Method and device for verifying vehicle-to-outside interaction information for controlling traffic flow

The vehicle computing device receives and verifys traffic control information, and solves the problem of insufficient information security of traffic control equipment, realizes the identification and prevention of false information, and improves traffic safety.

CN115708142BActive Publication Date: 2025-08-08CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202210985054.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-08-19
Filing Date
2022-08-17
Publication Date
2025-08-08
Estimated Expiration
2042-08-17

AI Technical Summary

Technical Problem

In the prior art, the information of traffic control devices such as traffic lights cannot effectively ensure functional safety, resulting in functions such as adaptive cruise control and other functions that cannot conduct dynamic driving intervention independently of the driver.

Method used

The vehicle's interactive information on the outside world is received and verified through the vehicle computing device, conduct consistency checks, identify false information, evaluate the credibility of the sending device, and improve functional safety.

Benefits of technology

Improve the functional safety of the traffic control system, identify and prevent false information from being interfered with, and ensure traffic safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115708142B_ABST
    Figure CN115708142B_ABST
Patent Text Reader

Abstract

A method and apparatus for verifying vehicle-to-outside interaction information for controlling traffic flow. The present invention relates to a method (100) for verifying vehicle-to-outside interaction information by a vehicle computing device, the method comprising the following steps: receiving (102) at least one vehicle-to-outside interaction information including a message for controlling traffic flow; and verifying (104) the at least one message, wherein, within the scope of the verification, at least a portion of the message content contained in the at least one message is subjected to a consistency check. Furthermore, the present invention relates to a corresponding apparatus (200) and the use of the apparatus in a vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for verifying interactive information transmitted by a vehicle to the outside world for controlling traffic flow and a corresponding device. Background Art

[0002] Currently, selected traffic control devices, such as traffic lights, are being configured in research and pre-development to transmit SPAT (Signal Phase and Timing) and MAP (Map) information using a corresponding transmitter in accordance with ETSI (European Telecommunications Standards Institute) or SAE (Society of Automotive Engineers) specifications. Vehicles equipped with a suitable vehicle-to-everything (V2X) interface can process the received messages and make them available to the driver. This includes messages about lanes (MAP), traffic light status or phase, and when the traffic light changes state (SPAT (Signal Phase and Timing)).

[0003] However, due to the lack of effective protection against false information in terms of functional safety, it has not been possible to use this information to provide, for example, the ACC (Adaptive Cruise Control, or Abstandsregeltempomat) function, which recognizes the traffic light status based on information received from the traffic light device, evaluates it, and can perform dynamic driving interventions independently of the driver. Summary of the Invention

[0004] It is therefore an object of the present invention to provide a device for increasing the functional safety of communication between infrastructure and vehicles (V2I).

[0005] The first aspect of the patent application published herein relates to a method for verifying vehicle-to-external information interaction information through a vehicle computing device, the method comprising the following steps:

[0006] - receiving at least one vehicle-to-external interaction message including a message for controlling traffic flow; and

[0007] - verifying the at least one message, wherein within the scope of the verification at least a part of the information content contained in the at least one message is checked for consistency.

[0008] The method can improve vehicle functional safety in vehicle-to-external communication and provide an assessment of the trustworthiness of the transmitting device. The information content here refers in particular to all messages contained in a message. Thus, messages for controlling traffic flow correspond to at least a portion of the information content. Vehicle-to-external communication messages, and in this case, messages for controlling traffic flow, are received in particular by a transmitting device of an infrastructure device for the purpose of controlling traffic flow. Messages for controlling traffic flow are in particular messages transmitted, for example, using MAP (Map) or SPAT (Signal Phase and Timing) information.

[0009] The verification of the information is carried out in particular based on the information content contained in the received information, wherein different criteria can be checked in an alternating and / or at least partially cumulative manner, as will be discussed further below.

[0010] According to at least one embodiment, if it is determined that the information content is not consistent, the information is discarded, and / or the sending device of the information is classified as untrustworthy, and / or at least a portion of the information content, such as the portion or the entire message content with consistent information content, is marked as having a corresponding low trust level and is further processed.

[0011] In principle, in particular if one or more information items are found to be inconsistent, provision can be made for a warning signal to be issued, for example for warning the vehicle driver via a human-machine interface or for processing by a (semi-)autonomous vehicle system. This situation can also be communicated to other road users and / or an external central data processing device via a wireless interface.

[0012] According to at least one embodiment, if the information content is determined to be consistent, the information is further processed and / or the information sending device is classified as trustworthy and / or at least a portion of the information content is marked as having high credibility and further processed.

[0013] The increase in functional safety is based on a consistency check of the messages contained in a single received message and of the messages contained in a plurality of successively received messages.

[0014] When examining messages received consecutively from the same sending device, these messages do not necessarily need to be received directly one after another. It is also possible that while the sending device is sending messages consecutively, it is also viewing and receiving messages from other sending devices. Messages sent consecutively by the same sending device can, but are not necessarily, sent consecutively in time, i.e., they are sent by the sending device in a directly consecutive manner or received by the sending device in a directly consecutive manner. The sending device may also send at least one message between these messages.

[0015] By verifying the vehicle-to-the-world interaction information received by traffic participants, the trustworthiness of the transmitting device can be assessed, thereby improving functional safety from the perspective of the receiving vehicle. In particular, false information whose content could endanger traffic safety and whose authenticity is unconditionally assumed can be identified. In this sense, false information refers in particular to information that pretends to be sent by one of the corresponding traffic control devices and / or contains manipulated messages. Manipulated messages may also be the result of external access (hacking) to the traffic control device and / or other transmitting devices. Therefore, a transmitting device that is classified as trustworthy is particularly one that is assessed to be authentic and does not send false information, such as information with incorrect content. In principle, it can also be assumed that even in the presence of a large number of false messages, at least one non-false message, especially from a traffic control device, is received within an observation period. Based on the entire context of the information, an attempt can be made to identify the non-false message.

[0016] This also increases the functional safety of the entire communication system between traffic control devices and road users.

[0017] According to at least one embodiment, the reception rate of at least two consecutively received messages, which include messages indicating that they originate from the same transmitting device, is measured and then compared to a limit value. In particular, the reception rate of the at least two messages is checked to see whether it is less than or equal to a predefined limit value for the reception rate. If at least one message passes the verification test against this standard, the reception rate of the at least two messages should be less than or equal to the predefined limit value for the reception rate. The limit value can be set, for example, by mapping a standardized transmission rate to a specific message type, where messages of the same message type do not necessarily have to be received immediately in succession, and / or by, in principle, the maximum transmission rate of the transmitting device. In this way, fraudulent behavior can be detected.

[0018] The received information is, in particular, a message and / or a message type typically sent by a traffic control device, such as a traffic light system. According to other embodiments, the message describes a signal state and / or a remaining signal state time of the traffic control device and / or a topological definition of a lane, such as an intersection or a road section, and / or a connection between road sections and / or a lane type and / or lane-related movement restrictions. Relevant information types include, for example, SPAT (Signal Phase and Timing) information and / or MAP (Map) information in accordance with the ETSI (European Telecommunications Standards Institute) and SAE (Society of Automotive Engineers) standards.

[0019] For example, in the standardized SPAT (Signal Phase and Time) information format, the status and remaining status time of the complete traffic control device are mapped at once, so that not only messages directly relevant to traffic participants about the lane being traveled can be received, but also messages for all other lanes controlled by the traffic control device.

[0020] According to at least one embodiment, the information content includes a signal status message describing the permitted travel of multiple lanes on the road, wherein the vehicle to be executed by the method is in particular traveling in one of the multiple lanes, and wherein a consistency check is performed on the signal status messages for at least a portion of the multiple lanes. Thus, upon receiving a permitted travel signal, such as a green traffic light, a receiving traffic participant can verify the traffic control signal for the lane in which the vehicle is traveling by comparing it with other lanes, using information contained in, for example, MAP information. The traffic control device may, for example, not issue a permitted travel signal or issue a stop signal for all other lanes that intersect with the vehicle's lane or that could cause a collision with other traffic participants due to the permitted travel signal.

[0021] According to at least one embodiment, the information content includes a signal status message indicating whether travel is permitted, wherein the signal status message is checked using a vehicle light detection system, for example, using at least one vehicle camera. For example, in the case of a traffic light system, a green sign indicates that travel is permitted, and a red sign indicates that travel is prohibited. These signs can be detected by the vehicle camera and used accordingly to detect the information content.

[0022] According to other embodiments, provision can be made for verifying the signal state contained in the received SPAT (Signal Phase and Time) information using a vehicle light detection system, for example by means of at least one vehicle camera.

[0023] According to at least one embodiment, the information content includes a lane topology definition, wherein the lane topology definition is checked for consistency with infrastructure features detected by vehicle surrounding sensors. Examples of infrastructure features that can be checked include the number of lanes, curves, the number of signal groups at traffic lights, lane curvature, lane width, or multiple lane widths.

[0024] According to at least one embodiment, the message included in the received MAP information is verified by comparing infrastructure features described by the message included in the MAP information with infrastructure features detected by vehicle surrounding sensors.

[0025] The acceptable comparison error between the infrastructure features described by the lane topology definition in the information content and the infrastructure features detected by the vehicle's surrounding sensors is considered to be an error. This error depends, among other things, on the detection accuracy of the vehicle sensors used and on the situational environmental conditions. Correlations may arise due to factors such as the physical measurement principles of the respective sensors, weather conditions, and traffic density. In principle, the design of these errors can be predetermined as fixed and / or adjustable.

[0026] Furthermore, during the inspection it can be taken into account that, for example, only a portion of the infrastructure features described by the received MAP information message can be inspected, since the vehicle sensors cannot detect all features of the infrastructure described by the received MAP information message.

[0027] According to at least one embodiment, this check includes determining the reception direction of the signal transmitting the received information and checking whether the determined reception direction conflicts with the position information contained in the information content, which describes the position of the transmitting device. Based on the position of the transmitting device and taking into account the determined position of the vehicle receiving the information (e.g., determined using a Global Navigation Satellite System (GNSS) receiver on the vehicle), it can be checked whether the signal transmitting the information arrives from the expected direction relative to the position of the transmitting device. If a difference exceeding an error is detected between the determined reception direction and the determined expected reception direction, a fraudulent attempt may be present. In principle, the formation of the error can be predetermined to be fixed and / or adjustable. For example, the reception direction can be determined by detecting differences in the signal power and / or phase angle of the transmitted information when received by at least two antennas of the vehicle. In particular, at least one antenna array having at least two elements and / or at least two antennas can be provided as the receiving device of the vehicle.

[0028] According to at least one embodiment, the received power (RSSI (Received Signal Strength Indicator)) of the signal transmitting the received information is measured, and a check is performed to determine whether the measured received power conflicts with the position information contained in the information content, which describes the position of the transmitting device. Based on the position of the transmitting device and taking into account the position of the receiving vehicle, for example, as determined by a vehicle Global Navigation Satellite System (GNSS) receiver, a check can be performed to determine whether the signal transmitting the received information has the expected received power relative to the position of the transmitting device. This allows for verification of whether the measured received power corresponds to the calculated distance between the transmitting and receiving devices. If a discrepancy exceeding an error is detected, a fraudulent attempt may be present. In principle, the error can be predetermined to be fixed and / or adjustable.

[0029] According to at least one embodiment, a transmit power at which a transmitting device transmits a signal transmitting the received information is determined based on the measured received power, and a check is performed to determine whether the measured transmit power contradicts a prescribed transmit power. The transmit power is determined, in particular, taking into account a position message contained in the received information describing the position of the transmitting device and / or the determined own position of the vehicle receiving the information. Furthermore, the measured received power of the signal transmitting the received information serves as a basis for determining the transmit power. A simplified channel model can be calculated for determining the transmit power. To verify whether the prescribed transmit power is present, according to other embodiments, the measured transmit power is compared with the maximum transmit power (EIRP (Effective Isotropic Radiated Power)) of the channel, in particular, used to transmit the signal receiving the information. If the measured transmit power is less than or equal to the maximum transmit power and / or greater than or equal to the minimum transmit power, the prescribed transmit power is present. If the measured transmit power deviates from the prescribed transmit power, the prescribed transmit power is not present, which may indicate a fraudulent attempt. The underlying specification may, for example, be a specification of a relevant vehicle-to-the-world communication standard that defines transmit power.

[0030] To calculate the received power and / or the transmitted power, the antenna characteristics of the receiving antenna can be stored in a data memory and used for the calculation.

[0031] According to other embodiments, objects such as buildings that may affect the reception power of the signal transmitting the received information can be taken into account when determining the transmission power. Information describing the objects can be stored in at least one digital data memory or a digital map, wherein the vehicle and / or the vehicle-external data processing device can include one or more data memories.

[0032] In particular, a determination is implemented for information types that are not subject to a prescribed reduction in transmission power, such as the electronic emergency brake light (EEBL) or the triggering of an airbag. The prescribed maximum transmission power does not apply to all information types, so that for information types that are not subject to a prescribed reduction in transmission power, it can be better determined whether the used or measured transmission power is, for example, higher than the prescribed maximum transmission power. As an alternative or supplementary measure, a determination of the transmission power is implemented if the vehicle is in an area where information transmission is not permitted according to regulations, in particular the maximum transmission power. These areas are, for example, toll areas, because interference may be caused. These areas can be stored in a digital map and / or transmitted via a roadside unit (RSU) using CAM (Collective Awareness Information) information. Information types that are not subject to a prescribed reduction in transmission power are, for example, specified in at least one specification of the relevant vehicle-to-the-world communication standard.

[0033] According to at least one embodiment, the information content includes a message describing the transmit power of the signal transmitting the information. A check is performed to determine whether the measured received power conflicts with the transmit power description included in the information content and / or to determine whether the measured transmit power conflicts with the transmit power description included in the information content. The transmit power description message is inserted by the information transmitting device itself. This message insertion is implemented in a manner that makes manipulation of the message by external access more difficult than, for example, messages contained in other information. This improves message security and, according to this embodiment, functional safety. This allows for a more accurate observation of the transmission path, further contributing to improved safety if the transmit power specified in the information corresponds to the actual transmit power used. Furthermore, the transmit power obtained from this message can be used to verify the information, for example, by comparing it with the transmit power determined from the signal of the receiving device. According to other embodiments, the transmit power description message included in the received information can be compared with the measured transmit power. Substantial differences between the values may be due to incorrect information about the transmission path and / or the transmit power in the received information. Therefore, if insufficient knowledge of the transmission path is available, it is not possible to directly infer possible fraudulent attempts. If the transmit power specified in the information is to be used for information verification, this should be taken into account depending on the intended use.

[0034] According to at least one embodiment, the information content is checked using messages describing characteristics related to the transmitting device. These messages are stored in the vehicle's data memory and / or provided by a data processing device not associated with the vehicle. Characteristics related to the transmitting device may, for example, be its location and / or identifier. According to other embodiments, the messages describing characteristics related to the transmitting device may be contained in a digital map. The digital map and / or messages describing characteristics related to the transmitting device may be stored in the vehicle's data memory and / or provided, for example, by a central or decentralized data processing device (e.g., cloud computing, edge computing) via wireless data transmission. The messages describing characteristics related to the transmitting device are not provided by the transmitting device itself. The locations of traffic control devices generally do not change and are well known, allowing them to be stored statically or at least temporarily in a map. This is why messages related to traffic control devices are particularly useful for verifying received information. For example, if a message received from a transmitting device does not contain a message describing characteristics related to the transmitting device stored in its data memory or digital map, and no other messages have been received from a data processing device not associated with the transmitting device, the further processing of the information by the transmitting device, and possibly other information from the transmitting device, is considered untrustworthy.

[0035] According to at least one embodiment, the information content of at least two messages intended to be displayed as received by the same transmitting device is used to check the information content of at least one of the at least two received messages. According to another embodiment, the information content of the at least two received messages includes traffic control signals, which are checked for conflicts based on their chronological order and / or time division. For a positive result to be obtained for the criterion regarding the at least one verified message, the traffic control signal messages described by the at least two messages must not have any inconsistencies in their chronological order and / or time division.

[0036] Therefore, for a positive verification of the information, in particular at least one of the following prerequisites must be met:

[0037] The state of the traffic control signal, such as the state of the traffic light, cannot have any inconsistency, such as rapid oscillation. In this regard, there may be a prerequisite that the state of the traffic control signal must be maintained for at least 3 seconds, for example.

[0038] The temporal division of traffic control signal states, such as traffic light states, may only deviate under specific circumstances from the temporal division of previous traffic signal states, which can also be determined using the received information. In other words, the duration of traffic control signal states should generally be consistent or free of inconsistencies. Specific cases where there are no inconsistencies in this sense include, for example, pedestrian requests to cross lanes. In these specific cases, other inconsistencies in the traffic control signal should also not occur, such as simultaneous vehicle permission and pedestrian crossing indications in the same lane. Such a prerequisite could, for example, require that no signal state be updated for two seconds before a signal state change.

[0039] It is necessary to indicate that the reception rate of messages from the same transmitter (and therefore the transmission rate of the same transmitter) must not exceed a predetermined limit value. If, for example, messages from the same transmitter virtually block the reception of messages from other transmitters due to a reception rate exceeding a certain limit value, it can be provided that the messages from this transmitter are essentially discarded without further processing, since this may be a potentially interfering transmitter.

[0040] This verification is generally applicable not only when traffic control devices transmit information, but also in particular when communicating between traffic participants or vehicles.

[0041] Another aspect of the patent application published here relates to a device configured to perform the method according to at least one of the above-mentioned embodiments. The device can be used in particular in a vehicle.

[0042] The vehicle may be a motor vehicle, in particular a car, a truck, a motorcycle, an electric car or a hybrid car, a water vehicle or an air vehicle.

[0043] The device may be, for example, a computing device or an electronic control unit. The computing device may be any device configured to process at least one of the signals. The computing device may be, in particular, a processor, such as an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a digital signal processor, a main processor (CPU: "Central Processing Unit"), a multi-purpose processor (MPP: "Multi Purpose Processor"), or the like.

[0044] In another embodiment of the designation device, the designation device has a memory. In this case, the designation method is stored in the memory in the form of a computer program, and when the computer program is loaded from the memory into the computing device, the computing device predetermines the execution of the method.

[0045] According to another aspect of the invention, the computer program comprises program code means for executing all the steps of one of the methods described, if the computer program is executed on a computer or a designated device.

[0046] According to a further aspect of the invention, a computer program product comprises a program code stored on a computer-readable data carrier, which, when executed on a data processing device, causes one of the specified methods to be performed. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Other preferred embodiments can be derived from the following description of the embodiments with reference to the accompanying drawings.

[0048] Figure 1 An embodiment of the method for verifying vehicle-to-external interaction information according to the patent application disclosed herein is shown, and

[0049] Figure 2 An embodiment of a device according to the patent application published herein is shown. DETAILED DESCRIPTION

[0050] Figure 1 An embodiment of a method 100 for verifying vehicle-to-external interaction messages by a vehicle computing device is presented, wherein, in step 102, at least one vehicle-to-external interaction message is received, which includes a message for controlling a traffic flow, and in step 104, the at least one message is verified, wherein, within the scope of the verification, a consistency check is performed on at least a portion of the information content included in the at least one message.

[0051] Figure 2An exemplary embodiment of an electronic control unit 200 for verifying vehicle-to-external interaction information is shown, wherein the electronic control unit is configured to perform corresponding steps according to at least one embodiment of the method. The electronic control unit is carried by a vehicle 230 or installed in the vehicle.

[0052] In this embodiment of the electronic control unit 200, the designated device includes a processor 202 and a memory 204. Here, a given method is stored in the memory 204 in the form of a computer program, and if the computer program is loaded from the memory to the processor 202, the device 200 is pre-determined to execute the method.

[0053] The electronic control unit is configured to receive at least one vehicle-to-everything (V2X) interaction message 212, including a message for controlling traffic flow via a vehicle-to-everything (V2X) interaction communication device 210, and to verify the at least one message via a verification device 206. Within the scope of the verification, a consistency check is performed on at least a portion of the information content included in the at least one message 212. The V2X interaction communication device 210 can be configured, for example, as an antenna device for receiving V2X interaction messages, wherein the processing of the message or the information content is performed by the electronic control unit 200. According to at least one embodiment, the consistency check is performed using sensor data 216 from at least one sensor 214 of the vehicle 230.

[0054] According to at least one embodiment, if it is determined that the information content is not consistent, the received information is discarded or its information content and / or the information sending device is classified as untrustworthy and / or at least a part of the information content, such as a part of the information content with consistency or the entire message content, is marked as having a corresponding low trust level and transmitted to an evaluation device 218 that takes this trust level into account accordingly.

[0055] In principle, in particular if one or more information items are found to be inconsistent, it can be provided that a warning signal 220 is issued to the evaluation device 218, for example, to warn the vehicle driver via a human-machine interface or to be processed by a (semi-)autonomous vehicle system. This situation can also be communicated to other road users and / or an external central data processing device, for example, via the V2X communication device 210 or a telematics interface.

[0056] According to at least one embodiment, if the consistency of the information content is determined, the information content or a message 220 based thereon is at least partially sent to the evaluation device 218 and / or the information sending device is classified as trustworthy and / or at least a part of the information content is correspondingly marked as having high credibility and further processed taking into account the credibility level.

[0057] If, during the processing of a patent application, it is discovered that a feature or a combination of features is no longer necessary, the applicant shall redraft at least one independent claim that no longer includes that feature or group of features. This may involve, for example, a dependent combination of claims submitted at the filing date, or a dependent combination of claims submitted at the filing date that is limited by other features. Such redrafted claims or feature combinations are included in the scope of the published content of the patent application.

[0058] Furthermore, it should be noted that the designs, features, and variations described in the various designs or embodiments and / or shown in the figures of the present invention may be arbitrarily combined. Individual or multiple features may be arbitrarily substituted for one another. Such feature combinations are within the scope of this patent application.

[0059] References in the associated claims do not disclaim independent and objective protection for the features of the referenced dependent claims. These features may also be combined with other features in any way.

[0060] Features disclosed only in the description and only in conjunction with other features in the description or a claim generally have their own inventive significance and can therefore be included in the claims alone to define the prior art.

[0061] It should be noted that vehicle-to-infrastructure communication refers specifically to direct communication between vehicles and / or between vehicles and infrastructure devices. The term does not imply the direction of communication and, for example, can be understood as both vehicle-to-infrastructure (V2I) and infrastructure-to-vehicle (I2V) communication. It could be, for example, vehicle-to-vehicle or vehicle-to-infrastructure communication. As long as the present patent application addresses vehicle-to-vehicle communication, it can, in principle, be implemented within the context of vehicle-to-vehicle communication, typically without modem access via a mobile radio network or similar external infrastructure, thus distinguishing it from other solutions based on mobile radio networks. For example, vehicle-to-infrastructure communication can be implemented using the IEEE 802.11p standard or the IEEE 1609.4 standard. Vehicle-to-infrastructure communication can also be referred to as C2X / V2X communication. In some areas, it can be referred to as C2C / V2X (vehicle-to-vehicle) or C2I / V2I (vehicle-to-infrastructure). However, the present invention does not explicitly exclude vehicle-to-infrastructure communication, for example, via a mobile radio network with modem functionality.

Claims

1. A method (100) for verifying vehicle-to-external interaction information by a vehicle computing device, the method comprising the following steps: - receiving (102) at least one vehicle-to-external interaction information including a message for controlling traffic flow; as well as - verifying (104) the at least one message, wherein within the scope of the verification at least a part of the information content contained in the at least one message is checked for consistency, Based on the measured reception power, the transmission power at which the transmission device transmits the signal transmitting the received information is measured, and it is checked whether the measured transmission power conflicts with the prescribed transmission power. When measuring the transmission power, objects that may affect the reception power of the signal transmitting the received information are taken into consideration. If the received information does not correspond to an information type that requires a reduction in transmission power, and / or if the vehicle receiving the information is located in an area where transmission at a prescribed transmission power is not permitted, the transmission power is measured. The information content includes a message for describing the transmission power of a signal transmitting information, wherein a check is performed to determine whether the measured reception power conflicts with the message included in the information content and used to describe the transmission power, and / or a check is performed to determine whether the measured transmission power conflicts with the message included in the information content and used to describe the transmission power.

2. The method according to claim 1, wherein A reception rate of at least two consecutively received messages, the messages contained in which originate from the same transmitting device, is determined and compared with a limit value.

3. The method according to claim 1, wherein The information content includes signal status messages describing driving permissions for a plurality of lanes on the road, wherein the signal status messages of at least some of the plurality of lanes are checked for consistency.

4. The method according to claim 1, wherein The information content comprises a signal status message, wherein the signal status message is checked using a light detection system of the vehicle.

5. The method according to claim 1, wherein The information content includes a topological definition of the lanes, wherein the topological definition of the lanes is checked for consistency with infrastructure features detected by sensors of the vehicle's surroundings.

6. The method according to claim 1, wherein The reception direction of the signal transmitting the received information is determined and a check is performed to determine whether the determined reception direction conflicts with a position information contained in the information content and describing the position of the transmitting device.

7. The method according to claim 1, wherein The received power (RSSI) of the signal transmitting the received information is measured and a check is performed to determine whether the measured received power conflicts with a position information contained in the information content and describing the position of the transmitting device.

8. The method according to claim 1, wherein The information content is checked using messages describing characteristics related to the transmitting device, which are stored in a data memory of the vehicle and / or provided by a data processing device that is not part of the vehicle.

9. The method according to claim 1, wherein At least one of the information contents of the at least two received information items is checked using the information contents of the at least two received information items originating from the same sending device.

10. The method according to claim 9, wherein: The information content of the at least two received information items includes traffic control signals, which are checked in chronological order and / or time-divided for conflict.

11. A device (200) for verifying vehicle-to-outside interaction information, the device being configured to implement the steps of the method according to any one of the preceding claims.

12. A vehicle in which the device according to claim 11 is used.

Citation Information

Patent Citations

  • System and method for detecting attack

    CN106407806A

  • Traffic signal lamp information fusion decision-making method for intelligent network connection vehicle

    CN111932918A

  • Security apparatus, attack detection method, and storage medium

    US20180167360A1

  • Determination of plausibility of intelligent transport system messages

    US20190068639A1