Parallel Firmware Update Execution for Autonomous Vehicles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for software and firmware updates in autonomous driving vehicles are inefficient, leading to software security vulnerabilities, introduction of new bugs, and inability to update safety-critical systems over-the-air without causing disruptions or system failures.

Innovation Solution

A dynamic firmware/software update distribution architecture that enables safe, secure, and reliable over-the-air updates by straddling updates between versions, supporting forward- and backward-compatibility, using vehicle-to-vehicle communication channels, and encrypting supplier-specific software, allowing for background updates and parallel execution of new and old code to ensure safety and reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional OTA update methods are used to deliver software updates, then software version uniformity is improved, but system reliability deteriorates due to required downtime and reboot risks

Engineering Contradiction:
Improvesoftware version uniformityVSAvoidsystem reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary validation of software updates in a testing environment before deploying to production. Update packages are first deployed to a subset of vehicles for validation, and only after successful validation are they rolled out fleet-wide, preventing defective updates from compromising system reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains multiple software versions simultaneously in the fleet (current, previous, and testing versions) to create a buffer against update failures. This version diversity acts as a cushion, allowing rollback to previous working versions if new updates prove defective, thus protecting system reliability

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Productivity

If software updates are deployed to all vehicles simultaneously, then update speed is improved, but risk of widespread system failure increases

Engineering Contradiction:
Improveupdate speedVSAvoidrisk of widespread system failure
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The fleet is segmented into multiple groups (validation group and rollout group) that receive updates at different times. The validation group tests updates first, and only after successful validation does the rollout group receive updates. This segmentation prevents widespread failure by isolating potential issues to small subsets

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of deploying updates to 100% of the fleet simultaneously, the system uses partial action by first deploying to a small validation subset (e.g., 5-10% of vehicles). This partial deployment allows risk containment while maintaining overall fleet operation, balancing update speed with safety

Inventive Principle:
Principle #16Partial or excessive action

3Device complexity

If conventional update systems are used, then simplicity of update mechanism is maintained, but forward- and backward-compatibility deteriorates

Engineering Contradiction:
Improveupdate mechanism simplicityVSAvoidforward- and backward-compatibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system maintains multiple software versions across the fleet simultaneously, enabling a single update mechanism to serve multiple compatibility requirements. The cloud platform can distribute different versions to different vehicle groups, supporting both forward-compatibility (new features) and backward-compatibility (legacy vehicle support) through one unified system

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Use of energy by moving object

If software updates are applied without parallel execution capability, then resource consumption is reduced, but ability to rollback on error deteriorates

Engineering Contradiction:
Improveresource consumptionVSAvoidability to rollback on error
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The system prepares and validates update packages before full deployment, performing error detection and compatibility checks in advance. This preliminary validation reduces the need for rollback operations and minimizes resource consumption during actual updates by preventing failed deployments

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11204750B2Systems, methods and apparatus for distributed software/firmware update and software versioning system for automated vehicles
Publication Date: 2021.12.21 INTEL CORP
  • US11204750B2 patent drawing
  • US11204750B2 patent drawing
  • US11204750B2 patent drawing

AI summary

The disclosed embodiments generally relate to methods, systems and apparatuses for dynamic firmware/software (FW/SW) update distribution in highly and fully autonomous or automated vehicles. In one embodiment, the disclosure relates to an apparatus to dynamically upgrade code in a vehicle. The apparatus may include: a communication module for one or more of wireless or landline communication; a central processing unit (CPU) in communication with the communication module, the CPU configured to receive an indication requiring a code upgrade to an existing vehicle code software and receive the code upgrade; store the code upgrade; execute code upgrade in parallel with the existing vehicle code software; log one or more error indications resulted from execution of the code upgrade; replace the existing vehicle code with the code upgrade if the logged error indication is less than a first threshold; and direct the code upgrade to a second vehicle to update the second vehicle code. The disclosed embodiments may be implemented in autonomous driving (AD) vehicles as well as vehicles having operating code or software/firmware.