Vehicular Software Update Rollback via Safety Label Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the automotive field, software-related errors during updates can lead to vehicles being unable to function for extended periods, posing safety and security risks, and existing solutions either take too long to resolve issues or compromise safety by disabling software.
Innovation Solution
A software updating device that includes software storage with label information for safety-related aspects and a control unit that selects a software unit for rollback based on identical safety-related label information, allowing for quick and safe software updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If software updates are performed using FOTA/SOTA techniques, then software can be updated without returning vehicles to manufacturers, but software-related errors may occur during updates and resolve slowly taking several weeks
Solution Approach 1:
The system performs preliminary actions by creating and storing backup software units before updating, and by pre-validating backup candidates against safety labels. This ensures that if an update fails or introduces errors, the system can immediately rollback to a known good state without waiting weeks for manufacturer intervention.
Solution Approach 2:
The system prepares compensatory measures in advance by maintaining validated backup software units with verified safety labels. These backups act as a cushion against update failures, allowing rapid recovery while maintaining safety standards without requiring slow manual intervention.
2Reliability
If software is disabled until a fixing patch is distributed, then safety and security problems are avoided, but vehicle functionality is compromised for extended periods
Solution Approach 1:
Instead of disabling software, the system performs preliminary actions by identifying and validating backup software units before errors occur. The backup units are pre-checked for safety label compatibility, enabling immediate rollback to functional safe states rather than disabling functionality entirely.
Solution Approach 2:
The system discards the faulty software unit and recovers by activating a pre-validated backup unit with matching safety labels. This maintains both safety and functionality simultaneously, avoiding the need to disable software while waiting for patches.
3Speed
If rollback is performed without safety label verification, then update speed is improved, but safety and security standards may be compromised
Solution Approach 1:
The rollback mechanism performs self-service by automatically verifying safety labels during the selection of backup units. This automated verification integrates safety checks into the rapid rollback process itself, maintaining both speed and safety without requiring separate manual verification steps.
Solution Approach 2:
The system uses feedback from safety label comparisons to guide the rollback selection process. By continuously checking whether backup units match the required safety labels, the system ensures that rapid rollback operations automatically select only safe candidates, maintaining safety standards while preserving speed.
4Reliability
If comprehensive safety validation is performed on all software units, then safety and security are ensured, but update time and complexity increase
Solution Approach 1:
The system extracts only the essential safety label information from software units for validation purposes. By focusing validation on specific safety-critical attributes rather than comprehensive analysis of all software characteristics, the system maintains rigorous safety validation while significantly reducing validation time and complexity.
Solution Approach 2:
The validation process applies different levels of scrutiny to different aspects of software. Safety labels receive thorough validation while other non-critical software attributes receive minimal or no validation. This localized quality approach ensures safety standards are met without unnecessarily increasing overall update time.
Data Source
AI summary
The present invention makes it possible to identify software that is safe and determines what software can be rolled back while maintaining a high level of safety and security. A software updating device E1000 includes: software unit storage E1520 that stores a plurality of software units UX000 that include label information UX400; and an update control unit E1400 that controls software updates for a vehicular control device ECU_EX000. The label information UX400 includes at least safety-related information for the software units UX000. Upon receiving a rollback command, the update control unit E1400 selects software from the plurality of software units UX000 that has safety-related label information UX400 that is identical to safety-related label information UX400 of software installed at the vehicular control device as software to roll back.


