Devices for protecting communications

JP7927848B2Active Publication Date: 2026-10-01MERCEDES BENZ GROUP AG
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024534452
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-12-21
Filing Date
2022-11-30
Publication Date
2026-10-01
Estimated Expiration
2042-11-30

AI Technical Summary

Benefits of technology

【0023】 一方または他方の変形形態の本発明に基づく装置または本発明に基づく方法は、加入者間のあらゆるタイプの通信を保護するために使用することができ、それにより、加入者の位置という形の物理的特性によってさまざまな種類のアカウントを検証することが可能である。本方法は、特に、自動車メーカーのサービスセンターとそのメーカーによって製造された車両との間の通信を保護するために非常に適している。これに応じて、本発明に基づく方法の有利な使用によれば、車両またはサーバーと車両との間の通信を保護するために本方法を用いるように設けられている。これにより、より安全な通信を確立することができ、また伝達されるデータに関して非常に高い安全性を保証することが可能になる。本発明に基づく方法により、ほとんどの操作を排除する可能性を生み出すことが可能になり、それによって、例えば走行機能、ドライバーアシスタントシステム、自動運転機能などを含む、安全に関連する内容を含むソフトウェアアップデートなど、重要な情報を自動車メーカーのサーバーから車両に伝達することができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007927848000001
    Figure 0007927848000001
  • Figure 0007927848000002
    Figure 0007927848000002
  • Figure 0007927848000003
    Figure 0007927848000003
Patent Text Reader

Abstract

The invention relates to a device for protecting communication between at least two subscribers (1, 2) via a communication device, each of which has an identification (ID) and a protection element (PIN) that are used for communication, preferably in encrypted form, the communication device being configured for authenticating at least one of the subscribers (1, 2) and calculating its current geodetic position (PP3, PP4) by communicating with at least one transceiver (3.1, 3.2, 3.3), thereby comparing the currently detected position (PP3, PP4) with a position (P3, P4) communicated or stored by the respective other subscriber (2, 1) or checking the validity of the currently detected position on the basis of said position. The invention is characterized in that the communication device is configured for detecting the current position (PP3, PP4) of at least one of the subscribers (1, 2) by detecting and evaluating the angles of arrival (α, β, γ) of the signals used for communication and / or the signal strengths (SS1, SS2, SS3) of the signals used for communication.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an apparatus for protecting communications between at least two subscribers, as described in the broader concepts of claims 1 and 3, and to a method for protecting communications between at least two subscribers, as described in claim 9. Claim 12 illustrates preferred uses of the apparatus and method.

[0002] Methods for properly protected communication between two or more subscribers are known from the prior art. Typically, each subscriber has identification information such as a username or user code, and protective elements for communication such as a password-protected account. Therefore, the actual protection of communication is technically achieved through the encryption process. The password is also the "key" for this.

[0003] A constant problem with such approaches is the fundamental risk that subscriber data, such as their identification and passwords, may be stolen. Thus, a criminal hacker can contact another subscriber on behalf of a previous subscriber and, based on the identification and password known to the hacker, convince the other subscriber that they are the real subscriber. This type of verification is widespread and commonly used in many communication methods, as other means, such as storage media, can be used instead of passwords. However, as the above examples show, this type of verification is no longer secure if user data is known to others, stolen, or hacked.

[0004] Regarding prior art, you can refer to Non-Patent Document 1. In summary, these documents basically describe verifying the subscriber's location from two data sources.

[0005] Furthermore, authentication of subscriber location is also described in the applicant's Patent Document 1, which uses satellite-based positioning, and for that purpose, the propagation time of the signal used for communication between the satellite and the subscriber is evaluated. Patent Document 2 describes an advanced form of this that enables location detection by signal propagation time even when the number of visible satellites is small. The methods described in the two aforementioned documents by the applicant utilize satellite positioning and, in particular, evaluation of signal propagation time for signals traveling back and forth across multiple satellites to determine the position of each subscriber on the Earth's surface, i.e., to identify the subscriber's actual physical or geodetic position. Next, to authenticate the subscriber, the position claimed by the subscriber can be compared with the actual physical or geodetic position. If there is an unacceptably large deviation in the position comparison, authentication fails. In fact, in order to manipulate information, it might be theoretically possible for a hacker, for example, to be located very close to one of the subscribers (such as a static server), use a false satellite frequency and identifier, and take over the satellite's role with a correspondingly high signal strength. In that case, even if countermeasures are taken, there is a risk that data could be manipulated, for example, safety-critical manipulation of software updates distributed to fleet vehicles. [Prior art documents] [Patent Documents]

[0006] [Patent Document 1] DE102020003329A1 [Patent Document 2] DE102021003610A1 [Non-patent literature]

[0007] [Non-Patent Document 1] ALLIG,C.et al.Trustworthiness Estimation of Entities with Collective Perception;in:IEE Vehicular Networking Conference(VNC),2019,Page 8,ISSN 2157-9865 and European Standard ETSI EN302637-2V1.3.2(2014-09).Intelligent Transport Systems(IST);Vehicular Communications;Basic Set of Applications;Part 2:Specification of Cooperative Awareness Basic Service; pages 1~44 [Overview of the Initiative] [Problems that the invention aims to solve]

[0008] Therefore, the object of the present invention is to provide a device for protecting communications between subscribers that offers even higher security. [Means for solving the problem]

[0009] Based on the present invention, this problem is solved by a device for protecting communications between at least two subscribers, having the features described in any one of claims 1 or 3. Advantageous embodiments of the device become apparent from the respective dependent claims. Furthermore, claim 9 also describes a method for protecting communications by such a device. Again, advantageous embodiments and variations become apparent from its dependent claims. Finally, claim 12 also indicates a preferred use of the device or the method.

[0010] Claims 1 and 3 provide two alternative methods for determining the current location of two subscribers in communication between two subscribers, for the purpose of authenticating the subscribers, via devices configured for that purpose. To authenticate the subscribers, a location claimed by the subscriber, or a location known or stored to the subscriber, can be compared to an actual physical or geodetic location.

[0011] According to claim 1, the angle of arrival of the signal used for communication is detected and evaluated for location determination. Then, the geodetic position can be calculated in a well-known manner using trigonometric functions from the angles of arrival of signals from at least one, preferably three, different transceivers, particularly from satellites.

[0012] The angle of arrival, also known as "Angle of Arrival" or its abbreviation "AoA" in English, can be detected via the antenna array of communication equipment, depending on the favorable developmental form. For example, if a hacker's drone disguised as a transceiver is placed between one subscriber and a transceiver, the angle of arrival of the signal at the other subscriber's location will differ from the angle of arrival expected from a real transceiver. This is because, for example, the drone is naturally at a much lower altitude than a real transceiver, especially one that can be configured as a satellite.

[0013] The alternative embodiment according to claim 3 utilizes largely the same basic structure, but uses the signal strength (SS) of the signal used for communication instead of the angle of arrival. This signal strength is based on the strength of the transmitted signal and the losses that occur along the transmission path, and is usually affected by the relevant air layer, its temperature, humidity, etc. This signal strength also allows for the detection of the subscriber's location by estimating the distance to the transceiver from the received signal strength. Therefore, if there are preferably at least three transceivers (especially satellites), an accurate and unique geodetic position can be determined.

[0014] Since signal intensity fluctuates relatively large depending on ambient conditions, it is reasonable to include ambient conditions as parameters in the evaluation, such as meteorological data, so that the expected decrease in signal intensity can be estimated.

[0015] Nevertheless, a hacker could relatively easily simulate a subscriber's signal strength by skillfully amplifying or attenuating their own signal, and if they knew the approximate magnitude of this type of signal strength, they might be able to illegally obtain authentication. In that case, a further advantageous embodiment of the device based on the present invention would be helpful. In this device, the communication equipment is configured to dynamically change the signal strength of the outgoing signal over time according to a defined pattern and to filter the received signal with respect to this defined pattern. For example, one subscriber could have their signal change over time, for example, so that the signal attenuates by 5 dB for a defined time at the start of the communication, increases by 10 dB during the communication, and attenuates again at the end of the communication. Modulation of frequency, amplitude, and / or polarity may also be considered. Then, when the other communication equipment receiving the signal recognizes this defined pattern, it can evaluate the signal strength as such by filtering it again, and in this case, the risk of intentional manipulation can be further reduced.

[0016] Furthermore, in addition to one or two of the described methods, the apparatus according to the present invention may be configured, with respect to the communication equipment of the apparatus, to utilize the detection of the current position of at least one subscriber by the propagation time of the signal used for communication between the transceiver and the satellite, particularly between the satellite and at least one subscriber. The calculation of position by propagation time, also known as Transfertime or TT, provides a further (third) possibility for detecting the current position, which can be used basically as an alternative or as a supplement to the physical methods proposed herein, as described in the prior art mentioned at the beginning.

[0017] In this case, since a part of the communication equipment of the apparatus configured to execute the individual steps can be arranged at each subscriber's side, these subscribers can detect each other with respect to their current positions and thereby perform authentication.

[0018] At this time, according to a very advantageous development, if computing capacity permits, it is also possible to install part of the communication equipment in the used transceiver, particularly in a satellite. In this case, authentication can be performed only by the transceiver, so communication will not be forwarded by a hacker detected based on an unauthorized position, and communication will already be blocked at the transceiver.

[0019] This principle is applicable to all conceivable types of satellite transceivers. Accordingly, transceivers may particularly include fixed stations that cover many moving objects as central transceivers, for example, radio towers such as mobile radio networks, radio stations or television stations. However, according to an advantageous embodiment of the device according to the present invention, it is particularly preferable that the transceiver is configured as a satellite. Satellites (e.g., GPS and equivalent systems) not only have high availability over almost the entire surface of the Earth, but also provide high reliability protection. This is because it is practically impossible for a hacker group to use their own satellites for authentication operations.

[0020] A method according to the present invention for protecting communication between at least two subscribers via a device of this kind utilizes, in the communication equipment of the device, a comparison performed between a known position, for example, a known stationary position such as a service center already stored in a vehicle control system when the vehicle is manufactured, thereby ensuring that communication is actually performed with the corresponding service center. Alternatively, if the subscriber is a moving object such as a vehicle, only a validity check will be possible. For example, the corresponding position of the vehicle from previous communication can be temporarily stored, and then that position can be compared with the current position. For example, if the last communication was several hours ago, such a validity check can determine the possibility that the vehicle is within a radius of 200 to 300 km from the previous position. If this is the case, a positive validity check result is generated. If this is not the case, and the distance is so large that it is impossible under normal circumstances at this point in time, for example, there is a distance of thousands of kilometers between the last stored position and the current position within several hours, a negative validity check result is generated. In the method according to the present invention for protecting communication by such a device, communication is canceled when a negative comparison result or such a negative validity check result occurs. This is because a subscriber having a negative comparison result or a negative validity check result can be classified as untrustworthy, and in particular, it is assumed that the subscriber is a hacker who attempts to transmit manipulated data to the other subscriber user, or attempts to eavesdrop on the confidential data of this subscriber.

[0021] In a particularly preferred embodiment of the method according to the present invention, one, two or three of the aforementioned methods can be used to specify the position of a subscriber, thereby being configured to authenticate the subscriber. This enables authentication to be performed according to the situation, for example by any one method, another method, or a combination of these methods, and safety is greatly improved compared to the case where only one method is used.

[0022] In addition to pure authentication using one or more of the methods described above, it is also possible to use one or two authentication methods, namely one or two methods for identifying the actual location of the subscriber in question, while also using one or more other methods to appropriately verify this authentication, i.e., to directly or at least recheck the transmitted values ​​for their validity. This can be done in any combination and / or any order, depending on the situation and especially on the computing power available to each subscriber. For example, in authentication by signal propagation time, it may suffice to verify the authentication by evaluating the angle of arrival and / or signal strength of only one transceiver. This saves resources and computing power.

[0023] Apparatus or methods based on one or the other variant of the present invention can be used to protect all types of communications between subscribers, thereby enabling verification of various types of accounts based on physical characteristics in the form of subscriber location. The method is particularly well suited to protecting communications between an automobile manufacturer's service center and vehicles manufactured by that manufacturer. Accordingly, an advantageous use of the method based on the present invention is provided to be used to protect communications between a vehicle or server and a vehicle. This makes it possible to establish more secure communications and to guarantee a very high level of security with respect to the data being transmitted. The method based on the present invention makes it possible to eliminate most operations, thereby enabling the transmission of important information from an automobile manufacturer's server to a vehicle, such as software updates containing safety-related content, including driving functions, driver assistance systems, and autonomous driving functions.

[0024] Further advantageous embodiments of the apparatus and method according to the present invention are also evident from the examples shown below in detail with reference to the figures. [Brief explanation of the drawing]

[0025] [Figure 1] This figure illustrates the procedure for protecting communications and utilizing protective elements according to the method of the present invention. [Figure 2] This figure shows a scenario for determining the location of a satellite based on its signal propagation time. [Figure 3] This figure shows a first scenario for positioning using the angle of arrival (AoA) of a signal. [Figure 4] This figure shows a second scenario for positioning using the angle of arrival (AoA) of the signal. [Figure 5] This figure shows a scenario for location determination using signal strength (SS). [Modes for carrying out the invention]

[0026] Figure 1 schematically illustrates how a method according to the present invention functions and is available in a series of sequential steps. On the left side of Figure 1, subscriber 1 is shown in the form of vehicle 1, and on the right side of Figure 1, a service center 2, for example, an automobile manufacturer or its backend server, is shown as subscriber 2. Vehicle 1 can communicate with the service center as subscriber 2 by the applicable account. The identification information (ID) may be, for example, a vehicle identification number. In the embodiment shown herein, this number is V1. Furthermore, vehicle 1 as subscriber has a PIN, which is exemplary designated as N5. Similarly, service center 2 as a second subscriber has an ID, which is exemplary designated as S2. The PIN of service center 2 is exemplary designated as N6. Furthermore, both subscribers 1 and 2 are in applicable locations, i.e., geodesic locations. These locations are defined as P3 for vehicle 1 as subscriber and as P4 for service center 2 as subscriber.

[0027] In the first step 100, a request is sent from service center 2 to vehicle 1, which has identification information V1, along with a message indicating, for example, that a software update is available. As a subscriber with identification information V1, vehicle 1 establishes communication with the service center using an account with identification information V1 and a PIN, and inquires who sent the message from the first step 100. This is shown in Figure 1 as the second step 200. Next, the third step 300 takes place in the service center 2's area, where the service center transmits its current location P4 along with the identification information and timestamp T8. This data is transmitted to vehicle 1 in the fourth step 400. Then, in the fifth step 500, vehicle 1 calculates the physical location PP4 of service center 2, based on, for example, the timestamp T8, the signal propagation time between service center 2 and satellites 3.1, 3.2, 3.3, and 3.4 shown in Figure 2 and later, and with the involvement of the satellite control center as necessary. Once this fifth step 500 is completed, it can then be checked whether the calculated location PP4 matches the transmitted location P4. If they match, the communication is verified, and in return, in the sixth step 600, the vehicle's unique location is compiled along with its unique ID and unique timestamp 9, which are then sent to the service center 2 in the seventh step 700 along with confirmation of the verification on the vehicle 1 side. If P4 and PP4 do not match, the communication is canceled by the vehicle 1 in step 610.

[0028] Next, in the eighth step 800, the verification performed on vehicle 1 in the fifth step 500 is also performed on the service center 2 side. That is, in the eighth step, which is here labeled 800, service center 2 calculates the same data in the same manner, and vehicle V1 reaches the calculated position PP3 without actively influencing the calculation of this value. This position is as reliable as the previous position PP4 of service center 2, regardless of whether vehicle 1 has been hacked or not. If this calculated position PP3 and the communicated position P3 are again identical in step 900, verification is performed on the service center 2 side, and this is communicated to the vehicle in the tenth step 1000. If they are not identical, cancellation is performed in step 910.

[0029] Following positive verification of both subscribers 1 and 2, the protected communication is performed as a bidirectional communication in step 1100, for example. As already stated at the beginning of this specification, the security of this communication is considerably high because the verification of physical characteristics in the form of the locations of subscribers 1 and 2 makes it virtually impossible or extremely costly for a hacker to carry out an attack. Next, in the communication in this 10th step 1000, for example, a software update can be loaded from the service center 2 to the vehicle 1. At this time, since this communication can be protected by a one-time key that is valid only for the current communication, even if the key falls into the hands of a malicious person after the communication has ended, the key becomes virtually worthless.

[0030] Figure 2 shows a first scenario for positioning by signal propagation time (Transfer Time-TT) of satellites 3.1, 3.2, 3.3, and 3.4. Here, four satellites 3.1, 3.2, 3.3, and 3.4 are illustrated exemplarily above the Earth's surface 4, of which three satellites 3.1, 3.2, and 3.3 are used for positioning, and the fourth satellite 3.4 is used in a known manner for time synchronization.

[0031] Starting from satellite 3.1, a circle indicated by 5.1 can be drawn on the Earth's surface based on the signal propagation time Δt1 of the first satellite 3.1, as shown by the dotted line. In this case, the propagation time from each point in this circle 5.1 to satellite 3.1 at that moment, or the propagation time from satellite 3.1 at that moment, is the same. Therefore, in determining the signal propagation time Δt1, it is only necessary to calculate that the desired point is one of the points on circle 5.1. At the same time, this method evaluates the signal propagation time Δt2 of the second satellite 3.2. Here again, a circle is formed by points with the same signal propagation time Δt2, which is drawn by a dashed line and indicated by reference numeral 5.2. From this, only two intersection points remain between the two circles 5.1 and 5.2 in the embodiment illustrated here, and the possible positions of vehicle 1, which is shown here simply as an example, are already limited accordingly. From the third satellite 3.3 and its signal propagation time Δt3, a third circle 5.3 can be calculated accordingly, from which a clear intersection of these three circles 5.1, 5.2, and 5.3 is obtained, and therefore the position of the vehicle 1 on the ground surface 4 shown herein is determined.

[0032] The fourth satellite 3.4 shown here can be used, on the one hand, to correct propagation time errors due to refraction in the ionosphere, and also to adjust the time. This is because, generally, the systems and satellites within the vehicle 1 do not have a sufficiently accurate clock to omit such adjustments, and in practice, an additional satellite is necessary and common for this purpose.

[0033] Next, instead of vehicle 1 as the legitimate first subscriber 1, here, symbol 1 is used as an example circle. * If the hacker indicated by [the symbol] were to infiltrate, this hacker would simply be on circle 5.1 as an example, but not on the other circles 5.2 and 5.3 which would ultimately prove the exact location of vehicle 1. * It is impersonating vehicle 1. Therefore, the same first signal propagation time Δt1 is calculated for location determination. However, the hacker has two other signal propagation times Δt2 * and Δt3* Since the original propagation times Δt2 and Δt3 corresponding to the position of the transmitted vehicle 1 are different, a different position may be identified here. Accordingly, communication is interrupted.

[0034] In other words, this first method uses the signal propagation time, also known as Transfer Time (TT). This first method is primarily based on the method described in Patent Document 1. If the number of visible satellites is small, the method described in Patent Document 2, mentioned at the beginning, can of course be used as an alternative.

[0035] As an alternative to this location determination by signal propagation time TT, the angle of arrival (AoA) of the signal is used. To detect such an angle of arrival with sufficient accuracy, here, an array of multiple antennas is required to detect the angle of arrival in addition to the pure signal. In the scenario illustrated in Figure 3, equivalent to Figure 2, this angle of arrival AoA is considered to be, for example, the angle of arrival of the signal relative to the virtual connection lines perpendicular to the ground surface 4 of each satellite 3.1, 3.2, and 3.3, respectively, and is here denoted by the symbols α, β, and γ. As in the embodiment in Figure 2, Hacker 1 is located at a different position. * Then, a different signal arrival angle will arise. Here, these different arrival angles are α * , β * gamma * This is shown. Due to the angle deviation, the fact that the indicated position does not match the actual position is detected here as well, and therefore the authentication fails.

[0036] If subscribers 1 and 2, whose locations are to be verified for authentication, are service centers 2 with unique locations on the ground surface 4, rather than vehicles 1 as shown in Figures 2 and 3, then by storing this location within the system, for example within vehicle 1, the transmission by service center 2 can essentially be omitted. In particular, automobile manufacturers can implement the precise location of service centers 2 within the control system of vehicle 1, especially on a regional basis.

[0037] In a further alternative embodiment, in the scenario according to Figure 3, satellite 3.4 is no longer required, and it would also be possible to appropriately monitor incoming signals at the side of satellites 3.1, 3.2, and 3.3. Based on independently stored data or data previously requested from another subscriber, for example a service center as subscriber 2, satellites 3.1, 3.2, 3.3, which have part of the communication equipment necessary for establishing protected communication, would be able to perform the comparison directly. Then, when the signal of the apparent hacker 1 * arrives at satellites 3.1, 3.2, 3.3 with an incorrect angle of arrival (AoA), the hacker's data can be immediately discarded and prevented from being forwarded to another subscriber 2.

[0038] Figure 4 shows a further scenario in which only one satellite 3.1 is illustrated merely by way of example. Here again, vehicle 1 assumes the role of subscriber 1, but a service center 2 as subscriber 2 can also take its place, which is indicated here by a broken line. In this scenario, hacker 1 * impersonates the network to attempt to manipulate communication via a fake satellite. In this case, for example, a drone flying at high altitude 6 may impersonate satellite 3.1 to one or both of participants 1 and 2. In this case, similarly, through evaluation of the angle of arrival at one or both of subscribers 1 and 2, for the signal transmitted from drone 6, a wrong angle α relative to the vertical line to the ground surface with respect to the expected angle of arrival of the signal α from the genuine satellite 3.1 * is detected and evaluated, whereby the manipulation can be discovered.

[0039] Figure 5 illustrates further scenarios in which signal strength (SS) is evaluated as appropriate, instead of signal propagation time TT or angle of arrival AoA. This signal strength SS is affected not only by distance but also by weather conditions along the path, such as humidity, clouds, and rain. Therefore, for subscriber 1, in the case of communication with satellites 3.1, 3.2, and 3.3, whose locations are relatively unique, triple signal strengths SS1, SS2, and SS3 are generated, and in this case, a certain degree of tolerance can always be expected in the signal strength SS due to atmospheric conditions. Hacker 1 * If it is clearly in a different location, then for this hacker, the signal strength SS1 is clearly different by comparison. * SS2 * SS3 * This results in the detection of an incorrect location, allowing communication to be interrupted at the appropriate time and operation to be prevented.

[0040] In this case, it is particularly useful to combine different methods TT, AoA, and / or SS with one another. For example, the signal propagation time TT can be used to determine the location for the purpose of authenticating subscribers 1 and 2. Then, the angle of arrival AoA and / or signal strength SS can be used to verify this result and ensure that it has not been manipulated in any way.

[0041] In this case, there is a certain limit to the signal strength SS. This is because the signal strength can be manipulated relatively easily if the losses along the path are known or predictable. In that case, a hacker can adjust the transmission performance accordingly to generate the desired signal strength. At the same time, because atmospheric and / or weather conditions can change, a relatively large tolerance range must be set for this signal strength, and the risk of manipulation cannot be completely eliminated.

[0042] To further reduce this risk, the transmitted signal can be encrypted dynamically over time. For example, the signal strength, frequency, amplitude, or polarization can also be varied over time. If this follows a predetermined pattern appropriately stored in the communication equipment of the actual subscribers 1 and 2, this variation added by the transmitting subscribers 1 and 2 can be filtered by the receiving subscribers 2 and 1, thereby allowing them to assess the true signal strength. This further enhances security against potential manipulation.

[0043] Of course, this technology allows for the swapping of various methods. For example, authentication could be performed using the angle of arrival (AoA), and verification using the signal propagation time (TT) and / or signal strength, or authentication could be performed using signal strength alone. Alternatively, two methods could be used for authentication, or a third method could be used for verification. Or all three methods could be used for authentication, or different combinations of methods could be used in any way. In particular, security can be further enhanced by constantly and repeatedly changing these combinations according to various parameters.

Claims

1. An apparatus for protecting communications between at least two subscribers (1, 2), at least one transceiver (3.1, 3.2, 3.3), and communication equipment, wherein a portion of the communication equipment is located at each of the subscribers (1, 2), and a portion of the communication equipment is located at the transceiver (3.1, 3.2, 3.3), and the two subscribers (1, 2) each have identification information (ID) and protection elements (PIN), which are used in an encrypted form for communications, and the communication equipment located at one of the subscribers (1, 2) is configured to authenticate the other subscriber (2, 1), and one of the subscribers (1, 2) However, the device detects the physical location (PP4, PP3) of the other subscriber (2, 1), and thereby, before the protected communication is performed as a bidirectional communication, it compares the detected physical location (PP4, PP3) with the location (P4, P3) transmitted or stored by the other subscriber (2, 1), or checks the validity of the detected physical location based on said location (P4, P3), and in the same manner, swaps one subscriber (1, 2) with the other subscriber (2, 1), and compares the detected physical location (PP3, PP4) with the transmitted or stored location (P3, P4), or checks the validity of the detected physical location, in the device, The apparatus is characterized in that the communication equipment located at one of the subscribers (1, 2) is configured to detect the physical position (PP4, PP3) of the other subscriber (2, 1) based on the angle of arrival (α, β, γ) of the signal used by the other subscriber (2, 1) for communication, and to detect the physical position (PP3, PP4) of the one subscriber (1, 2) in the same manner by swapping the two subscribers (1, 2) with the other subscriber (2, 1).

2. The apparatus according to claim 1, characterized in that the communication device has an antenna array.

3. An apparatus for protecting communications between at least two subscribers (1, 2), at least one transceiver (3.1, 3.2, 3.3), and communication equipment, wherein a portion of the communication equipment is located at each of the subscribers (1, 2), and a portion of the communication equipment is located at the transceiver (3.1, 3.2, 3.3), and the two subscribers (1, 2) each have identification information (ID) and protection elements (PIN), which are used in an encrypted form for communications, and the communication equipment located at one of the subscribers (1, 2) is configured to authenticate the other subscriber (2, 1), and one of the subscribers (1, 2) However, the device detects the physical location (PP4, PP3) of the other subscriber (2, 1), and thereby, before the protected communication is performed as a bidirectional communication, it compares the detected physical location (PP4, PP3) with the location (P4, P3) transmitted or stored by the other subscriber (2, 1), or checks the validity of the detected physical location based on said location (P4, P3), and in the same manner, swaps one subscriber (1, 2) with the other subscriber (2, 1), and compares the detected physical location (PP3, PP4) with the transmitted or stored location (P3, P4), or checks the validity of the detected physical location, in the device, The communication equipment located at one of the subscribers (1, 2) has a signal strength (SS) of the signal used for communication by the other subscriber (2, 1). 1 , SS 2 , SS 3 The device is characterized in that it is configured to detect the physical location (PP4, PP3) of the other subscriber (2, 1) based on the above, and to detect the physical location (PP3, PP4) of the other subscriber (1, 2) in the same manner by swapping the one subscriber (1, 2) with the other subscriber (2, 1).

4. The aforementioned communication device further determines the signal strength (SS) of the transmitted signal according to a defined pattern. 1 , SS 2 , SS 3 The apparatus according to claim 3, characterized in that it is configured to dynamically change ) over time and to filter the received signal with respect to the defined pattern.

5. A device for protecting communication between at least two subscribers (1, 2), at least one transceiver (3.1, 3.2, 3.3) and communication equipment, wherein a portion of the communication equipment is located at each of the subscribers (1, 2), and a portion of the communication equipment is located at the transceiver (3.1, 3.2, 3.3), the two subscribers (1, 2) each have identification information (ID) and protection elements (PIN), which are used in an encrypted form for communication, and the communication equipment located at one of the subscribers (1, 2) is configured to authenticate the other subscriber (2, 1), and one of the subscribers (1, 2) However, the device detects the physical location (PP4, PP3) of the other subscriber (2, 1), and thereby, before the protected communication is performed as a bidirectional communication, it compares the detected physical location (PP4, PP3) with the location (P4, P3) transmitted or stored by the other subscriber (2, 1), or checks the validity of the detected physical location based on said location (P4, P3), and in the same manner, swaps one subscriber (1, 2) with the other subscriber (2, 1), and compares the detected physical location (PP3, PP4) with the transmitted or stored location (P3, P4), or checks the validity of the detected physical location, in the device, The communication device arranged at one of said subscribers (1, 2) is configured to measure the propagation time (Δt 1 , Δt 2 , Δt 3 ) of a signal used for communication between said transceivers (3.1, 3.2, 3.3) and the other of said subscribers (2, 1), detect said physical position (PP4, PP3) of the other of said subscribers (2, 1), and detect said physical position (PP3, PP4) of one of said subscribers (1, 2) in the same manner after swapping one of said subscribers (1, 2) and the other of said subscribers (2, 1). Said apparatus, characterized in that.

6. The apparatus according to any one of claims 1 to 5, characterized in that at least one of the transceivers is configured as a satellite (3.1, 3.2, 3.3).

7. A device comprising at least two subscribers (1, 2), at least one transceiver (3.1, 3.2, 3.3), and communication equipment, wherein the communication equipment protects communication between at least two subscribers (1, 2), wherein a portion of the communication equipment is located at each of the subscribers (1, 2), and a portion of the communication equipment is located at the transceiver (3.1, 3.2, 3.3), and each of the two subscribers (1, 2) has an identification information (ID) and a protection element (PIN), which are used in an encrypted form for communication, and the communication equipment located at one of the subscribers (1, 2) is configured to authenticate the other subscriber (1, 2), and one of the subscribers (1 , 2) detects the physical location (PP4, PP3) of the other subscriber (2, 1), thereby comparing the detected physical location (PP4, PP3) with the location (P4, P3) transmitted or stored by the other subscriber (2, 1), or checking the validity of the detected physical location based on the location (P4, P3), and similarly comparing the detected physical location (PP3, PP4) with the transmitted or stored location (P3, P4), or checking the validity of the detected physical location, by swapping one subscriber (1, 2) with the other subscriber (2, 1), The communication equipment provided to one of the subscribers (1, 2) is: Based on the arrival angles (α, β, γ) of the signals used for communication by the other subscriber (2, 1), Based on the signal strength (SS1, SS2, SS3) of the signals used by the other subscriber (2,1) for communication, and / or Based on the propagation time (Δt1, Δt2, Δt3) of the signal used for communication between the transceiver (3.1, 3.2, 3.3) and the other subscriber (2, 1), The physical locations (PP4, PP3) of the other subscriber (2, 1) are detected. and The method is characterized by detecting the physical location (PP3, PP4) of one of the subscribers (1, 2) in the same manner, by swapping one subscriber (1, 2) with the other subscriber (2, 1).

8. The method according to claim 7, wherein if a negative comparison result or a negative validation result occurs, the communication is canceled.

9. In order to detect the physical location (PP4, PP3) of the other subscriber (2, 1), The angles of arrival of the aforementioned signal (α, β, γ), The signal strength (SS) of the aforementioned signal 1 , SS 2 , SS3), and / or The propagation time of the aforementioned signal (Δt 1 ,Δt 2 ,Δt 3 ), The method according to claim 7, characterized in that one or two of the methods are used, and one or two previously unused methods are used to verify the results.

10. For protecting communication between a vehicle (1) and an external server (2) when transmitting a software update, Use of the apparatus according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Procedures for securing communication

    DE102020003329A1

  • Procedures for securing communication

    DE102021003610A1

  • Device, system and methods using angle-of-arrival measurements for ADS-b authentication and navigation

    JP2014238388A

  • Autonomous vehicle positioning system for misbehavior detection

    US20130297195A1

  • Systems and methods for determining the position of a wireless access device within a vehicle

    US20210072341A1