Method, device and computer program for a vehicle

By using a decentralized database to validate and determine the trustworthiness of road condition information shared between vehicles, the method enhances data security and authenticity, addressing the issue of incorrect or malicious data transmission in existing systems.

DE102018221740B4Active Publication Date: 2025-06-05VOLKSWAGEN AG
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
DE102018221740
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2018-12-14
Publication Date
2025-06-05
Estimated Expiration
2038-12-14

AI Technical Summary

Technical Problem

Existing systems for sharing road condition information between vehicles lack robust security measures, leading to potential transmission of incorrect or malicious data, which compromises the trustworthiness of the information.

Method used

A method for a first vehicle to obtain information about a travel path's state from other vehicles or infrastructure, validate this information through messages from third vehicles, and determine its trustworthiness using a decentralized database, such as one based on distributed ledger technology, to enhance data security and authenticity.

Benefits of technology

This approach significantly increases the security and trustworthiness of data transmission between vehicles, enabling more reliable autonomous or semi-autonomous vehicle control by ensuring that only validated information is used for decision-making.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for a first vehicle (100), the method comprising: Obtaining (110) information about a condition of a route from a second vehicle or a traffic infrastructure (200); Receiving (130) information about a validation of the information about the condition of the route from one or more third vehicles (300); Determining (140) a trustworthiness of the information about the condition of the track based on the information about the validation of the information about the condition of the track received from the one or more third vehicles; Determining (170) a trustworthiness of the second vehicle or the traffic infrastructure (200) and / or the one or more third vehicles (300) based on the trustworthiness of the information about the condition of the route, whereby the information on the condition of the track and the information on the validation of the information on the condition of the track are transmitted between the vehicles via a decentralised database.
Need to check novelty before this filing date? Find Prior Art

Description

The present invention relates to a method, apparatus and computer program for a first vehicle, more particularly, but not exclusively, to a method for determining a trustworthiness of information about a state of a travel path.In automotive research, a focus is on the development of safety functions. One possible safety function is the transmission of information to other road users who will possibly pass the same route section, for example information about construction sites, soiled roads and the like, so that the other road users can possibly bypass the impaired route section or have increased attention. Since this information can potentially be provided by each road user, incorrect information can be passed on, for example on account of incorrect measurements or on account of a transmitter's intention to damage.European patent EP 2 122 598 B1 describes a system for detecting road conditions. Therein, a state of the road in the vicinity of the respective vehicle is evaluated and relayed by different vehicles. If the self-measured state now conflicts with the state reported by other vehicles, the vehicle can estimate which information is more reliable. The respective information is stored by the vehicles in local databases, which can be shared with other vehicles.US patent application US 2005 / 0 149 259 A1 shows a system and method for updating a geographical database by means of feedback. In this case, the geographical database is kept up-to-date by a multiplicity of vehicles. The updates are in turn distributed among the vehicles.DE 10 2008 020 590 A1 discloses a driving information collection device. In this case, driving information is collected from measurement vehicles, gathered in an information center, statistically processed and categorized. These can subsequently be called up by an application.U.S. Pat. No. 7,912,628 B2 relates to the determination of traffic conditions by means of a plurality of data sources. In this case, information from various vehicles and measuring stations is collected on the road shoulder and gathered on a server.Patent publication US 2018 / 0 211 524 A1 describes how shared event information can be verified. The presence of an incident event is checked when a vehicle arrives at the geographic location of the incident. A verified incident event is subsequently published and incorporated into an incident event blockchain that serves to manage incident information. By using two blockchains, it is possible that the vehicles that obtain the incidents via an incident event blockchain can check, by means of the information stored on a incident persistence evidence blockchain, whether or not these incidents are erroneous.DE 10 2010 012 402 A1 presents a technique for transmitting messages about possible hazardous road conditions by means of a wireless communication network. The vehicles acting on this network are equipped with sensors that can detect potentially hazardous conditions such as rain, fog, squadish or traffic jams. Multiple vehicles that determine the same road condition provide a confidence value indicating that that condition exists. The confidence values are merged by the vehicles to produce a merged result that indicates the probability of the detected road condition occurring.An object of the present invention is to provide a concept with which the security of data transmission between vehicles can be increased, which in turn increases the trust and thus the usability of third-party information.This object is achieved by the method, the computer program and the apparatus according to the independent claims.Exemplary embodiments provide, for example, a method for a first vehicle. This vehicle is on the way along a travel path, such as a road, and receives information about a state of the travel path, such as that there is a risk of glansis or that the traffic jams at a specific location of the road, from other vehicles or from a traffic infrastructure, such as a traffic light or a road sign. Now, in order to enhance the security that this information is correct information, the vehicle waits for messages from one or more third vehicles to determine whether the first received information is acknowledged by the third vehicles or these third vehicles report identical information and thus indirectly acknowledge the first received information. If this is the case, the vehicle can be used, after overwriting a threshold at which a user of the first vehicle is informed of the correctness of the information, for example to adapt autonomous or semi-autonomous control of the vehicle and, for example, to initiate a braking process or an adaptation of the route guidance. If the first vehicle is already located at the location described by the information about the state of the road, the method can furthermore check the information about the state of the travel path on the basis of its own sensor measurements and provide the result of the check to the other participants in the network. In a simple implementation, the information may be exchanged directly between the vehicles and / or the traffic infrastructure, such as via vehicle-to-X communication. In a preferred exemplary embodiment, the information is exchanged via a decentralized database, which can be based, for example, on distributed ledger technology, which can furthermore provide protection against a subsequent change in the exchanged information.Exemplary embodiments thus provide a method for a first vehicle. The method comprises obtaining information about a state of a travel path from a second vehicle or a traffic infrastructure. The method further comprises obtaining information about a validation of the information about the state of the travel path of one or more third vehicles. The method further includes determining a trustworthiness of the information about the state of the travel path based on the information about the validation of the information about the state of the travel path obtained from the one or more third vehicles. This enables a distributed determination of the trustworthiness of the information about the state of the travel path. The user or the participant (vehicle, etc.) can then decide, for example ad-hoc, whether he is familiar based on the determined trustworthiness of the information about the state of the travel path, or he can specify in advance a threshold value for the trustworthiness, from which the information about the state of the travel path is to be considered true. The method further comprises determining a trustworthiness of the second vehicle or of the traffic infrastructure and / or of the one or more third vehicles based on the trustworthiness of the information about the state of the travel path. The information about the state of the travel path and the information about the validation of the information about the state of the travel path are transmitted via a decentralized database between the vehicles.The method can furthermore validate the information about the state of the travel path on the basis of a sensor signal. In this case, the determination of the trustworthiness of the information about the state of the travel path can be further based on the validation of the information about the state of the travel path based on the sensor signal.The method may further comprise providing information about the validation of the information about the state of the travel path by the first vehicle for one or more further vehicles via the decentralized database. This confirms and denotifies the information about the travel path through the first vehicle with respect to the further vehicles, which can allow other vehicles to assess the trustworthiness of the information about the state of the travel path.The information about the state of the travel path and / or the information about the validation of the information about the state of the travel path is transmitted via a decentralized database between the vehicles. This allows for a transmission of the information about the state of the travel path and / or the information about the validation of the information about the travel path between the vehicles, in which additional security and / or validation functionalities may be included.For example, the decentralized database can be based on a distributed ledger technology (DLT, decentralized ledgers / transaction database). The decentralized database can, for example, be based on a directed acyclic graph (also engl. Directed Cyclic Graph, DAG). This enables a transmission of the information such that a subsequent manipulation of the transmitted information becomes more difficult to practically impossible (depending on the technology or platform chosen). If, for example, a DAG is used for this purpose, sufficient scalability of the decentralized database can be achieved. The increasing data volume can be counteracted with extensions of technology such as, for example, the (geographical) fragmentation of the network (such as "shading" (for access), "economic clustering" (for grouping according to economic aspects), etc.).The method may further include obtaining at least a portion of the remote database based on a position of the first vehicle. This allows the first vehicle to use the relevant entries in the decentralized database at its position.In exemplary embodiments, the determination of the trustworthiness of the information about the state of the travel path is carried out by the first vehicle. This enables a more rapid and latency-less assessment of the trustworthiness of the information about the state of the travel path.The method may further include controlling the first vehicle based on the information about the state of the travel path if the trustworthiness of the information about the state of the travel path exceeds a threshold value. If the first vehicle is an autonomous or a semi-autonomously controlled vehicle, this enables the reaction of the first vehicle to a hazardous situation on the travel path or an optimization of the travel parameters.For example, the threshold may be a user-selected threshold. This enables each driver / user of the first vehicle himself, starting from which threshold he is familiar with the information about the state of the travel path. Additionally or alternatively, the threshold value may be dependent on a type of the information about the state of the travel path. For example, the threshold value may depend on a risk potential of the information about the state of the travel path. For example, lower thresholds may be selected if an immediate response is provided and higher thresholds may be selected if the risk potential is less high. In many cases, the risk potential can be derived from the type of information about the state of the travel path or can be estimated based thereon.In at least some exemplary embodiments, the information about the validation of the information about the state of the travel path of the one or more third vehicles indicates whether the one or more third vehicles confirm the information about the state of the travel path. In determining the trustworthiness of the information about the state of the travel path, the trustworthiness of the information about the state of the travel path can be increased if a vehicle of the one or more third vehicles confirms the information about the state of the travel path. The trustworthiness of the information about the state of the travel path can be reduced if a vehicle of the one or more third vehicles desensitizes the information about the state of the travel path. This allows a simple assessment of the trustworthiness of the information about the state of the travel path, which information can be implemented with counters.The method includes determining the trustworthiness of the second vehicle or the traffic infrastructure and / or the one or more third vehicles based on the trustworthiness of the information about the state of the travel path. The determination of the trustworthiness of the information about the state of the travel path can be based on a previous trustworthiness of the second vehicle or of the traffic infrastructure and / or of the one or more third vehicles. For example, the first vehicle may store in a long-term memory which vehicles or traffic infrastructures have provided trusted messages in the past, and provide messages from these vehicles or traffic infrastructures with belief rather than other vehicles or traffic infrastructures (and vice versa). In this case, the first vehicle can create so-called black lists and / or white lists (literal black and white lists, lists of vehicles that are never or are familiar with at least earlier, i.e., with a lower threshold value).For example, the method can further comprise providing information about the trustworthiness of the second vehicle or of the traffic infrastructure and / or of the one or more third vehicles to one or more further vehicles. This allows the other vehicles to transitively utilize the estimates of the trustworthiness of the second vehicle or the traffic infrastructure and / or the one or more third vehicles.In some exemplary embodiments, the information about the validation of the information about the state of the travel path can be assigned based on a comparison of a type of the information about the state of the travel path and the information about the validation and based on a comparison of the location of the information about the state of the travel path and the information about the validation of the information about the state of the travel path. This enables a use of validations that do not directly relate to the information about the state of the travel path for determining the trustworthiness of the information about the state of the travel path. Alternatively or additionally, the information about the validation of the information about the state of the travel path can comprise a reference to the information about the state of the travel path. The information about the validation of the information about the state of the travel path can be assigned based on the reference of the information about the state of the travel path. This enables a simple assignment between the information about the validation of the information about the state of the travel path and the information about the state of the travel path.The determination of the trustworthiness of the information about the state of the travel path can be further based on information about a trustworthiness of sensor measurements of a vehicle type of the second vehicle or of the traffic infrastructure and / or of the one or more third vehicles. For example, it is also possible to take account of the fact that sensors of a specific vehicle type are particularly trustworthy or particularly unreliable-in the last case without the information transmitter per se being set to a blacklist, but only the specific information type concerned (for example "smoothis" in the case of an inaccurate anti-slip sensor).Embodiments furthermore provide a computer program for carrying out the method when the computer program runs on a computer, a processor, or a programmable hardware component.Exemplary embodiments furthermore provide a device for a first vehicle. The apparatus comprises at least one interface for exchanging information (for example with a second vehicle or traffic infrastructure and / or with one or more third vehicles). The device further comprises a control module configured to obtain information about a state of a travel path from a second vehicle or a traffic infrastructure (for example via the at least one interface). The control module is configured to validate the information about the state of the travel path on the basis of a sensor signal or to obtain information about a validation of the information about the state of the travel path of one or more third vehicles (for example via the at least one interface). The control module is configured to determine a trustworthiness of the information about the state of the travel path on the basis of the validation of the information about the state of the travel path and / or on the basis of the information about the validation of the information about the state of the travel path obtained from the one or more third vehicles. The control module is configured to determine a trustworthiness of the second vehicle or of the traffic infrastructure and / or of the one or more third vehicles on the basis of the trustworthiness of the information about the state of the travel path. The information about the state of the travel path and the information about the validation of the information about the state of the travel path are transmitted via a decentralized database between the vehicles.Further advantageous embodiments are described in more detail below with reference to the exemplary embodiments illustrated in the drawings, to which exemplary embodiments are generally, however, not restricted overall. The following are shown: FIGS. 1 aand 1 b show flowcharts of exemplary embodiments of a method for a first vehicle; FIG. 1 cshows a block diagram of an embodiment of a device for a first vehicle; FIGS. 2a to 2c show an embodiment in which correct information on the state of the travel path is confirmed by following vehicles; FIGS. 3a to 3c show an embodiment in which wrong information about the state of the travel path is de-specified by following vehicles; and FIG. 4 illustrates a commutation system.Various embodiments will now be described in more detail with reference to the accompanying drawings, in which some embodiments are illustrated.Although embodiments may be modified and modified in various ways, embodiments are shown in the figures as examples and will be described in detail herein. It is to be understood, however, that there is no intention to limit embodiments to the particular forms disclosed, but rather that embodiments are intended to cover all functional and / or structural modifications, equivalents, and alternatives falling within the scope of the invention. Identical reference numerals designate identical or similar elements throughout the description of the figures.Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the embodiments belong. It will be further understood that terms, e.g., those defined in commonly used dictionaries, should be interpreted as having the meaning that is consistent with their meaning in the context of the relevant art and will not be interpreted in an idealized or overly formal sense unless expressly defined herein.At least some embodiments are concerned with secured traffic data distribution for supporting driving assistance systems and automated and autonomous driving.In scenarios in which vehicles independently make decisions, they can have access to a database with respect to the traffic conditions, which database is not only as complete as possible (at least with respect to the relevant route section, i.e. to be traveled on, and with respect to the relevant parameters, such as, for example. Traffic density, road condition, etc.), but rather can also be protected against attacks and manipulations in order to prevent third parties from influencing the decision criteria of the vehicle logic system and thus also indirectly the control of the vehicle.Such a database can be provided by trusted data sources (for example, traffic data distributed by the manufacturer, by governmental institutions, TMC, etc.). More up-to-date and thus more valuable information can, however, be provided by other vehicles which have passed the route section to be traveled shortly before. For example, the ASR control (anti-slip control) of a vehicle traveling ahead may be used. Smooth or flash ice reports long before this information becomes known to and can be distributed from centralized mechanisms and data sources. Road damage can likewise be detected by the vehicle sensor system and reported to following vehicles.Architectures and mechanisms already exist for the networking between vehicles, such as, for example, Car2Car or Car2X communication. In principle, such information could also be distributed in this way.To draw such data from more or less unknown data sources may be critical. On the one hand, it may be possible here for attackers to output as a vehicle driving ahead and to send false information or else for third parties to enter such communication links in order to manipulate the data distributed by other subscribers.Thus, in at least some cases it is expedient to protect these data on the one hand from subsequent manipulations and on the other hand to ensure the authenticity of the data generator.This is, for example, the blockchain (literally translated chain of blocks) or more generally the distributed ledger technology. Manipulations of data can be prevented with this technology by virtue of the fact that, on the one hand, the data concerned are present in a thousand-fold redundant manner, i.e. in a mirrored manner. If a manipulation attempt is to be successful, it may thus not be sufficient to corruption a data source-at least 51% of the copies of this data would have to be manipulated, which may become more difficult and practically impossible at some point with an increasing number of copies. On the other hand, the introduction of manipulated transactions into such a network can generally be recognized and rejected by the network.The data quality can be increased by each transmitter having a unique identifier and thus manipulating subscribers being able to be recognized and blocked.Blockchain technology is also often associated with high energy consumption and low transaction throughput. This is true for some prominent implementations of this technology. However, there are also developments which no longer have these negative properties. However, they can formally be, for example, not blockchains, but rather so-called distributed ledger technologies (DLTs), which define a distributed transaction history within the basic idea. Blockchains are an expression of these DLTs. Another form is, for example, so-called directed acyclic graphs (DAGs), which conceptually enable a significantly higher scalability and-depending on the implementation of the platform used-also have a significantly lower energy consumption. As a result, the technology for the stated application is interesting and usable. Alternatively, vehicle-to-vehicle or vehicle-to-infrastructure communication may be used, which may however provide less protection.Traffic data are currently mostly delivered in a centralized manner (such as, for example. TMC-traffic message channel, traffic message channel, or map providers) and frequently have a lower up-to-dateness than is possible by the information from vehicles traveling directly ahead (for example a few kilometers). In addition, centralized systems are a significantly more worthwhile target of attack, since they are easier to locate, on the one hand, and only one data source needs to be manipulated, on the other hand, and not thousands. The possibility of a man-in-the-middle (man-in-middle) attack is also mostly present here, since all the consumers of the data retrieve them from one or a few service instances. Not least, a great disadvantage of such centralized services is that manipulations can also be carried out subsequently simply and very quickly when accessing the database, which makes the distributed ledger technology very difficult.Providers of map applications may use the information sent by users of the applications to a computer of the manufacturer to update the map applications. However, this cannot prevent at least partially old data, and in addition these data are usually stored in a centralized manner and could possibly be compromised by an attacker. In addition, solutions of card manufacturers or TMCs usually have no access to the vehicle sensor system and can therefore usually only distribute pure traffic flow data.The manifold and exact vehicle sensor system makes it possible today to record the current traffic situation in very detail. Thus, in the future, connected vehicles can make warning and info messages early to other vehicles which subsequently travel the same route section, which communicate danger potentials (such as accidents, construction sites, traffic jams, smooth ice, uneven roadway / holes, crosswind or else also all types of regulation by traffic signs) directly and with very low latency. This represents an enormous advance over present-day warning systems, since not only are very much more risk potentials and data acquired and processed in comparison with these centralized systems, but they are available directly and are therefore highly up-to-date. At the latest in highly automated or even autonomous driving, such data sources may be essential.If one wishes to take advantage of these new options, these data can of course be incorporated into the decision making of the driver or vehicle (adaptation of the speed or the travel route, etc.). At the latest during autonomous driving, there is the risk that attackers can influence the traffic situation by feeding in incorrect data or by manipulating actually correct data or, in the worst case, can even provoke accidents by different road users receiving different, i.e. conflicting, data. On the other hand, however, one would be don't wish to use such highly up-to-date and source accurate data.At least some exemplary embodiments use a transmission of information by means of decentralized databases, for example based on distributed ledger technology. These are decentralized networks which make it possible to distribute data (in this case traffic data, for example information about the state of a travel path or information about a validation of the information about the state of the travel path) in a manipulation-protected manner. Such networks provide pseudonymity from the home, i.e. the person behind them (or the vehicle supplying data) may remain unknown, but data from this data generator is unambiguously identifiable in the network.The challenge in decentralized, public networks of this type is usually that attackers (who have the aim, for example, of compromise data) often have free access only once and can also feed incorrect data into the network. However, if such networks are sufficiently dimensioned with respect to the number of subscribers, manipulations are rejected by the majority and are thus depleted and are therefore not part of the data accepted by the network. For example, the BitCoin (Literally Translated Bitmunch) blockchain has built up such a network that makes it possible to carry out secure financial transactions without intermediary products, such as, for example, intermediate products. The invention also relates to banks, which in centralized systems check the authenticity and legitimacy of the individual transactions. These networks are partially designed in such a way that they can also be shared there with their own business cases in order to use them, for example, for data distribution without being tied to financial transactions.However, the concept present here continues to a considerable extent. Distributed ledger technology provides for invariable storage of data and assignment of the data to the producer. However, if it is used for distributing proprietary data, it does not inherently offer any way of checking the content of the data distributed in the network. However, these data are publicly visible within this network, as a result of which each network participant receives insight into them and can thus validate the content. The concept provides that the trust in the authenticity of the information is increased the more frequently such a data packet is positively validated.The concept presented is illustrated below with reference to the method, the device and the computer program identified in the patent claims.FIGS. 1 aand 1 b show a flow chart of an exemplary embodiment of a method for a first vehicle 100. The method may be (completely) executed by the first vehicle, for example by a device 10 of the vehicle. Alternatively, the method can be carried out by another unit, for example by a traffic infrastructure. Thus, the references to the first vehicle are exemplary of this embodiment and may be replaced by the traffic infrastructure in another embodiment.The method comprises obtaining 110 information about a state of a travel path from a second vehicle or a traffic infrastructure 200. The method further comprises validating 120 the information about the state of the travel path based on a sensor signal. Alternatively (or in addition), the method comprises obtaining 130 information about a validation of the information about the state of the travel path of one or more third vehicles 300. The method further comprises determining 140 a trustworthiness of the information about the state of the travel path based on the validation of the information about the state of the travel path and / or based on the information about the validation of the information about the state of the travel path obtained from the one or more third vehicles.FIG. 1 cshows a block diagram of an exemplary embodiment of a (corresponding) device 10 for the first vehicle 100. The device 10 comprises at least one interface 12 for exchanging information. The device 10 comprises a control module 14. The control module 14 is designed to receive information about a state of a travel path from a second vehicle or a traffic infrastructure 200. The control module 14 is designed to validate the information about the state of the travel path on the basis of a sensor signal. Alternatively (or in addition), the control module 14 is designed to obtain information about a validation of the information about the state of the travel path of one or more third vehicles 300. The control module 14 is configured to determine a trustworthiness of the information about the state of the travel path on the basis of the validation of the information about the state of the travel path and / or on the basis of the information about the validation of the information about the state of the travel path obtained from the one or more third vehicles. FIG. 1 cfurther shows the first vehicle 100 with the apparatus 10. FIG. 1 cfurther shows a system comprising the first vehicle 100, the second vehicle or the traffic infrastructure 200 and the one or more third vehicles 300.The following description relates to the method of Figures 1a and 1b and to the apparatus of Figure 1c.Exemplary embodiments are based on checking information about a state of a travel path which is provided by a second vehicle or by a traffic infrastructure, based on own sensor measurements, or determining whether the information about the state of the travel path is trustworthy by evaluating validations of the information about the state of the travel path of third vehicle. In this case, the information about the state of the travel path can be validated and confirmed by other participants and thus become more trusted. In this case, the transmitter does not necessarily have to be trusted, but rather the trust can be based on the network. Rather, the identity of the sender is unimportant, making the concept much anonymous and more decentralized (and thus more secure). By distributing the data pseudonymized over the public network in at least some exemplary embodiments, any interested party can take advantage of this. Thus, not only for the case of autonomous driving, but for all possible cases in which the subscribers of such a decentralized network validate and confirm their data with respect to content and thus improve the usability and the trust in the data.For example, the information on the state of the travel path may indicate whether the travel path is icy at a position, whether traffic jams at a position of the travel path, whether a construction site is at a position of the travel path, etc. In other words, the information on the state of the travel path refers to a position, and the information on the validation of the information on the state of the travel path includes information on whether the information on the state of the travel path is correct at that position. For example, the information about the state of the travel path can indicate that at the position:the travel path is icy,the track is soiled,the travel path is uneven (for example due to impact holes),side wind prevails,traffic jams on the travel path,an accident on the travel path has taken place,a construction site is located on the travel path,the travel path is regulated by a (temporary) traffic sign, orthe travel path is blocked at the location.For this purpose, the corresponding information must be transmitted between the vehicles. For this purpose, in at least some exemplary embodiments, the information is transmitted via a decentralized database, which can be based, for example, on a distributed ledger technology. In other words, the information about the state of the travel path and / or the information about the validation of the information about the state of the travel path can be transmitted via a decentralized database between the vehicles. The term decentralized database means that, in contrast to a central storage under the control of a single network component, it is stored decentralized under the control of a plurality of network components and on a plurality of network components. This increases the security of the data (redundancy) and, as will be explained in more detail below, can also be used to increase the reliability and the protection against manipulations. The decentralized database can correspond, for example, to a database according to a DLT, in particular a blockchain or a technology following a multidimensionally directed graph. In this case, the decentralized database can be based on distributed ledger technology and / or on a directed acyclic graph. In this case, a network having a plurality of network components or computers is used which, via a sequence of transactions, update some of the transactions and data with these transactions. This data is then stored distributed over the network components involved. Because the components previously agree on transactions and the data manipulated thereby, later manipulations carried out on the data or transactions can be recognized. The information about the state of the travel path and / or the information about the validation of the information about the state of the travel path can be protected from manipulations and / or transparently stored in the decentralised database. Accordingly, connections are formed between the individual network components, which connections can in principle be directed or non-directed. In at least some embodiments, a directed acyclic graph may be used.For transmitting the information between the vehicles, the information about the state of the travel path and / or the information about the validation of the information about the state of the travel path can comprise one or more identifiers of the first vehicle, of the second vehicle / of the traffic infrastructure and / or of the one or more third vehicles, for instance so that the respective information can be assigned to the first vehicle, to the second vehicle / of the traffic infrastructure and / or to the one or more third vehicles.For example, the identifier may be a pseudonym of the first vehicle, the second vehicle / the traffic infrastructure or the one or more third vehicles, for example an identifier which identifies the vehicle / traffic infrastructure but does not make it possible to track it in a person-related manner. For example, the identifier may correspond to a digital signature originating from a manufacturer of the second vehicle / the traffic infrastructure and / or of the one or more third vehicles, but only identifying them as vehicles / traffic infrastructure. In at least some exemplary embodiments, the identifier can be replaceable. The identifier can be changed, for example, regularly or on instruction of a user of the vehicle / traffic infrastructure. In at least some exemplary embodiments, the information about the state of the travel path and / or the information about the validation of the information about the state of the travel path is additionally signed, for example based on a digital key of the first vehicle, of the second vehicle / of the traffic infrastructure and / or of the one or more third vehicles. All distributed messages (for example the information about the state of the travel path) can be signed with a certificate, so that forgery or tampering of the messages is made more difficult.In at least some embodiments, as shown in FIG. 1 b, the method further comprises obtaining 105 at least a portion of the decentralized database based on a position of the first vehicle. For example, obtaining 105 the portion of the decentralized database may include requesting the portion of the decentralized database from a network node, for example based on the position of the first vehicle on an anticipated route of the vehicle. Alternatively, the portion of the decentralized database is distributed via a broadcast (broadcast) mechanism.Alternatively, the information can be transmitted directly between the vehicles and / or the traffic infrastructure without the detour via a decentralized database. In principle, the concept of the weighting system (and ultimately also of the commutation system) can also be applied in clean vehicle-to-X environments (without distributed ledger). That is, even in such environments, a vehicle can assess the trustworthiness of information by counting how many participants / vehicles have made this information available identically or similarly. When using a DLT, however, the benefit may be higher (in which I can also retrieve and use information about remote positions and can thus take it into account, for example, in the route planning and I can thus resort to a larger and thus more secure database), although even without DLT, the defenses against erroneous / malicious messages can be increased. In other words, the information about the state of the travel path and / or the information about the validation of the information about the state of the travel path can be transmitted between the vehicles and / or the traffic infrastructure via direct vehicle-to-vehicle communication or direct vehicle-to-vehicle communication (combined: vehicle-to-X communication). Alternatively, vehicle-to-vehicle communication may be (or may not be) used with support by a cellular mobile communication system (such as the coming 3GPP cellular standard 5G). Cellular Vehicle-2-X).The method comprises obtaining 110 the information about a state of a travel path from the second vehicle or the traffic infrastructure 200. If the information about the state of the travel path is transmitted via the decentralized database, obtaining the information about the state of the travel path can comprise retrieving the information about the state of the travel path from the decentralized database. The information about the state of the travel path is stored in advance by the second vehicle or the traffic infrastructure in the decentralized database. Alternatively, the information on the state of the travel path may be transmitted via vehicle-to-vehicle communication. For example, obtaining the information about the state of the travel path may correspond to receiving the information about the state of the travel path via (direct) vehicle-to-vehicle communication.In some cases, the method further comprises validating 120 the information about the state of the travel path based on a sensor signal. If the method is carried out by the first vehicle, the sensor signal can originate, for example, from a sensor module of the first vehicle. For example, the sensor signal may be based on an environment sensor of the vehicle, for example a radar sensor, an ultrasonic sensor, a lidar sensor, a temperature sensor, a rain sensor, or a combination of a plurality of these sensors. For example, the validation of the information about the state of the travel path can correspond to a comparison of the information about the state of the travel path with the image of the environment obtained via the sensor signal. In this case, the information about the state of the travel path can be confirmed if the sensor signal comprises or maps information which corresponds to the information about the state of the travel path. Alternatively or additionally, the vehicle sensors can be used to interrogate the user of the vehicle about the state of the travel path. In suitable cases, a vehicle could even make the (co) rider an assessment (within the scope of a superimposition in the human-machine interface (also engl. HMI)). Example: "Can you confirm that the right lane is not drivable?", or the like. At the latest in autonomous vehicles, this distraction would also be non-critical. Thus, the sensor signal can be based, for example, on an input of the user of the vehicle, for example an input via a touch-sensitive screen (also known as "Engl". Touch Screen) or an Input via a Microphone. The information about the state of the travel path can be validated based on the user input.The method in some cases further comprises obtaining 130 information about a validation of the information about the state of the travel path of one or more third vehicles 300. The information about the validation of the information about the state of the travel path of the one or more third vehicles 300 may indicate, for example, whether the one or more third vehicles confirm the information about the state of the travel path. In a simple implementation, the information about the validation of the information about the state of the travel path may comprise one or more binary values indicating whether the one or more third vehicles confirm or de-sign the information about the state of the travel path. Alternatively or additionally, the information about the validation of the information about the state of the travel path can comprise information about a state of the travel path detected by sensors of the one or more third vehicles. This information can now be evaluated by the first vehicle.Previously, the information about the validation of the information about the state of the travel path can be assigned to the information about the state of the travel path. Here, for example, the following procedures may be adopted. Either the information about the information about the state of the travel path and the information about the state of the travel path can be compared in terms of content, for example based on a type of the information about the state of the travel path and based on a position on the travel path on which the information relates, or the information about the validation relates directly, for example via a reference or an identifier, to the information about the state of the travel path. In other words, in the first case, the information about the validation of the information about the state of the travel path can be assigned based on a comparison of a type of the information about the state of the travel path and the information about the validation and based on a comparison of the location of the information about the state of the travel path and the information about the validation of the information about the state of the travel path. Here, the types of the travel path state information and the information on the validation of the travel path state information and the positions of the two information are compared. In the second case, the information about the validation of the information about the state of the travel path can comprise a reference to the information about the state of the travel path. The information about the validation of the information about the state of the travel path can be assigned based on the reference of the information about the state of the travel path.The types of information about the state of the travel path can be derived from the various states which can be reported via the information about the state of the travel path. For example, the information about the state of the travel path may correspond to a type of the group of a message about an icy travel path, a message about a soiled travel path, a message about an uneven travel path, a message about crosswind on the travel path, a message about congestion on the travel path, a message about an accident on the travel path, a message about a construction site on the travel path, and a message about a (temporary) traffic sign on the travel path.The method is based on the fact that the information about the state of the travel path is checked in a self-learning network formed by the first vehicle and the one or more third vehicles, in order to be able to assess the trustworthiness of the information about the state of the travel path. This consists, for example, of two components: on the one hand, the information about the state of the travel path is confirmed or desensitized by the one or more third vehicles by providing the information about the validation of the information about the state of the travel path, and in addition, in a further step, it can be understood which vehicles or traffic infrastructures provide predominantly trusted information about the state of the travel path or correctly confirm, so that these vehicles or traffic infrastructures can be trusted rather than others over time. The method thus further comprises determining 140 a trustworthiness of the information about the state of the travel path. The trustworthiness may in some cases be determined based on the validation of the information about the state of the travel path. Thus, the information about the state of the travel path can be estimated as trusted if the information about the state of the travel path is confirmed by the sensor signal. Alternatively or additionally, the trustworthiness can be determined on the basis of the information on the validation of the information on the state of the travel path obtained from the one or more third vehicles. Thus, in determining the trustworthiness of the information about the state of the travel path, the trustworthiness of the information about the state of the travel path can be increased if a vehicle of the one or more third vehicles confirms the information about the state of the travel path, that is to say if the information about the validation of the information about the state of the travel path indicates that a vehicle of the one or more third vehicles confirms the information about the state of the travel path. Likewise, an evaluation of the trustworthiness is also possible, so the trustworthiness of the information about the state of the travel path can be reduced if a vehicle of the one or more third vehicles desensitizes the information about the state of the travel path, that is to say if the information about the validation of the information about the state of the travel path indicates that a vehicle of the one or more third vehicles desensitizes the information about the state of the travel path.In this case, the information of the second vehicle / the traffic infrastructure and of the one or more third vehicles can be evaluated differently, for example on the basis of previous experiences of the first vehicle with the second vehicle / the traffic infrastructure and / or with the one or more third vehicles. Thus, for example, vehicles / traffic infrastructures can be more familiar if they have provided or correctly validated pieces of trusted information about the state of the travel path in the past. In other words, the method may further comprise, as shown in FIG. 1 b, determining 170 a trustworthiness of the second vehicle or of the traffic infrastructure 200 and / or of the one or more third vehicles 300 based on the trustworthiness of the information about the state of the travel path. In this case, trustworthiness (also known as "score") denotes the quality of the data that a subscriber controls to the network. However, this is optional since, in at least some exemplary embodiments, the information about the state of the travel path can also be used without trust in the transmitter if sufficiently other subscribers have confirmed it.For example, the trustworthiness of the second vehicle or of the traffic infrastructure 200 can be increased if the trustworthiness of the information about the state of the travel path which originates from the second vehicle or of the traffic infrastructure 200 is more trusted, and / or reduced if the trustworthiness of the information about the state of the travel path which originates from the second vehicle or of the traffic infrastructure 200 is less trusted. The trustworthiness of a vehicle of the one or more third vehicles 300 can be increased if the information about the validation of the information about the state of the travel path corresponds to the information about the validation of the information about the state of the travel path of further vehicles of the one or more third vehicles, for example if the information about the validation of the information about the state of the travel path is compliant with the trustworthiness of the information about the state of the travel path, and vice versa. At this time, the reduction may be omitted when the type of the travel path state information or the information on the validation of the travel path state information describes a state that is short in duration, such as crosswind.The trustworthiness of the second vehicle or of the traffic infrastructure and / or of the one or more third vehicles determined in this case can then be used to estimate the trustworthiness of the information about the state of the travel path. In this case, the information about the state of the travel path and the information about the validation of the information about the state of the travel path can be weighted and / or evaluated differently on the basis of the trustworthiness of their sources. In other words, the determination of the trustworthiness of the information about the state of the travel path can be based on a previous trustworthiness of the second vehicle or of the traffic infrastructure and / or of the one or more third vehicles.Further, the trustworthiness of the information about the state of the travel path may be determined based on a reliability of sensors on which the information about the state of the travel path is based. For example, in some vehicle types, it may be known that their sensors frequently cause information about the state of the travel path that is in in incumbent with respect to trust. In other words, the determination of the trustworthiness of the information about the state of the travel path can be further based on information about a trustworthiness of sensor measurements of a vehicle type of the second vehicle or of the traffic infrastructure and / or of the one or more third vehicles.The goal is, in at least some embodiments, that the first vehicle is controlled based on the information about the state of the travel path. In this case, the first vehicle can be, for example, an autonomously controlled vehicle (autonomous vehicle for short) or a semi-autonomously controlled vehicle, that is to say a vehicle which is controlled by means of driving assistance systems and requires the driver to intervene only in exceptional cases. Alternatively or additionally, the information about the state of the travel path can be used to support the driver via driving assistance systems. A prerequisite for this is that a user of the vehicle trusts the information about the state of the travel path. This can be done, for example, by the first vehicle explicitly inquiring the first user for each piece of information about the state of the travel path whether he is familiar with the first user based on the available information about the state of the travel path. A more practical approach is one in which the user defines one or more threshold values for trustworthiness, from which he trusts the information about the state of the travel path. In other words, as shown in FIG. 1 b, the method may further comprise controlling 160 the first vehicle based on the information about the state of the travel path if the trustworthiness of the information about the state of the travel path exceeds a threshold value. Alternatively or additionally, the method may further comprise providing driving assistance based on the information about the state of the travel path if the trustworthiness of the information about the state of the travel path exceeds the threshold value. The threshold may be, for example, a user-selected threshold. In this case, the threshold value for the different types of information about the state of the travel path can be set differently. In other words, the threshold value may be dependent on a type of the information about the state of the travel path. The threshold value may depend on a risk potential of the information about the state of the travel path. The risk potential can be derived from the type of information about the state of the travel path, i.e. based on the type of information about the state of the travel path.In at least some exemplary embodiments, not only is the trustworthiness of the information about the state of the travel path estimated for the first vehicle, this information can furthermore be passed on to further vehicles. Thus, the method can further comprise providing 150 information about the validation of the information about the state of the travel path by the first vehicle for one or more further vehicles, for example via the decentralized database or via (direct) vehicle-to-vehicle communication. The method can further comprise providing information about the trustworthiness of the information about the state of the travel path for one or more further vehicles, for example via the decentralized database or via (direct) vehicle-to-vehicle communication. Alternatively or additionally, the method may further comprise providing 175 information about the trustworthiness of the second vehicle or of the traffic infrastructure 200 and / or of the one or more third vehicles 300 for one or more further vehicles, for example via the decentralized database or via (direct) vehicle-to-vehicle communication. In this case, black lists and / or white lists of the first vehicle can be provided to the further vehicles. If the further vehicle is familiar to the first vehicle, it may also be familiar with its blacklist / whitelist and takes over or uses it at least to adapt the threshold values in the case of information provided by an affected vehicle.In at least some exemplary embodiments, the first vehicle, the second vehicle and / or the one or more third vehicles can correspond, for example, to an autonomously controlled vehicle, a semi-autonomously controlled vehicle, a land vehicle, a watercraft, an aircraft, a rail vehicle, a road vehicle, a car, a off-road vehicle, a motor vehicle, or a truck.The traffic infrastructure may correspond to a device configured to monitor or control travel paths, such as a traffic light system, a traffic sign, a traffic sensor, a weather satellite or a central traffic monitoring system of a navigation solutionThe at least one interface 12 may correspond, for example, to one or more inputs and / or one or more outputs for receiving and / or transmitting information, for example in digital bit values, based on code, within a module, between modules, or between modules of different entities.In embodiments, the control module 14 may correspond to any controller or processor or programmable hardware component. For example, the control module 14 can also be realized as software that is programmed for a corresponding hardware component. In this respect, the control module 14 can be implemented as programmable hardware with correspondingly adapted software. Any processors, such as digital signal processors (DSPs), may be used.Embodiments are not limited to a specific type of processor. Any processors or even a plurality of processors are conceivable for implementing the control module 14.Examples are illustrated below to illustrate the concepts presented.A vehicle (for example the second vehicle) reports to the network (for example the decentralized database) on a winter day that smoothis exists on the A2 on a valley bridge (detected by the vehicle sensor system-for example the ASR). The information comprises a time stamp, the type of event ("smoothis") and the geo-coordinate (in the case of a plurality of lanes, optionally additionally the lane concerned). A vehicle (for example the first vehicle) following shortly thereafter receives this message (for example as information about the state of the travel path), but determines that no confirmations regarding this information exist and must thus decide on its own whether it contributes relevance to this information. When passing through the aforementioned location, the sensor system of this vehicle now recognizes that the information was correct and confirms it (for example by validating the information about the state of the travel path). As a result, the message receives a higher weight in the network. With each successive vehicle that can validate this information, the weight of the information increases. Likewise, following vehicles may of course also mark this information as "not validated" if they are thought to be incorrect.FIGS. 2a to 2c show an embodiment in which correct information on the state of the travel path is confirmed by following vehicles. FIGS. 2 ato 2 c show the vehicles 1 to 5 (reference numerals 201- 205) and the blockchain / distributed ledger 210. In FIG. 2 a, vehicle 1 reports "Smoothis at Geo-Position X" 220 to the network with time stamps. This event 220 is communicated to vehicles 2 and 3 via blockchain / distributed ledger 210. In FIG. 2 b, vehicle 2 confirms "smoothis at geo position X" 230 with time stamps to the network. The confirmation 230 is communicated to the vehicles 3 and 4 via the blockchain / distributed ledger 210. In FIG. 2 c, vehicle 3 confirms "smoothis at geo position X" 240 with time stamps to the network. This confirmation is communicated 240 to vehicles 4 and 5 via blockchain / distributed ledger 210.The situation is different in the example of Figs. 3a to 3c. FIGS. 3a to 3c show an embodiment in which incorrect information about the state of the travel path is desensitized by following vehicles. FIGS. 3 ato 3 c show the vehicles 1 to 5 (reference numerals 301- 305) and the blockchain / distributed ledger 310. In FIG. 3 a, vehicle 1 sends the false message "Excellent weather at geo position X" 320 with time stamp to the network. This event 320 is communicated to vehicles 2 and 3 via blockchain / distributed ledger 310. In FIG. 3 b, vehicle 2 sends a contradiction to the false notification and the actual weather (reference numeral 330) to the network. This contradiction and the actual weather 330 is communicated to the vehicles 3 and 4 via the blockchain / distributed ledger 310. In FIG. 3 c, vehicle 3 sends an acknowledgement for smoothis reporting and contradiction to false reporting (reference sign 340) to the network. This confirmation and contradiction 340 is communicated to the vehicles and 5 via the blockchain / distributed ledger 310.Here too, there is naturally the possibility in such decentralized networks that an attacker marks correct information as a false message. However, if it is a correctly documented event for a subscriber when passing the corresponding event location, the false detector is delarvoked. A subscriber's classification as "untrusted" (i.e. inclusion in a blacklist) should of course not be made in the first false message. This is because, on the one hand, a vehicle sensor system may be installed at the participant, which did not recognize the event, or, on the other hand, the effect of the event "smoothis" at this participant could have been significantly reduced due to other influences (for example less crosswind) and thus not been perceived. However, if an autonomous vehicle builds up black and white lists for the other network participants or road users, a commutation system will arise over time, which can assess the trustworthiness of event messages of other network participants. Thus, not only does the event detector get a higher trust bonus if its event message turns out to be true, but also all network subscribers who marked this event message as true.FIG. 4 illustrates the commutation system. Thus, the event of vehicle 1 201 from the examples of FIGS. 2 ato 2 cwas confirmed by vehicles 2 and 3, which increases the representation of the vehicle and identifies it as a trusted vehicle. However, the event reported by vehicle 1 301 from the examples of FIGS. 3 ato 3 cwas counteracted by vehicles 2 and 3, so that vehicle 1 301 is identified as a suspect vehicle and as a malicious vehicle, respectively.With regard to this commutation system, a comparison with the network can also take place in turn, so that a manipulative participant can also be recognized if even none of his false information could be cleared to date. An attacker could still regularly generate new identities or use different existing identities, but would then be left out of weighting: his false messages would only be trusted if enough (trusted) participants confirm them. Due to game theoretical considerations, this is quite unlikely, since the confirmers of false messages are also at risk of losing their representation. Caution is also required for events that have only a short duration (e.g., "crosswind") and can no longer be validated by subsequent participants. In these cases, the information transmitter's representation must not suffer.In at least some exemplary embodiments, the last decision authority is always at the vehicle or the driver. Thus, each participant (human or vehicle or, if appropriate, the vehicle manufacturer for his customers) can define his own reasonable threshold value (for example the threshold value for the trustworthiness of the information about the state of the travel path), starting from which event messages (for example the information about the state of the travel path) are deemed to be valid-this possibly also as a function of the event types: a message that smoothis occurs, I may prefer rather than one who states that the smoothis event no longer exists, since the risk of a misobserving of the information in the first-mentioned case is significantly higher for me as road participants.Likewise, the detection of the event alarm's hypothesis (trustworthiness) can cause the effective threshold at the receiver to be decreased for participants classified as trusted (example: messages from vehicle X are also trusted with less weighting of the event message because this vehicle has exceeded my confirmation threshold in more than 500 cases), or the effective threshold to be increased for participants if they have delivered frequent false messages.The network (for example the decentralized database) can be sufficiently trainable that it is based on the quality of the sensor system in the case of different vehicle types. If, for example, it is known that certain vehicles of a manufacturer have problems with the detection of smoothis, since the sensor system is not sufficiently high-valued there in quality, this information could protect an affected road user from being classified as not trustworthy. Messages or positive and negative acknowledgments of the type concerned would then simply no longer be taken into account or stepped down at this subscriber.This last decision authority can also (always) be located at the vehicle because distributed ledger technology does not provide immediate real-time capability. On account thereof, an autonomously driving vehicle can also retrieve this information from the network (for example, according to its travel route (with a reasonable variance). determining all events in the next 20 km in the direction of travel with a variance of + / - 45 degrees to the direction of travel), for example by obtaining at least a part of the decentralized database.These mechanisms make it possible to familiarize significantly more the data which a subscriber receives from the network than if they were merely exchanged between two subscribers. Then not only the validation of the data by the network would be missing, but above all also the confirmation of information by further traffic participants. This delays the time at which information is trusted (waiting for higher weighting). However, this is in a shorter frame than would be possible by centralized systems (where the data would also need to be tested before being provided to generality).In addition, vehicle manufacturers can use these data for analysis purposes in order to improve their sensor system or assistance systems. In this case, it would become quickly apparent if a specific vehicle of the own portfolio has weaknesses in the detection of environmental factors (such as, for example. Glattis).At least some embodiments are characterized by the following characteristics:▪ Use of Distributed Ledger Technology (for instance the decentralized database) as a medium for exchanging traffic information (for instance the information about the state of the travel path) in order to distribute it in a tamper-proof manner. Weighting system in the other road user (such as, for example. Vehicles confirm information distributed by their sensor system) (for example the information about the state of the travel path) or mark it as incorrect (for example by exchanging the information about the validation of the information about the state of the travel path). This also allows, in networks in which the data suppliers are not always known, the data quality or information accuracy to be increased, trust to be created in data and thus the usability of data of unknown origin to be made possible. Commutation System to further increase the trust and quick usability of information (such as by determining the trustworthiness of the vehicle / traffic infrastructure)▪ (self) learning network that detects commonities (such as certain vehicle types having poor detection rates for certain environmental factors).The concept could also be implemented on a centralized platform. Thus, at least the method steps which map the features mentioned in points 2, 3 and 4 can also be implemented and utilized there.The solution based on distributed ledger technology mentioned in the first point makes it possible, in contrast to centralized solutions, to create trust in the authenticity of the data (i.e. that the data has not been manipulated). This confidence is achieved on the one hand by the conceptual resistance to manipulations, but also by the high transparency of the data. At least some centralized solutions, on the other hand, do not provide this trust (due to the characteristics and attack vectors described above). Associated therewith, decentralized solutions can offer a higher level of reliability (if a node or server is no longer reachable, hundreds or thousands of others are available), as a result of which such a system additionally scales even significantly better.At least some exemplary embodiments are applicable in scenarios in which connected vehicles provide their data to other participants or use data provided by other participants or in which the use of external data sources is expedient-thus primarily in autonomous vehicles but also for supporting existing assistance systems: for example, the information that the travel path behind the next curve is blocked by a horizontally lying vehicle can even today-i.e. in non-(partially) autonomously driving vehicles can lead to automatic braking or at least one hazard notice for the user (for example on the HUD or the instrument or acoustically). This not only means motor vehicles of a manufacturer, but also all types of mobility services (keyword "MaaS"), in which motor vehicles can only represent a part. It may be important, especially in such scenarios, to operate open networks to which all players involved in mobility may follow in order to exchange data - in order to link all data suppliers to one another and thus to give the customer the best support and user experience. These then include, for example. Railroad companies, local traffic conditions, taxi services, airline companies, etc. Thus, different means of transport can also benefit from the exchange of (environmental) data. The concept can be used in all areas in which data of other or unknowns are to be used and in which there is the possibility that other subscribers confirm them. A further example of this would be the mapping of (sustainable) supply chains, in which the progress of the process or the sustainability of different participants or process steps is confirmed by third parties.At least some exemplary embodiments deal with environmental data (for example the information about the state of the travel path) being distributed in a decentralized network in order to make it usable for other road users and, despite or rather, a significant increase in quality and upduality of the data being achieved by the decentralizedization. The focus is on environmental circumstances that can not only make autonomous driving safer and more planable.At least some exemplary embodiments also have a location and time reference, but also a reference to a (unique) pseudonym. In many cases it does not matter which person or vehicle has supplied the data or even the aim is for the greatest possible anonymisation. At least some exemplary embodiments provide with the commutation system that each participant can maintain white and black lists for himself with respect to other participants in order to let information of a pseudonym be considered to be valid more quickly. However, these may be optional, since the information is acknowledged by the network, i.e. other subscribers. Furthermore, the commutation system is based precisely on a pseudonym, i.e. a transmitter of information does indeed use a unique identifier, but it does not allow any conclusion to be drawn about the participant (the person, the vehicle) and can therefore not be used for identifying a driver.In at least some embodiments, subscriber decentralization is used as an advantage to collect data more quickly, as in approaches where subscribers collect the data in a central service. However, there one supplier must be trusted-not only that he keeps track of positive intentions by himself, but also that his systems are so well protected that not other malicious actors make use of the centrality of the solution. In a decentralized environment, it is firstly simpler for malicious actors to contribute incorrect data. However, due to the theoretical experience of games in sufficiently large networks, more and more benign participants who validate the data of the network can, paired with the invariable data storage (blockchain / DLT), greatly increase the data quality and independence from an intermediary. In order to further support this and make it even more efficient, at least some exemplary embodiments provide, on the one hand, the content-related confirmation of information in the network by other subscribers and, as a supplement, the commutation system.A further exemplary embodiment is a computer program for carrying out at least one of the methods described above when the computer program runs on a computer, a processor or a programmable hardware component. A further exemplary embodiment is also a digital storage medium which is machine- or computer-readable and which has electronically readable control signals which can interact with a programmable hardware component in such a way that one of the methods described above is carried out.The features disclosed in the preceding description, the following claims and the appended figures can be important and implemented both individually and in any combination for the realization of an exemplary embodiment in its various configurations.Although some aspects have been described in connection with a device, it is understood that these aspects also represent a description of the corresponding method, so that a block or a component of a device is also to be understood as a corresponding method step or as a feature of a method step. Analogously, aspects described in connection with or as a method step also represent a description of a corresponding block or detail or feature of a corresponding device.List of reference characters10 Device for a first vehicle 12 At least one interface 14 Control module 100 First vehicle 105 Obtaining at least part of a decentralized database 110 Obtaining information about the state of the travel path 120 Validating the information about the state of the travel path 130 Obtaining information about validation of information about the state of the travel path 140 Determining a trustworthiness of the information about the state of the travel path 150 Providing information about the validation of the information about the state of the travel path 160 Controlling the first vehicle 170 Determining a trustworthiness of the second vehicle or of the traffic infrastructure and / or of the one or more third vehicles 175 Providing information about the trustworthiness of the second vehicle or of the traffic infrastructure and / or of the one or more third vehicles 200 Second vehicle / traffic infrastructure 201- 205 vehicles 1 to 5 210 distributed ledger / blockchain 220 message "Smoothis at geo-position X" 230, 240 confirmation of message 300 One or more third vehicles 301- 305 vehicles 1 to 5 310 distributed ledger / blockchain 320 false message "Excellent weather at geo-position X" 330 contradiction to false reporting, and actual weather 340 confirmation to smoothis reporting and contradiction to false reporting

Claims

A method for a first vehicle (100), the method comprising: obtaining (110) information about a state of a travel path from a second vehicle or a traffic infrastructure (200); obtaining (130) information about a validation of the information about the state of the travel path from one or more third vehicles (300); determining (140) a trustworthiness of the information about the state of the travel path based on the information about the validation of the information about the state of the travel path obtained from the one or more third vehicles; determining (170) a trustworthiness of the second vehicle or of the traffic infrastructure (200) and / or of the one or more third vehicles (300) based on the trustworthiness of the information about the state of the travel path, wherein the information about the state of the travel path and the information about the validation of the information about the state of the travel path are transmitted via a decentralized database between the vehicles.The method of claim 1, further comprising validating (120) the information about the state of the travel path based on a sensor signal, wherein the determining (140) the trustworthiness of the information about the state of the travel path is further based on the validating of the information about the state of the travel path based on the sensor signal.The method according to claim 1, wherein the method further comprises providing (150) information about the validation of the information about the state of the travel path by the first vehicle to one or more further vehicles via the decentralised database.The method of claim 3, wherein the remote database is based on distributed ledger technology and / or wherein the remote database is based on a directed acyclic graph.The method of any of claims 1 to 4, wherein the method further comprises obtaining (105) at least a portion of the remote database based on a position of the first vehicle.The method according to any one of the preceding claims, wherein the determining (140) of the trustworthiness of the information about the state of the travel path is performed by the first vehicle.The method according to any one of the preceding claims, wherein the method further comprises controlling (160) the first vehicle based on the information about the state of the travel path if the trustworthiness of the information about the state of the travel path exceeds a threshold value.The method of claim 7, wherein the threshold is a user-selected threshold and / or wherein the threshold is dependent on a type of the information about the state of the travel path, and / or wherein the threshold is dependent on a risk potential of the information about the state of the travel path.The method according to any one of the preceding claims, wherein the information about the validation of the information about the state of the travel path of the one or more third vehicles (300) indicates whether the one or more third vehicles confirm the information about the state of the travel path, wherein in the determining of the trustworthiness of the information about the state of the travel path the trustworthiness of the information about the state of the travel path is increased if a vehicle of the one or more third vehicles confirms the information about the state of the travel path, and wherein the trustworthiness of the information about the state of the travel path is decreased if a vehicle of the one or more third vehicles desensitizes the information about the state of the travel path.The method according to any one of the preceding claims, further comprising providing (175) information about the trustworthiness of the second vehicle or of the traffic infrastructure (200) and / or of the one or more third vehicles (300) to one or more further vehicles and / or wherein the determination of the trustworthiness of the information about the state of the travel path is based on a previous trustworthiness of the second vehicle or of the traffic infrastructure and / or of the one or more third vehicles.The method according to any one of the preceding claims, wherein the information about the validation of the information about the state of the travel path is assigned based on a comparison of a type of the information about the state of the travel path and the information about the validation and based on a comparison of the location of the information about the state of the travel path and the information about the validation of the information about the state of the travel path, or wherein the information about the validation of the information about the state of the travel path comprises a reference to the information about the state of the travel path, wherein the information about the validation of the information about the state of the travel path is assigned based on the reference of the information about the state of the travel path.The method according to any of the preceding claims, wherein the determining of the trustworthiness of the information about the state of the travel path is further based on information about a trustworthiness of sensor measurements of a vehicle type of the second vehicle or of the traffic infrastructure and / or of the one or more third vehicles.Computer program for carrying out the method according to one of Claims 1 to 12, when the computer program runs on a computer, a processor, or a programmable hardware component.Device (10) for a first vehicle (100), the device (10) comprising: at least one interface (12) for exchanging information; and a control module (14) configured to: obtain information about a state of a travel path from a second vehicle or a traffic infrastructure (200), obtain information about a validation of the information about the state of the travel path from one or more third vehicles (300), determine a trustworthiness of the information about the state of the travel path based on the information about the validation of the information about the state of the travel path obtained from the one or more third vehicles, and determine a trustworthiness of the second vehicle or of the traffic infrastructure (200) and / or of the one or more third vehicles (300) based on the trustworthiness of the information about the state of the travel path, wherein the information about the state of the travel path and the information about the validation of the information about the state of the travel path are transmitted via a decentralized database between the vehicles.

Citation Information

Patent Citations

  • Driving information collecting apparatus and method for learning driving information of a vehicle

    DE102008020590A1

  • Use of network-internal message generation, message aggregation, message distribution and message processing protocols based on V2X to enable road hazard warning applications

    DE102010012402A1

  • Road condition detecting system

    EP2122598B1

  • System and method for updating, enhancing, or refining a geographic database using feedback

    US20050149259A1

  • Information Sharing Among Mobile Apparatus

    US20180211524A1