Parallel Firmware Update Execution for Autonomous Vehicles
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for software and firmware updates in autonomous driving vehicles are inefficient, leading to software security vulnerabilities, introduction of new bugs, and inability to update safety-critical systems over-the-air without causing disruptions or system failures.
Innovation Solution
A dynamic firmware/software update distribution architecture that enables safe, secure, and reliable over-the-air updates by straddling updates between versions, supporting forward- and backward-compatibility, using vehicle-to-vehicle communication channels, and encrypting supplier-specific software, allowing for background updates and parallel execution of new and old code to ensure safety and reliability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional OTA update methods are used to deliver software updates, then software version uniformity is improved, but system reliability deteriorates due to required downtime and reboot risks
Solution Approach 1:
The system performs preliminary validation of software updates in a testing environment before deploying to production. Update packages are first deployed to a subset of vehicles for validation, and only after successful validation are they rolled out fleet-wide, preventing defective updates from compromising system reliability
Solution Approach 2:
The system maintains multiple software versions simultaneously in the fleet (current, previous, and testing versions) to create a buffer against update failures. This version diversity acts as a cushion, allowing rollback to previous working versions if new updates prove defective, thus protecting system reliability
2Productivity
If software updates are deployed to all vehicles simultaneously, then update speed is improved, but risk of widespread system failure increases
Solution Approach 1:
The fleet is segmented into multiple groups (validation group and rollout group) that receive updates at different times. The validation group tests updates first, and only after successful validation does the rollout group receive updates. This segmentation prevents widespread failure by isolating potential issues to small subsets
Solution Approach 2:
Instead of deploying updates to 100% of the fleet simultaneously, the system uses partial action by first deploying to a small validation subset (e.g., 5-10% of vehicles). This partial deployment allows risk containment while maintaining overall fleet operation, balancing update speed with safety
3Device complexity
If conventional update systems are used, then simplicity of update mechanism is maintained, but forward- and backward-compatibility deteriorates
Solution Approach 1:
The system maintains multiple software versions across the fleet simultaneously, enabling a single update mechanism to serve multiple compatibility requirements. The cloud platform can distribute different versions to different vehicle groups, supporting both forward-compatibility (new features) and backward-compatibility (legacy vehicle support) through one unified system
4Use of energy by moving object
If software updates are applied without parallel execution capability, then resource consumption is reduced, but ability to rollback on error deteriorates
Solution Approach 1:
The system prepares and validates update packages before full deployment, performing error detection and compatibility checks in advance. This preliminary validation reduces the need for rollback operations and minimizes resource consumption during actual updates by preventing failed deployments
Data Source
AI summary
The disclosed embodiments generally relate to methods, systems and apparatuses for dynamic firmware/software (FW/SW) update distribution in highly and fully autonomous or automated vehicles. In one embodiment, the disclosure relates to an apparatus to dynamically upgrade code in a vehicle. The apparatus may include: a communication module for one or more of wireless or landline communication; a central processing unit (CPU) in communication with the communication module, the CPU configured to receive an indication requiring a code upgrade to an existing vehicle code software and receive the code upgrade; store the code upgrade; execute code upgrade in parallel with the existing vehicle code software; log one or more error indications resulted from execution of the code upgrade; replace the existing vehicle code with the code upgrade if the logged error indication is less than a first threshold; and direct the code upgrade to a second vehicle to update the second vehicle code. The disclosed embodiments may be implemented in autonomous driving (AD) vehicles as well as vehicles having operating code or software/firmware.


