4.1 Umsetzung in der Akteursvielfalt: Systemleitbilder

Während sich auf die seit Jahren auf „Smart Traffic“-Kongressen oft schon nur traditionell gestellte Frage „Wem gehören die Daten?“ zumindest abzeichnet, dass bei den im Fahrzeug erzeugten und verbleibenden Daten die Fahrzeughersteller dafür als Erste infrage kommen, so macht der C-ITS-Report in aller Klarheit deutlich, dass es zwischen den Akteuren der beteiligten Branchen erhebliche Differenzen darüber gibt, wer für die Übernahme und Verarbeitung dieser fahrzeuggenerierten Daten in einer Serverarchitektur prädestiniert ist. “The shared server is substantially the same technical service platform infrastructure as the Extended Vehicle, with one major difference: the OEM backbone is replaced with a shared server operated by a neutral service provider commissioned and controlled by a consortium representing interested stakeholders. This shared server would control at least personal and business data, other data remaining under the control of vehicle manufacturers” (C-ITS 2016:81). Der Vorschlag, einen neutralen Dienstebetreiber mit einem Kontrollorgan aller Interessengruppen damit zu betrauen, konkretisiert zwar die besonders in der Medienöffentlichkeit oft als Platzhalter benutzte allgemeine Bezeichnung „Cloud“, entpuppt sich aber als schwer umsetzbar. “Vehicle manufacturers questioned the workability of such a solution. They underlined the organisational difficulties to set up such a consortium of stakeholders, to reach agreement on all details regarding the establishment, maintenance, operation and management of the shared server, the selection of the server operator and any modi cations that would need to be made over time. FIA distributed a document describing the shared server and providing answers to vehicle manufacturers’ questions” (ebd.).

Einer der Gründe, warum Fahrzeughersteller auf eine Branchenlösung drängen, ist in der Tatsache zu sehen, dass schon seit Jahrzehnten Fahrzeugdaten des „Autobordcomputers“ im Fahrzeugdisplay angezeigt, gespeichert und gegebenenfalls von der Markenwerkstatt ausgelesen werden. Dies ist aus Sicht einer Markenbindung durchaus nachvollziehbar. Nicht ohne Weiteres vorstellbar wäre im Sinne der Markenbindung die Echtzeitübertragung von Daten aus dem und vor allem von Daten ins Fahrzeug. Im Falle von verkehrssicherheitsrelevanten Daten und Informationen ist weder ein Markenbezug noch eine eindeutige rechtliche Verantwortung gegeben. “In addition, vehicle manufacturers claimed that due to liability reasons IDs linking the two databases could not be completely anonymised and complete encryption (without possibility for vehicle manufacturers to decrypt) would not be possible because it would lead to liability and type-approval issues. Therefore the shared server would not solve the service providers’ issues (i.a. the non-monitoring). Security issues were also mentioned by the vehicle manufacturers, to which FIA replied that same security measures than in the Extended Vehicle solution could be applied to a shared server. From the discussion to date, it appears that consensus will probably not be reached among the working group on this solution” (C-ITS 2016:81).

Ein neutraler Service Provider würde (unter anderem) die empfangenen Daten im „Shared Server“ gemäß den Gestaltungsprinzipien verschlüsseln, sodass kein Dritter Zugriff hätte, auch nicht die Kfz-Hersteller oder andere Akteure in der Wertschöpfungskette. “Vehicle manufacturers underlined that the proposed solution was a commercial platform, based on an open market (‘not only IBM’) to provide this kind of platform, and that it should still be possible to access data directly through the Extended Vehicle solution. In addition, they reminded that decryption between the vehicle and the vehicle manufacturer backend server should be open to vehicle manufacturers for liability reasons. Same need for access to decrypted data was deemed necessary for liability reasons for all actors along the service delivery. Independent operators and service providers explained that this proposal could be interesting only if end-to-end encryption would be ensured.” Bei einer solchen Lösung wären also durchaus komplizierte Einzelvereinbarungen für dienstespezifische Ende-zu-Ende-Verschlüsselung selbst für im Wettbewerb stehende kommerzielle Akteure erforderlich. Die Zwischenbilanz ist eher pessimistisch: „Talks within the working group are not yet completely exhausted, but first discussions seem to show that the added value of the B2B marketplace, in terms of solving the issues linked to the Extended Vehicle, seem to be rather limited” (C-ITS 2016:82).

Infrastrukturbau – wer fängt freiwillig an?

Hinter den technischen Fragen steckt also vor allem das bekannte (aber wenig erforschte1 ) Spannungsfeld zwischen Infrastrukturbau und Wettbewerbsprinzip. “Improve cooperation: as demonstrated by the above-mentioned main issues, it seems that although this working group is placed among the ‘technical issues’, most of the sticking points are not only technical issues, but also concerns linked to the lack of trust between direct competitors. Ways to improve cooperation should be explored to make some progress, in line with the overall objectives of the Digital Single Market Strategy. Need for an analysis on legal, liability, technical and cost-benefits aspects: in order to further progress and also to help in fulfilling the legislators request (cf Article 12[2] of the eCall type-approval Regulation), and on the basis of the five guiding principles, the different proposals for the data server platform put forward by the members of the working group should be included in a scenario-based analysis on legal, liability, technical and cost-benefits aspects of the different possible approaches” (C-ITS 2016:81).

Der hauptsächliche Streit um die Datenverfügbarkeit rührt (anders als in der netzpolitischen Diskussion vermutet) nicht in erster Linie aus dem kommerziellen Mehrwert dieser Daten bei einer Veräußerung2 , sondern aus Sicherheitsfragen und Verantwortung für bislang separat erhobene Daten. “Vehicle manufacturers expressed nevertheless strong reservations regarding the above described in-vehicle interface as well as regarding the on-board application platform (infra), mainly for security reasons. They argued that it is not sufficient to apply general security design rules to the connectivity control unit (CCU) to guarantee the security of the whole system. The CCU, when connected, becomes part of the vehicle EE architecture. Therefore, vehicle manufacturers consider that the CCU protection must be compatible with and complementary to the security features of other embedded systems. In their view, the potential security weakness depends on each single architecture design and needs to be addressed at the level of the whole system. Similarly, they argued that cyber-attack countermeasures may affect the performance of the whole system. For vehicle manufacturers, all this implies that security issues cannot be addressed in one additional ECU but must involve the whole embedded system” (C-ITS 2016:83). Die Autobauerbranche wehrt sich mit Datensicherheitsaspekten im jeweiligen Einzelfall gegen den Anspruch der IT-Betreiber, die Entwicklung der Datenarchitektur zu dominieren. “A parallel discussion to the discussions on technical solutions and data needs took place regarding the data access conditions, with the following strong disagreement:

  • vehicle manufacturers expressed their preference for an access depending on use cases, with a pre-defined list of data linked to each use case. Legal reasons were notably presented, in particular the fact that the access to personal data should be proportionate to the accurately defined needs.
  • independent operators and service providers explained that purely a use case based release of data would seriously restrict services and innovation. The data subject would give consent to applications, which would be based on a list of data described in the terms and conditions of each application. At least within the short reference set of data, each data type could then be combined with other data types, and not be part of a prefixed list linked to a specific use case. This would moreover allow for the exibility needed as regards innovation of new use cases” (C-ITS 2016:88).

Desiderat flächendeckendes Ad-hoc-Mobilfunknetz

Zu den datentechnischen Komplikationen für einen „Smart Traffic“ kommen noch grundsätzlich technisch bzw. physikalisch bedingte Schwierigkeiten des entstehenden dezentralen Ad-hoc-Mobilfunknetzes. “Cooperative intelligent transport systems (C-ITS) operating at 5.9 GHz for short range communication use an ad hoc network topology. This implies that there is no central coordinator, such as a base station or an access point, granting access to the wireless channel. All network participants are peers and share the wireless channel whenever they have something to transmit. However, when many network participants simultaneously want to access the channel, the performance of applications can be severely degraded due to saturation. To overcome this, a decentralized congestion control (DCC) scheme must be implemented. DCC specifications for day one applications on a single channel are already in place and it will function satisfactorily for low to moderate densities of ITS stations, but might not be sufficient for multi-channel and day two applications asking higher data throughput and enhanced spectrum efficiency.” (C-ITS 2016:91). Die Mobilfunkbranche betont – wie alle Netzbranchen – nur ungern die Kapazitätsgrenzen von Netzen in Abhängigkeit von Nutzern. Alle interaktiven Netze haben die Eigenschaft des „shared network“, selbst das Telefonnetz mit seinen (in Deutschland durchschnittlich zwei Kilometer langen) individuellen Teilnehmeranschlussleitungen in Kupferdoppelader hatte nur eine Belastungskapazität von rund 8 % gleichzeitiger Nutzung.

In Mobilfunknetzen stehen aus rein physikalischen Gründen3 viel geringere Bandbreiten zur Verfügung, bei den Ad-hoc-Netzen (etwa mit den Sendern in Fahrzeugen) können sich in der Fläche zudem bewegungsaktuelle Lücken auftun. Die fünfte Mobilfunkgeneration wird hier zwar Verbesserungen bei der Kapazität insgesamt bringen, aber es müssen auch koordinierte Kanalumschaltungen möglich werden.4 “ETSI ITS G5 has been developed as a standalone system (which is it strength). It uses an ad hoc network topology, which means direct communication can take place between all equipped traf c participants: vehicles, motorcycles, bicycles, pedestrians, urban rail and infrastructure as peers in the network. Since no access points or base stations are part of the network, there is no entity governing a possible channel switch if the communication channel is overloaded (e.g. handover between different base stations in mobile telephone systems). Hence frequency channels need to be fixed, otherwise interoperability throughout Europe would not be possible (e.g. a German vehicle can communicate with French infrastructure). Furthermore, as activity on the network cannot be predicted, all ITS-Stations need to implement DCC to ensure they have the same probability of success in accessing the channel” (C-ITS 2016:93).

Die Belastung der Mobilfunknetze durch Echtzeitdaten aus und für den „Smart Traffic“ wird sich auf die urbane Mobilität auswirken: “The introduction of future C-ITS services (e.g. inclusion of VRUs, infrastructure and automated use cases) will lead to a dramatic increase of ITS-Stations and channel loads, in particular in urban environments. The Working Group recommends that the 5855-5875 MHz, the 5905-5925 MHz and the 63-64 GHz band are designated to C-ITS services to cope with future capacity demand. (…) In order to accommodate safety critical applications (for example platooning and automated driving), predictability of upcoming DCC implementations is imperative and must be considered” (ebd.). Bei aller Anerkennung der technischen Fortschritte für diese im Hinblick auf Verkehrssicherheit und Verkehrsmanagement ausgerichteten ITS-G5-Mobilfunksysteme kommt die Arbeitsgruppe zu der Schlussfolgerung: “(…) that currently neither ETSI nor cellular systems can provide the full range of necessary services for C-ITS. Consequently a hybrid communication concept is needed in order to take advantage of complementary technologies.” (C-ITS:97).

Mit einem deutlichen Appell leitet der Report konsequent zur Arbeitsgruppe „Public Acceptance“ über: „Das Funkfrequenzspektrum ist eine begrenzte Ressource und Datenverkehrsabschätzungen zeigen eine wachsende hohe Nachfrage. Ressourcenaufteilung unter allen Nutzern ist erforderlich. Dies sollte auf der Basis fairer Politiken geschehen, die sicherstellen, dass die derzeitigen Dienste möglich bleiben und dabei die Sicherheit (safety5 ) erhalten bleibt“ (C-ITS-2016:98). Die Betonung der „safety“ im Zusammenhang mit „security“ könnte auch den eingangs dargestellten volatil verwendeten Begriffen selbst in Fachkreisen geschuldet sein.

  1. Selbst in der Breitbanddiskussion ist praktisch nicht berücksichtigt, dass bis zum Aufkommen der Glasfasertechnik-Produkte nach 1981 die Verkabelung der Bundesrepublik nur in einem genehmigten Sortimentskartell der Kabelfirmen möglich war. Ob öffentlich oder privat: Infrastruktur kann zu vertretbaren Kosten und Bauzeiten nicht im Konkurrenzverfahren realisiert werden. []
  2. In diesem Kontext hat sich auch die missverständliche Metapher von „Daten als Rohstoff“ in der Netzpolitik etabliert; vgl. Klumpp (2014b:10). []
  3. Im aktuellen Netz-Slang würde man wohl von „Physik 1.0“ sprechen. []
  4. Als Anhaltspunkt für LTE-Mobilfunk: The communication range for IEEE802.11p/ETSI ITS-G5 is up to 1000 meters in benign conditions but typically the coverage will be around 500 meters depending on the environment. When many ITS-Stations in the vicinity are sending Cooperative Awareness Messages (CAM) and Decentralized Environmental Notification Messages (DENM) studies have shown that the 1200 packets/sec limit is easily reached resulting in poor communication performance. []
  5. Die – über den Mobilfunk hinausgehende – prinzipielle Frage nach notwendiger und hinreichender „Safety“ bei sämtlichen elektronischen Systemen wird im thematischen Zusammenhang dieser Diskursanalyse nicht gestellt. Dies ist im globalen Maßstab ein seit vier Jahrzehnten dringendes Desiderat für Technikgestaltung (vgl. Klumpp 2010:262f.). []