Vehicle ECU Update Packages With Triple Integrity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle electronic control unit (ECU) update systems lack effective integrity verification mechanisms, leading to potential incomplete or incorrect updates, which can compromise vehicle performance and safety.
Innovation Solution
A center device and vehicle information communication system that generate and transmit verification values for new and difference data packages, allowing in-vehicle devices to verify the integrity of updates before writing them to non-volatile memory, ensuring proper data integrity through triple verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If verification values are generated and transmitted for each update package, then data integrity is improved, but communication data volume and processing complexity increase
Solution Approach 1:
The verification mechanism is segmented into three distinct verification values: first verification value for the distribution package, second verification value for the update package, and third verification value for the new difference data. Each verification value operates at a different stage of the update process, dividing the complex verification task into manageable segments that can be processed independently at appropriate times.
Solution Approach 2:
The first verification value is generated and transmitted in advance with the distribution package before the actual update installation occurs. This preliminary verification allows the in-vehicle device to validate the integrity of received data before committing resources to the update process, preventing wasted processing on corrupted data.
2Reliability
If multiple verification values are transmitted with distribution package, then update correctness is improved, but transmission data volume increases
Solution Approach 1:
Instead of transmitting redundant copies of the entire update data for verification purposes, the system transforms the verification requirement into compact parameter representations (verification values such as hash codes or checksums). These verification values are mathematical transformations of the original data that occupy minimal space but provide comprehensive integrity checking capability.
3Reliability
If integrity verification is performed at multiple stages, then update safety is improved, but processing time increases
Solution Approach 1:
The verification process is embedded continuously throughout the update workflow rather than being performed as separate batch operations. The first verification occurs immediately upon receiving the distribution package, the second verification occurs during update package extraction, and the third verification occurs during new difference data generation. This continuous verification approach integrates safety checks into the natural flow of operations, minimizing idle time and ensuring that each processing stage validates its inputs before proceeding.
Data Source
AI summary
A center device includes an update data storage unit in which new data and new difference data for updating to the new data from old data are stored for, among electronic control units mounted on a vehicle, a target device targeted for data update. The center device generates, using the new data, a first verification value for verifying integrity in the vehicle, and generates, using the new difference data, a second verification value for verifying integrity of the new difference data in the vehicle. The center device generates a package including the new difference data, the first verification values and the second verification values for a plurality of the target devices. The center device generates, using the distribution package, a third verification value for verifying integrity of the distribution package in the vehicle, and transmits the distribution package along with the third verification value to the in-vehicle device.


