Vehicle Gateway Proxy Firmware Update for ECUs Without Cache
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing firmware update technologies for electronic control units (ECUs) in vehicle networks face challenges when an ECU lacks necessary functions or capabilities for secure firmware updates, potentially disrupting vehicle operations during the update process.
Innovation Solution
A gateway device connected to multiple ECUs receives firmware update information and determines if an ECU satisfies specific conditions; if not, it executes necessary processes such as signature verification or firmware saving by proxy, ensuring secure and successful updates even for ECUs without required functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firmware update is performed on an ECU without necessary functions or capabilities, then the update process may fail or compromise security, but preventing the update reduces system adaptability and functionality
Solution Approach 1:
The gateway device serves as an intermediary between the external firmware source and the ECU. It performs preliminary verification of the ECU's update capability and condition, and mediates the firmware transfer process. This allows the system to maintain security requirements while enabling updates for ECUs that would otherwise be incompatible, thus resolving the contradiction between reliability and adaptability.
Solution Approach 2:
The gateway device performs preliminary verification of the ECU's update capability before initiating the firmware update process. It checks whether the ECU has necessary functions and meets update conditions in advance, preparing the system state to ensure secure updates. This preliminary action enables the system to adaptively enable updates for capable ECUs while maintaining security, resolving the contradiction between reliability and versatility.
2Manufacturing precision
If an ECU executes firmware update process, then firmware can be updated, but the ECU cannot exchange messages during the update which affects vehicle operation
Solution Approach 1:
The gateway device acts as a mediator that manages the firmware update process externally to the ECU. It handles firmware transfer and verification without requiring the ECU to remain actively operational throughout the process, thereby minimizing disruption to vehicle operations while ensuring complete firmware updates.
Solution Approach 2:
The system performs preliminary checks to determine optimal update timing and conditions, preparing necessary firmware and validation data before initiating the update. This allows the ECU to be taken offline for the update process only when necessary, minimizing operational disruption while ensuring update completion.
3Reliability
If the gateway device verifies all update conditions for each ECU, then update security is ensured, but the complexity of the update management system increases
Solution Approach 1:
The ECU itself provides information about its update capability and current state to the gateway device. This self-service approach allows the gateway to verify update conditions with minimal processing burden, as the ECU autonomously reports its readiness status, thereby maintaining security verification while reducing gateway complexity.
Solution Approach 2:
ECUs perform preliminary self-assessment of their update readiness and report their capability status to the gateway before the update process begins. This preliminary action shifts some verification burden to the ECU itself, simplifying the gateway's processing logic while maintaining comprehensive condition verification for security.
Data Source
AI summary
A gateway device is connected to a plurality of electronic controllers on-board a vehicle. The gateway device acquires firmware update information, which includes at least a part of updated firmware to be applied to a first electronic controller, patch data, and information indicating where to apply the patch data. When the gateway device determines that the first electronic controller does not include a firmware cache for performing a pre-update firmware cache operation, the gateway device executes a proxy process. In this regard, the gateway device requests the first electronic controller to transmit boot ROM data to the gateway device, merges the patch data and existing firmware to create updated boot ROM data with updated firmware, and transmits the updated boot ROM data to the first electronic controller that updates the boot ROM data and resets the first electronic controller with the updated firmware.


