Vehicle ECU Update Storage Partitioning for Flexible OTA Timing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity and size of vehicle control programs require large storage capacities, leading to insufficient storage during program updates, which restricts the timing of updates and increases storage capacity needs.

Innovation Solution

A program management device with a communication unit, control unit, and separate storage areas for vehicle control and non-control programs, allowing updates to be stored in areas that do not affect vehicle operation, thereby reducing storage capacity demands and avoiding insufficient storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a plurality of storage areas are provided to store programs during updates, then the restriction of timing for program update is reduced, but the storage capacity requirement increases substantially

Engineering Contradiction:
Improvetiming flexibility for program updateVSAvoidstorage capacity
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The storage area is segmented into three distinct regions: first program storage area for current vehicle control programs, second program storage area for update programs, and third program storage area for non-control programs. This segmentation allows independent management of different program types, enabling updates without requiring complete duplication of all storage areas.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different storage areas are assigned different functions with varying quality requirements. The first and second program storage areas require high reliability for vehicle control, while the third program storage area has different requirements. This local quality differentiation allows optimization of storage capacity allocation, providing update flexibility only where critical while reducing overall storage demands.

Inventive Principle:
Principle #3Local quality

2Quantity of substance

If a large-capacity storage device is mounted on vehicles to accommodate increasing program complexity, then the storage capacity is increased, but the storage area may still become insufficient during program updates

Engineering Contradiction:
Improvestorage capacityVSAvoidstorage sufficiency during update
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system performs preliminary actions by downloading and storing update programs in the second program storage area before actual updates are executed. This allows the system to prepare update content in advance during appropriate timing, ensuring that when updates are needed, the storage infrastructure is already in place and configured, preventing storage insufficiency during critical update operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The second program storage area acts as an intermediary between external update sources and the primary vehicle control programs. It serves as a buffer zone where update content is temporarily stored and validated before being applied, ensuring that the main vehicle control programs remain protected and that storage resources are managed efficiently during the update process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the third program storage area is made duplexed like the first and second areas, then the reliability during non-control program updates is improved, but the storage capacity increase becomes unnecessary

Engineering Contradiction:
Improvereliability during non-control program updateVSAvoidstorage capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Instead of making all storage areas duplexed (excessive action), the system applies partial duplexing only to the first and second program storage areas that contain critical vehicle control programs. The third program storage area for non-control programs uses single-copy storage, which is sufficient for its less critical function. This partial application of redundancy achieves adequate reliability where needed while avoiding unnecessary storage capacity consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12190096B2Vehicular software update management system and execution by electronic control unit
Publication Date: 2025.01.07 HONDA MOTOR CO LTD
  • US12190096B2 patent drawing
  • US12190096B2 patent drawing
  • US12190096B2 patent drawing

AI summary

A program management device including a communication unit that communicates with an external device, a control unit that executes a vehicle control program for controlling the vehicle, a first memory where the vehicle control program is stored, a second memory where the vehicle control program is stored, a third memory where an irrespective program is stored to perform control that is irrespective of driving of the vehicle, and a program update unit that executes first processing of storing in at least one of the first memory and the second memory a vehicle control update program received by the communication unit, the vehicle control update program being used to update the vehicle control program, and second processing of storing in the third memory a non-control update program received by the communication unit, the non-control update program being used to update the irrespective program.