Method for monitoring the function of a vehicle information system of a motor vehicle, electronic computing device, computer program and data carrier

Through blockchain and smart contract technology, the functional status of the vehicle information system is automatically monitored and penalty fees are enforced, which solves the problem of cumbersome monitoring process in existing technologies and improves the reliability and efficiency of service quality.

CN113454674BActive Publication Date: 2025-09-26MERCEDES BENZ GRP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202080014046.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-02-14
Filing Date
2020-02-04
Publication Date
2025-09-26
Estimated Expiration
2040-03-20

AI Technical Summary

Technical Problem

In existing technologies, the monitoring of vehicle information system functions and the enforcement of penalty charges for violations are difficult to automate, and the process is cumbersome and time-consuming, making it difficult to ensure service quality.

Method used

Through blockchain technology and smart contracts, the distributed ledger technology is used to mirror the register to automatically monitor the deviation between the actual working status of the vehicle information system functions and the ideal status in the framework conditions plan, and automatically execute penalty penalties based on the deviation.

Benefits of technology

It realizes the automated monitoring of vehicle information system functions and the execution of penalty for breach of contract, reduces manual intervention and improves the reliability and efficiency of service quality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113454674B_ABST
    Figure CN113454674B_ABST
Patent Text Reader

Abstract

The invention relates to a method for monitoring a function (FN) of a vehicle information system (FS) of a motor vehicle (KW), the function being requested by an off-board device (EI) via an interface (IN) and extending the functional scope of the vehicle information system (FS), and at least one functional characteristic (SA) of the function being defined according to a framework condition plan (SC) stored in a register (RE), the method comprising the following steps: requesting the function (FN) via the interface (IN); executing the function (FN) via the vehicle information system (FS); determining an operating state of the function (FN) of the vehicle information system (FS); comparing the operating state with the functional characteristic (SA) recorded in the framework condition plan (SC); and, if the operating state deviates from the functional characteristic (SA) recorded in the framework condition plan (SC), providing at least one value (W) representing the deviation to the register (RE) and / or at the interface (IN) of the vehicle information system (FS). Furthermore, the invention relates to a computing device, a computer program product, and a data carrier.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for monitoring the functionality of a vehicle information system of a motor vehicle. The present invention also relates to an electronic computing device capable of executing the method for monitoring the functionality of a vehicle information system. The present invention also relates to a computer program by which the method for monitoring the functionality of a vehicle information system can be executed on an electronic computing device. Finally, the present invention relates to a data carrier containing a computer program product and / or capable of executing the method for monitoring the functionality of a vehicle information system when used in an electronic computing device. Background Art

[0002] Vehicle information systems for motor vehicles, particularly passenger cars, which can perform assistance functions via telematics, for example, offer a wide range of functions. These systems, as a whole, can encompass various functions within the functional scope and are typically provided by different suppliers. These functions can be services or, in particular, services such as navigation. For example, a supplier can use a device (e.g., a computing device or a computing center) to provide services and / or service-required data that can be transmitted to and / or used by the vehicle information system. To ensure that these functions function as desired by the vehicle information system user, at least one agreement can be concluded between the supplier and the vehicle supplier and / or the vehicle information system user. The agreement can specify at least one functional characteristic. This functional characteristic can, for example, include a quality of service, which specifies, for example, the availability of the function and / or at least one other quality characteristic. This can be accomplished, for example, through a service level agreement (SLA), a framework agreement that includes the functional characteristics. Furthermore, conditions can be defined for non-compliance with the promised functional characteristics. Thus, if the SLA is, for example, a framework agreement, the default conditions can be defined as penalties.

[0003] If, for example, the navigation function provided by a supplier to a vehicle information system is not provided as expected or as guaranteed by the functional characteristics, navigation, for example, cannot be performed correctly. In this case, fulfilling the default condition or non-fulfillment condition proves difficult to achieve. For example, the user of the vehicle navigation system should, within the vehicle navigation system, provide feedback to the supplier that the navigation function is unavailable or not functioning as expected at a certain time. The supplier can be informed of this and, if necessary, verify this. Furthermore, the supplier may state that, according to its functional monitoring, the navigation function was functioning at the time in question. Therefore, fulfilling the non-fulfillment condition is usually a manual process that is generally rigid or complex and takes a certain amount of time.

[0004] A possible approach for automating the implementation of non-fulfillment conditions is outlined in the University of Zurich's technical report FIF-2018.02, titled "Automated SLA Compensation Based on Smartphone Trajectories," published in April 2018. Here, functional characteristics, particularly in the form of a service level agreement, are determined in a data-processable manner and monitored using a computer system.

[0005] The concept of blockchain is known from the financial sector, for example, in particular from cryptocurrencies such as Bitcoin or Ethereum. This blockchain, which can be understood as a register, in particular a distributed register, into which data can be written in series, provides a system that guarantees data integrity, for example, not only for providers but also for users.

[0006] WO 2018 / 006056 A1 discloses a method for a blockchain-based letter of credit for a commercial transaction contract between a buyer and a seller, wherein the blockchain-based letter of credit defines payment triggering events for the voucher flow and the supply chain flow. Summary of the Invention

[0007] The object of the present invention is to provide a method, an electronic computing device, a computer program product and a data carrier, by means of which the functions of a vehicle information system of a motor vehicle can be monitored in such a way that deviations of the actual operating state of the vehicle information system caused by the function from the functional characteristics and thus from the ideal operating state can be detected.

[0008] According to the invention, this object is achieved by the subject matter of the independent claims. Advantageous embodiments and developments of the invention are indicated in the dependent claims as well as in the description and the drawings.

[0009] A first aspect of the present invention relates to a method for monitoring a function of a vehicle information system of a motor vehicle, wherein the function may be or include a service or utility, for example, and the vehicle information system may include, for example, a driver assistance system and / or an infotainment system. The motor vehicle may be designed, in particular, as a passenger car. In the method according to the present invention, the function and / or, in particular, the data required for the function, are requested by an off-vehicle device via an interface, thereby expanding the functional scope of the vehicle information system. The device may be, for example, at least one electronic computing device, in the form of a server, which executes a program or service or provides the program and / or data required for execution via an interface, such as a radio modem. The function may thus be or include, for example, a service and / or program and / or data for executing the service and / or program. For example, the function may also be designed as a module of the vehicle information system, thereby performing, for example, a navigation function. At least one functional characteristic of the function is defined according to a framework condition plan stored in a register (in particular, a memory area of ​​at least one electronic computing device), and the functional characteristic characterizes a vehicle information system operating state that can be achieved by the function and is particularly advantageous for the function. The framework condition plan is therefore essentially an agreement stored in a digitally processable or information technology-processable manner, which includes at least the functional characteristic, which specifies the manner in which the functional scope of the vehicle information system is expanded, in particular by placing the vehicle information system in an operating state by means of the function, i.e., the operating state that expands the functional scope. In other words, the functional characteristic characterizes the ideal operating state that can be achieved by the vehicle information system using the function, or the functional characteristic characterizes the ideal operating state of the function.

[0010] The method according to the invention for monitoring the functionality of a vehicle information system comprises several steps:

[0011] In a first step, a function is requested via an interface. This function can be requested, for example, in the form of a program, service, and / or, in particular, data required to execute the function. The corresponding form can be predefined depending on the function. The vehicle information system can initiate a query to the device via the interface. The device also has a corresponding interface for this purpose, enabling communication between the vehicle information system and the function and device, for example, via a mobile radio network. Based on this request or query, the device provides the function, for example, in the form of a service such as vehicle navigation. The device can be designed, in particular, as a so-called backend and, for example, include at least one computing device, in particular a server, connected to an information network such as the Internet. The vehicle information system can then obtain the function from the device.

[0012] In the second step of the method of the present invention, the vehicle information system performs the function. During the execution, the vehicle information system is placed in an operating state in which its functional scope is expanded, for example, so that vehicle navigation (i.e., the aforementioned function) can be realized.

[0013] In the third step of the method, the operating state, in particular the actual operating state, of a vehicle information system function is detected. This means that information is collected that characterizes the function, such as vehicle navigation, in such a way that the actual operating state can be derived from this information. By detecting the operating state, it is possible to determine whether the functional characteristics documented or stored in the framework condition plan, in particular the functional scope of the vehicle information system extended by this function, are met. For example, if the output of required direction information is delayed during navigation, this can be detected by detecting the operating state.

[0014] In the fourth step of the method, the operating state, in particular the measured operating state, is compared with a functional characteristic specified in the framework conditions plan, which essentially characterizes the ideal operating state of the function and, therefore, the ideal operating state of the vehicle information system. The comparison thus determines, in particular, the difference or deviation between the ideal operating state defined by the specified functional characteristic and the current actual operating state of the vehicle information system. For example, if a delay is detected in the direction-giving function in the form of vehicle navigation, and this delay is, for example, a specific time X, which is in particular greater than a time Y deviation specified by the functional characteristic in the framework conditions plan and, therefore, in particular, permitted, this is determined based on the comparison performed by the method.

[0015] In the fifth step of the method, if the operating state deviates from the functional characteristics recorded in the framework conditions plan, at least one value representing the deviation is provided to a register and / or at an interface to the vehicle information system. The deviation determined by the comparison is thus assigned a value that specifies the magnitude of the deviation, for example, as the difference between time X and time Y. This value can be a simple value, but it can also include at least one parameter and / or variable, etc. This method now provides this value so that it is available at the interface to the vehicle information system and / or for the register, allowing it to be transferred or transmitted to the device via the interface or, for example, written to the register. This value can indicate the deviation, which, for example, indicates a malfunction or a restricted functional range, thereby enabling, in particular, automated measurement of the functional quality and thus checking whether the function meets the conditions defined and thus promised in the framework conditions plan, i.e., the promised characteristics for vehicle navigation.

[0016] An information system, such as a vehicle information system, is essentially a system whose task is to cover information requests and is therefore a system which, for example, generates, collects, distributes and / or processes data, thereby, for example, being able to influence the operation of a motor vehicle.

[0017] The register is advantageously based on distributed ledger technology, i.e., the register is mirrored in the form of at least one register map, i.e., there are in particular identical copies of the register, i.e., register maps. Almost any number of register maps can be created, wherein the register and register map are in particular identical and therefore indistinguishable. For example, the register can be stored on a vehicle information system, and the register map on the device, or vice versa. Other register maps can be stored on other devices, respectively, different from the device or vehicle information system. Having as many devices as possible containing or storing the registers or register maps is advantageous, for example, in terms of security against counterfeiting of the registers, since changes made in only one of the registers or register maps can be detected by comparison with the remaining unchanged registers or register maps.

[0018] Depending on the design of the information stored in the register, for example in particular a function or a framework condition plan containing the function and / or at least one value, the register including its register mapping can thus be designed as a blockchain.

[0019] The framework conditions plan is advantageously designed as a computer program and / or computer protocol, which, for example, includes algorithmic tools for checking the functional scope that can be predefined based on at least one functional characteristic against possible deviations therefrom, in particular those expected to the maximum extent by a user who, by utilizing the vehicle information system, issues a functional request via an interface. Thus, the framework conditions plan can essentially be designed as a smart contract. In other words, the framework conditions plan is advantageously a computer protocol that describes and / or checks an agreement or contract regarding the function, in particular between the device and the vehicle information system, and can technically assist in fulfilling the contract, i.e., executing the function, in particular based on the functional characteristics. Functional characteristics here essentially refer to framework conditions, in particular for recurring functions.

[0020] In other words, the functional characteristics define the service level agreement, which details the promised performance characteristics, for example, the performance range of the function in the case of vehicle navigation, such as processing response time and speed. An important component of the functional characteristics is the agreed performance quality and, therefore, the performance range (e.g., time or range) within which, for example, vehicle navigation can be used.

[0021] The present invention is based on the recognition that, in order to provide services or functions in a vehicle information system, data or functions must often be obtained from suppliers other than the vehicle information system supplier. Agreements are concluded with these suppliers, particularly suppliers, regarding the quality of service. These agreements define, in particular, the functional characteristics and, for example, stipulate availability and other quality features. Furthermore, default conditions, such as penalties, are stipulated, which must be paid if the supplier does not or cannot comply with the agreement. Agreements containing penalties can be concluded, in particular, between the supplier of the vehicle information system and another supplier or vendor. Agreements can also be concluded between the supplier and the user of the vehicle information system. Monitoring each individual agreement is particularly advantageous in order to ensure the enforcement of the penalties included in the respective agreement. Previously, monitoring of functional characteristics, if any, was primarily performed through manual inspection, and the collection of penalties was also performed manually. However, both are typically very time-consuming and inflexible, so penalties are often waived if the function is not performed. In particular, electronic framework conditions in the form of smart contracts, formed by computer protocols and / or computer programs or by algorithms to be executed accordingly, offer the possibility of automatically monitoring functional characteristics, in particular as a function of at least one value. Furthermore, in particular, the automatic initiation or execution of agreed-upon obligations or penalties for breach of contract are also possible.

[0022] Each function can be provided by a separate supplier, for example, so that the vehicle information system requests the corresponding function from the respective supplier in a first step of the method according to the present invention. In order to be able to monitor the overall function and thus each individual function in it in a very advantageous manner, the respective supplier defines the corresponding framework condition plan and thus at least one corresponding functional characteristic.

[0023] The present invention is also based on the recognition that cryptocurrencies such as Bitcoin or Ethereum offer the possibility of also processing framework condition plans. This makes it possible to store framework condition plans, as described above, based on a register map, using a blockchain or distributed register used for cryptocurrencies, in particular, publicly and, advantageously, in an unalterable manner. This eliminates the need for a central entity to check the functional characteristics agreed upon in framework condition plans, particularly in smart contracts, thereby allowing for a low level of trust between suppliers and users. Thus, in contracts based on smart contracts, which also utilize blockchain technology, for example, the cumbersome and rigid process of enforcing penalty fees for breaches, such as service level agreements, which can be designed similarly to functional characteristics, is eliminated.

[0024] The method according to the present invention also applies to monitoring the functionality of vehicle information systems. This advantageously reduces the number of personnel required to collect, evaluate, and respond to manual feedback regarding malfunctions or deviations from the ideal operating state of the vehicle information system, as the method according to the present invention allows for programmatic and automated determination of these processes. Furthermore, the method according to the present invention eliminates the need for unilateral changes to the planned framework conditions, for example by the user of the vehicle information system and / or the supplier or operator of the system. This ensures a highly reliable operation of the vehicle information system, as the operating state can be well predicted within a fixed timeframe set by the user of the vehicle information system.

[0025] In other words, the method of the present invention allows, for example, service-specific monitoring of providers, so-called content providers, using or via smart contracts. A motor vehicle is connected to a device, and at least one service, i.e., a function in the vehicle information system, is implemented based on data or services from the content provider. These functions may include, for example, traffic information services, gas station prices, parking services, etc. Furthermore, other services or functions may be used in the vehicle information system, such as audio services, video services, voice services, etc. The method of the present invention is therefore characterized by automatically monitoring the service level of a service provider of the vehicle information system, such as the service level of a traffic service provider regarding the vehicle navigation services they provide, via smart contracts. In this case, the framework conditions plan specifies, for example, the objects to be monitored, such as interfaces, so that services available via the internet, provided by the device or directly accessible by the motor vehicle for these services, such as these functions, can be checked. Furthermore, thresholds related to functional characteristics can be defined, for example. These thresholds specify the degree to which agreed-upon parameters must be adhered to, such as a minimum availability of 99.99%, particularly online availability of URIs and / or URLs, and / or a maximum response time of 100 milliseconds. Here, the availability and response time are determined for each function or service to be monitored and the interface used therefor, in particular the content of the method performed in step 3. In step 4, the values ​​determined for the availability and response time are now compared with the threshold values ​​agreed upon in the protocol for each monitored interface or function, and finally, depending on the values ​​determined in step 5, a payment for the difference to the respective threshold value provided is triggered, so that, for example, a fee of 1 euro can be charged to the vehicle information system or its manufacturer and / or its user for a response time greater than 100 milliseconds.

[0026] In an advantageous embodiment of the present invention, the value is transmitted, in particular via the interface, at least to the device and / or to another device that accordingly contains the register and / or register mapping. In other words, by means of this method, a value representing the operating state deviation is provided to an instance that contains or provides or stores a version in the form of a register or its mapping in a storage area. This results in the advantage that the value can be accessed in addition to the vehicle information system on the device and / or other devices connected to the device and / or the vehicle information system, for example, via a data network, thereby allowing decentralized function monitoring. In this case, the device is, for example, an electronic computing device that can be part of a cloud environment, in particular in the form of a server. However, a personal computer of a user of the vehicle information system can also be used as another device, so that the value can be accessed from as many different locations as possible, depending on the location of the device and / or other devices and / or the vehicle information system.

[0027] In another advantageous embodiment of the present invention, the value is entered into the register and / or register map, particularly in encrypted form, i.e., encrypted using a cryptographic algorithm such as a hashing method, and thus, is entered into the entire register as a block or part of a block. In other words, the value is stored in the register similarly to how a value is stored in a blockchain, i.e., the block is particularly appended to the register, thereby expanding the register with the value, thereby enlarging the register's contents and, therefore, the register itself. Encryption can be performed, for example, using a key in the vehicle information system, particularly a private-public key method (private-public key), and, therefore, using an asymmetric cryptographic algorithm. This allows the value to be entered into the register in such a way that it can be unambiguously assigned to the vehicle information system. Advantageously, the value is also timestamped, so that it can be assigned over time. If the value is stored as a block, it is done in the form of a data block, so that the data block is a block of the blockchain and, therefore, a block of the register that is updated over time, thereby chaining successive blocks. When the value is stored in a block, a hash value of all blocks already in the register is advantageously generated using a cryptographic algorithm, in particular a hash function, so that a newly generated block can be unambiguously assigned to the blockchain at a specific point in time based on the blocks stored before it. Therefore, in addition to the value in the block, a hash value formed from the previously stored block using the hash function is preferably also stored simultaneously, thereby preventing subsequent manipulation of the value, at least in the case where the manipulator does not have access to a majority of the devices. Furthermore, encryption of the value itself, in particular using a private key, or personal key, of the vehicle information system, allows for a particularly forger-proof proof that the vehicle information system generated the value.

[0028] In an advantageous embodiment of the present invention, the input of values ​​is performed according to a consensus protocol. In other words, a value or a new block is only entered into a register when there is agreement between the device and / or other devices and / or the vehicle information system on the legal generation of the value. This has the advantage that forgery protection and, therefore, the enforceability of default conditions when the functional scope is not met can be achieved very securely. Furthermore, this ensures that all instances of the blockchain (devices, other devices, vehicle information systems) that have stored registers or register mappings contain the same register mapping. The consensus protocol or consensus method is guaranteed, for example, by the presence of a proof of rights, such as in the form of a stack proof, which allows one participant, such as the vehicle information system, to write the value to the register and thus generate the next block of the blockchain in a controlled manner. Furthermore, so-called validators can also be considered for use in the consensus method. These are essentially computer programs that can check the syntactic correctness of files.

[0029] Furthermore, in a further advantageous embodiment of the invention, the value is compared with a value table stored in the framework condition plan, in which a deviation operation, in particular a non-compliance condition, is specified at least for the value. For example, the value table is designed such that, for a corresponding value within a certain value range, a corresponding deviation operation is defined, which specifies the action to be taken by the device and / or the vehicle information system based on the deviation represented by the value, for example, to improve the actual operating state and / or to achieve deviation compensation.

[0030] In another advantageous embodiment of the present invention, a deviation calculation is performed based on the provided values. For example, if a function is unavailable at a certain time or for a certain period, an extension of the usage period can be considered. This is recorded in a value table that determines the deviation calculation, and the deviation calculation can be performed using this method. Thus, in the case of vehicle navigation, for example, if a failure occurs, the value table can be used to stipulate that if the usage period is, for example, one day, it will be extended by one day. Alternatively or additionally, there are various possibilities for interpreting non-compliance conditions or deviation calculations. For example, if a response time to a server query of the device, caused by a function, is too long, a payment of, for example, a certain amount in cryptocurrency could be made to the vehicle information system. In other words, the value table or comparison list could violate the agreed conditions defined in the functional characteristics in the registered framework condition plan. This advantageously allows for the initiation of possible operational status improvement measures and / or the provision of corresponding rewards based on the monitoring performed. The method can thus be implemented in a very advantageous manner automatically.

[0031] In another advantageous embodiment of the present invention, changes to the framework condition plan are performed based on values ​​entered into registers, in particular the blocks, and / or based on change specifications stored in the framework condition plan. This allows for a particularly dynamic adjustment of functional characteristics. It is thus possible to dynamically respond to certain situations, such as those affecting functionality, using other information stored in the framework condition plan, such as value tables. This allows, in particular, the functional scope of the vehicle information system to be kept as wide as possible depending on the situation, without causing disadvantages for the device and / or the user of the vehicle information system.

[0032] A second aspect of the present invention relates to an electronic computing device, such as, in particular, a vehicle information system, which is designed to carry out the method described.

[0033] The electronic computing device may also include multiple instances, which are connected to one another, for example, via inter-computer communication (peer-to-peer connection (P2P)), wherein each instance may contain registers, or the computing device may be one of the instances.

[0034] A third aspect of the present invention relates to a computer program product according to the present invention, which implements the method according to the present invention on an electronic computing device. The computer program product can, in particular, be in a form that can be directly loaded into a memory or storage area of ​​the electronic computing device. The computer program product has program means, in particular in the form of instructions, which, when executed on the electronic computing device, cause the electronic computing device to perform the method according to the present invention.

[0035] A fourth aspect of the present invention relates to a computer-readable data carrier. The data carrier according to the present invention comprises control information stored thereon, the control information including at least the computer program product according to the present invention and / or being designed to execute the method according to the present invention when the data carrier is used in an electronic computing device.

[0036] The features and improvements specified above and below and the corresponding advantages of the method according to the invention can be applied accordingly and mutatis mutandis to the electronic computing device according to the invention and / or the computer program product according to the invention and / or the data carrier according to the invention, and vice versa.

[0037] Furthermore, the present invention comprises a motor vehicle having a device, such as the electronic computing device, which is suitable for carrying out the method according to the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Further advantages, features, and details of the present invention are apparent from the following description of preferred embodiments in conjunction with the accompanying drawings. The features and feature combinations mentioned below in the description of the drawings and / or the features and feature combinations mentioned below in the description of the drawings and / or shown individually in the drawings can be used not only in the respectively indicated combination but also in other combinations or individually without departing from the scope of the present invention, including:

[0039] Figure 1 A schematic flow chart showing a method for monitoring the functionality of a vehicle information system of a motor vehicle, and

[0040] Figure 2 A schematic diagram shows a motor vehicle including a vehicle information system interacting with an off-vehicle device and registers that may be included as a register map in the device and / or in the vehicle information system. DETAILED DESCRIPTION

[0041] Figure 1 A schematic flow chart illustrates a method for monitoring a function FN of a vehicle information system FS of a motor vehicle KW, particularly a passenger car or another type of motor vehicle. In this method, the function FN is requested by an off-board device EI via an interface IN. The function FN expands the functional scope of the vehicle information system FS. At least one functional characteristic SA of the function FN, particularly in the form of a service level agreement, is defined according to a framework condition plan SC, particularly in the form of a smart contract, stored in a register RE.

[0042] In order to be able to carry out the monitoring of the function FN particularly advantageously, the method comprises a plurality of steps:

[0043] In a first step S1 of the method, a function FN is requested via an interface IN. In a second step S2 of the method, the function FN is executed by a vehicle information system FS. The vehicle information system FS is designed, for example, to include a driver assistance system and / or an infotainment system and a telematics unit, wherein the function FN can provide, for example, assistance functions of the driver assistance system. In a third step S3 of the method, the operating state, in particular the actual operating state, of the function FN of the vehicle information system FS is detected. During the detection of the operating state, information is collected that represents the state of the function FN, for example, in the form of the functions performed by the function FN in the vehicle information system FS. In a fourth step S4 of the method, the operating state is compared with a functional characteristic SA recorded / specified in a framework condition plan SC, in particular, representing an ideal operating state. In a fifth step S5 of the method, if the detected operating state deviates from the functional characteristic SA specified in the framework condition plan SC, a value W representing the deviation is provided to a register RE and / or to the interface IN of the vehicle information system FS.

[0044] Figure 2 The interaction between the motor vehicle KW or its vehicle information system FS and the at least one device EI is shown, and also in Figure 2 The upper area of ​​is shown a register RE and its components, for example a framework condition plan SC which contains and defines the functional characteristics SA.

[0045] A framework condition plan SC in the form of a smart contract is essentially a computer protocol that automatically checks, among other things, whether the functional characteristics SA or, for example, the deviation operations AO stored in the value table WT are being executed and thus whether the contractual conditions have been fulfilled. This method thus provides a monitoring option, since the performance characteristics promised by the device EI for compliance with the functional characteristics SA in the form of a service level agreement—for example, performance ranges, response times, etc., and also the maximum permissible deviations from the promised performance ranges—which are to be adhered to by the function FN, can be defined.

[0046] To enable particularly advantageous execution of the method, the value W is transmitted (in particular via the interface IN) at least to the device EI and / or another device (not shown) that accordingly contains the register RE and / or the register map RA. The register map RA is essentially an identical copy or version of the register RE, in particular a digital copy, so that the register map RA and the register RE cannot be distinguished. By assigning the register RE or the register map RA to at least the device EI or the vehicle information system FS, it is impossible to manipulate its version of the register RE or its register map RA, for example, the framework condition plan SC stored therein, by one of the instances, i.e., the device EI and / or the vehicle information system FS, without noticing differences when compared with the corresponding register map RA of the other instance. This essentially eliminates tampering with the monitoring.

[0047] The possibility of tampering is further reduced by signing the value W, in particular cryptographically, in particular using a key from a key pair of the device EI and preferably the vehicle information system FS. During the encryption process, the value W can be added, in particular as part of a block or data block, to information already present in the register RE, such as the framework condition plan SC or the value W1 already present in the register, thereby correspondingly expanding the register RE by at least the value W to be entered. Advantageously, in addition to the value W, another value or parameter, also advantageously encrypted using a hash function, is also entered, which contains a summary of the information previously present in the register RE, in particular in the form of a hash value, thereby further increasing the forgery resistance of the register RE. To ensure that only permissible values ​​W are entered into the register RE or register map RA, the value W is entered based on a consensus protocol. Various consensus methods are conceivable, such as using a validator and / or performing one of the following examples: proof of entitlement of the device EI and / or the vehicle information system FS. Additionally or additionally, proof of work is also possible. This can further enhance the security or verification of the function FN.

[0048] Advantageously, the value W is compared with a value table WT stored in the framework condition plan SC, in which a non-compliance condition or a deviation operation AO is specified for at least one value W1, which is to be performed as a response to a deviation between the actual operating state of the function FN of the vehicle information system FS and the ideal operating state determined by the function SA. Advantageously, the deviation operation AO is performed as a function of the provided value W.

[0049] The method can advantageously be performed by an electronic computing device, for example, having a vehicle information system FS. Furthermore, the method can be performed by a computer program product, in particular located in a memory of the electronic computing device, wherein the computer program product contains program means, in particular instructions, for executing the proposed method on the electronic computing device. Furthermore, a computer-readable data medium can contain the program means, which can be machine-readable (computer-readable), for example, by the electronic computing device.

[0050] The method described makes it possible, in particular, to monitor a provider of a function FN, i.e., a service, via a smart contract, by means of a framework conditions plan SC. The provider can be a content provider, such as an internet-connected car navigation system, and / or another service provider. Therefore, the function FN can be, in particular, a service, such as car navigation, also referred to as a service. The device EI is advantageously a backend, in particular a vehicle backend, having at least one electronic computing device. Communication between the interface IN of the device EI, designed as the backend, and the interface IN of the vehicle information system FS occurs via mobile radio. It is possible for the function FN provided by the device EI to contain data that, by providing this data to the vehicle information system FS, expands its functional scope and / or be designed so as to expand its functional scope. If, for example, the functional scope includes services such as traffic information services, gas station prices, parking services, etc., as in car navigation, these services can be used in the vehicle KW, in particular within the framework conditions plan SC. In addition to auxiliary services such as traffic information services, services for the infotainment system of the motor vehicle can also be provided, for example audio services in the form of music streaming or the like.

[0051] In particular, if the function FN is an Internet service, the interface can also be monitored, for example, via a framework conditions plan SC. Furthermore, thresholds can be set in the framework conditions plan SC, particularly in its functional characteristics SA. These thresholds include, for example, agreed parameters such as a minimum availability of 99.99% and / or a maximum response time of 100 milliseconds for the traffic service provider to respond to inquiries from the vehicle information system FS. Furthermore, the framework conditions plan SC can include regulations, particularly in the form of a value table WT, which can be used to determine, for example, fines payable in the event of a violation of the contractual conditions, i.e., failure to adhere to the functional scope of the vehicle information system FS guaranteed by the functional characteristics SA. Corresponding monitoring can be performed by executing the method multiple times, each time for one function FN, particularly if the respective functions FN are available from different suppliers.

[0052] Different suppliers can, for example, each use dedicated servers and / or shared servers, in particular in the form of a vehicle backend and / or cloud infrastructure, in order to store all functions FN provided for the vehicle information system FS. For example, the availability and response time are determined for each function FN. Furthermore, for each function FN, the values ​​W determined for the availability and response time are compared with agreed threshold values, i.e., the values ​​W are compared with a value table WT. Based on this value table WT, a deviation operation AO is then initiated. Different deviation operations AO can be specified for different deviations, i.e., different values ​​W, as in, for example, Figure 2AO is calculated by various deviations i As shown by the index numbers.

[0053] The register RE advantageously exists in the form of a blockchain, so that the framework condition plan SC is also part of the blockchain. This is stored, for example, using the aforementioned standards and / or other protocols in the blockchain and thus in the register RE. Storage is preferably performed on as many devices EI or vehicle information systems FS and / or other devices as possible. The register RE can also contain multiple framework condition plans SC, for example for each function FN or the corresponding function FN supplier, thereby enabling automated monitoring of all functions FN via the register RE.

[0054] Advantageously, the provider of the function FN can deposit a deposit, for example in the form of a security deposit and, for example, in the form of a cryptocurrency, in the framework conditions plan SC, so that if there is a deviation from the value W according to, for example, a value table WT as a deviation operation, the deposit stored in the framework conditions plan SC is transferred to the user of the vehicle information system FS and / or its manufacturer.

[0055] In this case, when adjusting via the value table WT, the amount can depend on the severity of the violation, e.g., if the actual availability is 99.8% instead of the required 99.99%, a fine of 100 euros is imposed. A tiered system can be used, so that if the actual availability is 99.7%, for example, a fine of 1000 euros is imposed.

[0056] In addition to the register RE, the functional characteristics SA, ie the compliance with the service level agreement or the service level, can also be reported automatically to the supplier or the device EI, for example, by means of e-mail.

[0057] In addition to the availability of the function FN, the functional characteristics may also require and / or stipulate other quality features, such as spatiotemporal relationships. Thus, the amount of GPS data on a certain traffic information service on a certain road in a certain time period, the timeliness of gas station prices in a certain area and / or the availability of external audio sources during the journey, for example, can all be part of the function SA.

[0058] If the quality characteristics specified by the service provider in the functional characteristics SA are time-dependent, for example, gas station prices may fluctuate, these deviations can also be specified in the function FN. Thus, for example, gas station prices should be updated every hour; otherwise, a deviation operation AO occurs. For parking space information, for example, it can be stipulated that a parking space should not be occupied for more than 30 minutes.

[0059] Furthermore, the quality characteristics of the supplier of the function FN can be spatially dependent. Thus, for example, the on-street parking information in Stuttgart can be more accurate and more available than in Copenhagen, that is, depending on the number of selections made by the user of the vehicle information system.

[0060] Furthermore, depending on the function FN, the quality characteristics may tolerate certain deficiencies. Thus, for example, a traffic service may provide less than 1% of GPS data at night, since, for example, traffic congestion is less likely at night. Another example is a function FN implemented by the vehicle information system FS as an interpreter or translation service. Therefore, the unavailability of languages ​​spoken by a minority may be subject to less stringent sanctions than the unavailability of languages ​​spoken by the majority.

[0061] Advantageously, the supplier or service provider can provide, for example, an interface IN for querying current quality characteristics at the device EI.

[0062] In the event of a violation of a characteristic such as availability and / or quality, particularly defined by the function SA, in the framework condition plan SC, the service provider can automatically pay a penalty for the violation, for example, based on a corresponding deviation operation AO using the payment assigned in the value table WT. Advantageously, the payment is made using cryptocurrencies such as Bitcoin or Ether.

[0063] Furthermore, for example, in the event of a violation of the framework condition plan SC, user limitations caused by the actual operating state can be compensated. Thus, for example, if the GPS data volume drops to less than 2%, a reliable warning of the end of a congestion can no longer be given. However, as long as more than 1% of GPS data is available for the corresponding route section, the remaining journey time can still be displayed in the vehicle.

[0064] Furthermore, a change statement AA for the framework conditions plan SC itself is executed based on the value W entered into the register RE and / or other information stored in the framework conditions plan SC. Thus, for example, all deviations of the function FN, for example in the form of the value W, can be evaluated in the register RE. The information obtained from this evaluation can be used, for example, in future negotiations regarding a new framework conditions plan SC. Furthermore, weaknesses in individual functions FN can be identified, making it particularly advantageous to determine the cause of the deviation, since the deviations can be tracked chronologically by the register RE.

[0065] For new functions FN, the respective supplier of the respective function FN or the device EI itself can provide a framework condition plan SC and store it in the register RE, in particular according to a consensus agreement.

[0066] In addition to automated processing and monitoring, another advantage of this method is that, for example, if a fee is required for a function FN request, this fee can be immediately settled, for example, with the payment included in the corresponding deviation operation AO, so that no accounting costs are incurred. Furthermore, this method can be used particularly advantageously in a decentralized manner, for example.

Claims

1. A method for monitoring a function (FN) of a vehicle information system (FS) of a motor vehicle (KW), the function being requested by an off-board device (EI) via an interface (IN) and extending the functional scope of the vehicle information system (FS), and at least one functional characteristic (SA) of the function being defined according to a framework condition plan (SC) stored in a register (RE), the method comprising the following steps: - requesting the function (FN) via the interface (IN); - executing the function (FN) by means of the vehicle information system (FS); - detecting the operating status of the function (FN) of the vehicle information system (FS); - comparing the operating status with the functional characteristics (SA) recorded in the framework condition plan (SC); - if the operating state deviates from the functional characteristics (SA) recorded in the framework condition plan (SC), providing at least one value (W) characterizing the deviation for the register (RE) and / or at the interface (IN) of the vehicle information system (FS); in, The framework condition plan is a smart contract, the register is a blockchain; the method further comprises the smart contract automatically checking whether a functional characteristic (SA) or a deviation operation (AO) stored in a value table (WT) is executed and thus whether a non-fulfilled condition is fulfilled; The method includes automatically monitoring the functional characteristic based on the at least one value and automatically initiating or executing an agreed-upon breach of contract obligation fulfillment or breach of contract penalty.

2. The method according to claim 1, wherein: The value (W) is transmitted at least in particular via the interface (IN) to the device (EI) and / or another device which respectively contains the register (RE) and / or the register map (RA).

3. The method according to claim 1 or 2, wherein: The value (W) is entered in particular in encrypted form into the register (RE) and / or the register map (RA).

4. The method according to claim 3, wherein: The input of the value (W) is performed according to the consensus protocol.

5. The method according to claim 1, wherein: The value (W) is compared with a comparison list stored in the framework condition plan (SC), in which a deviation operation (AO) is specified for the at least one value (W).

6. The method according to claim 5, wherein: The deviation operation (AO) is performed according to the provided value (W).

7. The method according to claim 1, wherein: The changes to the framework conditions plan (SC) are carried out according to the value (W) entered into the register (RE) and / or according to the change instructions (AA) stored, in particular, in the framework conditions plan (SC).

8. An electronic computing device designed to carry out the method according to one of the preceding claims. 9 . A computer program product which can be loaded into a memory of an electronic computing device and which comprises program means which, when executed on the electronic computing device, causes the latter to carry out the method according to claim 1 .

10. A computer-readable data carrier having control information stored thereon, the control information comprising at least one computer program product according to claim 9 and / or being designed such that, when the data carrier is used in an electronic computing device, the method according to one of claims 1 to 7 is executed.

Citation Information

Patent Citations

  • International trade finance blockchain system

    WO2018006056A1

  • Updating service level agreements based on a usage pattern for a subscriber at multiple locations during multiple times of day

    US10127530B1

  • Vehicle transaction validation

    US20180374283A1