ECU Software Update via External Memory Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional remote online software updating for motor vehicle ECUs is inefficient due to the risk of transient problems during reprogramming, leading to potential ECU non-functional states and prolonged downtime, as the previous software is deleted before the new software is successfully flashed.

Innovation Solution

Implementing a method where a new software version is initially stored in an external non-volatile memory, allowing the running software to remain functional until the new version is fully downloaded and validated, enabling seamless transition and minimizing downtime by maintaining the existing software until the update is complete.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the current software is deleted before downloading the new software, then the update process can proceed without interference from old code, but the ECU enters a non-functional state during the update

Engineering Contradiction:
Improveupdate speedVSAvoidECU functionality
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides the software storage into two separate memory areas: a first memory area for the current running software and a second memory area for the new software. This segmentation allows the system to maintain the current software in one area while downloading and storing the new software in another area, preventing the ECU from entering a non-functional state during the update process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by completely downloading and storing the new software version in the second memory area before deleting the current software from the first memory area. This ensures that the new software is fully available and validated before the system transitions, maintaining ECU functionality throughout the update process.

Inventive Principle:
Principle #10Preliminary action

2Manufacturing precision

If the ECU remains in a non-functional state during reprogramming, then the new software can be properly installed, but significant time is lost and the vehicle cannot be brought online

Engineering Contradiction:
Improvesoftware installation accuracyVSAvoiddowntime
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

By segmenting software storage into separate memory areas, the system can perform software updates without interrupting ECU operation. The current software continues to run from the first memory area while the new software is downloaded and stored in the second memory area, eliminating the need for the ECU to remain non-functional during the update process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables continuity of useful action by allowing the ECU to continue operating with the current software during the download and installation of the new software. The system maintains continuous functionality by switching between memory areas rather than interrupting operation, thus minimizing downtime while ensuring proper software installation.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If retry programming sessions are attempted for failed updates, then the ECU can potentially be recovered, but the process requires significant time and may not always succeed

Engineering Contradiction:
Improveupdate recovery capabilityVSAvoidrecovery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements beforehand cushioning by maintaining the current software in the first memory area as a backup during the entire update process. If the new software installation fails or is interrupted, the system can immediately revert to the current software without requiring retry programming sessions, thus providing recovery capability while minimizing time loss.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

4Ease of operation

If the software update is performed remotely while the vehicle is driving, then convenience is improved, but the update process is vulnerable to connection loss and power failure

Engineering Contradiction:
Improveremote update convenienceVSAvoidupdate completion rate
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by completely downloading and storing the new software in the second memory area before any deletion or switching occurs. This ensures that the full new software image is securely stored and can be validated before the update is committed, making the process resilient to connection loss or power failure during the update.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback mechanisms by validating the new software version before completing the update and by providing the ability to revert to the current software if validation fails. This feedback approach ensures that only verified, error-free software is installed, improving the completion rate of remote updates.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11237816B2Method for remote online software update in motor vehicles
Publication Date: 2022.02.01 THYSSENKRUPP PRESTA AG
  • US11237816B2 patent drawing

AI summary

A method can be employed to provide a remote online software update to a motor vehicle. The motor vehicle may have an ECU with an MCU having an internal memory, and with an external memory that is located outside the MCU and is configured to communicate with the MCU via a communication link. The method may involve starting to download a new software version, storing the new software version in the external memory, and once the new software version is fully downloaded deleting the software version running on the MCU and programming the new software version from the external memory.