Vehicle Software Update Management with Integrity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current software update management systems for vehicles lack the necessary infrastructure and security measures to ensure compliance with regulations, particularly for safety and security, especially when updating software post-certification or for adding new functionalities, which can compromise vehicle safety and integrity.
Innovation Solution
A system comprising a server computing device for providing software updates and vehicle computing devices configured to receive and execute updates, utilizing a package manager for integrity and authenticity checks, and a database management system for tracking and managing software updates, including a dedicated identifier for type approval compliance, ensuring secure and tamper-protected programming.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual updates by authorized technicians are used, then update capability is achieved, but security and integrity are compromised due to lack of sophisticated infrastructure
Solution Approach 1:
The patent introduces a dedicated server as an intermediary between the update source and the vehicle. This server manages the entire update process, including providing update information, verifying authenticity through digital signatures, and coordinating the actual software update transmission. The intermediary handles the complexity of security protocols and infrastructure management, allowing vehicles to receive secure updates without requiring complex on-board update infrastructure.
2Productivity
If automated update systems are implemented, then update efficiency is improved, but compliance with regulations concerning integrity and safety becomes difficult to ensure
Solution Approach 1:
The patent implements comprehensive feedback mechanisms throughout the update process. The server provides feedback to vehicles about available updates, the vehicle reports its current software version and status back to the server, and the server receives feedback about update completion. This feedback loop enables automated updates while ensuring compliance with regulations by continuously monitoring and verifying that updates meet integrity and safety requirements before being applied.
Solution Approach 2:
The patent performs preliminary actions by having the server pre-verify update authenticity through digital signatures before transmission to the vehicle. The update information is prepared and validated in advance on the server side, including checking against regulatory requirements. This preliminary verification ensures that only compliant updates are transmitted, allowing automated updates to proceed efficiently while maintaining regulatory compliance.
3Adaptability or versatility
If software updates are applied after certification, then functionality can be improved or corrected, but vehicle safety and certification criteria may be compromised
Solution Approach 1:
The patent implements preliminary verification of update authenticity and compliance before the update is applied to the vehicle. The server digitally signs updates and verifies them against certification criteria before transmission. This preliminary action ensures that even though updates can modify functionality after certification, the vehicle's safety and certification integrity are maintained by validating updates beforehand.
Solution Approach 2:
The dedicated server acts as an intermediary that mediates between the update source and the vehicle's software system. It verifies that updates comply with certification criteria and safety requirements before allowing the update to be applied. This intermediary role enables functional improvements while protecting vehicle safety and certification integrity through centralized verification.
Data Source
AI summary
The disclosure refers to a system for managing software updates for vehicles, comprising a server computing device configured to provide at least one software update from a software repository, and a plurality of vehicles, each of the vehicles having a vehicle computing device configured to receive and execute the at least one software update.


