reliability.
4Adaptability or versatility
If ECU complexity increases with more features, then functionality is enhanced, but managing software performance and bug fixes becomes more difficult
Solution Approach 1:
The patent segments the ECU into a stable read-only memory containing the core software and a separate reconfigurable logic device. This segmentation allows the core software to remain simple and unchanged while the reconfigurable logic portion can be independently updated to add new features or fix bugs, thereby enhancing functionality without increasing overall software management complexity.
Solution Approach 2:
The patent introduces dynamic reconfigurability to the ECU through the reconfigurable logic device that can be programmed and updated independently via JTAG interfaces. This dynamic capability allows the ECU to adapt its functionality without modifying the core software in read-only memory, thus enhancing versatility while keeping software management complexity contained to the reconfigurable portion only.
Data Source
AI summary
Disclosed embodiments relate to automatically providing updates to at least one vehicle. Operations may include receiving, at a server remote from the at least one vehicle, Electronic Control Unit (ECU) activity data from the at least one vehicle, the ECU activity data corresponding to actual operation of the ECU in the at least one vehicle; determining, at the server and based on the ECU activity data, a software vulnerability affecting the at least one vehicle, the software vulnerability being determined based on a deviation between the received ECU activity data and expected ECU activity data; identifying, at the server, an ECU software update based on the determined software vulnerability; and sending, from the server, a delta file configured to update software on the ECU with a software update corresponding to the identified ECU software update.


