Computer-implemented method and computer system for the automatic and tamper-proof documentation of vehicle data

DE102025130852B3Undetermined Publication Date: 2026-09-03TEPEG GMBH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
DE102025130852
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-08-04
Publication Date
2026-09-03
Estimated Expiration
2045-08-04

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a computer-implemented method for the automatic and tamper-proof documentation of vehicle data.The procedure comprises the following steps: Obtaining a vehicle identification number (VIN) of a vehicle by a server 100; Selecting a suitable read sequence for the vehicle 10 to read raw vehicle data using the VIN by the server 100; Sending the read sequence to a reader connected to a communication interface of the vehicle by the server 100 to read the raw vehicle data; Receiving the raw vehicle data read and signed by the reader 200 by the server 100; Translating the raw vehicle data into a data translation in a format suitable for further processing by the server 100; Generating a data record from the raw vehicle data and the data translation in a standardized format by the server 100. and signing 351 of the data record by the server 100 with a server certificate of the server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical field The invention relates to a computer-implemented method for the automatic and tamper-proof documentation of vehicle data. The invention further relates to a computer system configured to execute the computer-implemented method; a computer program that causes a computer system to execute the computer-implemented method; and a computer-readable storage medium containing the computer program. State of the art Methods are known from the prior art for reading vehicle data by connecting a reading device to an on-board diagnostics interface of the vehicle. Such methods are described, for example, in the publications US 2016 / 0 330 284 A1, GB 2 578 647 A, US 2013 / 0 246 135 A1 and US 11 158 138 B2. A particular disadvantage of established methods is that they require extensive user interaction with the diagnostic tool, making operation accessible only to technically trained users. Furthermore, it is not always possible to trace which raw diagnostic data was extracted and whether or how the vehicle data was altered after extraction. Additionally, many diagnostic tools are only compatible with specific vehicles, and the vehicle data is stored in different formats depending on the vehicle, complicating the analysis of data from various vehicles. Technical task The object of the invention is to create a universally applicable method and system with which vehicle data can be read and analyzed more easily, especially by untrained persons without special knowledge in the field of vehicle diagnostics, and documented in a tamper-proof manner. Technical solution The invention solves the technical problem by means of a computer-implemented method according to claim 1. Likewise, the problem is solved by a computer system according to claim 10, by a computer program according to claim 14, and by a computer-readable storage medium according to claim 15. Advantageous embodiments are the subject of the dependent claims. This process serves for the automatic and tamper-proof documentation of vehicle data. The process involves a server obtaining a vehicle identification number (VIN) from a vehicle. The vehicle is, for example, a motor vehicle, particularly an automobile. The server can comprise one or more physical and / or virtual servers, which may be located in one place or distributed across multiple locations. The data is obtained, for example, by reading and transmitting it using a reading device and / or by transmission from a user. The procedure involves the server selecting at least one suitable readout sequence for the vehicle to read raw vehicle data from a database, for example, using the vehicle identification number (VIN). The readout sequence includes, for example, a communication description for communicating with the vehicle's control units (ECUs), which may be contained in a diagnostic protocol, a transport protocol, and / or a bus protocol. The procedure involves the server sending the readout sequence, for example via a mobile network, to a reading device connected to a communication interface of the vehicle, for example an on-board diagnostics interface of the vehicle, in particular an OBD-2 socket of the vehicle, for reading the raw vehicle data. In some versions of the procedure, the server selects several readout sequences and sends the multiple readout sequences, in particular one after the other, to the readout device. The process involves the server receiving the raw vehicle data read out by the reading device, which has been signed and preferably time-stamped. The process involves translating the raw vehicle data into a data translation in a format suitable for further processing by the server. The process involves the server generating a data set from the raw vehicle data and translating the data into a standardized format, for example in XML format and / or in JSON format. The process involves the server signing the data record or a sub-data record of the data record with a server certificate issued by the server. The method preferably comprises timestamping the data record or a sub-data record of the data record by the server at the time of signing, wherein the timestamping preferably comprises applying a timestamp from a timestamping service to the data record. The data set preferably comprises, in the standardized format, the vehicle raw data, a signature of the reading device for the vehicle raw data, a public key of a device certificate of the reading device used for the signature of the reading device, a timestamp for the time of the signature by the reading device, the data translation, a signature of the server for the entire data set, a public key for a server certificate of the server used for the signature of the server and / or a timestamp for the time of the signature by the server. The procedure preferably includes storing the data record by the server in a database, the storage preferably being compliant with the General Data Protection Regulation (GDPR) of the European Union. Beneficial effects Because the server automates the process, user interactions with the reading device and / or the server are minimized, allowing even untrained users to use the process. By selecting a suitable readout sequence based on the vehicle identification number, the procedure can be used universally for any vehicle. Translating the raw vehicle data into a data translation, especially one that is standardized for the process, makes it possible to process and analyze data from different vehicles in a uniform way, thereby simplifying the further processing and analysis of the data. By signing and timestamping the data record, it is possible to reliably determine retrospectively when the raw vehicle data was translated, which system read the raw data, and when and by which system the translation of the raw data took place. Furthermore, the signatures prevent any undetected alteration of the data record. Embodiments of the invention The reading device preferably performs the following steps automatically, particularly in the order mentioned, as soon as the reading device is connected to the communication interface: Establishing a communication connection with the server; Receiving the readout sequence for reading the raw vehicle data from the server via the communication connection; Reading the raw vehicle data via the communication interface; Signing the raw vehicle data with a device certificate of the reading device and / or with a user certificate of the user received from a user device of a user of the reading device; Preferably timestamping the raw vehicle data at the time of signing; and / or sending the raw vehicle data to the server via the communication connection. The communication link is preferably established online, in particular via a mobile network, so that the procedure can be carried out regardless of the vehicle's location. Timestamping preferably involves applying a timestamp from a timestamping service to the raw vehicle data. By signing the raw vehicle data with the device certificate and timestamping it, it is possible to reliably determine when the raw vehicle data was read, thus preventing undetected manipulation of the data set. Signing with the user certificate allows for the reliable identification of who initiated the data readout. The user device includes, for example, a smartphone, a smartcard, and / or a USB, NFC, RFID, or Bluetooth token belonging to the user. By automatically performing the aforementioned steps as soon as the reader is connected to the communication interface, the operation of the reader is simplified, and manipulation of the raw vehicle data before sending the raw vehicle data to the server is excluded. The reading device preferably performs the following steps automatically, particularly in the order mentioned, as soon as the reading device is connected to the communication interface: reading the vehicle identification number via the communication interface; transmitting the vehicle identification number to the server via the communication link if the reading is successful, or transmitting a server error message to the server via the communication link and a user error message to a user of the reading device if the reading is unsuccessful; and, upon receipt of the server error message, providing a user input interface, preferably a website, for the user to transmit the vehicle identification number.The transmission includes, for example, manual entry of the vehicle identification number, transmission of a photo of the vehicle identification number and / or voice input of the vehicle identification number by the user. These steps allow the server to automatically obtain the vehicle identification number (VIN), thus avoiding user interactions that would complicate the process and make it more prone to errors. If automatic retrieval fails, the process can still be carried out by submitting the VIN via the user input interface. Reading the vehicle identification number preferably includes a diagnostic query according to an on-board diagnostic standard, for example the OBD-2 standard, and / or a check for the presence of control units of the vehicle and diagnostic communication with existing control units to query the vehicle identification number. The user error message preferably includes an acoustic signal, for example a beep, a sequence of beeps and / or a voice output, and / or a visual signal, for example a light signal and / or a graphic and / or textual screen display. Preferably, an access code, preferably a QR code, to the user input interface is attached to the reading device, and / or the access code is displayed by the reading device. The access code allows the user to easily access the user input interface, for example, by scanning the QR code with a smartphone. Establishing the communication connection preferably includes the server identifying the reader and / or verifying the reader's authorization to communicate with the server and / or the need to update the reader's software and / or configuration. Identifying the reader allows the server, for example, to provide a user input interface for the vehicle identification number (VIN) that matches an access code statically affixed to the reader. Authorization verification ensures that only authorized readers communicate with the server, preventing the server from receiving erroneous or harmful data that could impair its functionality. Furthermore, authorization verification protects against unauthorized users of the system injecting raw data into the data translation process. The method preferably comprises an automatic update of the software and / or configuration of the reading device, preferably directly after the communication connection is established and before the reading device performs any further steps. The software and / or configuration update of the reading device preferably occurs without user intervention and / or is device-specific. The software and / or configuration update preferably occurs without physical access to the reading device. This allows the reading device, for example, to be prepared for use with new vehicle types without user intervention, thus enabling long-term and easy use of the reading device. The method preferably includes the server shutting down the readout device after receiving the raw vehicle data, particularly after receiving all raw vehicle data acquired through multiple readout sequences. By initiating the shutdown, the server ensures that the readout device only shuts down once the server has received all necessary data. The shutdown process preferably includes the transmission of a completion message by the readout device to a user of the readout device. This completion message particularly preferably includes an acoustic signal, especially a beep, a sequence of beeps, and / or a voice output, and / or a visual signal, especially a light signal, and / or a graphic and / or textual screen display. The completion message preferably includes a status message, for example, visual and / or acoustic, to a user of the readout device. The status message indicates, for example, whether the server's reception of the raw vehicle data was successful, faulty, complete, or incomplete. The method preferably includes the creation of a human-readable report from the data set by the server, with the report being created, for example, in an HTML format and / or in a PDF format. The procedure preferably includes sending the report and / or the data set to a user of the reading device by the server, for example via an email and / or an application programming interface (API). The raw vehicle data includes, for example, the contents of an event data recorder, diagnostic data, fault codes, fault environment data, measured values ​​from a control unit and / or mileage information of the vehicle and / or an aging state and / or a state of charge of an energy storage device, in particular a battery, of the vehicle. The invention relates to a computer system configured to execute a computer-implemented method according to an embodiment of the invention, wherein the computer system comprises at least one server configured to execute the steps performed in the method by the server mentioned in the method. The computer system preferably comprises at least one readout device which is configured to perform the steps carried out in the method by the readout device mentioned in the method. The diagnostic tool preferably includes a connection element for connecting the diagnostic tool to the vehicle's communication interface, wherein the connection element is preferably designed to supply the diagnostic tool with power from the communication interface. Thus, the diagnostic tool can advantageously be operated without a separate power supply. The connection element includes, for example, an OBD-2 connector. The reading device preferably includes a reading module for communication with the vehicle via the vehicle's communication interface, in particular for reading the vehicle's raw data via the communication interface. The reading device preferably includes a communication module for establishing a communication connection with the server, wherein the communication module preferably comprises a cellular module, a WiFi module and / or a Bluetooth module. The communication module advantageously allows the reading device to be used regardless of location. The reading device preferably comprises a local certificate storage and / or a hardware token, preferably permanently installed in the reading device, comprising a device certificate of the reading device. The reading device preferably comprises an output module for outputting a user error message and / or an access code, preferably comprising an acoustic signal and / or a visual signal, to a user of the reading device. The output module includes, for example, a loudspeaker, a speech output unit, at least one indicator light, and / or a screen. The reading device preferably does not include a user input interface. This prevents incorrect operation of the reading device and manipulation of the raw vehicle data by the user. The reading device preferably comprises a receiving module for receiving a user certificate of a user of the reading device from a user device of the user, for example from a smartphone, from a smartcard and / or from a USB, NFC, RFID or Bluetooth token of a user; wherein the receiving module preferably comprises an RFID reader, a USB interface, a Bluetooth interface and / or an NFC interface. The reading device preferably comprises a computing unit, comprising, for example, at least one processor and one working memory, for executing the steps of the procedure to be performed by the reading device. The server preferably includes a local certificate store and / or a hardware token, particularly one permanently installed in the server, comprising a server certificate of the server. The server preferably includes a data storage device for storing the raw vehicle data, the data translation, the data set consisting of the signed raw vehicle data and the data translation, and / or a human-readable report generated from the data set, for example in a database, with storage preferably being GDPR-compliant. The data storage can be physical and / or virtual, as well as localized and / or distributed. The server preferably comprises at least one computing unit, comprising, for example, at least one processor and one working memory, for executing the steps of the procedure to be performed by the server. The server preferably includes an output interface for outputting the data set and / or a human-readable report, in particular an HTML report and / or a PDF report, from the data set to a user of the reading device, for example by sending an email to the user. The server preferably includes one or more application programming interfaces (APIs), in particular for outputting the data set and / or a human-readable report and / or for administrative configuration of the reading device. The invention relates to a computer program that causes a computer system to execute a computer-implemented method according to an embodiment of the invention when the computer system executes the computer program. The invention relates to a computer-readable storage medium containing a computer program according to an embodiment of the invention. Brief description of the drawings Further advantages, objectives, and features of the invention are explained with reference to the following description and accompanying drawings, which illustrate exemplary embodiments of the invention. Fig. 1 shows a schematic representation of a computer system according to one embodiment of the invention. Fig. 2 shows a schematic representation of a computer-implemented method according to one embodiment of the invention. Fig. 1 Fig. 1 shows a schematic representation of a computer system according to one embodiment of the invention. The computer system shown includes a reading device 200 for reading raw vehicle data from a vehicle 10. The reading device 200 shown includes a connection element 210, for example an OBD-2 connector, for connecting the reading device 200 to the communication interface of the vehicle 10. The reading device 200 shown includes a reading module 220 for communication with the vehicle via the communication interface of the vehicle 10, in particular for reading the raw vehicle data. The reading device 200 shown includes a communication module 221 for establishing a communication connection 222 with a server 100, wherein the communication module 221 includes, for example, a mobile communication module. The reading device 200 shown includes a local certificate storage 230 containing a device certificate of the reading device 200. The reading device 200 shown includes a computing unit 270 for controlling the reading device, in particular for reading the vehicle raw data, for signing and / or timestamping the vehicle raw data and / or for forwarding the vehicle raw data via the communication link 222 to the server 100. Optionally, the reader 200 can include a receiver module 250 for receiving a user certificate from a user device 20, for example, a smart card and / or a USB token. The receiver module 250 includes, for example, a USB interface and / or an NFC interface. The reading device 200 shown includes an output module 240, in particular for outputting a user error message and / or an access code, wherein the output module 240 includes, for example, a speech output device and / or a screen. The server 100 shown includes a local certificate store 130 containing a server certificate of server 100. The server 100 shown comprises a computing unit 170 for controlling the server 100, in particular for selecting at least one readout sequence suitable for the vehicle 10 for reading the raw vehicle data using a vehicle identification number, for sending the readout sequence to the readout device 200, for translating the raw vehicle data into a data translation, for generating a data record 191 from the raw vehicle data and the data translation, for signing and / or timestamping the data record 191 and / or for creating a human-readable report 192, 193 from the data record 191. The server 100 shown includes a data storage device 160 for storing the raw vehicle data, the data translation, data record 191 and / or the report, for example in a database. The data storage device 160 can also contain read sequences for reading raw vehicle data from different vehicles depending on their vehicle identification number. The server 100 shown includes an output interface 190 for outputting the data record 191 and / or an HTML report 192 and / or a PDF report 193 from the data record 191 to a user of the reading device 100, for example by sending an email to the user. The server shown (100) can include one or more application programming interfaces (APIs) (180). Fig. 2 Fig. 2 shows a schematic representation of a computer-implemented method for documenting vehicle data of a vehicle 10 according to an embodiment of the invention. The procedure shown begins with the establishment of a communication connection 222 between the reader 200 and the server 100. This establishment may include a check 301 by the server 100 to determine whether a software and / or configuration update 302 of the reader 200 is necessary, and / or whether a vehicle identification number (VIN) for the vehicle 10 is available. If an update 302 is necessary (+), the reader 200 is updated 302, possibly followed by a restart 303 of the reader 200. If no update 302 is necessary (-) and no vehicle identification number is available (-), the check 301 is followed by a reading 310 of the vehicle identification number from a control unit 11 of the vehicle 10 by the reading device 200. If the reading operation 310 fails (-), a server error message 311 is transmitted to server 100 and a user error message is sent to a user of the reading device 200 by the reading device 200. The transmission of the error messages 311 may be followed by a restart 303 of the reading device 200. If the check 301 shows that a vehicle identification number already exists (+) or if the reading 310 of the vehicle identification number is successful (+), the reading device 200 transmits the vehicle identification number 312 to the server 100. Once the server 100 has received the vehicle identification number, the server 100 selects at least one suitable readout sequence for the vehicle 10 to read the raw vehicle data of the vehicle using the vehicle identification number and sends the readout sequence to the reader 200. Once the readout device 200 has received the readout sequence, the readout device 200 reads 330 the vehicle raw data from at least one control unit 11 of the vehicle 10, signs 331 the vehicle raw data with a device certificate of the readout device 200, and optionally with a user certificate from a certificate store 20 connected to the readout device 20, and sends 332 the vehicle raw data to the server 100. The server 200 receives the raw vehicle data (340) and then translates the raw vehicle data into a data translation (341) by the server 100. If further readout sequences exist for the vehicle identification number (+), the server 100 can also perform a selection 320 and the subsequent steps for each of the further readout sequences. If no further read sequences are available for the vehicle identification number (-), server 100 generates a data record 191 from the raw vehicle data and the data translation, followed by signing and preferably timestamping the data record 191 by server 100. Server 100 can then store the data record. Server 100 performs a creation 352 of a human-readable report 192, 193 from the data set 191 and a sending 353 of the report 192, 193 to a user of the reading device 200, for example by email. The procedure may include a query to determine whether an API transmission of data record 191 and / or report 192, 193 is desired. If an API transmission is desired (+), the procedure involves server 100 sending data record 191 and / or report 192, 193 via API 354. If the query is not intended or no API transmission is desired (-), the sending of 353 is followed by the termination of the procedure 355. List of reference symbols 10 Vehicle 11 Control Unit 20 User Device 100 Server 130 Certificate Store (Server) 160 Data Store 170 Computing Unit (Server) 180 API 190 Output Interface 191 Data Record 192 HTML Report 193 PDF Report 200 Readout Device 210 Connection Element 220 Readout Module 221 Communication Module 222 Communication Connection 300 Establish 301 Check 302 Update 303 Restart 310 Read (VIN) 311 Transmit (Error Message) 312 Transmit (VIN) 320 Select 321 Send (Readout Sequence) 330 Read (Vehicle Raw Data) 331 Sign (Vehicle Raw Data) 332 Send (Vehicle Raw Data) 340 Receive 341 Translate 350 Generate 351 Sign (Data Record) 352 Create 230 Certificate Store (Reader) 240 Output Module 250 Receive Module 270 Computing Unit (Reader) 353 Send (Report) 354 API Send 355 Exit

Claims

A computer-implemented method for the automatic and tamper-proof documentation of vehicle data, comprising the following steps: a. Receiving a vehicle identification number (VIN) of a vehicle by a server (100); b. Selecting (320) at least one read sequence suitable for the vehicle (10) to read (330) raw vehicle data from the vehicle using the VIN by the server (100); c. Sending (321) the read sequence by the server (100) to a read device (200) connected to a communication interface of the vehicle to read (330) the raw vehicle data; d. Receiving (340) the raw vehicle data read and signed by the read device (200) by the server (100); e. Translating (341) the raw vehicle data into a data translation in a format suitable for further processing by the server (100); f.Generating (350) a data record (190) from the vehicle raw data and the data translation in a standardized format by the server (100); and signing (351) the data record (190) by the server (100) with a server certificate of the server. A computer-implemented method according to claim 1, wherein the readout device (200) automatically performs the following steps as soon as the readout device (200) is connected to the communication interface: a. Establishing (300) a communication connection (222) with the server (100); b. Receiving the readout sequence for reading the vehicle raw data from the server (100) via the communication connection (222); c. Reading (330) the vehicle raw data via the communication interface; d. Signing (331) the vehicle raw data with a device certificate of the readout device (200) and / or with a user certificate of the user received from a user device (20) of a user of the readout device (200); e. Timestamping the vehicle raw data at the time of signing; and f. Sending (332) the vehicle raw data to the server (100) via the communication connection (222). A computer-implemented method according to claim 2, wherein the reading device (200) automatically performs the following steps as soon as the reading device (200) is connected to the communication interface: a. Reading (310) the vehicle identification number via the communication interface; b. Transmitting (312) the vehicle identification number via the communication link (222) to the server (100) if the reading is successful, or transmitting (311) a server error message via the communication link (222) to the server (100) and a user error message to a user of the reading device (200) if the reading is unsuccessful; and c. Providing, by the server (100) upon receipt of the server error message, a user input interface, preferably a website, for the user to transmit the vehicle identification number. Computer-implemented method according to claim 3, a. wherein the reading (310) of the vehicle identification number comprises a diagnostic query according to an on-board diagnostic standard and / or a check for the presence of control units of the vehicle and diagnostic communication with existing control units to query the vehicle identification number; b. wherein the user error message comprises an acoustic signal and / or a visual signal; and / or c. an access code, preferably a QR code, to the user input interface on the reading device (200) is provided and / or displayed by the reading device (200). A computer-implemented method according to any one of claims 2 to 4, wherein the establishment (300) of the communication link (222) comprises identifying the readout device (200) by the server (100) and / or verifying (301) by the server (100) the authorization of the readout device (200) to communicate with the server (100) and / or the need to update software and / or configuration of the readout device (200). Computer-implemented method according to one of claims 1 to 5, wherein the method comprises timestamping the data record (190) by the server (100) at the time of signing. A computer-implemented method according to any one of claims 1 to 6, wherein the method comprises shutting down the readout device (200) by the server (100) after receiving the raw vehicle data, wherein the shutdown preferably comprises transmitting a completion message by the readout device (200) to a user of the readout device (200), wherein the completion message particularly preferably comprises an acoustic signal and / or optical signal. A computer-implemented method according to any one of claims 1 to 7, wherein the method comprises creating (352) a human-readable report (192, 193) from the data set (190) by the server (100), wherein the method preferably comprises sending (353) the report (192, 193) to a user of the reading device (200) by the server (100). Computer-implemented method according to any one of claims 1 to 8, wherein the vehicle raw data comprises contents of an event data storage device, diagnostic data, fault codes, fault environment data, measured values ​​of a control unit and / or mileage information of the vehicle and / or an aging state and / or a state of charge of an energy storage device of the vehicle. A computer system configured to execute a computer-implemented method according to any one of claims 1 to 9, wherein the computer system comprises a server (100) configured to execute the steps performed in the method by the server (100) mentioned in the method. Computer system according to claim 10, wherein the computer system comprises a readout device (200) configured to perform the steps carried out by the readout device (200) mentioned in the method, the readout device (200) comprising: a. a connection element (210) for connecting the readout device (200) to the communication interface of the vehicle (10), wherein the connection element (210) is preferably designed to supply the readout device (200) with energy from the communication interface; b. a readout module (220) for communicating with the vehicle (10) via the communication interface of the vehicle (10), preferably for reading the raw vehicle data; c. a communication module (221) for establishing a communication connection (222) with the server (100), wherein the communication module (221) preferably comprises a mobile communication module; and d.a local certificate store (230) and / or a hardware token comprising a device certificate of the read device (200). Computer system according to claim 11, the readout device (200) comprising: a. an output module (240) for outputting a user error message and / or an access code, preferably comprising an acoustic signal and / or an optical signal, to a user of the readout device (200); b. no user input interface for a user of the readout device (200); and / or c. a receiver module (250) for receiving a user certificate of a user of the readout device (200) from a user device (20) of a user, wherein the receiver module (250) preferably comprises an RFID reader, a USB interface, a Bluetooth interface and / or an NFC interface. Computer system according to one of claims 10 to 12, the server (100) comprising: a. a local certificate store (130) and / or a hardware token comprising a server certificate of the server (100); and / or b. a data storage device (160) for storing the vehicle raw data, the data translation, the data set (190) from the signed vehicle raw data and the data translation and / or a human-readable report generated from the data set (190). Computer program that causes a computer system to execute a computer-implemented method according to any one of claims 1 to 9 when the computer system executes the computer program. A computer-readable storage medium containing a computer program according to claim 14.

Citation Information

Patent Citations

  • Encrypted automotive data

    GB2578647A

  • Method and system for preserving and processing vehicle crash data evidence

    US11158138B2

  • System, device and method of remote vehicle diagnostics based service for vehicle owners

    US20130246135A1

  • Systems and methods for server based processing of on board diagnostics (OBD) data

    US20160330284A1