Procedures for protecting vehicle data against manipulation

A central database system with M2M communication and plausibility checks addresses the issue of manipulated vehicle data, ensuring transparent and tamper-proof records of critical vehicle properties, reducing fraud and environmental harm.

DE102016124047B4Active Publication Date: 2025-07-17DEUTSCHE TELEKOM AG
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
DE102016124047
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2016-12-12
Publication Date
2025-07-17
Estimated Expiration
2036-12-12

AI Technical Summary

Technical Problem

Existing methods fail to effectively prevent manipulations of critical vehicle data, such as fuel consumption, mileage, and exhaust gas quality, leading to economic loss and environmental harm, as these data are often altered locally and difficult to verify across a fleet of vehicles.

Method used

A method involving a vehicle module that transmits critical vehicle data to a central database via M2M communication, ensuring data integrity by allowing only authorized devices to write to the database, and using plausibility checks to verify the data, thereby preventing manipulations.

Benefits of technology

Ensures transparent and tamper-proof vehicle data, enabling reliable verification of vehicle properties across a fleet, reducing fraud and environmental impact by maintaining accurate records of mileage, fuel consumption, and exhaust gas behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for protecting vehicle data against manipulation, at least concerning the protection against manipulation of vehicle data of the categories describing the properties of a vehicle (1) - Energy consumption of the drive system, - total distance travelled by the vehicle, characterized in that data (3) recorded on the vehicle (1), which either directly describe the said vehicle properties or from which data for describing these vehicle properties can be derived, are transmitted by a permanently installed vehicle module in an automated M2M process, i.e. machine-to-machine, via a mobile radio network (4) in a time-cyclically manner to a central database (2), wherein write access to the vehicle data held in the central database (2) is only possible for devices for M2M communication.
Need to check novelty before this filing date? Find Prior Art

Description

The invention relates to a method for protecting against manipulations of vehicle data which relate to essential properties of vehicles. It relates to motor-driven vehicles, namely-but not limited thereto-in particular to automobiles. From the present point of view, the invention relates in particular to an application in motor vehicles, i.e. in vehicles whose traction drive is an internal combustion engine. In perspective, however, use of the invention, which is not restricted in this respect, is also possible in vehicles with an electric drive. With regard to the current focus for the use of the invention, the following explanations relate mostly to motor vehicles having an internal combustion engine, but, if reference is not made to data relevant only for this type of vehicle, this is not intended to limit the invention.The data to be protected against manipulations are in particular data on the energy consumption of the traction drive and data on the total distance covered by a vehicle, that is to say since its first start-up (mileage). In motor vehicles with an internal combustion engine, the data relating to the energy consumption of the traction drive naturally relate to data relating to the fuel consumption of a respective vehicle. With respect to such vehicles, statements or data on the quality of the exhaust gas cleaning and on the status of the exhaust gas cleaning system are furthermore of particular interest.Only as a precautionary measure in this context is it pointed out that it will in principle be impossible to completely prevent manipulations. Accordingly, the invention is intended to offer a solution for at least largely preventing manipulations on the data mentioned, that is to say in any case making them significantly more difficult.Manipulations of data relating to performance characteristics of vehicles or vehicle operating data have hitherto unfortunately belong to common practice. They cause considerable economic damage in the recent consequence and may lead to adverse effects on the environment and nature and on health. A currently very popular example is the manipulation of systems for the purification of the exhaust gases of motor vehicles, with the aim of beauty exhaust gas values and, at least, seem to meet official regulations at comparatively low cost. The issue under the heading "Off-gas Scale" has recently dominated the press and media for weeks. At least one vehicle manufacturer had to permit the exhaust gas values of diesel motor vehicles to be manipulated in that they corresponded to the strict legal standards under test conditions or on stationary test stands, whereas these standards were clearly missed during practical operation of the vehicles in all-day situations.As has been shown, for this purpose, the vehicle manufacturer has used software in the exhaust gas purification system of his motor vehicles-in particular diesel vehicles-by means of which it is detected whether a vehicle is in a test cycle or on a test stand or is moved under normal practical conditions. This software then further provided that the exhaust gas purification during practical operation of the vehicle was partially or completely shut off with the aim of providing the engine power otherwise indicated by the manufacturer. Finally, other vehicle manufacturers had to be able to agree in the so-called of this skandal that they deactivate the exhaust gas purification during the practical operation of their vehicles, for example when certain ambient temperatures are undershot. These vehicles, too, therefore fundamentally meet the legal exhaust gas standards only on paper, but not in reality.Another issue discussed for years has been fuel consumption in motor vehicles. In this case, a large number of drivers regularly charge that the fuel consumptions indicated in the data sheets relating to motor vehicles are not approximately complied with in reality. In the practical use of the motor vehicles, up to 40% deviation from the manufacturer's specifications has been or are recorded. The manufacturers argue on a corresponding request that they are single cases in this respect, which may be attributable to an inadequate driving style or to requirements for tire pressures not being complied with by the motorists. However, since findings concerning the difference between fuel consumptions indicated in data sheets and actually detected are confirmed by a large number of motorists, it is now considered an open secret that these values are also spoken by the vehicle manufacturers by raising the values indicated in their data sheets under quite specific test conditions which are not oriented to reality. In the last consequence, apart from the environmental drawbacks, fraud at the customer is present. Depending on how great the differences between theory (values recorded under test conditions) and practice lie or how extensive the individual manufacturers make use of such procedures, however, such pronounced values can also lead to considerable distortions of the competition.A further focus is manipulations of mileage at tachometers of used vehicles. As has become known, the mileages of the vendors of the vehicles, optionally with the assistance of workshops, are frequently reduced in contradiction in order to achieve a higher sales value. Corresponding manipulations can be carried out simply and at low cost, partly within a few seconds. Elevations have shown that such manipulations in Germany on average lead to an illegal increase in value of approximately 3,000,00 Euro per sold vehicle. This means that the buyers of such manipulated vehicles are damaged approximately 6 billion euros annually. This in turn takes place at the expense of the buyers of used cars, but ultimately also of redial used car dealers.In NAGY, R. [et al.]: EcoH-Android, Bachelor Work, Spring 2011, an app for a mobile terminal is presented, which is intended to assist a motorist using it in improving his driving style with a view to reducing the fuel consumption. In this case, data describing the driving style (gear selection, position of the accelerator pedal and fuel consumption) are read repeatedly by means of the mobile terminal equipped with the app via a vehicle interface designed for this purpose, are subjected to an evaluation and recommendations for a fuel-saving driving style are derived from this and visualized clearly for the user on the mobile terminal. The evaluation of said data can be effected at least partially by means of a central server to which the data are transmitted by the mobile terminal. The user has the possibility here of addressing the server mentioned using a password-protected account also with the aid of other computer-assisted devices and downloading data or evaluation results based on them to other devices. The user can have corresponding data acquired and evaluated for different vehicles driven by him, but his participation is necessary in order to assign these data to the respectively correct vehicle. A secure detection of the absolute mileage for a specific vehicle, which is also protected against manipulations, is not possible, however, by means of this solution, which is always linked to the participation of the user.It is an object of the invention to provide a solution by means of which the aforementioned drawbacks are eliminated by preventing manipulations of important vehicle data, but at least largely preventing them. A corresponding method is to be specified for this purpose.The object is achieved by a method having the features of claim 1. Advantageous embodiments and further developments of the invention are given by the dependent claims.The method proposed for the protection of vehicle data against manipulations relates to the protection against manipulation of vehicle data which describe essential properties of a vehicle or of data from which the aforementioned vehicle data can be derived. Essential design-related properties or properties describing the state of the vehicle after a certain period of use are considered here to be, in particular, the energy consumption of the traction drive and the total distance traveled by the vehicle since the time of its first startup (mileage). Accordingly, the proposed method is designed to protect vehicle data from manipulations which describe either properties of one or both of the aforementioned categories.In this case, the method can be derived from the consideration that the cause of the manipulations which occur with comparatively high frequency according to the prior art can be seen in the lack of transparency of the data retention or data storage, wherein this lack of transparency is in particular caused by the corresponding data being held exclusively locally in a respective vehicle. If data relating to properties which are attributed to all vehicles of a specific vehicle type due to the design are adulterated or manipulated in this case, such as, for example, the typical fuel consumption of a specific vehicle type, this is accompanied by the fact that, owing to the local data management in the individual vehicles of a relevant vehicle type, it is only very difficult to verify statements relating to such vehicle properties in a type-dependent manner, that is to say to check statements relating to a multiplicity of vehicles of this vehicle type or even the entire fleet.According to the method according to the invention, it is therefore provided that data recorded on a vehicle, which data either directly describe the vehicle properties mentioned or from which data for describing these vehicle properties can be derived (data indirectly describing vehicle properties), is transmitted to a central database in an automated sequence in a time-cycle manner by a vehicle module fixedly installed in the respective vehicle. According to the invention, the time-cyclical, i.e. repeated, transmission of relevant data with respect to the mentioned vehicle properties to the central database takes place by means of a vehicle module fixedly installed in the respective vehicle by way of an M2M transmission, i.e. a machine to machine transmission, via a mobile radio network. Of course, in the case of a practical implementation of the method, a multiplicity of vehicles--on account of corresponding legal obligation of the vehicle manufacturers, preferably all vehicles--are equipped with the vehicle module mentioned for M2M communication and data for a correspondingly large number of vehicles are held in or in a central database. Depending on legal regulations or organization regulations, a central database is built for all vehicles or a central database is built for each manufacturer. However, this is less a question of technical requirements than a question of organization considerations and should therefore not be further emphasized at this point. The respective vehicle data are stored for each vehicle under a unique ID in the central database. This ID can be, for example, the vehicle license plate (car number) or a unique license plate permanently assigned to the respective vehicle module.Due to the data transmission taking place with M2M, a human intervention in the actual transmission process itself taking place with a manipulative objective, i.e. a manipulation of data during its transmission to the central database, is largely ruled out. In a preferred embodiment of the method, it is therefore provided that only the devices for the M2M communication are allowed a writing access to the vehicle data held in the central database.If need be, it could be provided that employees of government-authorized organs, such as the Federal Of Motor Vehicles, also have writing access to the vehicle data held in the or in a central database by means of computer devices more suitable for this purpose. Basically, however, there is no need for this, so that it is sufficient and therefore preferable for these employees to have only read access to the vehicle data held in the database. Independent of this is the question of any writing access specifically to authorized persons (for example, the stated authorities) for recording additional data (for example, to the respective current vehicle owner) or of notes / comments or for other organization purposes. In addition, the method is preferably designed such that, in addition to the vehicle modules communicating in an automated manner M2M, only such persons have read access to the database and the data stored therein for vehicles, and other persons who wish information about the data in question must be able to turn to the corresponding authorities.The transmission of data describing vehicle properties directly or indirectly from a plurality of vehicles to the central database, in combination with the writing access to the database, which preferably only allows the devices for M2M communication, ensures that according to the prior art there is a lack of transparency. This also makes it possible, in particular, to make statements about vehicle properties which are bound to a respective vehicle type on the basis of a comprehensive database with data held in a tamper-proof manner.For describing vehicle properties of one of the two categories mentioned at the beginning, the use of different data, these properties directly or indirectly, is considered. As an example, the mileage of a vehicle, i.e. the total route traveled by it since its initial startup, may be mentioned at this point. Statements on this essential vehicle property can of course be obtained directly here, in particular on the basis of the mileage indicated on the tachometer of the vehicle. Therefore, in particular tachometer data are transmitted to the central database in a time-cyclical manner.Another possibility for obtaining a statement about this essential vehicle property or about the feature of the total route traveled that significantly describes the vehicle state is given in that the vehicle module already addressed comprises a GPS receiver or interacts with such a receiver and transmits GPS data relating to the respective location of the vehicle to the central database in a time-cycle manner. In this case, no further explanation is certainly required that the mileage of the vehicle can optionally also be determined from these GPS data, which thus indirectly describe this vehicle property. The same applies correspondingly with respectively different accuracy with regard to a use of differently obtained localization data for the determination of a distance travelled by the vehicle or the total distance travelled by it since its initial start-up. Cell location data relating to the vehicle module equipped with a transceiver unit for M2M communication via a mobile radio network can also be used in principle for this purpose, although these would have to be transmitted cyclically to the central database by the network operator of the mobile radio network used for the method. With regard to this variant, the use of an ID of the vehicle module would be preferred as an ID for storing data relating to a respective vehicle in the central database.The last-mentioned possibility of determining the mileage of the vehicle with the aid of cyclically transmitted GPS data or comparable localization data is preferably carried out on the part of the central database. This presupposes that the central database, as is provided according to a possible embodiment of the method according to the invention, is coupled to a processing device, by means of which a corresponding program application for deriving data relating to vehicle properties from other data previously received in the central database is processed. With regard to the aforementioned example, the route traveled by the vehicle up to the input of this data at the central database would thus be determined on the basis of an interaction between units by which the central database is held with units of a processing device processing a corresponding program application from the GPS data or other localization data cyclically transmitted by a vehicle or by its vehicle module.A corruption (in this case at the expense of the vehicle owner who may later occur as a seller) based on localization data of statements on the mileage or on the total route traveled by, for example, an intermediate transport of the vehicle by means of a tow vehicle can be avoided in this context by a transmission of the localization data to the central database only if the vehicle is activated for the driving operation, i.e., the ignition is switched on, for example, in a motor vehicle with an internal combustion engine. This then also makes it possible, by means of the data held in the central database, to make statements not only about the total distance travelled by the vehicle, but also about the distance travelled during one (or more of the) last travel table(s).As far as the coupling of the central database to a central processing device is concerned, this can optionally be provided in that the database is directly part of such a processing device or together with it is realized on one and the same server or in that the database and processing device are realized on different servers which are possibly also remote from one another but are required for the exchange of data which are coupled to one another via a communication connection.Regardless of the type of the aforementioned coupling of database and processing device, however, the inclusion of a processing device interacting with the central database opens up a possibility used in a particularly preferred embodiment of the method. This possibility consists in carrying out a check of the plausibility of the data transmitted to the central database by means of the central processing device. Thus, for example, in this method configuration, provision is made for both cyclic transmission of tachometer data to the central database and also for checking the plausibility of the respectively transmitted tachometer data (GPS data or data for radio cell location of the vehicle module) and on the basis of the localization data by means of corresponding comparisons.The above explanations show that, in a practical implementation of the method according to the invention, vehicle data should be transmitted at comparatively short time intervals. In this case, a transmission at a distance of one to a maximum of five minutes is to be considered, but preferably even at distances of less than one minute. In connection with this, it could generally be provided that data transmission with the aforementioned time intervals always takes place only when the vehicle is activated for the driving operation, i.e., for example, the ignition is switched on in a motor vehicle with an internal combustion engine.According to a possible development of the method according to the invention, it is provided that the data representing the mileage are transmitted from the central database repeatedly (back) to the vehicle module and are forwarded by the vehicle module to a vehicle speedometer, the mileage of which is overwritten. If such a transmission of data to the vehicle likewise takes place cyclically during its operation, however, it is preferable in this case, with regard to the duration of the alternating data transmission and to the fact that a transmission of current data takes place in each case at certain time intervals, to compensate for a delta resulting therefrom, that is to say a certain deviation from the actual values, by means of suitable interpolation methods. A corresponding interpolation can be carried out before the (return) transmission of the data to the vehicle by the processing device of the central database or after the receipt of the data at the vehicle module, but before the forwarding thereof to the tachometer for overwriting the mileage specified there. In the latter case, the interpolation is carried out by a processing unit of the vehicle, which is designed as part of the vehicle module or is operatively connected to the latter in a corresponding manner.However, a possibly more practical embodiment in this respect is that the mileage is written back to the vehicle speedometer only at the moment when the vehicle is put into operation, i.e. in relation to motor vehicles with an internal combustion engine again at the moment when the ignition is switched on. If the mileage or the vehicle speedometer has been manipulated in the meantime, then at the latest when the vehicle is put into operation (the ignition is switched on), this manipulation is effectively reversed by overwriting the mileage held by the vehicle odometer with the mileage received at this moment from the central database and thus ultimately prevented. In the implementation of a method configured in this way, this would be realized in that the vehicle module of a relevant vehicle, at the moment of the start-up of the vehicle, again queries the mileage held in the central database by way of an M2M communication using the ID already addressed previously.With regard to the transmission of data for obtaining statements about the energy consumption of the vehicle drive, different possibilities are also provided in this regard. For example, the energy consumption-in the case of a motor vehicle with an internal combustion engine, the fuel consumption-could be detected by means of a suitable sensor system of the vehicle and transmitted immediately in a time-cyclical manner to the central database. Another possibility would be to derive the energy consumption on the part of the central database and the processing device interacting with it from GPS data (or other localization data) of the vehicle and the route determinable therefrom and from data transmitted in a time-cycle manner relating to the current state of the energy source of the vehicle in each case, that is to say for example the current fill level of the fuel tank of a motor vehicle or the charge state of the accumulator of an electric vehicle.With regard to the possibility, already mentioned, of a plausibility check of data by a central processing device operatively connected to the central database, the method is also preferably designed, with regard to the protection against manipulation of data relating to energy consumption, such that both directly consumption data recorded by sensors are transmitted to the central database with the processing device, and those which relate indirectly to the energy consumption or make it possible indirectly to determine it.For example, in a motor vehicle with an internal combustion engine, data relating to fuel consumption recorded by means of a flowmeter and transmitted to the central database can be checked for plausibility by means of localization data likewise transmitted cyclically to the database and data relating to the fill level of the fuel tank. The same applies to electric vehicles with regard to a plausibility check of measurement data for electrical consumption with the aid of localization data transmitted to the central devices and data on the state of charge of the accumulator. In this case, it should be recalled that the question of the route (range) which can be traveled with an electric vehicle until the battery charge is exhausted is a matter of great focus. In the course of a general changeover to electric vehicles, the method according to the invention could prevent a situation in which similar practice to that of the details of fuel consumption which have been spoken of for years also makes use of with regard to details of the range of electric vehicles.As already stated, data describing vehicle properties are already transmitted to the central database by way of an M2M communication in conjunction with the writing access to the database, which access to the database is preferably made possible only by the devices used, which access achieves, according to the prior art, a lack of transparency with regard to the reliability and credibility of the data. In a further embodiment of the method, this transparency is further increased significantly by the measures addressed for a plausibility check. It is also very advantageous that, in the case of a practical implementation of the method and its application to a large number of vehicles, reliable and largely tamper-proof statements about manufacturer- and type-related vehicle properties can be obtained.In a development of the method according to the invention relating to the use in motor vehicles with an internal combustion engine, it is additionally provided to protect data which describe the exhaust gas behavior of the motor vehicle from manipulations. In this case, the vehicle module transmits time-cyclical status and / or operating data of an exhaust gas purification system, such as operating data of the lambda probe of a catalytic converter, for example, to the central database. In this way, it would be possible, for example, to determine whether a vehicle manufacturer temporarily shuts down the exhaust gas purification system or reduces its mode of operation in favor of other vehicle parameters during operation of the vehicle under real conditions.An exemplary embodiment of the invention is to be explained below with reference to FIG. 1. FIG. 1 shows, in a schematic illustration, essential components involved in carrying out the method and relates in this case to a motor vehicle 1 (motor vehicle) or a passenger car with an internal combustion engine.An M2M communication module, not shown here, is permanently installed in the vehicle 1, which communication module reports the critical motor vehicle data, i.e. data 3 describing essential properties of the vehicle 1, such as mileage-as the total route traveled since the first startup-the fuel consumption determined by sensor, for example, and the status of the exhaust gas cleaning, and also parameters (for example temperature, speed) controlling the exhaust gas cleaning, cyclically to a central database 2 via a mobile radio network 4.Furthermore, the rough position of the vehicle 1 is determined by the method (by the network operator) by way of a cell assignment of the M2M communication effected via the mobile radio network 4 and stored in the central database 2 with the critical motor vehicle data reported by the vehicle 1. In the central database 2, the motor vehicle data are validated by plausibility checking algorithms. For example, for this purpose, the mileage or delta mileages reported by the vehicle 1 (mileage change since the last start-up of the vehicle) are matched to the rough position data (localization data) of the cell location.The mileage display on the passenger car tacho is then in future preferably no longer based on the direct measurement in the vehicle 1, but rather is called up by the central database 2 and temporarily up-calculated with the current vehicle data (movement between two calls to the central database 2). This means that the data 3 relating to the driving performance of a motor vehicle are no longer located in the vehicle 1 and thus no longer access for manipulations by the motor vehicle holder.In the central database 2 there are then also all real data relevant to the manufacturer within the scope of type approval. In this case, it is made transparent via corresponding evaluation programs, which is declared for the respective vehicle line or vehicle fleet of a vehicle type within the scope of the type permission of consumption and exhaust gas values and how data describing these important vehicle properties actually look in the real active operation.The central database 2 for the respective vehicle types could be placed at the vehicle manufacturers, who are to be given the edition by the legislator in the future, for example, as a edition for type approval of their vehicles 1. The manufacturer would then have to give the regulatory authorities, such as the passenger of the motor vehicle, accesses to the central vehicle data to be kept available from real operation. The authorities could thus compare the theoretical data with the real motor vehicle data and, in the case of large differences, officially withdraw the approval of the type to the manufacturer within the scope of an escalating method still to be developed. The manufacturer would thus be responsible not only for the tests within the scope of type approval, but also for compliance with data determined in this case in the control mode in order to describe vehicle properties. The ordering authorities, such as the passenger of the motor vehicle, would only monitor this sufficiently and intervene if necessary.In contrast to the implementation of the method described above by way of example with a database 2 managed in each case by the vehicle manufacturers, it would also be possible to set up a central database 2 independent of the manufacturer and under the management of a governmental agency. In this case, the vehicle manufacturers could, within the framework of the procedure for the type approval of vehicles 1 developed and manufactured by them, participate in the costs for the setting up and management of such a database 2 or emerge proportionally together with other vehicle manufacturers overall for the costs.The manufacturer is thus responsible for the technical features of a product which is the basis of a customer's purchase decision. The buyer of a vehicle 1 must be able to assume that the motor vehicle properties specified during sale match those of real operation. Otherwise, fraud of the vehicle manufacturer would have to be assumed. In order that vehicle manufacturers cannot manipulate the individual data from millions of motor vehicle customers, there should also be the option for the ordering authorities of random sampling of the M2M communication between individual vehicles 1 and the central database 2 and for validation of the data 3 in the central database 2.

Claims

Method for protecting vehicle data against manipulations, at least with regard to the protection against manipulation of categories describing vehicle data of the properties of a vehicle (1) - energy consumption of the travel drive, - travel distance covered overall by the vehicle, characterized in that data (3) recorded on the vehicle (1), which data either directly describe the vehicle properties mentioned or from which data for describing these vehicle properties can be derived, are transmitted by a permanently installed vehicle module in an automated sequence M2M, that is to say machine-to-machine, via a mobile radio network (4) in a time-cyclical manner to a central database (2), wherein writing access to the vehicle data held in the central database (2) is made possible only by devices for the M2M communication.Method according to Claim 1, characterized in that at least some of the data (3) transmitted by the vehicle module to the central database (2) are processed by a central processing device, which is coupled to the central database (2), with a program application which is executed by the central processing device for deriving data which describe vehicle properties.Method according to Claim 2, characterized in that position data of the vehicle (1) which is associated with the vehicle module or is operatively connected to it is transmitted cyclically by the vehicle module to the central database (2).Method according to Claim 2 or 3, characterized in that data (3) relating to the route travelled overall by the vehicle since its initial start-up, which is tachometer data of the vehicle (1) transmitted beforehand to the central database (2) or which are derived by the central processing device coupled to the central database (2) from GPS data transmitted beforehand to the central database (2) or other localization data associated with the vehicle (1), are transmitted from the central database to the vehicle module and are forwarded by the vehicle module to a vehicle speedometer, the mileage of which is overwriting.Method according to Claim 4, characterized in that data (3) relating to the route are transmitted cyclically from the central database to the vehicle module, the data (3) being corrected by interpolation before overwriting the tachometer, namely before transmission to the vehicle module by the processing device of the central database (2), or after transmission to the vehicle module, namely before forwarding to the tachometer by a processing unit of the vehicle (1), in order to take account of a possible route traveled in the meantime by the vehicle (1).Method according to Claim 4, characterized in that the mileage held by the vehicle speedometer is overwritten, at least on each restart of the vehicle (1), wherein the vehicle module queries the mileage held there for the vehicle, that is to say the total route travelled by the vehicle since its initial startup, from the central database (2).Method according to Claim 2 or 3, for protecting against manipulation of vehicle data of a motor vehicle equipped with an internal combustion engine, characterized in that data (3) relating to the fuel consumption detected by the sensor and / or localization data relating to both data (3) relating to the fill level of the fuel tank and the vehicle (1) are transmitted cyclically by the vehicle module to the central database (2).Method according to one of Claims 2 to 7, characterized in that the data (3) transmitted to the central database for a vehicle (1) are checked for plausibility by means of the central processing device and the program application processed by said central processing device.Method according to Claim 1 or 2, for protection against manipulation of vehicle data of a motor vehicle equipped with an internal combustion engine, wherein data describing the exhaust gas behavior of the motor vehicle are additionally protected against manipulations which describe exhaust gas values of the motor vehicle as a vehicle property, characterized in that status and operating data (3) of an exhaust gas purification system of the vehicle (1) are transmitted cyclically to the central database (2) by the vehicle module.

Citation Information

Patent Citations

  • Method for performing remote diagnosis of car in workshop, involves analyzing repair-related data to determine maintenance and / or repair procedures, classifying procedures into two classes, and displaying procedures to user

    DE102012011538A1