Computer-implemented procedure for secure data processing and information technology system

The computer-implemented method for secure data processing in vehicles addresses the risk of data misuse by encrypting and processing user data within a treuhand IT infrastructure's secured dedicated partition, ensuring secure and reliable data handling while protecting user privacy.

DE102023005091A1Pending Publication Date: 2025-06-12MERCEDES BENZ GROUP AG
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
DE102023005091
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-09
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

Existing methods for secure data processing in vehicles fail to adequately protect sensitive driving data from misuse, as they often require human intervention for key management, leading to risks of unauthorized access and data breaches.

Method used

A computer-implemented method for secure data processing that uses a treuhand IT infrastructure to encrypt user data generated by vehicles, stores it in a secured dedicated partition, and processes it using an analysis computer program product, ensuring that raw data is never accessible to humans or unauthorized systems.

Benefits of technology

This method significantly reduces the risk of data misuse by ensuring that sensitive user data is processed exclusively within a cryptographically secured environment, maintaining the privacy and security of vehicle users while enabling secure data analysis for third parties.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a computer-implemented method for secure data processing, wherein user data (2) generated by a vehicle (1) during use is cryptographically encrypted and stored at least temporarily in a trust IT infrastructure (3). The computer-implemented method is characterized by the following method steps: - Provision of a configuration file (4) by a third party (5) to the trust IT infrastructure (3); - providing an asymmetric key pair (8) by the third party (5); - providing an analysis computer program product (10) by the third party (5); - Reading the configuration file (4) by the trust IT infrastructure (3) and starting a user data collection defined by the configuration file (4); - Decrypting the third-party image (11) in the partition (12); - Decrypt the payload (2.enc) in the partition (12); - processing the user data (2) in the partition (12) with the analysis computer program product (10) to generate analysis data (13); and - Deleting at least the decrypted payload data (2) and transmitting the analysis data (13) to the third party (5), through the partition (12).
Need to check novelty before this filing date? Find Prior Art

Description

The invention relates to a computer-implemented method for secure data processing according to the type defined in more detail in the preamble of claim 1 and to an information technology system for executing the method.Modern vehicles are being equipped with an ever increasing number of sensors that allow large amounts of data to be collected, such as fuel consumption via engine performance up to a GPS position or driving behavior of a vehicle-guiding person. With the aid of wireless data transmission, this data can be transmitted to a vehicle-external location such as a cloud server and processed there. This makes it possible to obtain findings from the corresponding vehicle data and to use them in a beneficial manner. For example, the vehicle manufacturer can use the findings for the further development of individual vehicle components or vehicle systems.In addition, taps can be given to a vehicle-guiding person, in order to drive more efficiently and thus with a resource saving effect, how the driving behavior of the person's own can be improved. Thus, "bad" driving habits can be deposited. Information about the driving behavior can also be used by a insurance provider in order to offer tariffs dependent on the driving behavior for a motor vehicle insurance. Such insurance products are also referred to as pay-how-you-drive (PHYD) insurances.However, offering such insurance contracts requires a corresponding data processing of the driving data generated by the vehicle-guiding person during the use of their vehicle. This is especially sensitive data, since they relate to the personality right of the respective person and provide conclusions about the personal behavior and personal information. Thus, for example, the respective location of the person can be reconstructed from the GPS position determined in the vehicle for a previous period of time. Depending on the extent of the data obtained by a potential attacker, there is thus a risk of an identity theft or fraud. To prevent such misbruches, corresponding raw data should never leave the computing system used for data analysis. Ideally, the raw data should be treated in such a way that they cannot be viewed at any point from the elevation until corresponding findings are obtained by a human. This places great demands on the corresponding developers of respective data processing devices in order to simultaneously enable reliable data processing, but in the process to maintain the personality rights of the respective vehicle users and the data protection.DE 10 2019 220 244 A1 discloses a method for storing operating data of a motor vehicle. The method provides for encrypting the operating data arising during the use of a motor vehicle with a cryptographic key. In order to be able to decrypt the respective operating data, the participation of the vehicle driver is necessary. For this purpose, the operating data can be encrypted using an asymmetric key pair, the private key being transferred to the vehicle driver. The encryption of the operating data can take place in particular on a protected sphere of the vehicle driver, wherein the encrypted data can then be stored on any other data memory. The vehicle operator may pass his private key to a third party, such as a verifier, to provide the verifier with access to the operational data. However, the disadvantage here is that the private key of the vehicle driver is managed by one or more institutions, in particular humans. Thus, there is a high risk that the private key will be used and misutilized. Adequate data security is thus not possible.WO 2023 / 156005 A1 discloses a method for operating a central computer system. The publication likewise describes the gathering of usage data of the vehicles of a fleet of vehicles and storing these usage data in encrypted form on a server. The cryptographic key required for decrypting the usage data is managed by the server itself. A user can make an access request to the data via a corresponding input mask, whereupon the corresponding system enables access to the key for decrypting the usage data if the usage request is confirmed positively. For this purpose, it may be necessary for the respective user to have to present a cryptographic certificate. The cryptographic certificate can comprise the identity and / or a role description of the user. It is disadvantageous here once again that the corresponding usage data can be seen or processed by humans, so that the respective vehicle user must have confidence that respective persons charged with the processing of the usage data do not initiate any abuse therewith.The object of the present invention is to specify an improved computer-implemented method for secure data processing, by the use of which method the risk of abuse of the processed data can be reduced even further compared to solutions known from the prior art.According to the invention, this object is achieved by a computer-implemented method for secure data processing having the features of claim 1. Advantageous embodiments and refinements and an information technology system for executing the method are evident from the claims dependent thereon.A generic computer-implemented method for secured data processing, wherein user data generated by a vehicle during use are cryptographically encrypted and are at least temporarily stored in a treuhand IT infrastructure, has the following method steps according to the invention:providing a configuration file by a third party to the treuhand IT infrastructure, comprising at least one payload definition defining the amount of information to be included in the vehicle in the payload, and an identifier for each vehicle provided for collecting payload;providing an asymmetric key pair by the third party comprising a public and a private key, wherein the public key is stored in a key train managed by the trust IT infrastructure for access by the vehicles;providing, by the third party, an analysis computer program product comprising machine interpretable instructions for processing the decrypted payload, packing the analysis computer program product and the private key into a third party image, by the third party, and transmitting and storing the third party image in cryptographically encrypted form in a secured dedicated partition on the trust IT infrastructure;reading the configuration file by the trust IT infrastructure and starting a payload data collection in the respective vehicles defined by the configuration file by the trust IT infrastructure, wherein a respective vehicle reads the public key from the key train, encrypts payload data generated in the vehicle with the public key and transmits the encrypted payload data to the trust IT infrastructure for storage in the secured dedicated partition;decrypting the third party image in the partition;decrypting the user data in the partition with the private key;processing the payload data in the partition with the analysis computer program product to generate analysis data; anddeleting at least the decrypted payload and transmitting the analysis data to the third party, through the partition.The computer-implemented method according to the invention for secure data processing is based on the concept of preventing any access to corresponding raw data generated in the vehicle for humans or unauthorized IT systems. The processing of the corresponding user data takes place exclusively in the cryptographically secured dedicated partition on the trust IT infrastructure, so that a loss of unencrypted user data or also the misutilization of the user data by the trust IT infrastructure is reliably prevented.For this purpose, the user data are encrypted immediately following the generation in the vehicle within the vehicle and transmitted to the treuhand IT infrastructure via a secured channel. In particular, the encrypted user data is re-encrypted for this purpose. For example, a respective vehicle can have a telecommunication unit, via which the on-board electronics can be connected to the Internet by mobile radio, Wi-Fi or another suitable wireless communication technology. Corresponding communication protocols can be used for data transmission, such as in particular MQTT.The trust IT infrastructure can be, in particular, a server or server group. In the context, the treuhand IT infrastructure may also be referred to as a cloud environment. From the vehicle manufacturer's point of view, the treuhandle IT infrastructure forms a so-called backend. In order to start corresponding user data elevations in the respective vehicles, the treuhand IT infrastructure sends corresponding user data elevation signals to the respective vehicles of the vehicle fleet.In general, various third-party entities, such as insurance providers, a legal institution such as a dish, or the like, may be composed via a respective secured dedicated partition of the trust IT infrastructure. Such a dedicated partition can also be referred to as a so-called "secure cloud environment" or "secure cluster". Proven encryption methods implemented on the hardware and software side can be used to protect a respective dedicated partition from any unauthorized access. This means that there is no interface that allows a human to influence the operations occurring within the dedicated partition, in particular the reading out of processed data within the dedicated partition. Also, access by unauthorized computer systems to the data processed within the dedicated partition is not possible. Even the Trust IT infrastructure is unable to access the data processed in the dedicated partition, except for the dedicated data processing. Due to the hardware-side and software-side encryption, an improper access can thus be reliably prevented.The third party may be particularly interested in recognizing certain patterns in the respective user data and / or checking whether certain vehicle parameters lie within defined value ranges in certain situations. For example, parameters relevant to the driving behavior, such as the position of the accelerator pedal or brake pedal and / or the steering angle applied, can provide a strong indicator of how risky the driving style of the vehicle driver is. Accordingly, the analysis computer program product contains corresponding instructions for appropriately checking these patterns or vehicle parameters. It is generally no longer interesting for the third party to be able to read out the respective vehicle parameters or patterns as plain text. It can only be sufficient to check whether certain value ranges or patterns are present in the user data. Accordingly, the analysis data can describe that respective patterns or value ranges are or are not present within the payload data in a certain payload data packet or for a certain period of time. In general, however, the exact process for processing the decrypted user data does not play any role for the technical effect that can be achieved by the invention, that the information that is important for protection and is described by the user data is not to be used incorrectly, but in this case general processing is to be made possible.In order to enable seamless cryptographically secured processing of the user data, the user data must be processed within the secured dedicated partition. The program code used for processing the user data, i.e. the analysis computer program product, is likewise cryptographically encrypted in this case. The decoding of the analysis computer program product is likewise carried out, together with the user data, within the secured dedicated partition. The secured, dedicated partition then enables the processing of the user data with the analysis computer program product and the delivery of the corresponding analysis data. The processing of any raw data is thus carried out exclusively in the corresponding secured dedicated partition. Raw data cannot leave the secured dedicated partition to the outside. The analysis data are reduced in size compared to the payload data, in particular they have a fixed format. For example, the analysis data may be anonymousized or pseudonymized. The analysis data do not contain any information which jeopardize the data protection of the corresponding vehicle user or the personality rights thereof. The analysis data is transmitted back to the third party, which can now process the analysis data in order to obtain findings therefrom. For example, the third party is a insurance provider. This makes it possible to offer insurance rates dependent on the driving behavior, preserving data protection and personality rights.For communication with the treuhand IT infrastructure, the respective third party can use all usual computer systems such as a desktop computer, a server, a laptop, a smartphone, a tablet or the like. A connection of the respective third party or of the device used for data exchange is possible via proven communication interfaces. In particular, the treuhandle IT infrastructure provides a corresponding portal for the data exchange with the third party. This portal can be used via the Internet. In particular, any information exchanged between the treuhand IT infrastructure and the third party is transmitted cryptographically encrypted. Proven encryption mechanisms can be used for this purpose, such as PGP, AES, SSL and the like, in particular using a public key infrastructure (PKI).Thus, an advantageous development of the method according to the invention provides that the analysis data is transmitted to the third party in a cryptographically encrypted manner. In general, the analysis data in unencrypted form does not compromise the data protection or personality rights of the respective vehicle user, or at least not to the extent that the underlying raw data is. Thus, not only is there a lower cause for a potential attacker to waste the analysis data, but should an attacker get in possession of the analysis data, they contain information that is reduced in scope compared to the respective user data, so that the potential for abuse is also reduced. Nevertheless, there may also be an interest in cryptographically encrypting the analysis data in order to make inspection or processing by unauthorized entities even more difficult.According to a further advantageous embodiment of the method according to the invention, the treuhand IT infrastructure, in particular the dedicated partition, encrypts the analysis data with the public key of the third party. The third-party public key is present in any case in the treuhand IT infrastructure, so that it can be used accordingly for encrypting the analysis data. This reduces the effort in encrypting the analysis data. The third party is already in possession of the private key and is thus able to decrypt the analysis data encrypted with the public key again. In particular, here too, the analysis data is encrypted twice. Thus, the analysis data are first encrypted with the public key of the third party and then re-encrypted according to a cryptographic encryption method on which the communication protocol used for the data exchange with the third party is based, for example an SSL / TLS encryption carried out in connection with an https data transmission.A further advantageous embodiment of the method according to the invention further provides that the third party for each vehicle for which useful data is to be collected takes in the agreement of a respective vehicle user, includes the agreement in the configuration file and the trehand IT infrastructure starts the useful data collection only for those vehicles for which a respective agreement is present. As a result, abuse can be prevented even more reliably. It is thus not possible for user data to be collected from vehicles in which the respective vehicle user has not previously explicitly agreed to the data collection. In this context, the understanding is a corresponding digitally coded information. For example, it may be a stand-alone computer-readable file. Corresponding information can also be included in an already existing computer-readable file. In particular, this computer-readable file is likewise cryptographically secured in order to counteract manipulation. It is thus possible to prevent the agreement provided by a vehicle user from being artificially simulated or changed subsequently.For this purpose, the obtaining and checking of the agreement can preferably be carried out on the basis of an OAuth authorization. OAuth stands for open authorization and describes an open protocol for standardized secure API authorization. In addition to OAuth 1.0, there is now a further development in the form of OAuth 2.0, in particular using "OpenID Connect". With the aid of OAuth, it is possible for an end user to grant an application access to its data managed by another service without giving the application access to personal information such as a password for the corresponding service.A further advantageous embodiment of the method according to the invention further provides that the third party transmits an analysis data pattern to the treuhand IT infrastructure, defining criteria for the analysis data for maintaining a specific shape and / or a specific content, and the treuhand IT infrastructure, in particular the dedicated partition, carries out a control mechanism checking whether respective analysis data meet the criteria, wherein only such analysis data are enabled for leaving the treuhand IT infrastructure that meet the criteria. With the aid of the control mechanism thus provided, it is possible to check all information leaving the treuhand IT infrastructure for its conformance. Thus, it is possible to check, for example, whether such information is not nevertheless contained in the analysis data that could compromise the personality rights of a respective vehicle user and / or the data protection. It is also possible to determine whether the information actually required by the third party is contained in the respective analysis data. If this is not the case, the control mechanism can cause a fault reaction to be triggered, for example the sending of a fault or warning message to the third party and / or the operator of the Trauhand IT infrastructure. This enables the respective parties to take appropriate measures to initiate error recovery.According to a further advantageous embodiment of the method according to the invention, the vehicle identification number is used as an identifier for a respective vehicle. Using the vehicle identification number, reliable and unique identification of respective vehicles is possible.A further advantageous embodiment of the method according to the invention further provides that user data is collected in vehicles at intervals and transmitted to the treuhand IT infrastructure, in particular after a defined period of time has elapsed and / or when defined events arrive. This allows the amount of user data collected in the vehicle to be reduced. Thus, applicable data protection policies can be better complied with or complied with. Thus, only those data are collected which are actually required. In addition, the corresponding data are collected only when they are also needed. The collecting and transmission of corresponding user data can take place at defined times, i.e. for example at a defined frequency. For example, useful data corresponding to x minutes, x hours or x days can be collected and transmitted. It is also possible to link the raising and transmission of useful data to the arrival of events. For example, specific vehicle parameters can be defined, such as a specific acceleration value, for example, after the attainment of which the raising and sending of corresponding user data is to take place.In an information technology system, comprising a treuhand IT infrastructure, providing a communication interface to a third party, and at least one vehicle, the treuhand IT infrastructure and the vehicle are configured according to the invention to carry out a method described above. In order to obtain the respective information required by the third party, such as said configuration file and the third party image, the treuhand IT infrastructure thereby provides said communication interface. This can be, in particular, said online portal. The third party can proactively send the corresponding information or else, in particular automatically, initiated by a request from the trust IT infrastructure.Further advantageous embodiments of the computer-implemented method according to the invention for secured data processing and of the information technology system used for this purpose also result from the exemplary embodiments which are described in more detail below with reference to the figures.The following are shown: FIG. 1 is a schematic illustration of a data transmission process from a third party to a treuhand IT infrastructure; and FIG. 2 shows a schematic representation of the actors involved in a computer-implemented method according to the invention for secure data processing.Useful data 2 arising during vehicle use and depicted in FIG. 2 is data which is particularly necessary for protection. Such user data 2 can comprise or describe conclusions about the driving behavior of a vehicle-guiding person or also personal information such as the residential address or the working address. In order to maintain the data protection and personal interests of a respective vehicle user, therefore, the collection and processing of corresponding user data 2 should be reduced to a minimum and access to the respective data should be restricted. A computer-implemented method according to the invention is used for this purpose for secure data processing. By means of the computer-implemented method according to the invention, any access to the user data 2 is prevented both by persons and unauthorized computer systems. Data access is only still possible by the actual computer system carrying out the data analysis. Findings obtained by the data analysis are transmitted in the form of analysis data 13 (see likewise FIG. 2 ) to a third party 5 which is responsible for the data analysis.FIG. 1 shows a computer system 15 used by the third party 5, for example in the form of a desktop computer, a computer group, a server environment or the like. The third party 5 defines the respective information to be aggregated in the user data 2 via a user data definition 6. In addition, the third party 5 specifies a unique identifier 7 for each vehicle 1 shown in FIG. 2 in which user data 2 is to be collected. For example, the third party 5 is an insurance service provider who wishes to offer insurance tariffs dependent on the vehicle use. The height of the insurance policy may depend on the respective driving behavior of a vehicle user. If the respective vehicle user concludes the contract, he can communicate to the third party 5 the identifier 7 of his vehicle 1, for example in the form of the vehicle identification number.The identifier 7 can be present in the form of a list of a plurality of such vehicle identification numbers. It is thus possible to activate the corresponding payload collection in one step for a plurality of vehicles 1. Optionally, it may be necessary for a respective vehicle user to give his consent to collect corresponding user data 2. The third party 5 may collect a corresponding agreement 14, for example using an OAuth authorization. The payload data definition 6, the identifier 7 and the optional agreement 14 are packed by the third party 5 to form a configuration file 4 and transmitted to a treuhand IT infrastructure 3. For this purpose, a cryptographically secured communication channel is used in particular. The treuhand IT infrastructure is preferably a cloud environment provided by the vehicle manufacturer. This cloud environment may be provided by one or more servers.The configuration file 4 is stored on the treuhand IT infrastructure 3, preferably in a secured database 16.Furthermore, the third party 5 generates a key pair 8 of an asymmetric encryption method. The key pair 8 comprises a public key 8.1 and a private key 8.2. The public key 8.1 is likewise transmitted to the treuhand IT infrastructure 3 and stored there in a so-called key-fault 9. The key-train 9 can also be referred to as a key memory or key safe. The key-fault 9 is a protected sphere in which data, here in the form of the cryptographic keys 8 or 8.1, are stored cryptographically secured against access by unauthorized users. The respective vehicles 1 can access the key train 9 and thus read out respective public keys 8.1. This enables the user data 2 to be encrypted in the respective vehicles 1.Furthermore, the third party 5 provides an analysis computer program product 10 comprising machine-interpretable instructions for processing the user data 2. the analysis computer program product 10 is packaged together with the private key 8.2 to form a third party image 11 which is likewise transmitted, preferably via a secured communication channel, to the treuhand IT infrastructure 3. The third-party image can preferably be stored in a secured code memory 17.FIG. 2 illustrates the sequence of the computer-implemented method according to the invention. Indicated by an arrow 201, a new vehicle user 18 registers with the third party 5 and provides his respective identifier 7 and optionally said agreement 14. This information is transmitted from the third party 5 to the treuhand IT infrastructure 3.In step 202, the corresponding service activation takes place. For this purpose, the trust IT infrastructure 3, indicated by an arrow 203, obtains the configuration file 4 and the public key 8.1 from the secured database 16 and the key fault 9.The treuhand IT infrastructure 3 now controls the respective vehicles 1 of the fleet of vehicles of the vehicle manufacturer in order to start the corresponding payload collection. For this purpose, indicated by an arrow 204, a respective in-vehicle computing unit 19 is configured for data acquisition.The public key 8.1, indicated by an arrow 205, is stored in a key-train 9 in the vehicle 1. Corresponding user data 2, indicated by an arrow 206, are now collected and encrypted with the public key 8.1 in step 207.As the arrow 208 shows, the encrypted user data 2.enc are transmitted to the treuhand IT infrastructure 3. The encrypted user data 2.enc are supplied to a secured dedicated partition 12. This is a special instance on the trust IT infrastructure 3, which is protected from unauthorized accesses by hardware-side and software-side cryptographic safeguards. Proven cryptographic protection measures can be used for this purpose. A cache 20 is used to store the corresponding data.The third-party image 11 stored in cryptographically secured fashion is now read out of the secured code memory 17 and decoded. Known cryptographic encryption mechanisms are used for encrypting and decrypting the third-party image 11. Thus, the secured dedicated partition 12 receives access to the analysis computer program product 10 and the private key 8.2. With the aid of the private key 8.2, the encrypted user data 2.enc is now decrypted in step 209 and processed by the analysis computer program product 10. All of these steps take place within the secured dedicated partition 12, so that critical data cannot be picked up by an attacker at any point in the processing pipeline.As a result, the secured dedicated partition 12 supplies analysis data 13. Subsequently, a control mechanism 21 for checking the integrity of the analysis data 13 can optionally be carried out by the treuhand IT infrastructure 3. In this case, it is examined whether the analysis data 13 satisfy a specific format and / or have a content desired by the third party 5. The treuhand IT infrastructure 3 can receive corresponding specifications in advance from the third party 5 (not illustrated).Via a public end point 22, the third party 5 can now use a data consumer 23, indicated by an arrow 210, to pick off the analysis data 13 and obtain findings therefrom. In particular, the data transmission is also cryptographically secured here.Thanks to the method according to the invention, a secure and reliable data processing of particularly protectable person-related data is possible.References included in the specificationThis list of documents cited by the applicant has been produced in an automated manner and is only included for the better information of the reader. The list is not part of the German patent application or utility model application. The DPMA does not take any adhesion for any faults or omissions.Patent Literature citedDE 10 2019 220 244 A1

[0005] WO 2023 / 156005 A1

[0006]

Claims

Computer-implemented method for secured data processing, wherein useful data (2) generated by a vehicle (1) during use are cryptographically encrypted and are at least temporarily stored in a treuhand IT infrastructure (3), characterized bythe following method steps: - providing a configuration file (4) by a third party (5) to the treuhand IT infrastructure (3), comprising at least one useful data definition (6) defining the scope of the information to be included in the useful data (2) in the vehicle (1), and an identifier (7) for each vehicle (1) provided for collecting useful data (2); providing an asymmetric key pair (8) by the third party (5) comprising a public key (8.1) and a private key (8.2), wherein the public key (8.1) is stored in a key train (9) managed by the trust IT infrastructure (3) for access by the vehicles (1); providing an analysis computer program product (10) by the third party (5), comprising machine-interpretable instructions for processing the decrypted user data (2), packing the analysis computer program product (10) and the private key (8.2) to form a third party image (11) by the third party (5) and transmitting and storing the third party image (11) in cryptographically encrypted form in a secured dedicated partition (12) on the trusthand IT infrastructure (3) orchestrated by the partition (12); reading out the configuration file (4) by the treuhand IT infrastructure (3) and starting a payload data collection in the respective vehicles (1) defined by the configuration file (4) by the treuhand IT infrastructure (3), wherein a respective vehicle (1) reads out the public key (8.1) from the key fault (9), encrypts payload data (2) generated in the vehicle (1) with the public key (8.1) and transmits the encrypted payload data (2.enc) to the treuhand IT infrastructure (3) for storage in the partition (12); decrypting the third-party image (11) in the partition (12) by the partition (12); decrypting the user data (2.enc) in the partition (12) with the private key (8.2); processing the user data (2) in the partition (12) with the analysis computer program product (10) to generate analysis data (13); and deleting at least the decrypted user data (2) and transmitting the analysis data (13) to the third party (5), by the partition (12).Method according to Claim 1, characterized in that the analysis data (13) are transmitted to the third party (5) in cryptographically encrypted form.Method according to Claim 2, characterized in that the treuhand IT infrastructure (3), in particular the partition (12), encrypts the analysis data (13) using the public key (8.1) of the third-party (5).Method according to one of Claims 1 to 3, characterized in that the third-party (5), for each vehicle (1) for the user data (2) is to be collected, retrieves the agreement (14) of a respective vehicle user, includes the agreement (14) in the configuration file (4) and the treuhand IT infrastructure (3) only starts the user data collection for those vehicles (1) for which a respective agreement (14) is present.Method according to Claim 4, characterized in that the obtaining and checking of the agreement (14) takes place on the basis of an OAuth authorization.Method according to one of Claims 1 to 5, characterized in that the third-party (5) transmits an analysis data pattern to the treuhand IT infrastructure (3), defining criteria for the analysis data (13) for maintaining a specific shape and / or a specific content, and the treuhand IT infrastructure (3), in particular the partition (12), carries out a control mechanism (21) checking whether respective analysis data (13) meet the criteria, wherein only analysis data (13) which meet the criteria are released for leaving the treuhand IT infrastructure (3).Method according to one of Claims 1 to 6, characterized in that the vehicle identification number is used as an identifier (7) for a respective vehicle (1).Method according to one of Claims 1 to 7, characterized in that useful data (2) are collected in vehicles (1) at intervals and transmitted to the treuhand IT infrastructure (3), in particular after a fixed period of time has elapsed and / or when fixed events arrive.An information technology system comprising a treuhand IT infrastructure (3) providing a communication interface to a third party (5), and at least one vehicle (1), characterized in that the treuhand IT infrastructure (3) and the vehicle (1) are configured to perform a method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Method and system for managing user data of a user device

    DE102015103251A1

  • Automated procedure for the protection of electronic data for the purpose of data processing by third parties, including transparent and uninterruptible remuneration.

    DE102018204447A1

  • Method and device for the controlled provision of data and controlled evaluation of the provided data by an external arrangement

    DE102020204635A1

  • Concept for exchanging cryptographic key information

    DE102020205993B3