Validating and combining data sets

The method validates and combines data sets from external sources for driver assistance systems using checksums, signatures, and an m-of-n signature concept, addressing the challenge of ensuring data quality and security, and enhancing system-level protection against tampering.

DE102023212350A1Inactive Publication Date: 2025-06-12ZF FRIEDRICHSHAFEN AG
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
DE102023212350
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-07
Publication Date
2025-06-12
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing driver assistance systems face challenges in ensuring the quality and security of data sets received from external sources, which are vulnerable to tampering by hackers.

Method used

A method for validating and combining data sets from multiple external sources for driver assistance systems, where data integrity is checked using checksums, signatures, and an m-of-n signature concept, and only validated data sets are combined and encrypted before transmission.

Benefits of technology

This approach significantly enhances data quality and security by ensuring that only validated data sets are used, making it more difficult for hackers to manipulate the data, and providing a robust system-level protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method for validating and combining data sets (4, 5, 6) for a driver assistance system (9) of a vehicle (8). The method comprises the steps: - generating a plurality of data sets (4, 5, 6), each of the data sets (4, 5, 6) originating from an external data source (1, 2, 3) located outside a vehicle (8) having a driver assistance system (9) for which the data sets (4, 5, 6) are intended, - Checking the data records (4, 5, 6) for their data integrity, - Validate the data records (4, 5, 6) if the data integrity check has resulted in a positive result, - generating a combined data set (23) by combining at least a selection of the data sets (4, 6) when a predetermined minimum number (m) of the plurality (n) data sets (4, 6) has been validated, and - transmitting the combined data set (23) to the vehicle (8) for use of the combined data set (23) in its driver assistance system (9).
Need to check novelty before this filing date? Find Prior Art

Description

The invention relates to validating and combining data sets. In this context, a method for validating and combining data sets for a driver assistance system of a vehicle is claimed.One of the most important aspects of ADAS / AD driving is the data that is processed in a vehicle to the best (safest, most efficient, most comfortable, shortest, etc.) Finding a trajectory. Some of these data may be captured by an on-board sensor, and some of these data may be received from external resources (such as infrastructure, V2X, etc.). Some of these data are important information (information about road surface, road construction, speed limits, etc.), whereas other data at first glance does not seem to be truly important (e.g., whether a shopping center is located nearby). Cyber security and tampering protection must be implemented for all these data in order to protect them from tampering by hackers or other attackers. This applies in particular to sensitive information.Typically, cyber security and tamper protection is implemented within the data source. This means that the data received from an external data source (e.g. from an infrastructural component) is considered to be secure data by the vehicle. This makes these data sources an interesting goal for hackers, attackers or other bous actors. Especially, when this data is used for a plurality of vehicles on the road (road condition information, congestion information, there is an accident on the road, etc.), the protection can be further enhanced in this kind of central system-level data generation protection concept.An object of the present invention can be seen in increasing the data quality and safety for data sets intended and configured to be used in driver assistance systems of vehicles. The object is achieved by the subject matters of the independent claims. Advantageous embodiments are the subject matter of the dependent claims, the following description and the figures.In accordance with the present invention, validation of data sets is proposed. The data sets are configured to be used in ADAS and in AD systems. ADAS stands here for "Advanced Driver Assistance Systems" (in Deutsche: Advanced Driver Assistance Systems). ADAS relate to vehicle technologies and systems that have been developed to improve safety and ride comfort. These systems use sensors, cameras, radar, and other advanced technologies to assist drivers in vehicle control. Examples of ADAS include lane keeping assist, adaptive cruise control, emergency brake assist, and parking assist systems. AD stands for "autonomous driving" (in the German: Autonomous driving). AD describes the ability of a vehicle to navigate and operate without human intervention. There are various levels of endoscopy ranging from level 0 (no endoscopy) to level 5 (full endoscopy). Vehicles at higher levels of autonomy may take over tasks such as accelerating, braking, steering, and even navigation without human intervention. Autonomous vehicle development involves complex technologies such as artificial intelligence, machine learning, and advanced sensing. In order to significantly increase the quality of the transmitted data sets, the present invention proposes combining a plurality of data sets which are transmitted by more than one data source with one another. In order to simultaneously increase the security, however, this combination should only take place when a predefined minimum number of the data records has been previously validated. In this sense, according to one aspect of the invention, a method for validating and combining data sets for a driver assistance system of a vehicle is provided.According to the method, a plurality of data sets are generated, each of the data sets originating in each case from a data source which is located outside a vehicle. The vehicle has a driver assistance system for which the data sets are determined. For example, a first data source can generate a first data set, a second data source a second data set and a third data source a third data set. The data records generated by the data sources contain information that can be used by the vehicle during the execution of the driver assistance system. The data sets may provide information about traffic scenarios, road conditions, driver behavior, and other relevant factors useful for understanding the environment and safe navigation of the vehicle, for example. In contrast to the data sources of the vehicle (such as cameras, radar or lidar), external data sources are involved in the present invention. Examples of external data sources are traffic infrastructure components (provided in particular by traffic authorities or service providers), e.g. traffic signs and traffic lights, but also, for example, a weather service. Furthermore, components of the so-called V2X communication (vehicle-to-everything) can be understood and used as an external data source. Here, information is exchanged between vehicles on the one hand and in particular traffic infrastructure components on the other hand. This allows vehicles to share information about road conditions, traffic, and other relevant data.The data records are checked for their data integrity. In particular, this comprises a check as to whether the data sets have been manipulated, which is explained in more detail below in connection with specific embodiments of the invention. The data records are validated if the checking of the data integrity has led to a positive result. A positive result is understood here to mean that the data integrity is classified as sufficiently high, in particular because, based on the checking of the relevant data set, there is no sufficient tampering with the relevant data set. If a predetermined minimum number of the data sets have been validated, then a combined data set is generated by combining at least one selection of the data sets. In this case, in particular all those data sets which have been validated can be combined with one another. The predetermined minimum number of data sets can in principle be freely selected. The higher it is selected with respect to a total number of data sources or data records, the higher the requirements for the data integrity or validity of the data records. The combined data set is transmitted to the vehicle so that the combined data set can be used in or by the driver assistance system of the vehicle.During the validation, a so-called m-of-n signature concept can be implemented. In this case, "n" is the number of possible data sources. "m" represents the number of those data sources which must deliver valid data sets or the number of valid data sets which must at least be present in order to generate the final combined data set to be transmitted and to transmit it to the vehicle. As an example of a 2-by-3 signature data transfer (m=2, n=3), one may consider three data sources (e.g., two infrastructure data sources and one C2X data source) involved in the transfer of data sets about the road condition of a region. In order for this information to be combined and transmitted, at least two of these three data sources must be present and send valid data sets. In this sense, according to one embodiment, it is provided that three (n=3) data sets originate from three (n=3) external data sources, wherein the predefined minimum number (m) assumes the value two. If two of the three data sets have been validated (m=2), then these two data sets are combined into the combined data set. If three of the three data sets have been validated (m=3), then these three data sets are combined into the combined data set. If, on the other hand, only one or none of the three data sets has been validated (m=1 or m=0) then none of the three data sets is combined to form the combined data set.The data sets may each contain, for example, information describing a property of a region within which the vehicle is moving. For example, the roadway on which the vehicle is traveling may be in the region. The data sources generate the data records in particular in such a way that the data records contain similar information (e.g. about the state of the roadway for a specific roadway segment in the region). "Similar information" can in particular mean that the information permits the same interpretation even if the information of the data records is of different nature. The information thus behaves complementarily as far as the interpretation is concerned. For example, a first data source with a first data record can describe the weather in the region, the second data source with a second data record can describe the condition of the roadway, and a third data source with a third data record can describe how high a coefficient of friction on the roadway is at most.The security can be increased once again significantly if the combined data record is encrypted to form an encrypted combined data record before it is transmitted to the vehicle. The data sets are in particular merged, validated, combined and encrypted (e.g. using a hash function such as SHA256) and then transmitted. After the encrypted data record has been transmitted to the vehicle, the encrypted data record can be decrypted by the driver assistance system to form the original unencrypted data record. This allows access to the original, validated data records again, for example, in order to generate a representation of the environment of the vehicle and / or to control the vehicle, in particular autonomously or semi-autonomously. An advantage of the encryption is that the data sources remain anonymous to an attacker and the data manipulation is made more difficult. This approach has a positive effect on data security by making it difficult for a hacker to attack a data source since the transmitted data is encrypted and the hacker does not know which data source has signed the data or who sent the data. This makes it more difficult for an attacker to manipulate the data.After the vehicle has received the combined data record, it can check the integrity of the combined data record and the validated data records of the data sources contained therein on the basis of signatures which for this purpose can be contained in particular in a data body of the combined data record. In other words, the validation can be checked with a type of signature of the data sources. In this sense, according to a further embodiment, it is provided that the data sets are provided by the data sources with a signature of that data source which generates the relevant data set, and the combined data set contains the signatures of those data sources whose data sets have been validated. The driver assistance system checks the signatures before it uses the signatures to perform a driver assistance function, e.g., for at least partially autonomous driving, braking, or steering of the vehicle.Validating may include checking transaction numbers of the records. When checking the transaction numbers, the so-called "nonce" can be used. "Nonce" stands for "number only used once" (number used only once) in the distributed ledger technology. In Ethereum and other blockchain platforms, the nonce refers to a number that is used only once for a particular transaction. Each transaction sent from an account has a unique nonce. This is to ensure that each transaction is processed in the proper order and not performed multiple times. The nonce typically begins with 0 and is incremented by 1 for each subsequent transaction. This helps maintain the integrity and order of transactions in the blockchain. If transactions (e.g., the data records sent from the data sources) appear in a wrong order at the vehicle, or if a transaction is submitted multiple times with the same nonce, then this may be interpreted by the vehicle as a potential tampering by a hacker or the like, and may result in data records relating to the vehicle not being validated.Further, validating may include checking a signature of the records. For example, public / private keys can be checked. If the signatures are correct, then the data record in question can be validated. Otherwise, a validation can be rejected and the corresponding data record cannot be transmitted, but instead can be identified accordingly and / or reported as a non-valid data record.Further, the validating may include checking a checksum of the data sets. The checksum (checksum) can be a number which is calculated from the data sets before they are transmitted from the data sources in order to be able to identify errors in the transmission of the data sets. If the data sets were damaged during their transmission between the data sources and the vehicle (e.g. by an attack by a hacker), the checksum will change and not match the original checksum. In this case, the validation can lead to a negative result, so that the relevant data record is not validated.Furthermore, it is also conceivable to perform the validation after collecting different data sets (e.g. two data sets from 2-out-3). Here, in terms of a data pool (e.g. a data server which can be operated by a public data operator, for example), a central data storage unit can be envisaged to which a plurality of data records from a plurality of data sources are added. In such a data pool, it is possible to check whether the data records are valid or not. If yes, then a combined record may be generated and signed by the data pool (e.g., a combined record from the two valid records mentioned above). This combined data record can contain in particular the hash data of the two valid data records (including. Signature). The combined data record can then be sent to the vehicle. The combined data record contains, for example, a data body which comprises, in particular, a signature of the data pool and the two hash data of the two data records or of their data sources. This can serve as evidence that the data pool has created the information based on the two valid records. The ego vehicle may check data integrity in this manner. In this sense, according to a further embodiment, it is provided that the data sets are collected on a central data storage unit, wherein the data sets are checked and validated by means of the central data storage unit, and wherein the combined data set is generated and transmitted by means of the central data storage unit.Exemplary embodiments of the invention are explained in more detail below with reference to the schematic drawing, wherein identical or similar elements are provided with the same reference numerals. This shows FIG. 1 shows a traffic system for the secure transmission of data, and FIG. 2 shows a sequence of an exemplary embodiment of a method according to the present invention.FIG. 1 shows a first data source 1, a second data source 2 and a third data source 3. These data sources 1, 2 and 3 are external data sources which are not arranged in or on a vehicle 8, which is intended to receive data sets 4, 5 and 6 from the data sources 1, 2 and 3, but rather outside this vehicle 8. Examples of infrastructural components are Roadside Units (RSU) and Intelligent Roadside Stations (IRS). The second data source 2 can be, for example, a weather service. The third data source 3 can be, for example, a vehicle driving in front. The preceding vehicle 3 travels in front of the vehicle 8 which is intended to receive data sets 4, 5 and 6 from the data sources 1, 2 and 3, and can communicate with the other data sources 1 and 2 via car to X (C2X) communication, for example.In a first method step 100 (FIG. 2 ), three data sets 4, 5 and 6 are generated. In this case, the first data source 1 generates a first data record 4, the second data source 2 generates a second data record 5 and the third data source 3 generates a third data record 6. The fact that the three data sources 1, 2 and 3 generate only one data record 4, 5 and 6, respectively, is purely exemplary. The three data sources 1, 2 and 3 can each also generate a plurality of data sets.The three data sources 1, 2 and 3 ideally generate data sets 4, 5 and 6 which contain similar information (e.g. about the state of the road for a specific roadway segment). "Similar information" can in particular mean that the information allows the same interpretation with respect to a property of an object (e.g. the roadway 7) in the environment of the vehicle 8, even if the information differs from one another. The information thus behaves complementarily as far as the interpretation is concerned. For example, the data record 4 generated by the first data source 1 (infrastructural component) can contain the information that the roadway 7 is wet, the data record 5 generated by the second data source 2 (weather service) can contain the information that it is raining in the region of the roadway 7, and the data record 6 generated by the third data source 3 (vehicle driving in front) can contain the information that the roadway 7 enables a coefficient of friction of at most 0.6.In a second method step 200, the three data sets 4, 5 and 6 are transmitted to a central storage unit 24. For this purpose, the three data sets 4, 5 and 6 can be encrypted beforehand in order to increase their security against attacks. The central storage unit 24 can be, for example, a data pool, for example a data server which is operated by a public data operator.In a third method step 300, the three data sets 4, 5 and 6 are checked by means of the central memory unit 24 with regard to their data integrity. If this check leads to a positive result, the relevant data record 4, 5 or 6 is validated, otherwise not. For this purpose, a processor unit 25 of the memory unit 24, for example, can be used, which is correspondingly instructed to do so by a computer program product 26. In the exemplary embodiment shown by FIG. 1, this computer program product 26 is stored in the memory unit 24 purely by way of example.The validation can include checking a checksum ("checksum"). In this case, for example, the three data sources 1, 2 and 3 can each apply a checksum algorithm 22 to the data sets 3, 4 and 5 during the generation of the three data sets 4, 5 and 6 in the first method step 100 in order to generate a checksum 10, 11 and 12 for each of the data sets 4, 5 and 6. This checksum algorithm 22 operates deterministically, i.e. it always generates the same checksum 10, 11 and 12 for the same data record 4, 5 and 6 (in unencrypted or encrypted form).During the validation in the third method step 300, the processor unit 25 of the central memory unit 24 can calculate validation checksums 13, 14 and 15 for the received three data sets 4, 5 and 6, for example by the processor unit 25 using the same checksum algorithm 22 as the three data sources 1, 2 and 3. The processor unit 25 can compare the newly calculated validation checksums 13, 14 and 15 with the received checksums 10, 11 and 12 contained in the data sets 4, 5 and 6. If the checksums match (first checksum 10 corresponds to first validation checksum 13, second checksum 11 corresponds to second validation checksum 14 and third checksum 12 corresponds to third validation checksum 15), then processor unit 25 can interpret this in such a way that received data sets 4, 5 and 6 have not been manipulated with a sufficiently high probability. In this case, the processor unit 24 will validate the data sets 4, 5 and 6. However, if one, more or all checksums 10, 11 and 12 do not match validation checksums 13, 14 and 15, this indicates that a respective data set 4, 5 or 6 could be corrupted or erroneous. In this case, the processor unit 25 will not validate the relevant data set or sets 4, 5 and 6.For the validation of the decrypted data records 4, 5 and 6, alternatively or additionally, for example a signature (e.g. public / private key) 16, 17 and 18 of the data records 4, 5 and 6 can be checked. The validation can also take place at least partially at the transmitter level in that the data sources 1, 2 and 3 validate their respective data sets 4, 5 and 6 themselves and provide only those data sets 4, 5 and 6 with the signature 16, 17 and 18 which have been validated. The processor unit 25 of the central memory unit 24 can check the signatures 16, 17 and 18 by a comparison, for example. If the signatures 16, 17 and 18 are correct, the data records 4, 5 and 6 are validated, otherwise not. Alternatively or additionally, for example, transaction numbers (e.g. nonces) 19, 20 and 21 of the data records 4, 5 and 6 can also be checked. For this purpose, the data sources 1, 2 and 3 can provide each data record 4, 5 and 6 with a transaction number 19, 20 and 21, respectively, which is checked by the processor unit 25 of the central memory unit 24. If, for example, the sequence of the transaction numbers 19, 20 and 21 is correct and the checked transaction number 19, 20 and 21 has not already been used previously, the data records 4, 5 and 6 are validated, otherwise not. The validation methods described above are merely exemplary and not intended to be exhaustive and further validation aspects exist which depend on the technology implemented in each case.After the validation of the individual data records 4, 5 and 6, a decision is made in a fourth method step 400 as to whether some or all three data records 4, 5 and 6 are combined with one another and the combination is carried out in the case of a positive decision. In such a combination of data sets, the information of the data sets combined with one another is combined in the combined data set. An m-out-of-n approach is used for this decision. "m" and "n" are here two variables, the arguments of which can each assume integers. In our example, m=2 and n=3. The variable n describes the total number of data sources, in our case the three data sources 1, 2 and 3. The variable m describes the number of those data sources whose data sets must be valid (in our example, they must be two of the three data sources 1, 2 and 3 or the data sets 4, 5 and 6), in order for the processor unit 25 of the central memory unit 24 to combine the validated data sets with one another. If, for example, based on the check of the checksums 10, 11 and 12, the first data record 4 (contains, for example, the information that the roadway 7 is wet) of the first data source 1 and the third data record 6 (contains, for example, the information that the roadway 7 enables a coefficient of friction of at most 0.6) of the third data source 3 have been validated, the criterion m=2 from n=3 is fulfilled. The first data record 4 and the third data record 6 are then combined with one another by the processor unit 25, so that a combined data record 23 is produced. The combined data record 23 then contains, for example, the information that the roadway is wet and enables a coefficient of friction of at most 0.6. The non-validated second data set 5 of the second data source 2 does not flow into the combined data set, but is ignored by the processor unit 25 and, if applicable, marked and / or reported as a faulty data set 5 of a faulty data source 2.If all three data sets 4, 5 and 6 had been validated, then the processor unit 25 would have combined all three data sets 4, 5 and 6 to form the combined data set 23. If only one of the three data sets 4, 5 and 6 had been validated, e.g. the first data set 4 or the third data set 6, then m=1 and thus the criterion m=2 would not be fulfilled. In this case, the processor unit 25 would have not combined any of the three data sets 4, 5 and 6 to form the combined data set 23. In the chosen example, a combination would also not be possible at all for a single valid data record 4. However, this is due to the example deliberately kept simple with only n=3 data sources. In an extended scenario, however, n=8 data sources could be available, for example, wherein a combination should only take place if at least m=6 data sets have been validated by the n=8 data sources. If the check reveals that, for example, only five of the eight data sources generate validated data sets, then no combination of the five validated data sets takes place.Following the combination, the combined data record 23 can be sent to the vehicle 8. In a fifth method step 500, however, the combined data record 23 is first encrypted to form an encrypted, combined data record 23'. The encrypted, combined data record 23' is then transmitted in a sixth method step 600 to the vehicle 8 or to its driver assistance system 9. The driver assistance system 9 decrypts the encrypted, combined data record 23' in a seventh method step 700 in order to restore the unencrypted data record 23 and to be able to access the information contained therein.In addition to the above-described data sets 4 and 6 or the information contained therein (e.g. wet roadway 7 having a maximum coefficient of friction of 0.6), the combined data set 23 can contain in particular a data body having hash data 27, 28 of the two valid data sets 4 and 6. Furthermore, the data body of the combined data set 23 contains, in particular, the first signature 16 of the first data source 1 and the third signature 18 of the third data source 3. This information can serve the driver assistance system 9 as evidence that the data pool 24 has created the information based on the two valid data sets 4 and 6. The vehicle 8 or its driver assistance system 9 can check the integrity of the data sets 4 and 6 in this way in an eighth method step 800. If this check has failed positively, then the driver assistance system 9 can use the information contained in the combined data set 23 in order, for example, to carry out an autonomous or semi-autonomous driving function in which, for example, an engine, a brake or a steering of the vehicle 8 can be controlled.Reference numerals denote reference numeralsm Minimum number of valid data sources / data sets n Total number of data sources / data sets 1 First data source 2 Second data source 3 Third data source 4 First unencrypted data set 5 Second unencrypted data set 6 Third unencrypted data set 7 Roadway 8 Vehicle 9 Driver assistance system 10 First checksum of first encrypted data set 11 Second checksum of second encrypted data set 12 Third checksum of third encrypted data set 13 First validation checksum of first encrypted data set 14 Second validation checksum of second encrypted data set 15 Third validation checksum of third encrypted data set 16 First signature of first data set 17 Second signature of second data set 18 Third signature of third data set 19 First transaction number of first data set 20 Second transaction number of second data set 21 Third transaction number of third data set 22 Checksum algorithm 23 Combined data set 23' Encrypted combined data set 24 Central storage unit 25 Processor unit 26 Computer program product 27 Hash value of first data set 28 Hash value of third data set 29 Signature of central storage unit 100 First method step 200 Second method step 300 Third method step 400 Fourth method step 500 Fifth method step 600 Sixth method step 700 Seventh method step 800 Eighth method step

Claims

Method for validating and combining data sets (4, 5, 6) for a driver assistance system (9) of a vehicle (8), the method comprising the steps of: - generating a plurality of (n) data sets (4, 5, 6), each of the data sets (4, 5, 6) originating in each case from an external data source (1, 2, 3) which is located outside a vehicle (8) which has a driver assistance system (9) for which the data sets (4, 5, 6) are intended, - checking the data sets (4, 5, 6) with regard to their data integrity, - validating the data sets (4, 5, 6) if the checking of the data integrity has led to a positive result, - generating a combined data set (23) by combining at least one selection of the data sets (4, 6) if a predefined minimum number (m) of the plurality of (n) data sets (4, 6) has been validated, and - transmitting the combined data set (23) to the vehicle (8) for use of the combined data set (23) in its driver assistance system (9).Method according to claim 1, wherein - three (n=3) data sets (4, 5, 6) originate from three (n=3) external data sources (1, 2, 3), - the predetermined minimum number (m) assumes the value two, - two of the data sets (4, 6) are combined to the combined data set (23) if these two data sets (4, 6) have been validated, - three of the data sets (4, 5, 6) are combined to the combined data set (23) if these three data sets (4, 5, 6) have been validated, and - none of the three data sets is combined to the combined data set (23) if less than two of the three data sets have been validated.The method according to claim 1 or 2, wherein the plurality of (n) data sets (4, 5, 6) each contain information describing a property of a region within which the vehicle (8) travels.Method according to one of the preceding claims, wherein the combined data record (23) is encrypted to form an encrypted data record (23') before it is transmitted to the vehicle (8).Method according to Claim 4, wherein the encrypted data record (23') is decrypted by the driver assistance system (9) to form the original unencrypted data record (23) after the encrypted data record (23') has been transmitted to the vehicle (8).Method according to one of the preceding claims, wherein - the data sets (4, 5, 6) are provided by the data sources (1, 2, 3) with a signature of that data source (1, 2, 3) which generates the relevant data set (1, 2, 3), - the combined data set (23) contains the signatures (17, 19) of those data sources (1, 3) whose data sets (4, 6) have been validated, and - the driver assistance system (9) checks the signatures (17, 19) before it uses the signatures (17, 19) for executing a driver assistance function.The method according to any of the preceding claims, wherein the validating includes checking transaction numbers (19, 20, 21) of the data sets (4, 5, 6).The method of any preceding claim, wherein validating includes checking a signature (16, 17, 18) of the records (4, 5, 6).Method according to one of the preceding claims, wherein the validation includes checking a checksum (10, 11, 12) of the data sets (4, 5, 6).Method according to one of the preceding claims, wherein - the data sets (4, 5, 6) are collected on a central data storage unit (24), - the data sets (4, 5, 6) are checked and validated by means of the central data storage unit (24), and - the combined data set (23) is generated and transmitted by means of the central data storage unit (24).

Citation Information

Patent Citations

  • Method, device and computer program for a vehicle

    DE102018221740A1

  • System and method for securely defending against collusive attack under internet of vehicles

    US20220279352A1

  • Misbehavior detection using data consistency checks for collective perception messages

    WO2022235973A1