A method for anonymous data transmission

By using token server verification and random delay mechanisms, the anonymity and security issues in vehicle data transmission are resolved, ensuring that only authorized vehicles can transmit data, thus achieving secure and anonymous transmission.

CN117999766BActive Publication Date: 2025-11-14MERCEDES BENZ GRP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202280064722.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-10-01
Filing Date
2022-09-28
Publication Date
2025-11-14
Estimated Expiration
2042-09-28

Smart Images

  • Figure CN117999766B_ABST
    Figure CN117999766B_ABST
Patent Text Reader

Abstract

This invention relates to a method for anonymously transmitting vehicle data (D) to a computing unit (R) with which the vehicle forms a data link, wherein the vehicle is authenticated before transmitting the data (D). According to the invention: the vehicle is authenticated as a client (A, B) using one or more authentication methods in a token server (S); the token server (S) checks the authentication and authorization (A / A) of the client (A, B); if the token server (S) determines that the client (A, B) is not disabled, the token server (S) sends a currently valid fleet token (FT1 to FT3) to the vehicle acting as the client (A, B), which is identical to all clients (A, B) for a predetermined time period; before the vehicle transmits the data (D) to the computing unit (R) using the fleet token (FT1 to FT3), the vehicle waits for a random duration (Z) within a configurable time period to prevent the vehicle and the transmitted data (D) from being linked by time measurement.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for anonymously transmitting vehicle data to a computing unit that forms a data link with the vehicle, wherein the vehicle is authenticated for data transmission. Background Technology

[0002] WO 2010 / 090664 A1 discloses a token-based centralized authentication method for accessing user information regarding the relationship between a user and a service provider. For the service provider, the authentication method includes the following steps: authenticating a user presenting a user token at a user terminal, wherein the user token is stored on the user terminal as a user identifier; deriving a resource identifier using at least two data input elements, wherein these at least two data input elements include the user's user ID and the service provider's service provider ID, wherein the user information is stored in a storage network and the resource identifier is associated with the user information; retrieving the user information from the storage network using the resource identifier; and providing the retrieved user information to the service provider.

[0003] DE 10 2020 007 078 B3 relates to a method for anonymously transmitting time- and location-referenced vehicle sensor data to a computing unit outside the vehicle. The method is designed to send the vehicle's global positioning data to the computing unit at fixed time intervals during vehicle operation, wherein the positioning data is first sent after the vehicle begins driving, after a randomly determined time period, or after the vehicle has started driving and traveled a randomly determined distance.

[0004] DE 10 2016 207 984 B3 describes a method for transmitting route data collected by a vehicle to a database located separately from the vehicle. Here, a route database record contains route data along with the location and time of collection. The collected route database records are stored in a memory of the vehicle. Once at least the first batch of route database records is present in the memory, a route data message is sent to the database. Here, a route data message contains route data and its associated collection location. After the route data is collected, and / or when the vehicle moves away from a predetermined radius centered on the collection location, a route data message is sent at a randomly selected time point within a first time period. This message can be sent directly to the database or through a minimum number of intermediate receivers that act as the data source and transmit the data to their respective receivers.

[0005] US2018 / 0356837 A1 discloses a network device that receives an operator's request to select parameters relating to at least one remote control command sent to at least one autonomous vehicle. Based on the selected parameters, the network device generates a control token for the autonomous vehicle and transmits the control token to at least one autonomous vehicle via a wireless network. Summary of the Invention

[0006] The purpose of this invention is to provide a method for anonymously transmitting vehicle data to a computing unit that forms a data link with the vehicle.

[0007] According to the present invention, this objective is achieved by a method having the features described in claim 1.

[0008] Advantageous designs of the present invention are the subject of the dependent claims.

[0009] This invention relates to a method for anonymously transmitting vehicle data to a computing unit linked to the vehicle, wherein the vehicle is authenticated for data transmission. Specifically, the vehicle, acting as a client, authenticates itself at a token server using one or more authentication methods. The token server checks the client's authentication and authorization / official permission / authority. If the token server determines that the client is not disabled, it sends a currently valid fleet token, identical to all clients for a specified time, to the client vehicle. Subsequently, before using the fleet token to transmit data to the computing unit, the vehicle waits for a random duration within a configurable time period, thereby preventing the connection between the vehicle and the transmitted data from being established through time measurement.

[0010] By using this method, vehicles can transmit data anonymously to the computing unit with which they form a data link, thereby ensuring that virtually only authorized vehicles can transmit data to the computing unit as clients.

[0011] Additionally, during a subsequent token rotation, specific vehicles acting as clients can be disabled if needed, and even with token rotation synchronization, the load on the token server (i.e., the time period during which tokens are updated within the client) will still be allocated. Attached Figure Description

[0012] Embodiments of the present invention will now be explained in more detail with reference to the accompanying drawings.

[0013] in:

[0014] Figure 1A sequence diagram schematically illustrates a method for anonymously transmitting vehicle data to a computing unit with which it forms a data link.

[0015] Figure 2 A sequence diagram illustrating token usage is shown schematically.

[0016] Corresponding parts in all the accompanying figures are labeled with the same reference numerals. Detailed Implementation

[0017] Figure 1 A sequence diagram is shown of a method for anonymously transmitting data D from vehicles acting as clients A and B to a computing unit R that forms a data link with the corresponding vehicles. Figure 2 The diagram shows a sequence of token usage.

[0018] Clients A and B, especially vehicles, should be able to anonymously transmit data D to computing unit R, while computing unit R cannot determine the identity of the corresponding clients A and B. However, it must be able to ensure that only authorized (i.e., authorized) clients A and B can transmit data D, and that clients A and B can be disabled individually if necessary (e.g., due to a hacker attack).

[0019] The method recommended below can be used to anonymously transfer data D from clients A and B to computing unit R. In addition, this method can disable clients A and B one by one when needed.

[0020] The method is designed such that the corresponding vehicles of clients A and B submit a request F for a fleet token FT1 at a token server S, which employs client-based authentication. Subsequently, clients A and B authenticate themselves using one or more client-based authentication methods (e.g., shared keys, client certificates, or client tokens).

[0021] Next, the token server S checks the authentication and permissions A / A of clients A and B. If the check (e.g., through a blacklist or whitelist) finds that clients A and B submitting request F are not disabled for data transmission, then clients A and B will obtain a currently valid fleet token FT1. This fleet token FT1 obtained by the corresponding clients A and B is the same for all clients A and B (e.g., for all vehicles in the fleet) within a specified time period. That is, the fleet token FT1 obtained by the corresponding clients A and B is indistinguishable even in terms of expiration time and / or signature.

[0022] Next, before the vehicle transmits data D to the computing unit R using the fleet token FT1, clients A and B, which appear as vehicles, will wait for a random duration Z within a settable time period, thereby minimizing the possibility of establishing a connection between the vehicle and the transmitted data D through time measurement.

[0023] However, before the current valid fleet token FT1 expires, a new fleet token FT2 will be provided by token server S, and the corresponding clients A and B will obtain the new fleet token FT2 as described above. In other words, before the current valid fleet token FT1 expires, clients A and B will obtain a new fleet token FT2 through distributed synchronous token rotation. However, the currently valid fleet token FT1 will continue to be used until the new fleet token FT2 takes effect (i.e., the usage period begins).

[0024] All clients A and B (i.e., all vehicles) that are authorized to transmit data D to computing unit R will switch to using the new fleet token FT2 when it takes effect.

[0025] Figure 2 Taking two clients, A and B, as examples, the specific usage of fleet tokens FT1 to FT3 relative to time t is shown.

[0026] Here, the validity period of the corresponding fleet tokens FT1 to FT3, as specified by the token server S, is shown by the shaded portion.

[0027] For the corresponding clients A and B, the corresponding random duration Z (represented as the waiting time) is shown, and then the corresponding fleet tokens FT1 to FT3 are used to anonymously transmit data D between the two clients A and B (these two clients are vehicles belonging to the same fleet).

Claims

1. A method for anonymously transmitting vehicle data (D) to a computing unit (R) that forms a data link with the vehicle, wherein, In order to transmit data (D), the vehicle is authenticated, wherein - Vehicles acting as clients (A, B) authenticate themselves at the token server (S) using one or more authentication methods. - The token server (S) checks the authentication and authorization (A / A) of the client (A,B). If the token server (S) determines that the client (A, B) is not disabled, it will use the token server (S) to send a currently valid fleet token (FT1 to FT3) that is the same for all clients (A, B) within a specified time to the vehicle that is the client (A, B). Before a vehicle uses the fleet tokens (FT1 to FT3) to transmit the data (D) to the computing unit (R), the vehicle waits for a random duration (Z) within a set time period to prevent the vehicle from establishing a connection with the transmitted data (D) through time measurement.

2. The method according to claim 1, Its features are, Before the specified duration expires and after a new fleet token (FT2, FT3) is provided through the token server (S), the vehicle will acquire the new fleet token (FT2, FT3) at a random time, and the fleet token (FT1) will be used until its expiration date.

3. The method according to claim 1 or 2, Its features are, When the new fleet tokens (FT2, FT3) are in use, all clients (A, B) will simultaneously switch to using the new fleet tokens (FT2, FT3).

Citation Information

Patent Citations

  • Method for the anonymized transmission of time- and location-referenced sensor data from a vehicle to an external computer unit

    DE102020007078B3

  • Remote token-based control of autonomous vehicles

    US20180356837A1

  • Centralized authentication system with safe private data storage and method

    WO2010090664A1

  • Method and device for the transmission of route data recorded by a moving vehicle to a central database with improved protection of privacy

    DE102016207984B3

  • Method, device and computer-readable storage medium with instructions for processing data acquired by a motor vehicle

    DE102016225287A1