Vehicle Software Update via Intermediate Mobile Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional over-the-air (OTA) software updates for electronic units in vehicles are time-consuming and require the vehicle's propulsion system to be energized, and they pose security risks due to the transmission of vehicle identification numbers, which can be exploited for hacking and identity theft.
Innovation Solution
A system using an intermediate communications device, such as a mobile device, that receives a software update request from the vehicle, excluding personal data, and transmits the update using high-speed technologies like USB, WiFi, or Bluetooth, allowing updates to be installed even when the propulsion system is off, while ensuring security by using hashed identification keys and encrypting sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional OTA update method is used, then software update can be performed wirelessly, but update time is long and propulsion system must be energized
Solution Approach 1:
The patent performs preliminary actions by downloading and storing the complete software update package in the buffer memory of the electronic unit before the actual update installation begins. This allows the update data to be readily available when the vehicle is ready for installation, eliminating the need for time-consuming wireless transmission during the update process itself.
Solution Approach 2:
The patent introduces an intermediate buffer memory component that acts as a mediator between the wireless communication interface and the final software installation target. The update data is first transferred to this intermediate buffer, then installed from the buffer to the electronic control unit, separating the time-consuming download phase from the installation phase.
2Extent of automation
If conventional OTA update method is used, then update can be performed remotely, but vehicle identification number transmission creates security risks
Solution Approach 1:
The patent extracts and removes the vulnerable vehicle identification number from the update request transmission. Instead of sending the VIN, the system uses alternative identification methods that do not expose personally identifiable information, thereby eliminating the security vulnerability while maintaining remote update capability.
Solution Approach 2:
The patent applies preliminary anti-action by implementing security measures before the update process begins. The system pre-configures the electronic unit with unique identifiers and authentication credentials that do not include the VIN, preventing potential hacking and identity theft attacks before they can occur during the update transmission.
3Reliability
If vehicle propulsion system is energized for update, then electronic unit can be updated, but unnecessary energy consumption occurs
Solution Approach 1:
The patent performs the energy-intensive data download and storage operations in advance while the vehicle is in normal operation, so that when the update installation is needed, the data is already in the buffer memory ready for installation. This allows the update process to proceed with minimal or no propulsion system energization required.
Solution Approach 2:
The patent creates a dynamic update process where the download and installation phases can be separated in time. The system can download update data during periods when the vehicle is running normally, then install the update during maintenance periods when minimal power is needed, adapting the process to the vehicle's operational state rather than requiring a fixed energized state.
Data Source
AI summary
A system for updating software installed on an electronic unit on a vehicle can include a processor and a memory. The processor can be disposed on an intermediate communications device. The intermediate communications device can be a mobile device. The memory can store an update request module and an update existence module. The update request module can include instructions that when executed by the processor cause the processor to receive, from the electronic unit on the vehicle, a request for an update of the software. The request can include: (1) an identification of a version of the software currently installed on the electronic unit and (2) a key to specifically identify the electronic unit. The update existence module can include instructions that when executed by the processor cause the processor to receive, from a device associated with development of the software, information about an existence of the update.


