Software Update Synchronization for Motor Vehicle Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Safety-critical systems, such as motor vehicles, require offline updates to prevent operational instability, resulting in unwanted downtime and costs due to the need to transition from a safe to an undefined state during software updates.

Innovation Solution

A method allowing continuous operation during software updates by simultaneously running both old and new software versions, with the new version generating transmission data that is initially blocked and then switched in once it reaches a synchronization state with the old version, ensuring seamless operation without interruption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If offline updates are performed to ensure system safety, then system reliability is improved, but productivity deteriorates due to operational downtime

Engineering Contradiction:
Improvesystem safetyVSAvoidoperational continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The software system is segmented into two parallel versions (old and new) that can operate independently. The old version continues to handle operational tasks while the new version is installed and prepared in the background, allowing updates without stopping the system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The new software version is installed and prepared in advance while the system continues to operate with the old version. This preliminary installation allows the new version to be ready before it needs to take over, eliminating downtime.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If the system transitions to an undefined state during update, then software updates can be performed, but system stability deteriorates

Engineering Contradiction:
Improvesoftware update capabilityVSAvoidsystem stability
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The system prepares the new software version in advance and maintains it in a ready-but-inactive state, cushioning against potential update failures. If the new version fails, the system can revert to the old version without entering an undefined state.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

A switching mechanism acts as an intermediary between the old and new software versions, controlling which version actively processes operations. This mediator ensures smooth transitions and prevents the system from entering unstable intermediate states.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Duration of action of stationary object

If the old software version continues to send transmission data during update, then operational continuity is maintained, but data consistency deteriorates

Engineering Contradiction:
Improveoperational continuityVSAvoiddata consistency
Core Design Contradiction:
Duration of action of stationary objectVSReliability

Solution Approach 1:

The system dynamically switches the active software version based on readiness status. The old version continues operating until the new version is fully prepared and synchronized, at which point the system transitions to the new version without data inconsistency.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system continuously monitors the readiness and synchronization status of the new software version. This feedback mechanism ensures that the switch from old to new version occurs only when data consistency is guaranteed, maintaining both continuity and reliability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3724758B1Method for carrying out an update to a software application in a device which is operating, and device and motor vehicle
Publication Date: 2021.05.12 AUDI AG
  • EP3724758B1 patent drawingFigure 1
  • EP3724758B1 patent drawingFigure 2

AI summary

The invention relates to a method for carrying out an update to a software application (11) in a device (10) which is operating, wherein an old version (V1) of a software component (12) of the software application (11) which is already operating is operated and wherein the old version (V1) transmits transmission data (16) to at least one third-party application (15) via a communication unit (14) and, meanwhile, in a transition phase (P2) a new version (V2) of the software component (12) is saved in a memory (S) of the device (10) and then executed, wherein transmission data (16') of the new version (V2) are blocked by the communication unit (14), and after the new version (V2) has assumed a predetermined synchronization state (22) in respect of the old version (V1), in a changeover process (21) a) the old version is deactivated and/or the transmission data (16) of the old version are blocked by the communication unit (14) and b) the transmission data (16') of the new version (V2) are allowed through to the at least one third-party application (15) by the communication unit (14).