Hypervisor Recovery via External Rewrite Software

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic control systems face challenges in software recovery when Update and Configuration Management (UCM) on the operating system of a hypervisor fails due to corruption or memory leaks, leading to inability to rewrite software and perform recovery.

Innovation Solution

Implementing rewrite software (RPRG) outside the hypervisor, activated by an activation controller to rewrite the hypervisor or software when UCM activation fails, ensuring recovery through a backup mechanism.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If UCM is implemented on the OS of the hypervisor to manage software updates, then software update functionality is integrated into the system, but the system loses the ability to recover when UCM fails due to corruption or memory leaks

Engineering Contradiction:
Improvesoftware update functionalityVSAvoidsystem recovery capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a preliminary backup mechanism by placing rewrite software outside the hypervisor before any failure occurs. This rewrite software serves as a pre-prepared recovery tool that can restore the hypervisor or UCM if they become corrupted, ensuring system recoverability without requiring external intervention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary activation controller that manages both the UCM inside the hypervisor and the rewrite software outside the hypervisor. This intermediary component coordinates between the two, enabling the system to switch from the primary UCM to the backup rewrite software when failure occurs, thus maintaining recovery capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If UCM runs on the hypervisor OS to provide update management, then centralized software control is achieved, but single point of failure risk increases when UCM or OS becomes corrupted

Engineering Contradiction:
Improvecentralized software controlVSAvoidfailure resistance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the software update functionality into two independent parts: UCM running inside the hypervisor for normal operations, and rewrite software running outside the hypervisor for recovery operations. This segmentation ensures that failure of one component does not necessarily compromise the other, as they operate in separate environments with independent execution contexts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent prepares a cushioning backup mechanism by maintaining rewrite software in a protected state outside the hypervisor. This backup serves as a safety cushion that can absorb the impact of UCM or hypervisor corruption, preventing complete system failure and enabling recovery without external intervention.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If rewrite software is placed outside the hypervisor for backup purposes, then system recovery capability is improved, but device complexity increases

Engineering Contradiction:
Improvesystem recovery capabilityVSAvoidsoftware architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the rewrite software to be multi-functional, serving both as a backup recovery tool and as a standalone update mechanism. The activation controller also performs multiple functions by managing both UCM activation and rewrite software activation based on system state. This multi-functionality reduces the need for separate dedicated components, thereby limiting the increase in overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements a self-service recovery mechanism where the system can automatically detect UCM activation failure and autonomously activate the rewrite software to perform recovery. This self-service capability eliminates the need for complex external recovery procedures or manual intervention, offsetting the added architectural complexity with automated simplicity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250208854A1Electronic control system, data structure of software package, and computer program
Publication Date: 2025.06.26 DENSO CORP
  • US20250208854A1 patent drawing
  • US20250208854A1 patent drawing
  • US20250208854A1 patent drawing

AI summary

An electronic control system includes: an Update and Configuration Management (UCM) that has a function of rewriting software and runs on an operating system of a hypervisor; rewrite software having a function of rewriting software and operating outside the hypervisor; and an activation controller configured to activate the UCM and the rewrite software. When activation of the UCM fails, the activation controller activates the rewrite software, and causes the rewrite software to rewrite the hypervisor or the software on the hypervisor.