Communication units and associated communication system for communication between road users
Patent Information
- Application Number
- EP2024709383
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-03-10
- Filing Date
- 2024-03-05
- Publication Date
- 2026-01-14
AI Technical Summary
Current communication systems between road users, particularly between motorized vehicles and vulnerable road users (VRUs), face challenges in ensuring secure and reliable data exchange over different communication standards, which can lead to inadequate accident prevention and awareness, especially when relying on limited bandwidth and security concerns.
The system employs dual communication units with separate transmission and receiving units for long-range (4G/5G/LoRaWaN) and short-range (Bluetooth, UWB) connections, using cryptographic information to secure and verify status information like position and movement data, allowing secure data exchange and enabling both secure and non-secure data transmission based on trustworthiness assessments.
This approach enhances accident prevention by providing secure and reliable data exchange between road users, ensuring safety-critical applications can utilize redundant, low-latency communication paths, reducing the burden on limited bandwidth and improving acceptance among motor vehicles.
Smart Images

Figure EP2024055720_19092024_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] title
[0003] Communication units and associated communication system for communication between road users
[0004] State of the art
[0005] In the future, there will be increasing communication between motorized vehicles, with this communication taking place both over long distances, e.g., via 4G and 5G, and over short distances, e.g., via the Wi-Fi-based ITS-G5 standard or the Sidelink included in 4G / 5G starting with Release 14. A primary goal of this communication is accident prevention through increased awareness, warnings, coordinated maneuvers, and automated interventions. Automated vehicles will require such technologies, which can be used, for example, as a substitute for eye contact.
[0006] Consideration could also be given to involving vulnerable road users (VRUs) in this communication. This could also help prevent accidents between motorized vehicles and VRUs, such as bicycles or pedestrians.
[0007] The following approaches can and are currently being pursued:
[0008] • Using a 4G / 5G-based approach, smartphones can be configured to send the VRU's position and direction to a server, which calculates collision probabilities or forwards them to nearby road users. Warnings can be sent back from the server if necessary. Cycle computers can communicate directly with motorized road users, as is the case with ITS-G5 and PC5, for example.
[0009] • Bluetooth radio connections can be provided by VRLIs, but only information is sent from the VRU and no warning can be given to the VRLI.
[0010] Disclosure of the invention
[0011] The first communication device according to the invention for a first road user comprises a first transmitting unit which is configured to transmit information via a first type of radio connection, a second transmitting unit which is configured to transmit information via a second type of radio connection, and a control unit of the first communication device which is configured to transmit cryptographic first information associated with the first road user via the first transmitting unit and to transmit status information associated with the first road user together with cryptographic second information via the second transmitting unit, wherein the cryptographic first information is suitable for verifying the status information by means of the cryptographic second information.
[0012] The second communication device according to the invention for a second road user comprises a first receiving unit which is configured to receive information via a first type of radio connection, a second receiving unit which is configured to receive information via a second type of radio connection, and a control unit which is configured to receive cryptographic first information associated with a first road user via the first receiving unit, to receive status information associated with the first road user together with cryptographic second information via the second receiving unit, and to verify the status information based on the cryptographic first information using the cryptographic second information.
[0013] The method according to the invention for communication between a first road user and a second road user comprises transmitting cryptographic first information belonging to the first road user from the first road user to the second road user by means of a first type of radio connection, transmitting status information belonging to the first road user together with cryptographic second information from the first road user to the second road user via a second type of radio connection, wherein the cryptographic first information is suitable for verifying the status information by means of the cryptographic second information, and verifying the status information based on the cryptographic first information by means of the cryptographic second information by the second road user.
[0014] The status information is information that describes a status or characteristic of the first road user. The status information is preferably information that is transmitted as part of a V2X communication. The status information is, in particular, position and / or movement information of the first road user. Position information is any information that describes a position of the first road user, where the position can be described as an absolute or relative position. Movement information is any information that describes a movement of the first road user. The movement of the first road user can be described, for example, by an acceleration, speed, or trajectory of the road user.
[0015] The first communication device comprises the first transmitting unit, which is configured to transmit information via the first type of radio connection. The second communication device comprises the first receiving unit, which is configured to receive information via the first type of radio connection. The first type of radio connection is based on a different communication standard than the second type of radio connection. The first type of radio connection is a direct or indirect radio connection between the first transmitting unit of the first communication device and the first receiving unit of the second communication device. An indirect radio connection is a radio connection in which the communication is forwarded via an intermediate unit. The first type of radio connection is preferably a 4G, a 5G, a WiFi, or a LoRaWaN communication connection.This also includes the Sidelink communication connection included in 4G / 5G from Release 14.
[0016] The first communication device comprises the second transmitting unit, which is configured to transmit information via the second type of radio connection. The second communication device comprises the second receiving unit, which is configured to receive information via the second type of radio connection. The second type of radio connection is a direct radio connection. The second type of radio connection is, in particular, a broadcast communication originating from the first communication device. The second type of radio connection is, in particular, a Bluetooth, UWB, ITS-G5, or PC5 communication connection.
[0017] The second type of radio connection and the first transmitting unit of the first communication device and the first receiving unit of the second communication device used for this purpose are preferably provided for communication over greater distances, while the second transmitting unit of the first communication device and the second receiving unit of the second communication device are provided for communication in the near field of the first communication device.
[0018] The first communication device and the second communication device each comprise a control unit, which is, for example, a computing unit, by which the actions of the respective communication device are coordinated. The first cryptographic information is suitable for securely assigning the status information of the first road user provided via the second type of radio connection or, optionally, for preventing eavesdropping on the data. The first cryptographic information thus also comprises, in particular, information suitable for signing data in order to confirm its affiliation with the first communication device of the first road user. The first cryptographic information associated with the first road user serves to establish a secure data exchange with the second communication device of the second road user.The cryptographic information can thus secure the data exchange in such a way that, if possible, no other units can send information on behalf of the first road user.
[0019] The status information has been signed and / or encrypted or similarly secured by the first road user in such a way that it can be read using the cryptographic first information or at least securely assigned to the first road user. In this case, the data exchange is a secure data exchange.
[0020] The subclaims show preferred developments of the invention.
[0021] Preferably, the first transmitting unit of the first communication device is configured to transmit information to a communication server via a radio network, and the control unit of the first communication device is configured to transmit the first cryptographic information to the communication server. Further preferably, the second transmitting unit is configured to transmit the status information together with the second cryptographic information to the second road user via a direct radio connection. It is also advantageous if the first receiving unit of the second communication device is configured to receive information from a communication server via a radio network, and the control unit of the second communication device is configured to receive the first cryptographic information from the communication server.The communication server is preferably an application server or a geoserver. The communication server is preferably configured to forward the status information and / or the cryptographic second information partially or completely to another server for processing or evaluation. Further preferably, the second receiving unit is configured to receive the status information together with the cryptographic second information from the first road user via a direct radio connection. The communication devices are thus configured to transmit information via a radio network and exchange it via a communication server. The radio network is, in particular, a mobile radio network.The communication server is, in particular, an internet server that can be contacted via an internet connection provided by the wireless network in order to upload or download data to or from it. In particular, the application server sends messages to the second communication device to transmit the first cryptographic information.
[0022] The first communication device is preferably a mobile unit, in particular a bicycle computer or a smartphone. The mobile unit is a unit that can be carried by a user, even if they are not traveling in a motor vehicle. In this case, the user is considered a vulnerable road user. The first road user is preferably a pedestrian or a cyclist. More preferably, the second road user is a motor vehicle. The second communication device of the second road user is in particular a communication device that is also used in the context of V2X communication for transmitting information, in particular position and / or movement information.
[0023] Preferably, the first cryptographic information associated with the first road user comprises a digital certificate, and the second cryptographic information sent to the second road user comprises a hash value generated based on the digital certificate. In this way, a secure data exchange can be enabled for the road users, preferably via a certificate server, wherein the second communication device is enabled to ensure that the received status information was actually sent by the first road user and not by another entity. The control unit of the first communication device is preferably configured to sign the status information based on the first cryptographic information by calculating the second cryptographic information based on the status information.The control unit of the second communication device is preferably configured to use the cryptographic first information to check whether the status information corresponds to the cryptographic second information. In other words, this means that the status information is signed by the first communication device and the signature is checked by the second communication device. The first transmitting unit of the first communication device is preferably configured for transmission over a greater range than the second transmitting unit of the first communication device. The first receiving unit of the second communication device is preferably configured for transmission over a greater range than the second receiving unit of the second communication device. This means that the radio connection of the first type can bridge a greater range than the radio connection of the second type.Thus, the initial cryptographic information can already be transmitted via the first type of radio connection before any communication can even take place via the second type of radio connection. The initial cryptographic information is thus already available when needed to verify the state information.
[0024] Preferably, the first transmitting unit of the first communication device is configured to transmit larger data packets than the second transmitting unit of the first communication device. Likewise, the first receiving unit of the second communication device is configured to transmit larger data packets than the second receiving unit of the second communication device. Thus, the radio connection of the first type is preferably suitable for transmitting larger data packets, preferably over longer ranges, than the radio connection of the second type. Preferably, the radio connection of the second type is suitable for transmitting data packets with a lower latency than the radio connection of the first type.Larger data packets can preferably be transmitted via the first transmitting unit of the first communication device, but not as frequently as the comparatively smaller data packets transmitted by the second transmitting unit of the first communication device. This allows the packet size of the second wireless connection to be significantly reduced or even made possible in the first place by using hashes instead of full certificates. For example, in a Bluetooth Low Energy (BLE) wireless connection with extended advertising, a maximum of approximately 255 bytes can be transmitted in one data packet.
[0025] Preferably, the control unit of the second communication device is configured to use the status information received from the first road user via the second receiving unit for different support functions, depending on whether the status information can be successfully verified using the cryptographic second information. It is therefore advantageous if the status information of the first road user is received by the second communication device even if it cannot be reliably assigned to the first road user because the necessary cryptographic first information is not available. This can be the case in particular if this information was not transmitted from the first road user to the communication server, was not provided to the second communication device by the communication server, or radio communication of the first type is not possible.This allows the second communication device to decide for itself how to use the received state information. For example, the received state information can either be ignored or used only for non-safety-critical applications if verification is not possible.
[0026] It is therefore advantageous if the control unit of the second communication device is configured to use the status information received from the first road user via the second receiving unit for different support functions, depending on whether this information was received via a secure data exchange or a non-secure data exchange. Support functions are functions provided to a user by the second communication device. For example, the second communication device provides a user with a collision warning function, which alerts a user of the second communication device to possible collisions with the road user.For example, whether received position and / or movement information is used for such a warning message of a collision warning function can be decided by the second communication device.
[0027] An information system is also advantageous which comprises the first communication device and / or the second communication device and further comprises the communication server. In this case, the communication server is preferably configured to transmit the cryptographic first information associated with the first road user to the second communication device in response to a predefined first condition being met, wherein the predefined first condition is met in particular when the communication server has information which indicates an expected data exchange between the first communication device and the second road user via the second type of radio connection. It is therefore not necessary for the communication server to transmit all available cryptographic first information of different road users to the second communication device at all times.Only when it can be assumed that the second communication device intends to enter into a data exchange with the first road user is the first cryptographic information transmitted from the communication server to the second communication device. It is advantageous, for example, if position and / or movement information is continuously transmitted from the second communication device and the first communication device to the communication server. The first cryptographic information of the first road user is transmitted to the second communication device when the first communication device and the second communication device approach each other.
[0028] Preferably, the communications server is configured to prevent the transmission of the cryptographic first information associated with the first road user to the second road user in response to the existence of a predefined second condition. The predefined second condition is particularly fulfilled when the communications server has information that suggests limited trustworthiness of the first road user. For example, the communications server detects unusual behavior by the road user. In this way, it can be determined whether the road user is actually providing trustworthy information or whether the intention is to deceive other road users.However, trustworthiness is not limited to communication characteristics, but can be assessed, in particular, based on the provided state information when it is transmitted to the communication server. If trustworthiness is rated as low, the first cryptographic information is not provided by the communication server to the second communication device. However, it is up to the second communication device to decide whether the received state information is nevertheless used for certain support functions.
[0029] Short description of the drawings
[0030] Embodiments of the invention are described in detail below with reference to the accompanying drawings. In the drawing:
[0031] Figure 1 is a schematic representation of a communication system comprising communication devices according to the invention,
[0032] Figure 2 is a flowchart of a method according to the invention for communication between two communication devices, and
[0033] Figure 3 is a schematic representation of another
[0034] Communication system comprising communication devices according to the invention.
[0035] Embodiments of the invention
[0036] Figure 1 shows a communication system according to the invention. This system comprises a first communication device 10 according to the invention, a second communication device 20 according to the invention, and a communication server, which here is, for example, an application server 50.
[0037] The first communication device 10 is associated with a first road user 1 and is, for example, a bicycle computer of a bicycle. Alternatively, the first communication device 10 is a smartphone, which is, for example, arranged on a bicycle or carried by a pedestrian. The first communication device 10 comprises a first transmitting unit 11, which is configured to transmit information to the application server 50 via a radio network 40. Optionally, the first communication device 10 comprises a receiving unit associated with the first transmitting unit 11 of the first communication device 10 in order to receive information from the application server 50 via the radio network 40. The radio network 40 is a mobile radio network.
[0038] The second communication device 20 is associated with a second road user 2 and is, for example, a V2X unit of a motor vehicle. The second communication device 20 comprises a first receiving unit 21 configured to receive information from the application server 50 via the radio network 40. Optionally, the second communication device 20 comprises a receiving unit associated with the first receiving unit 21 of the second communication device 20 for receiving information from the application server 50 via the radio network 40.
[0039] Furthermore, the first communication device 10 comprises a second transmitting unit 12, which is configured to transmit information via a direct radio connection to a second receiving unit 22 of the second communication device 20. The second transmitting unit 12 of the first communication device 10 enables a direct radio connection to the second receiving unit 22 of the second communication device 20. This means that information can be transmitted from the first communication device 10 of the first road user 1 to the second road user 20 directly and without an intermediary device. Optionally, the first communication device 10 also comprises a second receiving unit, which is assigned to the second transmitting unit 12 and enables information to be received from the second communication device 20 via the direct radio connection.The first road user 1 and the second road user 2, together with the communication device arranged therein, are optionally part of the communication system.
[0040] Thus, communication over greater distances to the application server 50 is enabled via the first transmitting unit 11 of the first communication device 10. Short-range communication is enabled by the second transmitting unit 12 of the first communication device 10 or by the second receiving unit 22 of the second communication device 20. Communication via the radio network 40 is a first-type radio connection, and the direct radio connection is a second-type radio connection. The first-type radio connection is, for example, a communication connection based on the 4G or 5G standard. The second-type radio connection is, for example, a communication connection based on a V2X standard, a Bluetooth connection, or a UWB connection. The second-type radio connection preferably has a lower latency than the first-type radio connection.
[0041] The first road user 1 transmits first cryptographic information associated with the first road user 1 to the application server 50. This occurs via the radio network 40. Furthermore, the first communication device 10 transmits status information of the first road user 1 to the second receiving unit 22 of the second communication device 20 by means of the second transmitting unit 12 of the first communication device 10. The status information is, for example, position information of the first road user 1. Furthermore, the first communication device 10 transmits second cryptographic information of the first road user 1 to the second receiving unit 22 of the second communication device 20 by means of the second transmitting unit 12 of the first communication device 10.The cryptographic first information is suitable for verifying the state information using the cryptographic second information. For example, the cryptographic second information is a hash value or a signature of the state information calculated based on a certificate provided by the first cryptographic information. The cryptographic first information is suitable for verifying the state information using the cryptographic second information. For example, the cryptographic first information associated with the first road user 1 is either:
[0042] Encryption information or comprise a certificate, which enables at least a unique identification of the first road user 1 during communication. The first cryptographic information associated with the first road user 1 is provided by the first road user 1 to the application server 50 at any time, for example, when the first communication device 10 is put into operation. The first cryptographic information associated with the first road user 1 is stored by the application server 50.
[0043] The first communication device 10 transmits position information of the first road user 1 to the application server 50. For this purpose, the first communication device 10 comprises a control unit 13, which detects the position information of the first road user 1, for example, using associated sensors. Position information of the second road user 2 is also transmitted to the application server 50. The position information includes a position of the second road user 2.
[0044] The application server 50 checks whether a predefined first condition is met. This is the case when the first road user 1 is located in a defined area around the second road user 2, for example, is approaching within 100 m of the second road user 2. Whether this first condition is met can be determined by the application server 10 based on the position information of the first road user 1 and the position information of the second road user 2. If the first condition is met, the cryptographic first information associated with the first road user 1 is transmitted via the radio network 40 to the second communication device 20. Accordingly, the cryptographic first information associated with the first road user 1 is received via the first receiving unit 21 of the second communication device 20, ora control unit 23 associated with the second communication device 20. From this point on, the second communication device 20 can establish a data connection secured by means of the received cryptographic first information for a secure data exchange with the first communication device 10 of the first road user 1. In particular, the control unit 23 of the second communication device 20 can verify whether the status information received by the first communication device 10 of the first road user 1 was actually transmitted by the first communication device 10 of the first road user 1. It should be noted that the predefined first condition is selected here as an example.Alternative conditions could, for example, be defined such that cryptographic first information of the first road user 1 is transmitted to the second communication device 20 when it is requested by the second communication device 20, for example, because a directly transmitted signal is received by the first communication device of the first road user 1. Any first condition is advantageous which suggests that data exchange between the first communication device 10 and the second communication device 20 should take place via the direct radio connection, i.e., the second-type radio connection.
[0045] The control unit 23 of the second communication device 20 receives the status information, for example, position and / or movement information of the first road user 1, via the second transmission unit 22 of the second communication device 20. The position and / or movement information is secured, in particular signed, by means of the received cryptographic information of the first road user 1 and can thus be reliably assigned to the first road user 1.
[0046] The status information of the first road user 1 received from the first road user 1 is either evaluated by the second communication device 20 or transmitted to the application server 50 together with the second communication device 20's own position and / or movement information. Based on the status information of the first road user 20, warnings can be issued by the second communication device 20, which, for example, enable a collision warning if a collision between the first and second road users 1, 2 could be imminent. The corresponding evaluation is preferably carried out by the second communication device 20 or alternatively by the application server 50, wherein corresponding information is transmitted from the application server 50 to the second communication device 20 if the evaluation is carried out by the application server 50.The application server 50 prevents the transmission of the first cryptographic information associated with the first road user 20 to the second communication device 20 in response to the presence of a predefined second condition. For example, the application server 50 can perform an evaluation that allows a conclusion to be drawn as to whether the first road user 1 is providing reliable status information. Whether the status information is reliable or not can be determined either based on the status information itself or based on the first cryptographic information. For example, unreliable status information can be assumed if the first cryptographic information includes an invalid certificate or if the status information indicates an unrealistic movement of the first road user 1.If this evaluation suggests that the status information associated with the first road user 1, for example, the position and / or movement information provided by the first road user 1, does not appear to be reliable, the application server 50 can decide not to forward the cryptographic first information of the first road user 1 to the second communication device 20. Any condition that suggests limited trustworthiness of the first road user 2 is suitable as the second condition.
[0047] If the second communication device 20 does not have any cryptographic first information associated with the road user 1, the received status information cannot be verified. In this case, the second communication device 20 can decide whether the status information received from the first road user 1 is to be used for specific support functions, for example, by not transmitting it to the application server 10 or by not taking it into account in a local evaluation. In particular, received status information is used for different support functions depending on whether it could be verified. This also includes the possibility that status information that could not be verified is not used for any support function.This allows, for example, a user of the second communication device 20 to decide whether to display collision warnings regarding the first road user 1. Optionally, safety-relevant support functions can also be enabled only if the status information can be verified.
[0048] Preferably, cryptographic information of the second road user is transmitted from the second communication device 20 to the application server 10. In addition, status information of the second road user 2, along with associated cryptographic information, is optionally also transmitted to the first communication device 10. The transmission of status information can thus be carried out from the second road user 2 to the first road user 1 in the same manner as was previously described for the transmission of status information from the first road user 1 to the second road user 2.
[0049] Figure 1 shows the data connections used within the information system. A first data connection 31 is established via the radio network 40 from the first road user 1 to the application server 50. The first cryptographic information of the first road user 1 can be transmitted to the application server 50 via this first data connection 31.
[0050] A second data connection 32 is established between the application server 50 and the second road user 2 via the radio network 40. The cryptographic first information of the first road user 1 can be received by the second road user 2 via the second data connection 32.
[0051] A third data connection 33 is established between the first road user 1 and the second road user 2, via which the status information transmitted by the first road user 1 can be received by the second road user 2 together with the cryptographic second information. The third data connection 33 is a secure data connection so that the second road user 2 has the necessary associated cryptographic first information from the first road user 1 in order to verify this. Optionally, a fourth data connection 34 is established between the first road user 1 and the second road user 2, via which the status information transmitted by the second road user 2 can be received by the first road user 2 together with cryptographic information.The fourth data connection 34 is optionally a secure data connection, which has been secured in a corresponding manner, as has the third data connection 33.
[0052] Thus, the cryptographic information for secure data exchange is exchanged via a direct radio connection over a non-direct radio connection, here via the radio network 40. This makes it possible for cryptographic information to be exchanged even when a direct radio connection between the first road user 1 and the second road user 2 is not yet possible. This creates a particularly responsive system. It also makes it possible for the application server 50 to forward initial cryptographic information only if the corresponding source is considered trustworthy. However, the second communication device 20 is not restricted in its freedom of decision.
[0053] Figure 2 shows an exemplary flowchart for a method 100 according to the invention for communication between the first road user 1 and the second road user 2.
[0054] In a first method step 101, cryptographic first information belonging to the first road user 1 is transmitted from the first road user to the second road user 2 by means of the first type of radio connection.
[0055] Furthermore, in a second method step 102, status information associated with the first road user 1, here for example position and / or movement information, is transmitted together with the cryptographic second information from the first road user 1 to the second road user 2 via the second type of radio connection. The cryptographic first information is suitable for verifying the status information by means of the cryptographic second information.
[0056] In a third method step 103, the state information is verified based on the cryptographic first information by means of the cryptographic second information by the second road user 2, i.e. by the second communication device.
[0057] In the embodiment shown in Figure 1, data exchange takes place via a radio network 40 and an intermediate application server 50. In alternative embodiments, communication between the first transmitting unit 11 of the first communication device 10 and the first receiving unit 21 of the second communication device 20 also takes place via a direct radio connection. In particular, if this direct radio connection between the first transmitting unit 11 of the first communication device 10 and the first receiving unit 21 of the second communication device 20 has a greater range than the second type of radio connection, the cryptographic first information can also be provided before the status information is received together with the second information.
[0058] Figure 3 shows a further exemplary embodiment of the invention, wherein the information flow essentially corresponds to the embodiment shown in Figure 2. However, the first type of radio connection, here the fifth data connection 35, is a direct communication connection between the first transmitting unit 11 and the first receiving unit 21. Optionally, an additional data exchange with the communication server can take place via the first communication device 10 and / or the second communication device 20. In this embodiment, too, the first cryptographic information can be provided to the second communication device 20 before the status information associated with the first road user 1 is received together with the second cryptographic information.Thus, the received status information can be verified using the cryptographic second information and based on the cryptographic first information as soon as the status information is received by the second communication device 20. The range of the fifth data connection 35 is greater than the range of the third data connection 33. The approach of applying the same C-V2X technologies to a bicycle that are also used in cars is comparatively complex and expensive. Furthermore, based on current status, this technology will not be widely used in all regions of the world.In addition, the bandwidth of C-V2X direct communication is very limited and there is resistance from the automotive world to allowing vulnerable road users (such as bicycles or pedestrians) to transmit in this narrow frequency band, as there are fears that the frequency bands will be overloaded and safety applications between vehicles and infrastructure will be affected.
[0059] Therefore, the method according to the invention proposes the parallel use of long-range communication (4G / 5G / LoRaWaN) with short-range communication (e.g., BLE). Long-range communication is the communication via the first transmitting and receiving unit. Short-range communication is the communication via the second transmitting and receiving unit.
[0060] Long-range communication is optionally used for less time-critical purposes such as increasing awareness (mutual presence information between bicycles and cars) or collision warnings. Long-range communication is also used as a channel for ensuring safety and as one of two channels for more safety-critical applications, with long-range or "slow" information (such as warnings of quasi-static hazards such as black ice patches, weather, accidents, road closures, etc.) also being fed via long-range communication.
[0061] Short-range communication is used for time-critical communication between bicycle and vehicle, i.e. between mobile unit 1 and road user 20, in order to be able to send the future path and further information about the status of the bicycle or cyclist at high frequency and with low latency.
[0062] This is a combination of LongRange and ShortRange
[0063] Communication, in particular 4G / 5G / LoRaWaN with BLE or other short-range technologies (e.g. UltraWideBand) outside the sidelink communication provided for in Rel14 and later.
[0064] This is advantageous in several ways:
[0065] From a safety perspective, two parallel and technologically independent paths exist. Demands for such redundancy are becoming increasingly loud in the context of safety-critical applications (such as automated braking).
[0066] From a security perspective, a second, out-of-band and preferably long-range channel allows for the exchange of cryptographic information to secure the short-range interface. This channel thus enables the shifting of effort to the less time-critical and longer-distance communication interface.
[0067] The application server 10 interposed in the long-range communication (which also determines which other road users are nearby and to whom the message with cryptographic information must be forwarded) can include a caching function, for example, caching the certificates and proactively making them available to the communication partners as soon as short-range communication is expected.
[0068] In an advantageous configuration, the application server 10 can also be used to prevent the certificates from being forwarded, thus withdrawing trust from a communication partner without completely stopping communication. This allows the recipient to decide for which safety-critical reactions (e.g., automated emergency braking) it will still use the "degraded" information from the short-range channel.
[0069] The basis for such a "revocation" of certificates must be an assessment of the trustworthiness of the communication partners, which takes place in the background, for example, based on anomaly detection ("this road user is behaving strangely, not in line with their profile, too many in one place (misuse) etc.). This allows for online revocation without using mechanisms in the underlying PKI (short-lived certificates according to ETSI cannot be revoked by design). The intermediary in the backend thus "orchestrates" the trustworthiness of the communication partners without participating in the communication itself.
[0070] Similarly, short- and long-range communication can be combined for ad-hoc communication without an intermediary, for example, using a combination of PC5 / WiFi-p with Bluetooth, so that only the exchange of hashes is necessary over Bluetooth. Instead, the necessary information is pre-provisioned over longer distances.
[0071] Applications that do not require very small latencies (such as a warning or information in the time range >1.5s before a dangerous situation) can be carried out bidirectionally via the LongRange interface and in particular via the application server 10, ie both the mobile unit 1 and other road users can warn the drivers in advance.
[0072] Applications that rely on very low latencies and high availability (such as supporting automated braking intervention) benefit from the short latencies of direct communication (ShortRange), plus the increased safety provided by dual-channel technology.
[0073] Since safety-relevant automated interventions primarily involve interventions on the side of road user 10 (such as automated braking interventions, AEB), unidirectional communication is also sufficient for short-range communication. In both cases, short-range communication can occur, enabled by intelligent caching, even if the long-range channel is not continuously available.
[0074] Another advantage is that this type of communication doesn't burden the low bandwidth of potential sidelink communication. This can lead to greater acceptance among motor vehicles, because safety-critical communication between different vehicles is then not compromised by VRUs. - TI -
[0075] Thus, in the described information system, a bicycle comprising the mobile unit 1 is connected to a backend (the application server 10) via the long-range connection, for example, at least on a timescale of a few seconds. If the bicycle moves toward a hazard (static or dynamic), information / warnings can be transmitted to the bicycle.
[0076] If necessary, the communication frequency can be increased, but there will be limitations regarding latency, which is why LongRange technology (also due to possible "dead spots") tends to be unsuitable for supporting an emergency braking function in cars.
[0077] This is where short-range communication comes into play, enabling low-latency communication with the car without relying on a cellular network. For example, CAM / VAM messages can be sent via BLE at 10 Hz, providing information about the car's position, direction, speed, predicted path for the next few seconds, driver type, and driver reactions, helping the car initiate the correct maneuvers.
[0078] In order to avoid having to transport complete key material (the complete cryptographic information) on this path, this can be done in advance on the long-range communication so that the (limited) short-range communication can concentrate on the essential, safety-relevant content.
[0079] The LongRange communication also serves as a second, independent channel, which will be very helpful (if not necessary) for security applications.
[0080] In addition to the above written disclosure, explicit reference is made to the disclosure of Figures 1 to 3.
Claims
Claims 1 . A first communication device (10) for a first road user (1), comprising: a first transmitting unit (11) configured to transmit information via a first type of radio connection, a second transmitting unit (12) configured to transmit information via a second type of radio connection, and a control unit (13) of the first communication device (10), configured to transmit cryptographic first information associated with the first road user (1) via the first transmitting unit (11), and to transmit status information associated with the first road user (1) together with cryptographic second information via the second transmitting unit (12), wherein the cryptographic first information is suitable for verifying the status information by means of the cryptographic second information.
2. First communication device (10) according to claim 1, wherein the first transmitting unit (11) is configured to transmit information to a communication server (50) via a radio network (40), and the control unit (13) of the first communication device (10) is configured to transmit the cryptographic first information to the communication server (50), and wherein the second transmitting unit (12) is configured to transmit the status information together with the cryptographic second information to a second road user (2) via a direct radio connection.
3. First communication device (10) according to one of the preceding claims, wherein the cryptographic first information associated with the first road user (1) comprises a digital certificate and the cryptographic first information sent to the second road user (2) second information may include a hash value generated based on the digital certificate.
4. First communication device (10) according to one of the preceding claims, wherein the first transmitting unit (11) is provided for transmission over a greater range than the second transmitting unit (12), and / or the first transmitting unit (11) is configured to transmit larger data packets than the second transmitting unit (12).
5. A second communication device (20) for a second road user (2), comprising: a first receiving unit (21) configured to receive information via a first type of radio connection, a second receiving unit (22) configured to receive information via a second type of radio connection, and a control unit (23) configured to: receive cryptographic first information associated with a first road user (1) via the first receiving unit (21), and receive status information associated with the first road user (1) together with cryptographic second information via the second receiving unit (22), and verify the status information based on the cryptographic first information using the cryptographic second information.
6. Second communication device (20) according to claim 5, wherein the first receiving unit (21) is configured to receive information from a communication server (50) via a radio network (40), and the control unit (23) of the second communication device (20) is configured to receive the cryptographic first information from the communication server (50), and wherein the second receiving unit (22) is configured to receive the status information together with the cryptographic second information from the first road user (1) via a direct radio connection.
7. Second communication device (20) according to one of the preceding claims 5 or 6, wherein the cryptographic first information associated with the first road user (1) comprises a digital certificate and the cryptographic second information sent to the second road user (2) comprises a hash value generated based on the digital certificate.
8. Second communication device (20) according to one of the preceding claims 5 to 7, wherein the first receiving unit (21) is provided for transmission over a greater range than the second receiving unit (22), and / or the first receiving unit (21) is configured to transmit larger data packets than the second receiving unit (22).
9. Second communication device (20) according to one of the preceding claims 5 to 8, wherein the control unit (23) is configured to use the status information received from the first road user (1) via the second receiving unit (22) for different support functions depending on whether the status information can be successfully verified by means of the cryptographic second information.
10. Communication system, comprising the first communication device (10) according to one of the preceding claims 2 and / or the second communication device (20) according to claim 6, further comprising the communication server (50), wherein the communication server (50) is configured to transmit the cryptographic first information associated with the first road user (1) to the second communication device (20) in response to a predefined first condition being met, wherein the predefined first condition is met in particular when the communication server (50) has information which indicates an expected data exchange between the first communication device (10) and the second communication device (20) via the second type of radio connection.
11. Communication system according to claim 10, wherein the communication server (50) is configured to prevent the transmission of the cryptographic first information associated with the first road user (1) to the second communication device (20) in response to the existence of a predefined second condition, wherein the predefined second condition is met in particular when the communication server (50) has information that indicates limited trustworthiness of the first road user (1).
12. Method (100) for communication between a first road user (1) and a second road user (2), comprising: Transmitting (101) cryptographic first information belonging to the first road user (1) from the first road user (1) to the second road user (2) by means of a radio connection of the first type (31), Transmitting (102) status information associated with the first road user (1) together with cryptographic second information from the first road user (1) to the second road user (2) via a second type of radio connection, wherein the cryptographic first information is suitable for verifying the status information by means of the cryptographic second information, Verifying (103) the state information based on the cryptographic first information by means of the cryptographic second information by the second road user.