Trust-based car-to-car communication

The method addresses the challenge of ensuring data trustworthiness in car-to-car communication by transmitting and weighting vehicle-specific trust indices with traffic data messages, enhancing the reliability of automated vehicle decisions and improving traffic safety.

DE102017113005B4Active Publication Date: 2025-05-22DEUTSCHE TELEKOM AG
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
DE102017113005
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2017-06-13
Publication Date
2025-05-22
Estimated Expiration
2037-06-13

AI Technical Summary

Technical Problem

Existing car-to-car communication systems face challenges in ensuring the trustworthiness of data transmitted between vehicles, which can lead to incorrect automated decisions due to intentionally or unintentionally distorted data.

Method used

A method that involves transmitting a vehicle-specific trust index with each message containing traffic data, which is then weighted by receiving vehicles to evaluate the trustworthiness of the data. This method uses a global trust index and a temporary trust index, updated based on historical data and current traffic context, to assess the reliability of messages.

Benefits of technology

The proposed method enhances the trustworthiness of automated decisions made by vehicles, reducing the risk of incorrect conclusions and interventions by weighting messages based on the trust indices, thereby improving traffic safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for increasing the trustworthiness of automated decisions by generating messages with traffic data based on sensor signals in an automated process by processing devices (2; 4; 5) of motor vehicles and transmitting them with the aid of a transmitting and receiving unit (1) and by a processing device (2; 4;5) a motor vehicle receiving messages from other motor vehicles with traffic data by means of its transmitting and receiving unit (1) by way of car-to-car communication, decisions are made to influence the driving behavior of the receiving motor vehicle, namely decisions about the output of messages for the driver and / or control signals for actuators that directly act on the driving functions of the motor vehicle by means of a vehicle management system (8), wherein the messages received by a motor vehicle are each weighted by the processing device (2; 4; 5) of the motor vehicle when a decision is made to influence the driving behavior of this motor vehicle by means of at least one vehicle-specific trust index transmitted together with the messages, which trust index is variable starting from an initial value in accordance with a set of rules, characterized in that ; - with each message containing traffic data sent by a motor vehicle, at least one vehicle-specific trust index is sent, i.e. one relating to the motor vehicle sending the message, which trust index represents the trust to be attributed to messages from this motor vehicle and is stored in a database (6; 7) in association with a unique identifier for the vehicle sending the message; - for a motor vehicle equipped to participate in the procedure, a global trust index and a temporary trust index are managed in association with its unique identifier and such a motor vehicle repeatedly transmits position data on its current position in association with its identifier; - the global confidence index is variable by processing historical data, namely as confirmation of messages containing traffic data sent by the motor vehicle in the past or driving data of other motor vehicles receiving the messages which are considered to contradict those messages, the initial value for the global confidence index of a motor vehicle being an index value determined for its first entry into service; - the temporary trust index, as a trust index relating to the current traffic context of the motor vehicle in question, is variable by processing driving data of other motor vehicles moving with it in the same traffic context according to their position data, whereby the initial value for the temporary trust index of a motor vehicle is its global trust index applicable when entering a new traffic context.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a solution for trust-based car-to-car communication. It particularly relates to increasing confidence in the accuracy of automated decisions made based on traffic data transmitted via car-to-car communication. The subject of the invention is a method that ensures this.

[0002] In order to drive a motor vehicle safely, reliably, and efficiently through traffic in terms of the time required and / or energy consumption, a driver often requires information that goes beyond that provided by their own vehicle. In the simplest case, they are supported by static information, such as that provided by unchanging traffic signs, signposts, and the like.

[0003] Electronic display systems have also been known for several decades. These are located along traffic routes and can provide drivers with changing information, preferably in direct response to current traffic conditions, such as the occurrence of a traffic jam. To generate the information displayed, data is generally collected by regional or supra-regional traffic control centers, where it is processed—of course, also with the aid of computer technology—for the electronic output devices intended for its output.

[0004] More recent developments, however, are aimed at obtaining traffic information from data that directly results from traffic events, both spatially and temporally, and is recorded by the vehicles involved or by the systems they carry. A rapidly developing approach pursuing this goal is car-to-car communication, also known as car-2-car communication or vehicle-to-vehicle (V2V). In this approach, the vehicles involved in the traffic automatically exchange data on the current traffic situation and / or emerging dangerous situations via radio. This data is recorded by the vehicles themselves using appropriate sensors in the vicinity of a particular vehicle and from within the vehicle, reflecting the driver's driving behavior.The data exchanged in this way by means of automatically generated messages can ultimately be used to automatically derive decisions on the basis of which, depending on the traffic situation, messages, possibly also warning messages, are issued to the driver or the driver of a motor vehicle receiving messages with traffic data by means of car-to-car communication or even control signals for actuators that autonomously influence the driving functions of a vehicle are provided.

[0005] However, data exchanged between vehicles can, in individual cases, be inaccurate for various reasons. This can be caused, for example, by technical errors, particularly malfunctions of individual sensors. Furthermore, it cannot be ruled out that data transmitted by one vehicle to other vehicles, which in turn are multiplied by these to other vehicles, may be unintentionally or even intentionally influenced by a driver and their driving behavior in a way that results in an inaccurate picture of the current traffic situation.

[0006] A detailed introduction to the field of car-to-car communication is provided, for example, in a manifesto developed by the Car-2-Car Communication Consortium in 2007, which is available online at "https: / / www.car-2-car.org / index.php?id=31." In this context, the document repeatedly points out that for car-to-car communication to function and achieve its intended goals, it is essential that the systems of a vehicle receiving data or information from other vehicles can be trusted for their accuracy. However, the document itself does not contain any statements on how to ensure that trust in the accuracy of the data and / or information itself can be supported or ensured.To the extent that the problem of the reliability or trustworthiness of the data and / or information transmitted between vehicles is addressed at all in publications, relevant documents deal at most with the question of encrypting the data for the purpose of transmitting it via radio and securing the transmission path against possible hacker attacks.

[0007] DE 10 2004 017 603 A1 describes a solution for improving the trustworthiness of data transmitted in a car-to-car network at the communications level. According to the document, this is achieved by allowing a vehicle, or a transmitting and receiving unit of a vehicle, to join an ad hoc network formed for the purpose of car-to-car communication only if trust information is available that favors the vehicle in question. The corresponding trust information therefore serves as a kind of authentication feature for the existing ad hoc network.The aim of this measure is to exclude participants or vehicles that do not have the appropriate trust information and could therefore potentially be disseminators of harmful data, such as viruses, from car-to-car communication in accordance with the procedure described in the document.

[0008] The solution described in WO 2016 / 130 148 A1 pursues a different approach. According to this solution, access to a network for car-to-car communication is not regulated, but rather the trustworthiness of data and / or messages received by a vehicle via such a network is assessed by the recipient. Regardless of the participant sending a message containing, for example, traffic data, the higher the number of participants or intermediate stations through which the message was forwarded to the recipient, the lower the trustworthiness of this message by the recipient.

[0009] EP 3 121 762 A1 discloses the car-to-car exchange of traffic data messages based on signals from various types of sensors between vehicles for the purpose of outputting messages to the driver of a vehicle or control signals for an advanced driver assistance system. When evaluating this traffic data by a receiving vehicle, unspecified trust and accuracy parameters are taken into account, particularly with regard to its origin.

[0010] DE 10 2007 028 093 A1 describes a method for controlling data communication between user devices in a communication network, for example, between vehicles. Within the method, each user device is assigned at least one attribute property and a global revocation list containing identification data of untrusted user devices is provided.

[0011] The object of the invention is to provide a solution using car-to-car communication, by means of which it can be avoided that falsified data and / or information is sent intentionally or unintentionally by individual drivers, but is classified as trustworthy by the recipient and subsequently incorrect conclusions are drawn from them, in particular incorrect decisions are derived in automated processes.

[0012] The method proposed to solve this problem accordingly relates to increasing the trustworthiness of automated decisions in which a processing device of a motor vehicle decides on the output of messages to the driver and / or control signals for actuators affecting driving functions of the motor vehicle based on traffic data messages received by a transmitting and receiving unit via car-to-car communication. The output of corresponding messages, such as warning messages and the like, or of control signals occurs in cooperation with a vehicle management system, whereby the aforementioned processing device can be a direct component of the vehicle management system or can be in direct operative connection with it.

[0013] The method therefore serves to increase the trustworthiness of decisions which are made in an automated process in which messages with traffic data are generated by processing devices of motor vehicles based on sensor signals and are sent out with the aid of a transmitting and receiving unit of the motor vehicle and in which, on the basis of these messages, decisions are made by a processing device of a motor vehicle which receives the messages by means of its transmitting and receiving unit, which decisions enable a reaction to occurring traffic situations, namely in particular to dangerous situations.

[0014] As already explained, a reaction to a perceived dangerous situation emerging from the received messages can be achieved by issuing a warning message to the driver of a motor vehicle receiving the corresponding message, informing them of the dangerous situation, or by a vehicle management system, prompted by the aforementioned processing device of the motor vehicle and the control signals issued by it, automatically intervening directly in the driving process using suitable actuators. In the latter case, for example, the speed of the motor vehicle is reduced by automatically activating its braking system or by automatically throttling its drive (in motor vehicles with an internal combustion engine, for example, throttling the fuel supply to the internal combustion engine).Of course, the process of such automatic intervention in the vehicle control system can also be accompanied by the issuance of a warning message to the driver.

[0015] It is obvious that, particularly in the case of automated intervention in the driving process, it must be ensured that the resulting automated decision is highly trustworthy. This means that the driver must be able to rely on their vehicle or its systems responding correctly and appropriately to emerging traffic situations. If such trustworthiness does not exist, the driver would certainly often find themselves forced to ignore any warning messages or to counteract any automated intervention in the driving process with appropriate countermeasures. This would be counterproductive for road safety.

[0016] To increase the trustworthiness of automated decisions of the type described above, according to the proposed method, at least one vehicle-specific trust index, i.e., one relating to the respective vehicle sending such a message, is transmitted with each message containing traffic data. This trust index is stored in a database (more details on the arrangement and design options for such a database will be discussed later) in association with a unique identifier for the vehicle sending the message.

[0017] This at least one trust index represents the trust to be attributed to the messages transmitted by this motor vehicle. The messages received by a motor vehicle are weighted by the processing device of this motor vehicle with the at least one vehicle-specific trust index transmitted along with them as part of the decision made in an automated process to influence the driving behavior of the motor vehicle receiving the messages (influence by issuing messages to the driver or automated intervention in the driving process). The at least one vehicle-specific trust index of a motor vehicle is variable, starting from an initial value according to a set of rules; further details on this will also be provided later.

[0018] According to the procedure, a global trust index and a temporary trust index are managed for a motor vehicle equipped to participate in this procedure, associated with the aforementioned unique identifier (e.g., a unique vehicle ID). Furthermore, such a motor vehicle repeatedly transmits position data about its current position. The transmission of the position data can occur in conjunction with the transmission of messages containing traffic data by this motor vehicle. However, it can also occur completely independently, at regular intervals, or in addition to the transmission of messages containing traffic and position data. The global trust index is subject to change due to the processing of historical data.This historical data is either confirmation of messages containing traffic data sent by the motor vehicle in the past or contradictory driving data from other motor vehicles receiving the messages.

[0019] The initial value for the global trust index of a motor vehicle is an index value determined for the initial commissioning of the respective motor vehicle. According to a first variant, this index value will be identical for all motor vehicles and will be stored in the database or in a suitable database upon commissioning, associated with the identifier already mentioned several times. Alternatively, according to another variant, it could be provided that the global trust index of certain motor vehicles, for example, vehicles intended for police use, is assigned a higher initial index value than for other motor vehicles.

[0020] The temporary trust index of a motor vehicle used in connection with the method is a trust index that relates to the current traffic context in which the motor vehicle in question is currently located. This temporary trust index is also variable, namely through the processing of driving data from other motor vehicles moving in the same traffic context as the motor vehicle to which this temporary trust index is assigned, based on their position data. The initial value for the temporary trust index of a motor vehicle is the global trust index assigned to the motor vehicle upon entering a new traffic context.

[0021] The position data of the motor vehicles equipped to participate in the method are preferably determined using a satellite navigation system, such as GPS or Galileo. The position data of a motor vehicle transmitting a message containing traffic data is mapped by the processing device of a motor vehicle receiving such a message to electronic map data stored in associated storage means. The processing device then checks, based on a set of rules also stored in these storage means, whether the motor vehicle transmitting the traffic message is in the same traffic context as the motor vehicle receiving these messages.

[0022] In the latter case, the received message containing traffic data is irrelevant for decision-making and is therefore not taken into account when deciding whether to issue a message to the driver of the receiving vehicle or whether to intervene directly in the vehicle's control system. Such a message, which is irrelevant due to the lack of a common traffic context, will at best be forwarded by the receiving vehicle in a value-neutral manner.

[0023] On the other hand, if a motor vehicle sending a message containing traffic data is in the same or a shared traffic context as a motor vehicle receiving the message, the message(s) from the sending motor vehicle will be included in the receiving vehicle not only by weighting them with the at least one confidence index also transmitted to derive decisions regarding the output of messages or control signals. Rather, it also follows that the motor vehicle receiving the message(s) (in this context, this naturally always means the system implemented in this motor vehicle for implementing the method, including the processing equipment required for this purpose) can influence the temporary confidence index of the sending motor vehicle.

[0024] This influence is such that, for example, the temporary trust index of the transmitting motor vehicle increases the longer this motor vehicle is in a shared traffic context with a motor vehicle receiving messages from it. The method according to the invention is based on the fact that a trust relationship established between motor vehicles via the temporary trust index becomes more significant for inducing automated decisions with every kilometer the motor vehicles travel in a shared traffic context.Ultimately, this applies both in the positive case, in which the motor vehicles are moving in a common traffic context without any incidents relevant to the decision or in which messages from a sending motor vehicle are confirmed by other motor vehicles moving with them in the same traffic context, and in the negative case, in which messages from a sending motor vehicle are not confirmed by other motor vehicles that have been moving with it in a common traffic context for some time, or in which the information conveyed by the messages is contradicted.

[0025] As already explained, the confirmation of or rejection of received messages is done indirectly based on driving data of the receiving vehicles and, preferably, also those forwarding the messages. For example, if a message conveys information indicating that a traffic jam is ahead of a vehicle receiving the message, it can be considered confirmation of the message in question if the vehicle receiving the message brakes within a certain time after receipt of the message.On the other hand, the message would be rejected if the driver of the vehicle receiving the message, for example, overrides an automatic intervention in the driving process (automatic braking of the vehicle receiving the message about the supposed traffic jam) by actively pressing the accelerator pedal (gas pedal in vehicles with internal combustion engines), thereby interrupting the braking process. In the latter case, the temporary trust index of the transmitting vehicle could then be reduced.

[0026] Whether and when the temporary trust index of a motor vehicle is increased or decreased based on driving data from another motor vehicle receiving messages from that motor vehicle is preferably decided on the basis of suitable mathematical models stored in the processing devices of the motor vehicles or according to the principles of machine learning. The mechanisms used for this purpose concern, on the one hand, questions of the respective implementation of the method, but on the other hand, they are not the subject of the invention described here, so they will not be discussed in detail here. Ultimately, the same applies to the question of how to handle competing statements based on driving data regarding the accuracy of information transmitted via messages containing traffic data.The question of how the temporary trust index managed for a motor vehicle in association with its identifier, i.e. the index value stored for it, is changed also depends on the implementation of the procedure and, in individual cases, also on the type of database in which the trust index is held.

[0027] From the above explanations, it becomes understandable why the method according to patent claim 1 is characterized, among other things, by the fact that "at least one trust index" of the sending motor vehicle is transmitted with a message containing traffic data. It might be sufficient to simply transmit the current temporary trust index of a motor vehicle sending messages containing traffic data and to weight the transmitted message at the receiving motor vehicle with this temporary trust index. This is because the global trust index is ultimately linked to the temporary trust index insofar as the global trust index for a motor vehicle is used as the initial value for the temporary trust index when entering a new traffic context.

[0028] On the other hand, when implementing the procedure, it would be sensible for the global trust index of a motor vehicle to change much more slowly than its respective temporary trust index, which may already increase simply because the motor vehicle in question travels with other vehicles in a shared traffic context for an extended period of time. Against this background, it would also be conceivable to transmit both the global and the temporary trust index with a single message containing traffic data and to incorporate both in different ways into the weighting of the information transmitted with the respective message. In this case, the temporary trust index will certainly be given greater weight.

[0029] In a further embodiment of the method, the vehicle registration number of the respective motor vehicle can also be stored in the database together with the identifier and the at least one trust index of a motor vehicle. The vehicle registration number can advantageously be used to obtain more precise information about which motor vehicles are in a common traffic context at a given point in time or within a given period. For this purpose, the motor vehicles can additionally be equipped with cameras which can be used as sensors for recording the vehicle's surroundings, such as road conditions, as a basis for generating traffic-relevant messages, but can also be used to recognize the vehicle registration numbers of other motor vehicles and thus to determine which motor vehicles are in a common traffic context.

[0030] According to a further advantageous embodiment of the invention, the messages containing traffic data, but in particular the at least one trust index transmitted together with such messages, are transmitted in encrypted form. If this is done, as is preferred, using an asymmetric encryption method, a component of a database used according to the invention is a table in which the identifiers of motor vehicles using the method are stored in association with their public key used to encrypt the at least one trust index.

[0031] The use, arrangement, and design of the database for managing a trust index or the database for managing multiple or different trust indices also depend on the implementation of the procedure. For example, two independent databases can be provided for the global trust index and the temporary trust index, with one managing the global trust index and the other managing the temporary trust index. For example, a central, internet-accessible database can be provided for managing the global trust index and for managing data on contractual relationships or motor vehicles participating in the procedure, whereas the temporary trust indices of the motor vehicles can be managed in a (tamper-proof) database held locally in the vehicles.According to an embodiment of the invention intended for a practical implementation of the method, a distributed database organized according to the blockchain principle is used as the database, in particular for the management of temporary trust indices of several motor vehicles in respective assignment to their identifier and against the background of an encrypted data transmission.

[0032] As the above explanations illustrate, the solution presented is a process for evaluating the trustworthiness of information transmitted by connected vehicles during a journey, enabling automated and simultaneously safer decisions to be made based on this information. During the journey, trust relationships are established between vehicles, and transmitted information is checked for consistency with data from other road users' vehicles. The trust relationships are established using at least one trust index.The verification of the consistency of transmitted information with the data of other road users serves as a regulatory mechanism through which the significance of at least one trust index and its value with regard to its suitability as a weighting factor for messages from the motor vehicle linked to it are continuously increased over longer periods of time.

[0033] During the journey, participating vehicles, provided their transmitting and receiving units are within range of each other, exchange information that ensures a shared driving context. The longer this shared driving context exists with a particular vehicle, the higher the trust in messages from that vehicle is rated. This trust is represented by the temporary trust index and used to weight incoming messages from that vehicle. If a vehicle enters a new traffic context, for example by entering a motorway via the motorway entrance, the initial trust in other vehicles is first determined based on the global trust index, which is stored, for example, in a global database. Access to this global database is via the Internet.In this database, the authenticity of messages is specified with an index, the global trust index, based on the reliability of the signals sent by a motor vehicle in the past.

[0034] The global and traffic-context-specific temporary trust indexes are assigned to vehicles using their unique identifiers, such as a unique serial number. Position-specific data to ensure a shared traffic context can also be confirmed, among other things, by comparing the license plate. An RSA signature method is used to uniquely assign a vehicle's messages to its serial number and license plate number. Using a blockchain-based signature system, messages can also be forwarded and verified across multiple vehicles without losing the connection to the original message source or its integrity. This system eliminates the possibility of falsification of the original message during transmission.This also enables the reception of messages from vehicles that were previously classified as trustworthy but are outside the transmission and reception range at the time the message is forwarded. The message can be further confirmed, revoked, or forwarded in a value-neutral manner by the vehicle that is further away. This information is also subject to the integrity of the blockchain-based signature process. The more vehicles in a signal chain verify a specific message during transmission, the higher the trustworthiness of the message can be assessed, especially if a positive relationship of trust already exists with the vehicle that originally sent the message and the vehicles that forwarded it.

[0035] A system for implementing the method using a global and a temporary trust index valid within a specific traffic context, which comprises system elements integrated into each motor vehicle participating in the network for executing the method, preferably consists essentially of a transmitting and receiving unit for each motor vehicle, a processing device for each motor vehicle, a local database, and a global database accessible via the Internet. The processing device, which can be embodied by a single unit or by several units interacting with one another, preferably via a data bus, comprises several hardware- and software-based functional groups or subsystems.In particular, it comprises a functional group for evaluating the relevance of messages received by a motor vehicle from other motor vehicles and their trustworthiness. The latter is carried out in the course of deriving decisions in an automated process by weighting incoming messages based on the at least one trust index transmitted with them. Preferably, the system is designed such that, based on corresponding decisions, messages can be issued to the driver of a motor vehicle receiving messages containing traffic data and, if necessary, driving functions of the motor vehicle can be directly and automatically influenced. The latter case requires an operative connection between the processing device and a vehicle management system.Furthermore, the processing device includes a functional group for verifying incoming and forwarded traffic data messages based on sensor-recorded driving data. The previously described system for implementing the method can also be supplemented by a camera unit, which also interacts with the processing device to identify license plates and to capture traffic context-specific characteristics of the environment, such as the roadway.

[0036] An embodiment of the method and the nature of a system of the type described above will be explained below with reference to the drawings. The drawings show: Fig. 1: A structural diagram of an exemplary system suitable for implementing a possible embodiment of the method, Fig. 2: An example of a possible traffic context when using the procedure.

[0037] The Fig. 1 shows an exemplary, highly schematic structure of a system suitable for implementing the method. The individual blocks of the structural diagram serve less to illustrate the concrete design of individual parts or elements of the system and their arrangement. Rather, they represent functional blocks intended to clarify the interaction of corresponding system components related to the method according to the invention. The processing device is not represented in the form of a self-contained unit (in this respect, it is not referred to as a processing unit), but is symbolized according to its functions by a plurality of the illustrated functional blocks, which are largely self-explanatory in the drawing.In accordance with these functions, it is in particular a component of the functional blocks signal processing unit 2, the vehicle management system 8, the verification system 5 and the system for assessing the trustworthiness and relevance of signal transmitters (message-emitting motor vehicles) 4.

[0038] The transmitting and receiving unit 1 of a motor vehicle serves to transmit messages generated by the motor vehicle's processing device based on sensor signals, as well as to receive or forward, i.e., retransmit, messages from suitable communication partners, i.e., from other motor vehicles in which a compatible system is used. RSA-signed messages are sent between motor vehicles. Furthermore, GPS coordinates of the motor vehicle can be determined via the transmitting and receiving unit 1, and access to the aforementioned global database 7 is enabled via a mobile internet connection (j).

[0039] Each motor vehicle has its own secret private key, which it uses to sign sent messages using the RSA method. In addition to the signed message, the vehicle's identifier (ID or serial number) used for identification is also transmitted. A defined protocol serves the purpose of authentication, establishing integrity when forwarding messages, and enabling the subsequent identification of the vehicle that originally sent a message. All public keys of other vehicles are available via the local database 6, which is managed by each vehicle, and can be queried using the communicated identifier (b).If the identifier matches, the signature can be verified with the corresponding public key, ensuring that the message originally came from the vehicle with the specified identifier, as only this vehicle is capable of generating corresponding signatures for sent messages.

[0040] In addition to the public key, database 6 can also contain a version of the license plate or vehicle registration number character string encoded with a different secret key. In this case, the signed message contains not only the actual message but also a key for decoding the license plate information in database 6, a current timestamp, GPS data, and roadway-specific properties. The processing device of the receiving motor vehicle can thus determine which motor vehicle the data originates from and whether the motor vehicle in question is in its surroundings, i.e., in the same traffic context, provided that the camera unit 3 of the motor vehicle receiving the message registers the license plate of the sending motor vehicle during the course of the journey.

[0041] Based on the timestamp, the processing device recognizes whether the message is current and, based on the GPS data, where the message was sent from. This prevents attacks or attempts at manipulation by unauthorized road users by re-sending messages at different times or in different traffic contexts. Lane-specific information can be used to establish a relationship of trust with the sending vehicle regarding the shared driving situation, its route, and its position. Only messages that follow the signature scheme described above are processed. This ensures that the originator of each message (the vehicle that originally sent the message) is known and that integrity is maintained. When messages are forwarded across multiple vehicles, all signatures are forwarded recursively and checked accordingly.

[0042] The processing device of a motor vehicle receiving messages containing traffic data from other motor vehicles decides on the relevance and trustworthiness of signal transmitters (vehicles transmitting messages) 4, which is implemented as part of the processing device. It decides whether a message is relevant to the current driving situation and, based on the trust index received with the message, whether the message should be considered trustworthy. Each message that appears relevant in terms of time and GPS range is also forwarded to other road users, i.e., to other motor vehicles, via the transmitting and receiving unit 1 (a).In any case, the originally signed message is transferred with the identifier of the motor vehicle that originally sent it and, if necessary, additionally enriched with the result of the verification system 5's own check (f).

[0043] Verification is performed by the verification system 5, which also forms part of the processing device, primarily based on the driving behavior depicted by sensor-recorded driving data or on direct or indirect feedback from the driver (e.g., braking or acceleration k). The verification result can also be submitted slightly later, if necessary, and then either verify or falsify the message. In the case of a neutral position, the message is forwarded without comment, or no verification result is submitted at all, provided nothing has been verified or falsified. Both the forwarded message from the originator with their signature and other contents are signed in their entirety with the author's own private key according to the scheme described above.

[0044] This approach not only ensures integrity, but also allows us to trace the path the original message took to the respective receiving vehicle and by which instances it was verified or falsified. Accordingly, this message history can be used, alongside other received messages, to better assess the trustworthiness of the original message under consideration. The more road users rated as trustworthy have automatically forwarded a message, preferably positively verifying it, the more trustworthy it is to be assessed.

[0045] If vehicles considered trustworthy explicitly falsify a message, this leads to a lower overall trustworthiness rating. Messages are generally only forwarded if there is a temporal and spatial connection (relevance) to the current driving situation. This way, vehicles only receive messages that could be relevant to their driving situation, and the messages are not forwarded for many kilometers without any reference. The result of the verification itself has no influence on the forwarding. Relevant information is attached and signed by the sender if necessary. It can also be forwarded subsequently with a reference to a previously sent message.

[0046] If the processing device decides, based on the transmitted GPS parameters, the time, and possibly other driving situation-specific information, that the information transmitted via a message is relevant, and if the message is also classified as trustworthy, it is forwarded to the vehicle management system 8 (e). This system can use the corresponding information to adapt driving behavior by influencing suitable actuators or to inform the driver, for example, to warn them of a dangerous situation. Messages with a low trustworthiness may also be used to warn the driver if they are very relevant or significant (for example, if they are distributed by many motor vehicles that are considered untrustworthy), but they cannot influence the driving behavior of a receiving motor vehicle.

[0047] According to the example considered here, it is assumed that cameras of a camera system 3 are mounted on the front, rear, and sides of each motor vehicle at a specified height and angle, interacting with the processing device, in order to capture vehicle license plates, measure the roadway, and determine other properties of the roadway and road edge. Vehicle license plates are automatically extracted from the resulting image data and their character strings are recognized using hardware and / or software-based image recognition tools, i.e., corresponding units of the processing device. During the journey, color and lighting conditions, license plate information, road width, and information regarding the lane in which the vehicle is located are extracted from the image material and logged in the local database 6 with the GPS position and a timestamp (g).Information about the position of other vehicles whose license plates were recognized is also included in the log, if available. In addition to the lane, the system also determines which vehicles are in front of, behind, or next to the vehicle. This information can be exchanged with other vehicles using the same camera system to evaluate the authenticity and relevance of transmitted messages or to confirm the vehicle's own authenticity and relevance (h, c).

[0048] In the practical implementation of the procedure, both the vehicles that originally transmitted certain information with a message and the vehicles that forwarded this message and, if necessary, verified or falsified it accordingly are preferably evaluated for their trustworthiness, i.e., the trust index transmitted with the messages is taken into account when deriving decisions. The information transmitted with the messages is described with unique codes and parameters and can thus be assigned and evaluated across multiple senders.

[0049] The goal is to establish a type of trust relationship with specific vehicles during the journey, which is reflected by the vehicles' trust indices and depends primarily on the duration of the shared traffic context between different vehicles. In addition to sending traffic-relevant messages, vehicles also regularly send information about their position and parameters perceived at that position to vehicles in the immediate vicinity. Their respective camera systems 3 record properties such as road width, lighting conditions, lane position, and specific colors on the roadside, as well as information about vehicle license plates encountered at specific locations.This information can be reproduced to some extent by nearby motor vehicles, especially if they are in the same GPS area shortly after or before and ideally in the same lane.

[0050] Based on the information transmitted for identified vehicle license plates, vehicles confirm to each other that they are currently in the same traffic context. If the position of a vehicle in relevant lanes is recognized by the vehicle's own vehicle based on the license plate or confirmed by other vehicles, this is a particularly strong indicator of a shared traffic context. Messages to establish the trust relationship are exchanged using the described signature principle (c), enabling a clear, unadulterated assignment to a respective vehicle (i).

[0051] If a motor vehicle has been in the same traffic context for a longer period, the relevance of messages from that vehicle is rated higher than, for example, messages from a motor vehicle that was previously traveling on a different road. If consistent information was received from that vehicle over a longer period of time, the trustworthiness of the traffic situation-specific information is also rated higher. A suitable example of why weighting based on the duration of the shared traffic context is useful is a motor vehicle that is in close proximity to the entrance to a motorway on which all other road users have been traveling for some time and that transmits driving data about unusual braking maneuvers.Messages from this motor vehicle containing traffic data would be less trustworthy and relevant than those of other road users, as they have been on the same lane for a longer period and are participating in the same traffic flow, i.e., traffic context, as the vehicle itself. If the motor vehicle is still on the entrance ramp, the relevance for the vehicles in the lanes of the motorway also decreases. This can already be detected by transmitting the lane and position data and is accordingly incorporated (d) by the respective signal processing unit 2 as part of the processing device of a motor vehicle receiving messages, taking into account the protocols (g) created by the camera unit 3 and maintained in the local database 6.As the motor vehicle continues driving on the highway, it subsequently builds a relationship of trust with the other vehicles, and the temporary trust index and thus the trustworthiness of the message transmitted by this vehicle increases over time. If the motor vehicle is located in corresponding lanes, the relevance of the messages it transmits also increases, or these messages become relevant for the other vehicles in these lanes for the first time. Using the respective camera unit 3 of the motor vehicles, the veracity of information transmitted in the messages, such as lane information, can be verified if necessary and included in the trustworthiness assessment.

[0052] The trustworthiness of messages from an already known vehicle is determined not only by the duration of the trust relationship, but also by its global trust index, messages it has previously transmitted, and its driving behavior as perceived by the sensors of other vehicles. If a vehicle has previously attracted attention due to unusual driving behavior unrelated to the actual traffic situation, such as excessive braking without any apparent reason, subsequent messages sent by it will be given a lower weighting than if the vehicle suddenly deviates from an otherwise very consistent driving and braking behavior.If there is no common traffic history with a motor vehicle, historical data, namely its global trust index reflecting this data for assessing the trustworthiness of messages sent by it, can first be obtained from the global database 7.

[0053] The connection to the global database 7 is established via the Internet (j, c). The base values ​​available there depend on past evaluations of all road users or motor vehicles participating in the system that have been in a shared traffic context with the motor vehicle at some point. A detailed trust and relevance assessment is abstracted, and each road user only reports the GPS area in which the corresponding motor vehicle sent a message and whether this message was verified or falsified by the verification system 5. Overall, this creates a picture of how reliably the information or traffic data transmitted with messages from a motor vehicle have been perceived in the past and in which GPS areas messages with relevant content have already been sent.The global trust index therefore depends mainly on past transmission behavior and the initial relevance is estimated via GPS areas but also via transmitted lane information.

[0054] The base value for the trust index (global trust index) available from the global database for a previously unknown motor vehicle in a traffic context can, if necessary, be enhanced by existing trust relationships with other motor vehicles. This requires that these other motor vehicles communicate their existing trust relationship with this motor vehicle to road users and prove their traffic history with this vehicle through appropriately signed messages (c). The verification is carried out using a system similar to that used for the forwarding of messages across multiple motor vehicles. By mutually signing the exchanged messages to establish the trust relationship with appropriate timestamps and mutual confirmation, the shared driving history can be verified at a later point in time.

[0055] If a motor vehicle receives a message about a specific traffic situation, such as a traffic jam, via its transmitting and receiving unit 1, it can interpret the driver's behavior, after the driver has been warned of the traffic jam, for example, via a message, to determine whether the traffic situation actually exists or not. Another example scenario, in addition to a warning to the driver or vehicle operator, would be that the vehicle automatically reduces speed due to the message, but the driver then presses the accelerator again. In this case, the driver would falsify the veracity of the message depending on their own driving situation. However, it could also be that the driver deliberately slows down or reduces speed even further. This would verify the message.Decisions are made depending on the traffic situation, the type of message and the driver's behavior.

[0056] If a very high level of trust already exists with a motor vehicle, particularly based on its temporary trust index, this relationship is also used for verification in the absence of contradictory indicators in the form of corresponding actions by the driver. A message is continuously verified until it is no longer considered relevant. If the driving course results in a change in the verification result, this is communicated directly to other road users via a message sent by the transmitting and receiving unit 1 (c).

[0057] In addition to the public keys, the associated identifiers of the motor vehicles, and, if applicable, information on the vehicle registration numbers of potential communication partners, the local database 6 also contains logs of motor vehicles, events, and messages created in the current traffic context. All messages received by a motor vehicle are logged with signatures during a journey so that their integrity can be verified and, in the event of an accident, the originators of faulty messages can be identified. Furthermore, trust indicators, namely temporary trust indices, are created and continuously updated in the local database 6 for the respective motor vehicles in the shared traffic context. The messages exchanged to establish mutual trust (c) are also stored in the local database 6, including signatures (i).

[0058] Via mobile internet, such as LTE, all motor vehicles gain access (j) to the central database 7, via which global trust indices for given vehicle identifiers can be queried. Thus, information about the verification of messages sent by the respective motor vehicle in the past can also be transmitted. Authenticity and integrity are verified by transmitting the vehicle's signature and can be verified by the system using the associated public key. However, only global trust indices and the calculated relevance for a given GPS area can be queried from the central database 7, but not the signed messages of other motor vehicles.

[0059] The central database 7 is also used to update vehicle-specific information in the local database 6 (b, j). For example, the global trust index of a motor vehicle is used as the initial value for its temporary trust index in a new traffic context when entering this traffic context. Therefore, the information status of the local database 6 must be kept as up-to-date as possible so that newly registered motor vehicles or, if applicable, changes, such as a different vehicle license plate, are recorded as much as possible.

[0060] If the vehicle management system 8 receives binding information from the signal processing unit 2 of the processing device indicating an unforeseeable event, an adjustment of the driving speed in the road context, or, for example, an impending traffic jam (e), it can, in an automated process by influencing suitable actuators provided for this purpose, reduce the speed of the motor vehicle, initiate other automated maneuvers, and alternatively or additionally warn the driver of the occurrence of certain situations. A warning can also be issued if the authenticity of a signal is unclear but could be of importance to the driver. The driver could, for example, be instructed to be particularly careful.A possible scenario would be that a vehicle's sensors detect animals on the road and send out a corresponding message, but this message cannot be confirmed or is even falsified by many other vehicles. Depending on the relevance and danger level, the receiving vehicle should nevertheless at least warn the driver or even reduce its speed.

[0061] Signals output by the processing device based on automated decisions made on the basis of received and weighted messages can be provided to driver assistance, accident avoidance, and engine management systems (e). In addition, the verification system 5 has access to vehicle sensors and in-vehicle messages that allow conclusions to be drawn about the driver's driving behavior or that give the driver explicit feedback options for warnings or for initiated measures of the vehicle management system 8, for example by actuating a switch on the steering wheel.

[0062] The determination and change of the temporary trust index valid for a specific traffic context could be carried out according to a corresponding framework, for example as follows: - Initial value = global trust index (0 - 100 points) + shared traffic history with motor vehicles in the current / same traffic context (1 point per kilometer per motor vehicle) + 10 points for confirmation of the current shared traffic context (for example, through license plate recognition) + jointly confirmed traffic context without false signals (2 points per kilometer) - Message turns out to be misleading (50 points per message) + Message turns out to be accurate and helpful (30 points per message)

[0063] Based on the Fig.Figure 2 outlines a possible implementation of the method for an exemplary traffic situation and the corresponding conditions occurring at two points in time t1 and t2. Vehicles A, B, and C, which are shown in the figure from a bird's eye view, are on a motorway or on a motorway slip road (vehicle A), respectively, are symbolized by rectangles. The sequence of the method within the time window limited by points in time t1 and t2 is explained below from the perspective of vehicle A.

[0064] By entering the motorway via the motorway entrance, motor vehicle A enters a new traffic context with motor vehicles B and C, which were previously unknown to motor vehicle A. A is also previously unknown to motor vehicles B and C, but the two motor vehicles B and C have already been in the same traffic context for several kilometers and have shared their reception area several times. Thus, in a sense, they already "know" each other.

[0065] Using the described signature process, vehicle A initially sends its signed vehicle-specific data and traffic-context-specific information, such as the lane it is currently in, via appropriate messages upon initial contact. Vehicle A receives the same information from vehicles B and C. Vehicle A then requests the shared traffic history of vehicles B and C and receives the mutually signed messages as verification of this traffic history. This shows that vehicles B and C have already traveled 5 kilometers in the shared traffic context and have confirmed this, among other things, by mutually registering their license plates. In addition, vehicle A requests the initial assessment of the trustworthiness of vehicles B and C via its mobile internet connection.A vehicle can receive between 0 and 100 global confidence points, depending on how other road users have evaluated its signals in the past. If no signals have been evaluated, the default value is 50.

[0066] The query reveals that vehicle B has 60 out of 100 global trust points and vehicle C has 80. Due to the 5 kilometers they traveled together, both vehicles receive an increase of 5 points (1 point per kilometer). Therefore, compared to vehicle A, vehicle B receives a base trust value of 65 for the temporary trust index, and vehicle C a value of 85. This data was already transmitted between times t1 and t2. Lane information was also exchanged, which is why messages from vehicles B and C are initially not considered relevant, because A is still in the slip lane and not on the motorway itself. At time t2, however, it is already clear from the driving behavior and lane path that vehicle A intends to move into the right-hand lane soon.Furthermore, by recognizing the license plate number of vehicle C, vehicle A has already confirmed the shared traffic context with it and knows that this vehicle is in front of it in the right lane. This increases vehicle C's trust score for vehicle A by 10 points, resulting in a total of 95 points. As the journey continues, the trust score would increase by a further 2 points for each kilometer traveled.

[0067] Motor vehicle C now transmits a message with traffic data containing the information that there is an obstacle on the road. While motor vehicle C reduces its speed, motor vehicle B ignores the corresponding message and increases its speed in the left lane. It forwards the message from motor vehicle C to motor vehicle A and additionally falsifies it. The signal processing unit 2 of the processing device of motor vehicle A must now decide how to evaluate the messages received from motor vehicles B and C. In doing so, the trustworthiness of the contradictory statements from motor vehicles B and C is first weighed against each other.Since vehicle C, with a temporary trust index of 95, has a much higher trustworthiness than vehicle B, with a trust index of only 65, the processing device of vehicle A trusts the message received from vehicle C. Furthermore, vehicle C is demonstrably located in the lane into which vehicle A was just about to change, so its messages are highly relevant to the traffic context.

[0068] The signal processing unit 2 of the processing device transmits control signals to the vehicle management system 8 (e) based on a decision derived from the received messages. This system immediately issues a warning message to the driver and brakes the vehicle on the entrance. The driver then regains control of vehicle A and can check for themselves whether there is an obstacle on the road. If so, they can verify the original message from vehicle C or falsify it if they are certain there was no obstacle. If the signal from vehicle C is verified, it receives an additional 30 confidence points, increasing its temporary confidence index to 125. In the event of a falsification, it loses 50 confidence points, but vehicle B would then receive 30 confidence points because it correctly falsified the message.In this case, the temporary trust index of motor vehicle B would be 95, while that of motor vehicle C would be only 45.

[0069] Based on the collected experience and on the corresponding messages from vehicle A, the global trust indices of vehicles B and C in the global database 7 can also be updated via the mobile internet connection (j).

Claims

[1] Method for increasing the trustworthiness of automated decisions by generating messages with traffic data in an automated process by processing devices (2; 4; 5) of motor vehicles based on sensor signals and transmitting them with the aid of a transmitting and receiving unit (1) and by a processing device (2; 4;5) a motor vehicle receiving messages from other motor vehicles with traffic data by means of its transmitting and receiving unit (1) by way of car-to-car communication, decisions are made to influence the driving behavior of the receiving motor vehicle, namely decisions about the output of messages for the driver and / or control signals for actuators that directly act on the driving functions of the motor vehicle by means of a vehicle management system (8), wherein the messages received by a motor vehicle are each weighted by the processing device (2; 4; 5) thereof by means of at least one vehicle-specific trust index transmitted together with the messages, which trust index is variable starting from an initial value in accordance with a set of rules; characterized by , that - with each message containing traffic data sent by a motor vehicle, at least one vehicle-specific trust index is sent, i.e. one relating to the motor vehicle sending the message, which trust index represents the trust to be attributed to messages from this motor vehicle and is stored in a database (6; 7) in association with a unique identifier for the vehicle sending the message; - for a motor vehicle equipped to participate in the procedure, a global trust index and a temporary trust index are managed in association with its unique identifier and such a motor vehicle repeatedly transmits position data on its current position in association with its identifier; - the global confidence index is variable by processing historical data, namely as confirmation of messages containing traffic data sent by the motor vehicle in the past or driving data of other motor vehicles receiving the messages which are considered to contradict those messages, the initial value for the global confidence index of a motor vehicle being an index value determined for its first entry into service; - the temporary trust index, as a trust index relating to the current traffic context of the motor vehicle in question, is variable by processing driving data of other motor vehicles moving with it in the same traffic context according to their position data, whereby the initial value for the temporary trust index of a motor vehicle is its global trust index applicable when entering a new traffic context. [2] Method according to claim 1, characterized bythat the position data of motor vehicles equipped to participate in the method are determined by means of a satellite navigation system and that the processing device of a motor vehicle receiving a message with traffic data from another motor vehicle maps the position data of the motor vehicle sending the message to electronic map data which also takes lanes into account and is held in storage means of its processing device (2; 4; 5) and that the processing device (2; 4;5) on the basis of a set of rules also stored in the storage means, it is determined whether the motor vehicle sending the message is in the same traffic context as the one receiving the message, whereby the message is only used to derive automated decisions for the receiving motor vehicle if the answer is yes and is weighted with the at least one trust index of the sending motor vehicle transmitted with it; [3] Method according to claim 2, characterized by that, in order to assess whether a motor vehicle is in the same traffic context as at least one other motor vehicle and to generate messages to be sent with traffic data, additional sensor data from a camera system (3) of motor vehicles equipped to participate in the process are used. [4] Method according to one of claims 1 to 3, characterized bythat the data transmitted by motor vehicles equipped to participate in the method are transmitted in encrypted form, messages containing traffic data being decrypted by the processing devices (2; 4; 5) of the motor vehicles receiving them by means of a key stored in a database (7) in association with the identifier of a motor vehicle sending a respective message. [5] Method according to claim 1, characterized by that at least the temporary trust index of a motor vehicle and the identifier assigned to it are stored in a distributed database (6) organised according to the blockchain principle.

Citation Information

Patent Citations

  • Direct vehicle to vehicle communication signal transmission procedure uses vehicle relay links with transmission addresses determining position in sequence

    DE102004017603A1

  • Method for controlling data communication between subscriber units in communication network, involves transmitting local revocation list with identification data of unreliable subscriber units at respective group

    DE102007028093A1

  • Sensor fusion of camera and v2v data for vehicles

    EP3121762A1

  • Flexible security rating and decision mechanism for machine type communications

    WO2016130148A1