Vehicle Software Update Checks in a Stopped State
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
During software updates for vehicle control systems, there is a risk of unintentional vehicle behavior due to operation checks being performed while the vehicle is in a runnable state, which can lead to reliability issues and safety concerns.
Innovation Solution
The vehicle control apparatus ensures operation checks are conducted only when the vehicle is in a stopped state, with permission from the occupant, and discontinues processing if the vehicle transitions to a runnable state, thereby preventing unintentional movements and enhancing reliability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If operation check is performed by executing update software while vehicle is in runnable state, then reliability of vehicle control software is improved, but unintentional vehicle behavior may occur
Solution Approach 1:
The system requires the vehicle to be in a stopped state before executing operation checks of update software. This preliminary condition ensures that any unintended actions during software execution cannot cause harmful vehicle behavior, thus resolving the contradiction between improving reliability through operation checks and preventing unintentional vehicle behavior.
Solution Approach 2:
The control apparatus introduces an intermediate state (stopped state) as a mediator between the runnable state and the software execution state. By requiring the vehicle to transition to a stopped state before operation checks, the system creates a safe intermediate condition that prevents direct execution of potentially harmful software operations while maintaining reliability verification capabilities.
2Reliability
If operation check is performed to verify normal vehicle operation, then software update safety is improved, but vehicle mobility is restricted
Solution Approach 1:
The system performs operation checks only after the vehicle has been brought to a stopped state as a preliminary condition. This ensures software update safety is verified before allowing the vehicle to return to runnable state, thus improving software update safety while minimizing impact on vehicle mobility through a temporary, controlled restriction.
Solution Approach 2:
The operation check process is implemented as a periodic or阶段性 (phased) action rather than a continuous restriction. The vehicle transitions to stopped state temporarily for the duration of the operation check, then can resume normal operation, thus balancing software safety verification with operational convenience through time-limited restrictions.
Data Source
AI summary
A vehicle control apparatus including: a storage portion configured to store therein a vehicle control software for controlling a vehicle; an updating portion configured to update the vehicle control software stored in the storage portion, to an update software, and an operation check portion configured, when the update software is stored in the storage portion, to make an operation check as to whether the vehicle operates normally or not, by executing processing of the update software on condition that the vehicle is in a vehicle stopped state in which the vehicle is suppressed from being moved in forward and reverse directions. When it is checked by the operation check portion that the vehicle operates normally with the processing of the update software, the updating portion is configured to update the vehicle control software to the update software.


