Interface device, vehicle with interface device and method to integrate a vehicle component into a vehicle with interface device

The interface device on-board vehicles simplifies the integration of vehicle components into encrypted communication systems by allowing on-site access and integration using public keys and certificates, addressing the complexity of existing systems and enhancing maintenance efficiency.

EP4414239B1Active Publication Date: 2025-08-06SIEMENS MOBILITY GMBH +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
EP2024154656
Authority / Receiving Office
EP · EP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-02-10
Filing Date
2024-01-30
Publication Date
2025-08-06
Estimated Expiration
2044-01-30

AI Technical Summary

Technical Problem

Existing vehicle communication systems, particularly in modern rail vehicles, require complex integration of vehicle components, especially when the system is encrypted, often necessitating external servers and data connections, which complicates maintenance and component replacement.

Method used

An interface device on-board the vehicle allows authorized operators to enter public keys and integrate vehicle components into the encrypted communication system, using a camera to read codes containing certificates or public keys, and a computing device to form a PKI server, enabling secure, on-site integration without external servers.

Benefits of technology

Facilitates easy and secure integration of vehicle components into encrypted communication systems, minimizing manual effort and eliminating the need for external data connections, ensuring seamless maintenance and replacement processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IMGF0001
    Figure IMGF0001
  • Figure IMGF0002
    Figure IMGF0002
  • Figure IMGF0003
    Figure IMGF0003
Patent Text Reader

Abstract

The invention relates, among other things, to a vehicle with a communication system (20) comprising an interface device (60).According to the invention, the communication system (20) is an encrypted communication system (20), the interface device (60) is arranged on board the vehicle and allows an authorized operator (70) on board the vehicle to access the communication system (20), and the interface device (60) is designed to enable the authorized operator (70) to input a public key (01-04) of an encryption key pair, the private key of which is implemented in a vehicle component (41-44) of the vehicle, and after input of such a public key (01-04), to integrate the corresponding vehicle component (41-44) into the communication system (20) of the vehicle, whereby its public key (01-04) is stored in the communication system (20).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for integrating a vehicle component into a communication system of a vehicle by means of an interface device, to interface devices for carrying out such methods and to vehicles equipped with such interface devices.

[0002] Modern rail vehicles and railway trains usually have an internal train data bus to which a large number of vehicle components are connected.

[0003] Such vehicles are known, for example, from US 2021 / 018909 A1 or WO 2019 / 219333 A1.

[0004] The invention is based on the object of specifying a vehicle in which the integration of vehicle components into a vehicle-side communication system, for example during assembly of the vehicle or later during repair work, is particularly easy, even if the communication system is an encrypted communication system.

[0005] This object is achieved according to the invention by a vehicle having the features according to claim 1. Advantageous embodiments of the vehicle according to the invention are specified in the subclaims.

[0006] According to the invention, the interface device is arranged on board the vehicle and allows an authorized operator on board the vehicle access to an encrypted communication system, and the interface device is designed to enable the authorized operator to enter a public key of an encryption key pair, the private key of which is implemented in a vehicle component of the vehicle, and to integrate the corresponding vehicle component into the communication system of the vehicle after entering such a public key, the public key of which is stored in the communication system.

[0007] A key advantage of the vehicle according to the invention is that the interface device provided according to the invention allows maintenance personnel to integrate vehicle components into the encrypted communication system on-site or on-board, without requiring the involvement of external trackside servers or a data connection between the vehicle and external trackside servers. This makes it particularly easy to replace vehicle components, for example, during maintenance work and integrate the new vehicle components with their new public keys into the vehicle's own communication system, because the establishment of secure data connections to the outside world is no longer necessary.

[0008] It is advantageous if the interface device enables the authorized operator to enter a certificate assigned to the vehicle component, which contains the public key and other data.

[0009] After entering such a certificate, the interface device integrates the vehicle component into the vehicle's communication system, preferably including the additional data.

[0010] The certificate preferably contains all the data required for automated integration of the respective vehicle component; in such a configuration, the manual effort required by the operating personnel can be minimized.

[0011] In an embodiment variant considered to be particularly advantageous, it is provided that the interface device comprises a camera which enables the reading of a one-dimensional or two-dimensional code which contains a certificate containing the public key of the vehicle component or at least the public key of the vehicle component.

[0012] The interface device preferably extracts the certificate or at least the public key from the code read by the camera.

[0013] The public keys or certificates of the vehicle components integrated or to be integrated into the communication system are preferably expiration-free or without an expiration date. Alternatively, the expiration dates of the keys or certificates can be virtually expiration-free because they are so far in the future that the theoretically conceivable or planned service life of the vehicle components ends before the expiration date is reached. Expiration-free or quasi-expiration-free keys and certificates avoid additional maintenance work that would be necessary if expiration dates were reached or exceeded.

[0014] To prevent keys from being altered improperly, it is considered advantageous if the private key of the encryption key pair is stored in the vehicle component in a non-rewritable manner.

[0015] The vehicle component preferably prevents deletion or overwriting of the private key or addition of other private keys via its communication interface connected to the communication system.

[0016] The certificate containing the public key preferably includes an identification code describing and / or identifying the vehicle component. The interface device integrates the vehicle component into the vehicle's communication system, preferably by including the identification code.

[0017] It is particularly advantageous if the certificate alone enables automated integration of the vehicle component into the communication system and the interface device automatically integrates the vehicle component into the vehicle's communication system after reading the certificate, including the identification information.

[0018] The certificate is preferably stored permanently in the vehicle component and cannot be changed.

[0019] It can also be provided that the interface device also enables the input of public keys or certificates from outside the vehicle; in this embodiment, the operator can therefore decide whether certificates or public keys should be made available in the vehicle or from outside the vehicle.

[0020] The interface device preferably comprises a computing device which is programmed by means of a software program product in such a way that the computing device forms a so-called PK (public key) infrastructure, in particular a PKI server, or provides the functionality of a PK (public key) infrastructure.

[0021] The interface device preferably has an input device that enables the operator to enter authorization data, for example in the form of a keyboard or a smart card reader.

[0022] The invention also relates to a method for integrating a vehicle component into a vehicle.According to the invention, with regard to such a method, it is provided that before or after the installation of the vehicle component in the vehicle, an interface device of an encrypted communication system located on board the vehicle carries out an authorization check on an input device of the interface device in response to an attempt to access the communication system by an on-board operator, the interface device, if authorization exists, allows the authorized operator to enter a public key of an encryption key pair that is implemented in the vehicle component of the vehicle that has already been installed or is still to be installed, and the interface device integrates the corresponding vehicle component into the communication system of the vehicle in terms of communication after the public key has been entered.

[0023] With regard to the advantages of the method according to the invention and advantageous embodiments of the method according to the invention, reference is made to the above statements in connection with the vehicle according to the invention and its advantageous embodiments.

[0024] The interface device preferably has a camera and detects the public key preferably by reading and evaluating the image data of the camera.

[0025] The camera can serve not only as an input device for key capture, but also, for example, as an input device for detecting an access attempt or for authorization verification. An access attempt can be detected, for example, based on the camera's image data if an operator performs predefined movements, such as waving. Authorization verification can include facial recognition, for example.

[0026] It is advantageous if a one-dimensional or two-dimensional code is depicted on the vehicle component, the code defines a certificate stored in the vehicle component in an unwritable manner or at least a public key stored in the vehicle component in an unwritable manner, and the interface device receives the certificate or the public key by reading and evaluating image data showing the code depicted on the vehicle component.

[0027] It is particularly advantageous if the vehicle component, as delivered, contains a removable sticker depicting a one-dimensional or two-dimensional code. The code applied to the sticker preferably defines the certificate stored in the vehicle component in a non-rewritable manner, or at least the public key stored in the vehicle component in a non-rewritable manner. The interface device preferably obtains the certificate or public key by reading and evaluating image data showing the sticker removed from the vehicle component and presented in front of the camera.

[0028] The invention also relates to an interface device for a vehicle equipped with a communications system. According to the invention, with regard to the interface device, the interface device is connectable to the communications system on board the vehicle and allows an authorized operator on board the vehicle access to the communications system. The interface device is designed to enable the authorized operator to enter a public key of an encryption key pair, the private key of which is implemented in a vehicle component of the vehicle, and, after entering such a public key, to integrate the corresponding vehicle component into the communications system of the vehicle, wherein the public key of the encryption key pair is stored in the communications system.

[0029] With regard to the advantages of the interface device according to the invention and advantageous embodiments of the interface device according to the invention, reference is made to the above statements in connection with the vehicle according to the invention and its advantageous embodiments.

[0030] It is advantageous if the interface device is designed to carry out a method as described above.

[0031] The invention is explained in more detail below using exemplary embodiments, which show, for example: Figure 1 shows, in a schematic representation, components of an embodiment of a rail vehicle according to the invention, which is equipped with an embodiment of an interface device according to the invention and on the basis of which an embodiment of a method according to the invention is explained, Figure 2 shows the rail vehicle according to Figure 1during the integration of a vehicle component into an encrypted communication system of the rail vehicle, Figure 3 the rail vehicle according to the Figures 1 and 2 after integrating the vehicle component, Fig. 4-7, the integration of further vehicle components into the communication system of the rail vehicle according to Figure 3 , Figure 8 a preferred mode of operation of the interface device according to the Figures 1 to 7 , Figure 9 in a schematic representation of components of a further embodiment of a rail vehicle according to the invention, Figure 10 a variant of the embodiment according to Figure 9 , and Figure 11 shows a preferred embodiment of the interface device according to the Figures 1 to 9 in more detail.

[0032] For the sake of clarity, the same reference numerals are used in the figures for identical or comparable components.

[0033] The Figure 1shows components of an embodiment of a rail vehicle 10 according to the invention, which is equipped with an encrypted communication system 20.

[0034] The communication system 20 comprises a data bus 30 to which a plurality of vehicle components are connected; for reasons of clarity, Figure 1 In the rail vehicle 10, only a first vehicle component 41 is shown by way of example. The vehicle components can communicate in an encrypted manner with a vehicle control unit 50 connected to the data bus 30 by means of the communication system 20. The vehicle control unit 50 is preferably an ATO (Automatic Train Operation) vehicle control unit 50, i.e., one that enables the rail vehicle to travel autonomously.

[0035] For the purpose of encrypted communication, a private key of a key pair is stored in each vehicle component connected to the data bus 30, which includes a public key in addition to the private key.

[0036] The public keys are preferably stored in the vehicle control unit 50 and / or in a central PKI server of the communication system 20, which can communicate the stored public keys to the vehicle control unit 50 upon request. Such a central PKI server can be integrated into an interface device 60 of the communication system 20.

[0037] The key pairs can be generated, for example, using an asymmetric cryptographic method such as the RSA (Rivest-Shamir-Adleman) method. The public key of the first vehicle component 41 is stored in the Figure 1 marked with the reference symbol O1.

[0038] The Figure 1 1 also shows in more detail the interface device 60 of the communication system 20 connected to the data bus 30. The interface device 60 is arranged on board the rail vehicle 10 and allows an authorized operator 70 to access the communication system 20 and enter public keys, in particular public keys of vehicle components that are already installed in the rail vehicle 10 or are still to be installed in the rail vehicle 10.

[0039] The interface device 60 is equipped with a camera 61 that can capture images and thus, for example, convert one- or two-dimensional codes into digital image data BD. A computing device 62 of the interface device 60 is connected to the camera 61 and evaluates its image data BD; in this way, the computing device 62 can recognize and further process codes located in front of the camera 61. The computing device 62 can form the aforementioned central PKI server.

[0040] The interface device 60 is in the embodiment according to Figure 1 also equipped with a keyboard 63 which allows manual entry of data D.

[0041] The keyboard 63 and the camera 61 form input devices of the interface device 60, which together or individually enable interaction with an operator, for example, detecting access attempts and enabling input of public keys or certificates.

[0042] The Figure 1 also shows a second vehicle component 42, which is held by an operator 70 and is to be mounted in the rail vehicle 10. It can be seen that a two-dimensional code 82, for example in the form of a QR code, is depicted on the surface of the second vehicle component 42.

[0043] The Figure 2The operator 70 on board the rail vehicle 10 is shown in front of the interface device 60, after an authorization check has already been performed by the interface device 60 to determine whether the operator 70 is authorized to register vehicle components and to enter public keys of vehicle components. Such an authorization check can include the entry of passwords on the keyboard 63 and / or an evaluation of biometric data of the face of the operator 70. The biometric data can be generated by evaluating the image data BD from the camera 61.

[0044] In the Figure 2The operator 70 is shown holding the code 82 of the second vehicle component 42 in front of the camera 61 so that the camera can capture the code 82 and forward image data BD reproducing the code 82 to the computing device 62. The computing device 62 recognizes the code 82 and evaluates it, determining the public key O2 assigned to the second vehicle component 42. It then stores the public key O2 in a key memory 80 of the communication system 20.

[0045] The key memory 80 can, for example, be integrated into the interface device 60 if the latter is to form the PKI server or assume the function of a PKI server. Alternatively or additionally, the key memory 80 can be integrated into the vehicle control unit 50; such an embodiment is shown by way of example in Figure 2 .

[0046] When designing according to Figure 2the interface device 60 transmits the public key O2 to the key memory 80 as soon as it has determined it from the read-in code 82.

[0047] In many cases, but not always, the complete integration of the second vehicle component 42 into the rail vehicle 10 or into the communication system 20 of the rail vehicle 10 will require the input of further data D, for example a designation of the second vehicle component 42 and / or a description of the function of the second vehicle component 42 and / or a description of the installation location of the second vehicle component 42. The input of such further data D can, for example, be carried out by the operator 70 on the keyboard 63 or by reading out a data memory which the operator 70 connects to a corresponding connection of the interface device 60.

[0048] The Figure 3shows the rail vehicle 10 after the input of the public key O2 and the further data D of the second vehicle component 42 has been completed and the operator 70 or another assembly person has installed the second vehicle component 42 in the rail vehicle 10. The second vehicle component 42 can, for example, be an axle speed sensor that is installed in the area of one of the axles of the rail vehicle 10. The further data D that the operator 70 enters into the interface device 60 preferably include the installation location of the second vehicle component 42, in particular when several vehicle components of the same type or with the same function have already been installed or are still to be installed in the rail vehicle 10.

[0049] The Figure 4 shows a third vehicle component 43, on whose surface a two-dimensional code 83 is depicted. The two-dimensional code 83 according to Figure 4 defines a certificate. The certificate according to Figure 4 In addition to the public key O3 of the third vehicle component 43, it comprises further data, preferably all those further data D that enable complete integration of the third vehicle component 43 into the communication system 20. Thus, unlike the second vehicle component 42, the third vehicle component 43 can be automatically integrated into the communication system 20 simply by presenting the code 83 in front of the camera 61, so that manual input of the further data D on the keyboard 63 or in any other way by the operator 70 is not necessary.

[0050] In other words, the advantage of a code that defines a certificate with the additional data D, compared to a code that only defines a public key, is that the operator 70 can effect the fully automated integration of the respective vehicle component simply by presenting the code that represents the certificate.

[0051] The Figure 5 shows the rail vehicle 10 after the interface device 60 has integrated the public key O3 of the third vehicle component 43 into the communication system 20 and the operator 70 or another assembly person has installed the third vehicle component 43 in the rail vehicle 10. The third vehicle component 43 can also be an axle speed sensor.

[0052] The Figure 6shows a fourth vehicle component 44, which has already been installed in the rail vehicle 10 before its public key O4 or certificate has been recorded. Unlike the third vehicle component 43, the fourth vehicle component 44 not only has a two-dimensional code 84 on its surface that defines a certificate, but also a removable sticker 90 that displays the same code 84.

[0053] After the fourth vehicle component 44 has been installed, the sticker 90 can be removed and the operator 70 can hold the removed sticker 90 in front of the camera 61 for the purpose of integrating the fourth vehicle component 44 into the communication system 20, in order to enable the computing device 62 to capture the certificate and integrate the fourth vehicle component 44, as explained in connection with Figure 3; presenting the removed sticker 90 in front of the camera 61 shows the Figure 7 .

[0054] The Figure 8 shows a flowchart of a preferred mode of operation of the interface device 60 in the case of reading in a code that only defines a public key, as described in the Figure 2 shown, or a certificate with further data, as described in the Figures 3 to 7 is shown.

[0055] After the interface device 60 has detected an access attempt ZV, it performs an authorization step 810 to check the authorization of the accessing operator 70. The authorization step 810 can include the evaluation 811 of inputs E of the operator 70 on the keyboard 63 and the evaluation 812 of image data BD of the operator 70.

[0056] If the authorization step 810 shows that the operator 70 is authorized to access the interface device 60, he or she carries out a reading step 820 in which he or she reads in a code C presented in front of the camera 61, which is assigned to a vehicle component to be integrated.

[0057] In a subsequent evaluation step 830, the interface device 60 checks whether the code only includes a public key. If this is the case, it requests, if necessary, the input of additional data D that are necessary for a complete integration of the vehicle component 41 or at least simplify this process. It then performs an integration step 840, in which it completes the integration of the vehicle component into the communication system by embedding the public key in the key memory.

[0058] If the evaluation step 830 shows that the code C already contains, in addition to the public key, the additional data that enable a complete integration of the vehicle component 41, the interface device 60 jumps directly to the integration step 840.

[0059] The above statements in connection with the Figures 1 to 8 apply analogously to multi-unit rail vehicles, i.e. railway trains. Figure 9 shows exemplary components of a railway train 100 equipped with an interface device 60 (for example, one as described above) and with vehicle components integrated into a communication system 20 (for example, such as the vehicle components 41-44 described above). The data bus 30 preferably extends through all carriages of the railway train 100.

[0060] In the embodiments described above, it can furthermore be provided that the interface device 60 additionally enables the input of public keys or the input of certificates from outside the vehicle, for example by radio using radio signals FF; this is shown by way of example in the Figure 10 using the example of train 100 according to Figure 9 .

[0061] The Figure 11 shows an embodiment of a computing device 62 which is used in the interface device 60 according to the Figures 1 to 7 and the Figures 9 to 10 can be used.

[0062] The computing device 62 comprises a computing unit 62a and a memory 62b. A software program product SPM is stored in the memory 62b, which, when executed by the computing unit 62a, results in the operation described above.

[0063] The software program product SPM according to Figure 11comprises an authorization software module SW810 which, when executed by the computing unit 62a, causes the latter to carry out the authorization step 810 in accordance with Figure 8 to execute.

[0064] The authorization software module SW810 preferably has an evaluation software module SW811 which, when executed by the computing unit 62a, causes the computing unit 62a to carry out the evaluation 811 according to Figure 8 of inputs E of the operator 70 on the keyboard 63.

[0065] The authorization software module SW810 preferably has, alternatively or in addition to the evaluation software module SW811, an evaluation software module SW812 which, when executed by the computing unit 62a, causes the computing unit 62a to carry out the evaluation 812 according to Figure 8 of image data BD of the operator 70 for the purpose of authorization verification.

[0066] The software program product also comprises a reading software module SW820 which, when executed by the computing unit 62a, causes the computing unit 62a to carry out the reading step 820 according to Figure 8 to execute.

[0067] The software program product further comprises an evaluation software module SW830 which, when executed by the computing unit 62a, causes the computing unit 62a to carry out the evaluation step 830 according to Figure 8 to execute.

[0068] The software program product SPM also comprises an integration software module SW840 which, when executed by the computing unit 62a, causes the computing unit 62a to carry out the integration step 840 according to Figure 8 to execute.

[0069] The software program product SPM is preferably configured such that the computing device 62 or its computing unit 62a forms a so-called PK (public key) infrastructure, in particular a PKI server, or provides the functionality of a PK (public key) infrastructure. The key memory 80, which is arranged in the vehicle control unit 50 in the figures, can in such a case—alternatively or additionally—be integrated into the memory 62b of the computing device 60.

[0070] Regardless of the grammatical gender of a particular term, persons with male, female or other gender identities are included. List of reference symbols

[0071] 10Rail vehicle 20Communication system 30Data bus 41Vehicle component 42Vehicle component 43Vehicle component 44Vehicle component 50Vehicle control unit 60Interface device 61Camera 62Computing device 62aComputing unit 62bMemory 63Keyboard 70Operator 80Key memory 82Code 83Code 84Code 90Sticker 100Railway train 810Authorization step 811Evaluation of inputs 812Evaluation of image data 820Reading step 830Evaluation step 840Integration step BDImage data CCode DData EInputs FFFradio signal O1public key O2public key O3public key O4public key SPMSoftware program product SW810Authorization software module SW811Evaluation software module SW812Evaluation software module SW820Reading software module SW830Evaluation software module SW840Integration software module ZVAccess attempt

Claims

1. Vehicle with a communication system (20) comprising an interface device (60), wherein - the communication system (20) is a communication system (20) which operates in an encrypted manner, - the interface device (60) is arranged on board the vehicle and permits an authorised operating person (70) on board the vehicle access to the communication system (20) and characterised in that - the interface device (60) is designed to enable the authorised operating person (70) to input a public key (O1-O4) of an encryption key pair, the private key of which is implemented in a vehicle component (41-44) of the vehicle, and after inputting such a public key (O1-04) to embed the corresponding vehicle component (41-44) into the communication system (20) of the vehicle, wherein its public key (01-04) is stored in the communication system (20).

2. Vehicle according to claim 1, characterised in that - the interface device (60) permits the authorised operating person (70) to input a certificate assigned to the vehicle component (41-44), said certificate containing the public key (01-04) and further data (D), and - after inputting such a certificate the interface device (60) embeds the vehicle component (41-44) into the communication system (20) of the vehicle by also including the further data (D).

3. Vehicle according to one of the preceding claims, characterised in that - the interface device (60) comprises a camera (61), which permits a one-dimensional or two-dimensional code (82-84), which contains a certificate containing the public key (01-04) of the vehicle component (41-44) or at least the public key (01-04) of the vehicle component (41-44), to be read in and - the interface deice (60) removes the certificate or at least the public key (01-04) from the code (82-84) read in by means of the camera (61).

4. Vehicle according to one of the preceding claims, characterised in that - the vehicle component (41-44) is connected to the communication system (20), - the private key (01-04) of the encryption key pair is permanently stored in the vehicle component (41-44) in a non-overwritable manner, and - the vehicle component (41-44) prevents a deletion or overwriting of the private key (01-04) or addition of another private key (01-04) by way of its communication interface which is connected to the communication system (20).

5. Vehicle according to one of the preceding claims 2 to 4, characterised in that - the certificate containing the public key (01-04) comprises an identification detail which describes and / or identifies the vehicle component (41-44), and - the interface device (60) embeds the vehicle component (41-44) into the communication system (20) of the vehicle by including the identification detail.

6. Vehicle according to claim 5, characterised in that - the certificate alone permits an automated embedding of the vehicle component (41-44) into the communication system (20) and - after reading in the certificate the interface device (60) automatically embeds the vehicle component (41-44) into the communication system (20) of the vehicle by including the identification detail.

7. Vehicle according to one of the preceding claims 2 to 5, characterised in that the certificate is permanently stored in an unchangeable manner in the vehicle component (41-44).

8. Vehicle according to one of the preceding claims 2 to 5, characterised in that the certificate in the vehicle component (41-44) is free of an expiry date or almost free of an expiry date because an expiry date is so far into the future that the theoretically conceivable or planned service life of the vehicle component (41-44) ends before reaching the expiry date.

9. Vehicle according to one of the preceding claims, characterised in that the interface device (60) also permits input of a public key (O1-O4) or input of certificates in addition also from outside of the vehicle.

10. Method for integrating a vehicle component (41-44) into a vehicle, wherein before or after assembly of the vehicle component (41-44) in the vehicle, an interface device (60) of a communication system (20) which operates in an encrypted manner and is located on board the vehicle, - the interface device (60) carries out an authorization check in response to an access attempt to the communication system (20) on the part of an on board operating person (70) on an input device of the interface device (60), characterised in that - with an existing authorisation the interface device (60) permits the authorised operating person (70) to input a public key (01-04) of an encryption key pair which is implemented in the vehicle component (41-44) which is already assembled or still to be assembled and - the interface device (60) embeds the corresponding vehicle component (41-44) after inputting the public key (O1-O4) in a communication-related manner into the communication system (20) of the vehicle.

11. Method according to claim 10, characterised in that the interface device (60) has a camera (61) and detects the public key (01-04) by reading in and evaluating the image data (BD) of the camera (61).

12. Method according to claim 11, characterised in that - a one-dimensional or two-dimensional code (82-84) is mapped on the vehicle component (41-44), - the code (82-84) defines a certificate stored in a non-overwritable manner in the vehicle component (41-44) or at least one public key (01-04) stored in a non-overwritable manner in the vehicle component (41-44), and - the interface device (60) obtains the certificate or the public key (01-04) by reading in and evaluating image data (BD) which shows the code (82-84) mapped on the vehicle component (41-44).

13. Method according to claim 11 or 12, characterised in that - in the delivery state the vehicle component (41-44) contains a removable sticker (90) on which a one-dimensional or two-dimensional code (82-84) is displayed, - the code (82-84) defines a certificate stored in a non-overwritable manner in the vehicle component (41-44) or at least one public key (01-04) stored in a non-overwritable manner in the vehicle component (41-44) and - the interface device (60) obtains the certificate or the public key (01-04) by reading in and evaluating image data (BD), which shows the sticker (90) removed from the vehicle component (41-44) and located in front of a camera of the interface device.

14. Interface device (60) for a vehicle which is equipped with a communication system (20), wherein - the interface device (60) on board the vehicle can be connected to the communication system (20) and permits an authorised operating person (70) on board the vehicle access to the communication system (20) and characterised in that - the interface device (60) is designed to permit the authorised operating person (70) to input a public key (O1-O4) of an encryption key pair, the private key (O1-04) of which is implemented in a vehicle component (41-44) of the vehicle, and after inputting such a public key (O1-O4) to embed the corresponding vehicle component (41-44) into the communication system (20) of the vehicle, wherein its public key (01-04) is stored in the communication system (20).

15. Interface device (60) according to claim 14, characterised in that the interface device (60) is designed to carry out a method according to claims 10 to 13.

Citation Information

Patent Citations

  • Method, devices, railway vehicle, computer program and computer-readable storage medium of storing network information

    EP3860078A1