Method for transferring a data set between a tachograph and a control unit

The tachograph's method of generating a cryptographic signature with a transmission identifier and count value ensures secure and efficient data transmission to external control devices by selectively applying integrity protection, addressing inefficiencies in existing systems.

DE102022210422B4Active Publication Date: 2025-11-13CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
DE102022210422
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-09-15
Filing Date
2022-09-30
Publication Date
2025-11-13
Estimated Expiration
2042-09-30

AI Technical Summary

Technical Problem

Existing methods for transmitting data from a digital tachograph to an external control device are inefficient and require unnecessary computational resources, lacking a simple and secure mechanism to ensure data integrity and authenticity.

Method used

A method where the tachograph collects and calculates data, decides on the need for integrity protection based on requests from the control device, generates a unique cryptographic signature using a transmission identifier and count value, and attaches it to the data before transmission, allowing the control device to verify the data's integrity and authenticity.

Benefits of technology

This approach simplifies and accelerates data transmission while ensuring data integrity and authenticity with low computational effort, protecting against replay attacks and optimizing resource usage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for transferring a data set between a digital tachograph (2) and an electronic control unit (4), wherein the tachograph (2) and the control unit (4) are connected at least temporarily for the purpose of transferring the data set by means of a data connection (6), the method comprising the steps: - Collecting and / or calculating data as tachograph data in the tachograph (2); - Decide whether the specified data of the tachograph data to be requested from the control unit (4) to the tachograph (2) for transmission requires integrity protection; if integrity protection is required for the specified data, then: - Requests for the specified data from the set of tachograph data and requests for integrity protection of the specified data from the control unit (4) at the tachograph (2); - Compilation of the requested specified data as raw data by the tachograph (2); - Generating integrity protection for the compiled raw data by the tachograph (2), wherein the integrity protection is generated from a shipment identifier created by the tachograph (2) and a unique count value assigned by the tachograph (2), and a cryptographic signature created by the tachograph (2) that captures the compiled raw data including the shipment identifier and the count value, wherein the cryptographic signature is created using a key selected by the tachograph (2) and wherein a key identifier of the selected key is added to the shipment identifier by the tachograph (2) when creating the shipment identifier; - Creating the dataset by attaching integrity protection to the compiled raw data; - Sending the data set from the tachograph (2) to the control unit (4).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for transmitting a data set between a digital tachograph and an electronic control unit, wherein the tachograph and the control unit are connected, at least temporarily, via a data connection for the purpose of transmitting the data set. The invention further relates to a data transmission system for carrying out the aforementioned method, as well as to a digital tachograph for such a data transmission system and a motor vehicle equipped with a tachograph.

[0002] One of the aforementioned methods is known, for example, in connection with a digital tachograph, also known as a digital speed recorder, in a motor vehicle. The tachograph stores and processes, among other things, driver data, such as driving and rest times, as well as vehicle-related data required by law.

[0003] These legally required data can be read from the tachograph via a data interface and, for example, evaluated and / or further processed on a central computer or a local evaluation device. To certify the integrity of the data read from the tachograph, it is known to digitally sign it. A corresponding digital signature procedure is automatically executed when the legally required data is read from the tachograph.

[0004] From DE 10 2006 048 029 A1, a method and a device for transmitting data between a tachograph and a data processing unit are known. The transmission takes place via a first path segment located between the tachograph and a communication control unit, and a second path segment comprising an air gap, located between the communication control unit and the data processing unit. Data is transmitted in encrypted form from the tachograph to the data processing unit via both the first and second path segments.

[0005] A system comprising a tachograph and a toll on-board unit as communication partners in a data communication is disclosed in DE 10 2007 058 163 A1. The tachograph and / or the toll on-board unit are configured as senders of data for determining a cryptographic verification value based on user data transmitted to the respective communication partner via a data interface.

[0006] A method for verifying the data integrity of a device on board a vehicle is known from US 2014 / 0025955A1. This method involves a procedure for storing data that includes transmitting data to be signed. A tachograph installed in the vehicle is integrated into the procedure.

[0007] A method for outputting a representation of a state relevant for the safe operation of a vehicle by means of an output module of the vehicle, wherein a signing of a sensor signal is provided, is known from DE 10 2019 216 030 A1.

[0008] A method and device for message authentication over a controller area network are disclosed in US 10 630 481 B2.

[0009] US 10 735 206 B2 discloses a method for exchanging data between a vehicle and an entity outside the vehicle.

[0010] The invention is based on the objective of making data present in the tachograph, in particular data not based on legal regulations, available to an external device in a simple method that can be adapted to individual requirements and allows for a simple way of checking the integrity of the data.

[0011] The problem is solved according to the invention by a method of the type mentioned above and by the fact that the method comprises the following steps: - Collecting and / or calculating data as tachograph data in the tachograph; - Decide whether the specified data of the tachograph data to be requested from the control unit for transmission requires integrity protection; if integrity protection is required for the specified data, then: - Requests for specified data from the set of tachograph data and integrity protection requests for the specified data from the control unit at the tachograph; - Compilation of the requested specified data as raw data by the tachograph; - Generating integrity protection for the compiled raw data by the tachograph, wherein the integrity protection is generated from a shipment identifier created by the tachograph and a unique count value assigned by the tachograph, and a cryptographic signature created by the tachograph that captures the compiled raw data including the shipment identifier and the count value, wherein the cryptographic signature is created using a key selected by the tachograph and wherein a key identifier of the selected key is added to the shipment identifier by the tachograph when creating the shipment identifier; - Creating the dataset by attaching integrity protection to the compiled raw data; - Sending the data set from the tachograph to the control unit.

[0012] A particular advantage of the method according to the invention is that it provides a way to make data available to a tachograph with comparatively low computational effort, ensuring its integrity and authenticity and protecting it against so-called replay attacks. Furthermore, it is advantageous that integrity protection is not required for all data transmitted by the tachograph, but only for the data for which such protection is deemed necessary by the requesting control unit. This not only simplifies and accelerates data transmission between the tachograph and the control unit, but also prevents the unnecessary tying up of tachograph resources that would then be unavailable for other tachograph tasks, such as communication with other control units.The method according to the invention makes it possible to easily provide tachograph data, i.e., vehicle data collected and / or calculated in the tachograph, including, for example, driver-related data of the driver of the vehicle in which the tachograph is installed, to an external control unit, wherein the data provided in this way is credibly of a trustworthy origin, namely the tachograph. Integrity means that the actual origin of the data corresponds to the expected origin, namely here from the tachograph, and / or that the data actually obtained corresponds to the data expected, for example, with regard to the data content (e.g., a speed reading).

[0013] The electronic control unit is an external control unit, meaning it is not, and especially not an integral part of, the tachograph. The control unit can be connected to the tachograph for data transmission, for example, via a plug connection, a cable connection, or wirelessly. The connection between the control unit and the tachograph can be permanent. However, it is at least temporary for the transmission of data from the tachograph to the control unit. The control unit can, for example, be permanently installed in the vehicle in which the tachograph is mounted and connected to the tachograph via a data bus. Alternatively, the control unit can also be located outside the vehicle.

[0014] The tachograph is connected to a vehicle's speed sensor (also known as a speed sensor or, for example, an inductive sensor) and, if applicable, to other data sources of the vehicle. Such a connection can be established, for example, by integrating the tachograph into the vehicle's data network. From the speed sensor and, if applicable, other data sources, the tachograph collects information in the form of raw data, e.g., about the vehicle and / or its journey. It is also conceivable that the tachograph calculates further data from the collected data. The collected and / or calculated data can, for example, be stored in the tachograph's data memory. The data present in the tachograph, i.e., the data collected and / or calculated by the tachograph, is the tachograph data.The tachograph data are raw data within the meaning of the present invention, so that the tachograph data represent a set of raw data.

[0015] For example, the control unit, or another device connected to the control unit, such as a central computer (also referred to as a server or back-end), which requests data from the tachograph via the control unit, decides whether integrity protection is required for this data. This decision depends in particular on whether the control unit or, for example, the central computer requires integrity protection for the specific, specified data. It follows that not all data is automatically protected, but only the specifically specified, i.e., defined and predefined, data.

[0016] The data is specified by and through the data request; that is, the control unit sends corresponding information to the tachograph with the data request, indicating which data (possibly all or only a portion) should be protected against data loss. This makes the method according to the invention fast and enables, for example, data transmission under real-time conditions or at least near real-time conditions. In principle, the control unit communicates with the tachograph to request data. However, the decision as to whether or not integrity protection is required for the requested data can be made either by the control unit itself or, if necessary, by a central computer connected to the control unit, for example, via remote communication.In principle, it is also possible that the decision as to whether the data requested from the tachograph by the control unit requires integrity protection is made automatically, depending on the information provided by the requested data, such as the vehicle's speed or distance traveled. Furthermore, it is conceivable that the control unit is configured in such a way that all data requested from the tachograph requires integrity protection, meaning that the decision regarding the requirement for integrity protection is always "yes".

[0017] The integrity protection for the compiled raw data is generated by the tachograph itself. This integrity protection includes, firstly, the shipment identifier created by the tachograph. The shipment identifier can be assigned by the tachograph or linked to the data record. It can, in particular, contain a content and / or origin identifier. Thus, the shipment identifier preferably provides information about the data content and / or origin of the compiled raw data in the data record. The shipment identifier can also, for example, contain a usage identifier, which can provide information about the intended further use of the compiled raw data in the data record. Secondly, the integrity protection includes the count value assigned by the tachograph, i.e., generated by it. It is important that the count value is unique, i.e., occurs only once.This can advantageously provide protection against replay attacks. The count value can, for example, be incremented by a counter on the tachograph. However, instead of such an increment, a decrementing of the count value is also conceivable. Furthermore, the integrity protection features the cryptographic signature generated by the tachograph, which captures both the compiled raw data of the data set and the transmission identifier and the count value.

[0018] The tachograph sends the data set created by appending special integrity protection to the compiled raw data to the control unit and, if applicable, to other potential recipients, such as other control units connected to the tachograph, at least temporarily, via a data link. The control unit can then receive the data set sent by the tachograph and, if necessary, verify it.

[0019] Advantageous embodiments of the invention are specified in the dependent claims.

[0020] One could imagine, for example, that the method according to the invention is started only once (for example, in response to a diagnostic request from the control unit). However, targeted, regular data transmission can be achieved if, according to an advantageous embodiment of the invention, the control unit requests the specified data from the set of tachograph data and integrity protection from the tachograph only once, and if, subsequently, triggered by a time event and / or a process event, the data is compiled, the integrity protection is generated, the data set is created, and the data set is sent from the tachograph to the control unit. The time event can, for example, be a specific point in time (for example, a day) or occur after a certain period of time, thus occurring cyclically. The process event can, for example, be...This can be triggered by an operator inputting a signal into the tachograph or, for example, by a signal that the tachograph receives via a vehicle data network to which it is connected.

[0021] According to the invention, the cryptographic signature is created using a key selected by the tachograph. Preferably, the key is stored in a protected memory of the tachograph.

[0022] For a secure yet simple process, it is advantageous that, according to the invention, a key identifier of the selected key is added to the shipment identifier by the tachograph during its creation. This means that, in addition to, for example, a content and / or origin identifier, the shipment identifier also includes the key identifier. Thus, the shipment identifier can preferably contain a key identifier for a key that is used by the tachograph to create the cryptographic signature.

[0023] In another advantageous embodiment of the invention, a device identifier of the tachograph, for example an individual device number, is added to the transmission identifier by the tachograph when the transmission identifier is generated. In this embodiment, the device identifier of the tachograph is thus a component of the transmission identifier. In this way, it is possible to determine directly and effortlessly, based on the data set sent by the tachograph to the control unit, precisely which tachograph, and therefore also which motor vehicle (in which the tachograph is installed), the data set originates from.

[0024] In another advantageous embodiment of the invention, the count value is incremented by the tachograph after the data set has been transmitted. That is, in this embodiment, the count value is incremented after each transmission of a data set generated according to the inventive method. Performing such an increment can be referred to as a counting process. Preferably, the count value can be incremented by a value "1" so that the tachograph, in particular a counter of the tachograph, can easily increment the count value. However, the count value can also be incremented by a value other than "1". It is also conceivable that the value of the increment changes, i.e., is not the same for every counting process. For example, it is not fundamentally necessary for protection against replay attacks that, for instance,a complete, traceable transmission list of data records with, for example, consecutive count values ​​is available, but rather that in the further development of the invention described here, the count value of a subsequently transmitted data record is higher than the count value of the data record transmitted prior to this data record.

[0025] In another advantageous embodiment of the invention, the control unit verifies the data set, the verification comprising comparing the count value with a count value last received by the control unit as the corresponding count value. The control unit can preferably perform the comparison by means of a comparator. The count value last received by the control unit as the corresponding count value is a count value transmitted by the tachograph, in particular a count value transmitted by the control unit along with a data set previously sent by the tachograph to the control unit, created according to the inventive method, and received by the control unit. This count value last received by the control unit as the corresponding count value can, for example, be stored in a data memory of the control unit.In principle, the control unit can be designed such that it stores the count values ​​transmitted by the tachograph with the data sets created according to the invention in the aforementioned data memory of the control unit. Checking the data set according to the further development described here preferably includes determining whether the count value is unique, i.e., differs from the previously received count value(s), and / or whether the value of the count value is greater than the last received count value. If this is not the case, there is a suspicion of an integrity violation of the data set, and the control unit can, for example, generate a warning signal. If the control unit does not have a previous count value for comparison, e.g., in the case of the first receipt of a data set created according to the method according to the invention, then, for example,The control unit should prompt the user to confirm such a circumstance in order to avoid automatically concluding that this constitutes a possible integrity violation of the data set.

[0026] It is particularly advantageous for a simple, fast, and secure process flow if, according to another embodiment of the invention, the transmission identifier includes the key identifier and if the verification of the data record by the control unit comprises checking the cryptographic signature using a key selected based on the key identifier. The key itself can preferably be stored in a protected memory of the control unit.

[0027] In another advantageous embodiment of the invention, the transmission identifier includes a data content identifier, and the control unit's verification of the data set comprises checking the data content identifier against the raw data. This raw data consists of the specified data compiled by the tachograph from the data set sent to the control unit. Using the data content identifier, a plausibility check of the data can be easily performed during the verification process. If discrepancies are detected by the control unit during this verification, this indicates a possible integrity violation of the data set.

[0028] Furthermore, a data transmission system is described. The data transmission system comprises a digital tachograph and an electronic control unit. The data transmission system is configured to execute a method according to the invention for transferring a data set between the tachograph and the control unit using the tachograph and the control unit.

[0029] Furthermore, a digital tachograph is specified. The tachograph is configured to function as the digital tachograph within the aforementioned data transmission system. The tachograph thus represents the digital tachograph of the data transmission system.

[0030] Furthermore, a motor vehicle, in particular a commercial vehicle, is specified as being equipped with the aforementioned digital tachograph. Preferably, the motor vehicle may also have the aforementioned data transmission system.

[0031] The invention also includes further developments of the data transmission system and / or the digital tachograph and / or the motor vehicle, which have features already described in connection with the further developments of the method according to the invention. For this reason, the corresponding further developments of the data transmission system, the digital tachograph, and the motor vehicle are not described again here. The invention also includes combinations of the features of the described embodiments and further developments that are not listed individually.

[0032] Exemplary embodiments of the invention are shown in sketchy and schematic form in the drawing and are described in more detail below with reference to the figures.

[0033] They show Fig. 1: a data transmission system with a tachograph and a control unit, Fig. 2: a graphical representation of a procedure for transferring a data set, Fig. 3: a graphical representation of another method for transferring a data set and Fig. 4: An overview graphic of a procedure for transferring a data set.

[0034] Corresponding elements in all figures are provided with the same reference symbols.

[0035] Fig. Figure 1 shows a schematic representation of a data transmission system 1 with a digital tachograph 2 and an electronic control unit 4. The tachograph 2 and the control unit 4 are connected, at least temporarily, via a data connection 6 for the transmission of a data record. The data record, e.g., from a data storage device 8 of the tachograph 2, is sent from the tachograph 2 to the control unit 4 via the data connection 6. The control unit 4 receives the data record. It may be provided that the control unit 4 checks the data record, e.g., for its integrity.

[0036] In its intended use, the tachograph 2 is installed in a motor vehicle (not shown here), in particular a commercial vehicle, for example, a truck. The electronic control unit 4 can also be located in the motor vehicle. However, the control unit 4 can also be located outside the motor vehicle. The data connection 6 can, for example, be a wireless data connection. However, the data connection 6 can also be a wired data connection. For example, the data connection 6 can also be integrated into a possible plug connection between the control unit 4 and the tachograph 2. In general, the data connection 6 can be part of a data network.

[0037] The tachograph 2 receives data from various vehicle data sources, such as different vehicle sensors and / or vehicle control units, via a vehicle data network 9 of the motor vehicle (not shown in detail here), to which the tachograph 2 is connected in this embodiment. The tachograph 2 collects this data received from the vehicle's data sources and, if necessary, performs additional calculations based on the collected data. In this embodiment, the data collected and / or calculated by the tachograph 2 is stored as tachograph data in the data memory 8.

[0038] For the data connection 6 for transferring the data set between the tachograph 2 and the control unit 4, the digital tachograph 2 has a data interface 10. Corresponding to this data interface 10 of the tachograph 2, the electronic control unit 4 has a first data interface 12 for the data connection 6 with the tachograph 2. In the embodiment shown here, the control unit 4 also has a second data interface 14 for remote data transmission, e.g., to a central computer or, for example, a so-called back-end.

[0039] Control unit 4 is, for example, a telematics device. However, control unit 4 can also be any other type of control unit – e.g., one permanently installed in the vehicle and possibly connected to the vehicle data network 9 – which is designed to receive a data set from the tachograph 2.

[0040] In the Fig. 2, Fig. Figure 3 shows excerpts of exemplary embodiments of methods for transferring a data set between a digital tachograph 2 and an electronic control unit 4.

[0041] Fig. Figure 2 shows an electronic control unit 4 and a digital tachograph 2, which has a data storage device in which tachograph data is stored. The tachograph data was obtained by the tachograph 2 by collecting and / or calculating vehicle and / or driver data of a motor vehicle in which the tachograph 2 is installed.

[0042] From the set of tachograph data stored in the data storage unit, control unit 4 requests specified data and integrity protection for this specified data (RWIP). Tachograph 2 then compiles the requested specified data as raw data (CRD). Tachograph 2 then generates the integrity protection for the compiled raw data (DTIB). This integrity protection is generated from a shipment identifier for the data record created by tachograph 2 and a unique counter value, which is assigned by tachograph 2 and incremented by a counter within tachograph 2 (ICN). Using a key (SK) selected by tachograph 2 and stored in a protected memory within tachograph 2, tachograph 2 creates a cryptographic signature (CSWK) that captures the compiled raw data, including the shipment identifier and the counter value.A key identifier of the selected key is preferably included in the transmission identifier. By appending the integrity protection to the raw data compiled by the tachograph 2, the data record to be transmitted is created (AIRD). This data record is then sent by the tachograph 2 to the control unit 4 (RDIB).

[0043] In the embodiment shown here, the control unit 4 receives and verifies the data record transmitted by the tachograph 2. First, the control unit 4 selects the corresponding shared key stored in a protected memory of the control unit 4 based on the key identifier specified in the data record transmitted by the tachograph 2 (CISK). Next, to verify the data record, the counter value is compared with a counter value last received by the control unit 4 as the corresponding counter value (CCTL). Then, the cryptographic signature is checked using the key selected based on the key identifier. For this purpose, the cryptographic signature is calculated using this key (UKCS) and compared with the signature generated by the tachograph 2 contained in the received data record transmitted by the tachograph 2 (CSRS).

[0044] One of the in Fig. The two methods shown are similar to those in [reference to a specific method]. Fig. Figure 3 illustrates this. In contrast to a specific request for specified data by a control unit 4 in a tachograph 2, in the example shown... Fig. 3. Triggered by a time event and / or an operation event (TOOE), the tachograph 2 compiles the data, generates the integrity protection, creates the data record, and sends the data record to the control unit 4. For this purpose, at an earlier time, not specified in detail in this embodiment, the control unit 4 requests the specified data from the set of tachograph data and the integrity protection from the tachograph 2 once (OTIP). The time event that triggers the data compilation, generation of the integrity protection, creation of the data record, and transmission of the data record can be a cyclical time event. In this embodiment, such a cyclically generated data record containing integrity protection is sent from the tachograph 2 to the control unit 4 (CDIB). On the control unit 4 side, the following can then occur, corresponding, for example, to the process described in Fig. The procedures shown in section 2 involve receiving and verifying the data set sent by tachograph 2.

[0045] Fig. Figure 4 shows in particular how a data set 16, which has integrity protection 20, can be created. In a tachograph 2 having a tachograph control unit 3, data, e.g., speed data of a motor vehicle in which the tachograph 2 is installed, are collected and / or calculated and stored in a data memory 8 of the tachograph 2. From an electronic control unit 4 having a control unit 5, specified data from the set of tachograph data as well as integrity protection for the specified data are requested from the tachograph 2 (RWIP).

[0046] The requested specified data is compiled by the tachograph 2 as raw data 18 (which in this example represents a speed of "42 km / h"). The tachograph 2 then generates an integrity protection 20 for the compiled raw data 18. The integrity protection 20 is generated from a transmission identifier 22 created by the tachograph 2 (in this embodiment having a key identifier “Key1” and a content identifier “speed”) and a unique counter value 24 (in this example “42”), which is incremented by a counter 25 of the tachograph 2 (here, the already incremented value “43” for the next transmission of a future data record is given as an example), as well as a cryptographic signature 26 created by the tachograph 2 (here given as an example “0AFF24E3DA5A”) that captures the compiled raw data 18 including the transmission identifier 22 and the counter value 24.The creation of data set 16 ends in a final step with the addition of integrity protection 20 to the compiled raw data 18. Afterwards, data set 16 is sent by the tachograph 2 to the control unit 4 (RDIB).

[0047] The tachograph 2 and the control unit 4 each have a split set of keys, each with a unique key identifier. Key set 28 with the split keys 30, 30', 30'', 30''' is in Fig. 4 is displayed only once. It is stored with the respective key identifiers on the one hand in a protected memory of the tachograph 2 and on the other hand in a protected memory of the control unit 4.

[0048] After receiving data set 16, control unit 4 can check it, for example, by comparing the counter value 24 with a counter value last received by control unit 4 from tachograph 2 using a comparator 32 (the last received counter value "41" is given here as an example). If no potential integrity violation of data set 16 is detected, control unit 4 can continue to use the raw data 18 transmitted by tachograph 2 as a trusted value 34, in this case, a speed value (in this example, a speed of "42 km / h"). A potential integrity violation of data set 16 could, for example, consist of the counter value 24 not being unique from the perspective of control unit 4 and / or the counter value not being greater than the counter value last received by control unit 4 as a corresponding counter value.

[0049] Overall, the exemplary embodiments demonstrate how the invention enables data from potentially various data sources within a motor vehicle to be made available in a digital tachograph in a simple and reliable manner within an electronic control unit external to the tachograph, ensuring credibility and trustworthiness. Corresponding data integrity is of essential importance, whereas confidentiality and secrecy of the data are not strictly necessary. That is to say, the crucial aspect of the invention is the protection of data integrity, while data secrecy, although optional, is not required.

Claims

[1] Method for transferring a data set between a digital tachograph (2) and an electronic control unit (4), wherein the tachograph (2) and the control unit (4) are connected at least temporarily for the purpose of transferring the data set by means of a data connection (6), the method comprising the steps: - Collecting and / or calculating data as tachograph data in the tachograph (2); - Decide whether the specified data of the tachograph data to be requested from the control unit (4) to the tachograph (2) for transmission requires integrity protection; if integrity protection is required for the specified data, then: - Requests for the specified data from the set of tachograph data and requests for integrity protection of the specified data from the control unit (4) at the tachograph (2); - Compilation of the requested specified data as raw data by the tachograph (2); - Generating integrity protection for the compiled raw data by the tachograph (2), wherein the integrity protection is generated from a shipment identifier created by the tachograph (2) and a unique count value assigned by the tachograph (2), and a cryptographic signature created by the tachograph (2) that captures the compiled raw data including the shipment identifier and the count value, wherein the cryptographic signature is created using a key selected by the tachograph (2) and wherein a key identifier of the selected key is added to the shipment identifier by the tachograph (2) when creating the shipment identifier; - Creating the dataset by attaching integrity protection to the compiled raw data; - Sending the data set from the tachograph (2) to the control unit (4). [2] Method according to claim 1, characterized by, that the request for the specified data from the set of tachograph data and integrity protection from the control unit (4) to the tachograph (2) occurs only once, and that afterwards, triggered by a time event and / or by a process event, the compilation of the data, generation of the integrity protection, creation of the data record and sending of the data record from the tachograph (2) to the control unit (4) takes place. [3] Method according to any one of the preceding claims, characterized by , that a device identifier of the tachograph (2) is added to the shipment identifier by the tachograph (2) when creating the shipment identifier. [4] Method according to any one of the preceding claims, characterized by , that after the data set is sent the count value is increased by the tachograph (2). [5] Method according to any one of the preceding claims, characterized by, that the data set is checked by the control unit (4), the checking comprising comparing the count value with a count value last received by the control unit (4) as the corresponding count value. [6] Method according to any one of the preceding claims, characterized by , that the shipment identifier has the key identifier and that the verification of the data record by the control unit (4) includes a verification of the cryptographic signature using a key selected on the basis of the key identifier. [7] Method according to any one of the preceding claims, characterized by , that the shipment identifier has a data content identifier and that the verification of the data set by the control unit (4) includes a verification of the data content identifier against the raw data. [8] Data transmission system (1), characterized by, that the data transmission system (1) comprises a digital tachograph (2) and an electronic control unit (4) and is configured to perform a method according to one of the preceding claims by means of the tachograph (2) and the control unit (4). [9] Digital tachograph, characterized by , that the tachograph is configured to function as the digital tachograph (2) in a data transmission system (1) according to claim 8. [10] Motor vehicle with a digital tachograph (2) according to claim 9.

Citation Information

Patent Citations

  • Method and device for the transmission of data between a tachograph and a data processing device

    DE102006048029A1

  • tachograph, toll on-board unit, display instrument and system

    DE102007058163A1

  • Method and device for outputting representations of states relevant for the safe operation of a vehicle by means of an output module

    DE102019216030A1

  • Controller area network message authentication

    US10630481B2

  • Securing information exchanged between internal and external entities of connected vehicles

    US10735206B2