Vehicle Gateway Proxy Firmware Update for ECU Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing firmware update technologies for in-vehicle networks face challenges when ECUs lack necessary functions or capabilities for secure updates, potentially disrupting vehicle operations during the update process.
Innovation Solution
A gateway device connected to multiple ECUs in the vehicle network receives firmware update information and determines if an ECU satisfies specific conditions; if not, it directs another ECU or itself to execute necessary processes like signature verification or firmware saving, ensuring a secure and successful update.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If firmware update is performed on ECU during vehicle operation, then update speed is improved, but system reliability deteriorates due to potential disruption of vehicle operations
Solution Approach 1:
The gateway device performs preliminary checks before initiating firmware update by determining whether the ECU satisfies update conditions (such as checking if current communication load is within threshold). This preliminary action prevents updates that would disrupt vehicle operations, thereby maintaining reliability while enabling updates when safe
Solution Approach 2:
The system continuously monitors ECU communication status and provides feedback to the gateway device. The gateway device uses this feedback to dynamically adjust update decisions, stopping updates when communication abnormalities are detected and resuming when conditions improve, thus balancing update speed with system reliability
2Adaptability or versatility
If firmware update is performed on ECU without required functions, then update capability is improved, but security deteriorates due to inability to perform signature verification
Solution Approach 1:
The gateway device acts as an intermediary between the external update source and the ECU. It performs signature verification on the firmware before transmitting to the ECU, and can also perform verification on the ECU's side, ensuring security even when the ECU lacks built-in verification functions. This intermediary role enables universal update capability while maintaining security standards
Solution Approach 2:
The gateway device is designed with multi-functional capability to handle firmware updates for diverse ECUs with different functional configurations. It can perform verification itself or coordinate with ECUs that have verification functions, making the update system universally applicable across different ECU types while maintaining security through flexible verification approaches
3Extent of automation
If ECU executes firmware update process, then update autonomy is improved, but device complexity increases due to required verification and saving functions
Solution Approach 1:
The patent extracts the complex verification and coordination functions from the ECU and places them in the gateway device. The ECU only needs to execute the simple firmware writing process, while the gateway handles signature verification, update condition checking, and coordination with external devices. This extraction reduces ECU complexity while maintaining high automation through gateway-based control
4Reliability
If update condition checking is performed, then update security is improved, but update time increases due to additional determination steps
Solution Approach 1:
The gateway device performs partial checking of update conditions rather than exhaustive verification. It checks critical parameters such as communication load threshold and basic ECU status, performing more thorough verification only when necessary. This partial action approach maintains adequate security while minimizing the time penalty associated with comprehensive checking
Data Source
AI summary
A gateway device is connected via network(s) to electronic controllers on-board a vehicle, where at least one of the electronic controllers is implemented in a virtual machine. The gateway device includes one or more memories, and circuitry that acquires firmware update information. The circuitry determines whether a first electronic controller satisfies a second condition based on second information, which is whether the first electronic controller includes a firmware cache for performing a pre-update firmware cache operation. The circuitry also causes, when the second condition is not satisfied, the gateway device to execute a proxy process, where the gateway device requests the first electronic controller to transmit boot ROM data to the gateway device, creates updated boot ROM data with the updated firmware, and transmits the updated boot ROM data to the first electronic controller that updates the boot ROM and resets the first electronic controller with the updated firmware.


