Vehicle accident data recovery of distributed vehicle event data

By distributing EDR data segments and private key fragments in a dynamic vehicle network, the problem of unavailable EDR data after a vehicle accident is solved, enabling reliable data recovery and decryption, and supporting the integrity and accuracy of accident investigations.

CN121444486APending Publication Date: 2026-01-30INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480045588.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-07-07
Filing Date
2024-06-11
Publication Date
2026-01-30

AI Technical Summary

Technical Problem

In existing technologies, the availability of EDR data after a vehicle accident is limited by vehicle damage and the unavailability of the private key, resulting in the inability to fully recover and analyze the data, which affects the accuracy and effectiveness of the accident investigation.

Method used

By distributing replicated segments of EDR data and private key fragments in a dynamic vehicle network, and utilizing V2V communication and GPS positioning technology, a temporary dynamic vehicle network is formed. Member vehicles share private key fragments and data segments, ensuring that EDR data can be reconstructed after an accident involving the primary vehicle.

Benefits of technology

It enables reliable recovery and decryption of EDR data after a primary vehicle accident, providing data support in accident investigations and avoiding data privacy risks and single points of failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121444486A_ABST
    Figure CN121444486A_ABST
Patent Text Reader

Abstract

A computer-implemented method for distributing a copy of event data recorder (EDR) data of a vehicle includes transmitting index information uniquely identifying respective member vehicles of a dynamic vehicle network, the member vehicles of the dynamic vehicle network including candidate vehicles located within a predetermined geographic distance of a host vehicle; sending a segment of a private key associated with the EDR data of the host vehicle to a corresponding member vehicle of the dynamic vehicle network; distributing segments of replicated EDR data from the main vehicle between respective member vehicles; and in response to expiration of a predetermined lifecycle duration associated with the dynamic vehicle network and absence of an accident of the host vehicle, dismissing the dynamic vehicle network and initiating a next dynamic vehicle network including a next set of candidate vehicles.
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUND

[0001] The present invention relates to recovery of vehicle event data, and more particularly, to distributing recorded event data to member vehicles of a dynamic vehicle network.

[0002] Contemporary transportation vehicles are incorporating more and more technology and automation, such as global positioning systems (GPS), edge computing communications, and vehicle-to-vehicle (V2V) communications. V2V communications can exchange information about the operation of a vehicle, such as the speed and position of surrounding vehicles. V2V communications enable vehicles to broadcast and receive omni-directional messages 10 times per second at up to 1000 meters, establishing a 360° awareness of nearby vehicles. In addition to radar and cameras currently used during vehicle operation to detect potential threats, V2V communication technology enhances threat avoidance by providing alerts or, in some cases, providing an automatic response.

[0003] Vehicles can be equipped with event data recorders (EDRs), which include on-board recording and saving of multiple vehicle conditions and attributes when triggered by an event, such as a sudden change in acceleration, direction, or safety feature deployment. In some cases, EDR devices can continuously record vehicle operation data in a loop, overwriting previous data after completing the looped recording. EDR devices typically record and save data during a set period of time beginning before, during, and after a vehicle accident is detected. EDR data can include occupant behavior (i.e., the number of people in the vehicle, who is wearing a seatbelt); driver inputs (steering, throttle, and brake); the car’s location, speed, and yaw angle; and other details, such as the deployment of safety systems and passenger protection systems, and the force of any impact that can have occurred, in conjunction with contemporaneous car system diagnostics.

[0004] EDR data is often used for reconstruction and investigation of vehicle incidents, such as malfunctions, loss of control, collisions, fires, vehicle feature failures, and other events commonly referred to as "accidents." The data also includes information about the performance of vehicle features, systems, and safety features, and can help identify design issues or differences between specifications and performance. Such information and feedback can be used to further improve accident avoidance, performance of vehicle features, and safety features that protect drivers and passengers. In some jurisdictions (i.e., states), EDR data is considered part of the vehicle's property, and therefore part of the vehicle owner's property. In such jurisdictions, access to EDR data by someone other than the owner requires permission. In some cases, EDR data is protected by encryption and requires the owner's private key to access and view / analyze the recorded data. In other cases, within different jurisdictions, EDR data can be transmitted to a central data center for facilitating vehicle incident investigations, however, the volume of data and transmission lag and / or interference can limit the availability and usefulness of the central data storage. Conversely, EDR data can be corrupted due to a vehicle incident, such as a collision, fire, theft, or performance failure of a vehicle feature (e.g., airbag unexpectedly deploying, ABS system failure, autonomous vehicle failure, etc.). SUMMARY

[0005] According to various embodiments of the present invention, a computer-implemented method, computer program product, and computer system for distributing copies of event data recorder (EDR) data of a host vehicle are provided. The computer-implemented method includes sending, by one or more processors, index information uniquely identifying respective member vehicles of a dynamic vehicle network. The member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geographic distance of a host vehicle. The computer-implemented method further includes sending, by the one or more processors, a fragment of a private key associated with EDR data of the host vehicle to the respective member vehicles located within a predetermined geographic distance of a host vehicle. The computer-implemented method further includes distributing, by the one or more processors, segments of replicated EDR data from the host vehicle among the respective member vehicles. The EDR data segments are associated with index identification of the respective member vehicles and include a timestamp of the segment of the EDR data. The computer-implemented method further includes, in response to expiration of a predetermined duration of a lifetime associated with the dynamic vehicle network and in the absence of an accident of the host vehicle, dissolving, by the one or more processors, the dynamic vehicle network and initiating a next dynamic vehicle network including a next set of candidate vehicles. BRIEF DESCRIPTION OF DRAWINGS

[0006] Figure 1 is a functional block diagram illustrating a gas separation unit according to one embodiment of the present invention.

[0007] Figure 2 A flowchart depicting a data recovery procedure including distribution of a copy of event data recorder (EDR) data of a host vehicle, according to one embodiment of the application.

[0008] Figure 3 A block diagram depicting components of a computing system including a computing device configured to operatively execute a data recovery procedure Figure 2 according to one embodiment of the application. DETAILED DESCRIPTION

[0009] Embodiments of the application recognize that many modern vehicles include technical devices designed to detect vehicle incidents that occur and record and save vehicle related data before, during, and after the incident. Vehicle incidents can include accidents involving collisions, loss of vehicle control, fires, and vehicle malfunction, among others, which are recorded and saved on event data recorder (EDR) devices that have been included in the manufacture of certain vehicles for many years and can be included as aftermarket accessories.

[0010] Existing uses of EDR data can be compromised due to an accident that the vehicle has experienced or due to injury to the vehicle owner where the private key used to decrypt the EDR data is otherwise unknown or unavailable. To improve availability of accurate data after a vehicle incident, a solution is needed to securely recover vehicle data in an incident even when the vehicle local storage is compromised. Secure availability of event data recorder data is also valuable for semi-autonomous or fully autonomous vehicles to understand actions taken before, during, and after an incident and the condition of the driver and vehicle. For example, whether the driver was able to override control of the vehicle or whether safety features responded as expected.

[0011] Embodiments recognize that EDR data is intended to be read-only data saved in the local storage of the vehicle in the event of a vehicle incident, which is typically only accessible by the vehicle owner (i.e., the holder of the private key used to decrypt the EDR data). Embodiments recognize that there is a possibility of data distortion or otherwise affecting the data to avoid unfavorable results of an accident investigation, which suggests that a practice of sending EDR data to a verification center can be frequently employed. Embodiments also recognize that due to a vehicle incident, a massive amount of data can be generated in a short time, requiring local storage, however, in a severe accident, the local storage of data can be damaged or compromised.

[0012] In certain jurisdictions, embodiments recognize that EDR data is considered part of the property of the vehicle owner, and as such, access to the data can be protected and require the owner to access the EDR data or provide permission to others to access the EDR data. As part of EDR data protection, the records are typically encrypted and stored locally, which requires a private key to decrypt the data, and the private key can only be available to the vehicle owner. In a serious accident where the stored data is corrupted or the vehicle owner (as the driver) is seriously injured, the decryption private key cannot be provided or can not be available. If the owner is unable to provide the private key for decrypting the EDR data due to incapacitation or unwillingness, decryption of the EDR data for the accident can not be possible, and the investigation can still be incomplete. Access to EDR data associated with a vehicle accident provides valuable insight into the moments immediately preceding, during, and after a vehicle accident, and can provide even greater value for accidents involving semi-autonomous and fully autonomous vehicles as semi-autonomous and fully autonomous vehicles become more common and more numerous in quantity.

[0013] Because EDR data for a vehicle accident can provide an accurate and objective record of driver actions, vehicle state, performance, condition, and passenger information, the ability to recover EDR data that would otherwise be inaccessible can provide a clear picture of the cause of the accident and valuable information for the continued improvement of vehicle operation and safety features.

[0014] According to one embodiment of the present invention, a computer-implemented method for distributing event data recorder (EDR) data of a host vehicle is provided. The computer-implemented method includes sending, by one or more processors, index information uniquely identifying respective member vehicles of a dynamic vehicle network. The member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geographic distance of the host vehicle. The computer-implemented method also includes sending, by the one or more processors, a fragment of a private key associated with EDR data of the host vehicle to respective member vehicles located within the predetermined geographic distance of the host vehicle. The computer-implemented method further includes distributing, by the one or more processors, segments of replicated EDR data from the host vehicle among the respective member vehicles. The EDR data segments are associated with the index identification of the respective member vehicles and include a timestamp of the segment of EDR data. The computer-implemented method also includes, in response to expiration of a predetermined duration of a lifetime associated with the dynamic vehicle network and in the absence of an accident of the host vehicle, dissolving, by the one or more processors, the dynamic vehicle network and initiating a next dynamic vehicle network including a next set of candidate vehicles, thereby enabling reconstruction of a private key for decrypting the acquired EDR data.

[0015] Distributing the segmented EDR data to local storage devices among the plurality of member vehicles of the dynamic vehicle network created during operation of the host vehicle and the member vehicles enables reconstruction of the private key for decrypting the recovered EDR data in the event that the EDR data is corrupted or distorted after an accident of the host vehicle. Sharing the segments of the private key among the member vehicles of the dynamic vehicle network enables decryption of the recovered EDR data in the event that any one vehicle is unable to determine or reconstruct the private key. The identification of the member vehicles of the dynamic vehicle network allows investigators to recover and reconstruct the EDR data and decryption key even in the event that the locally recorded and saved EDR data is unrecoverable or remains encrypted due to the unavailability of the decryption key.

[0016] An advantageous aspect of some examples of the invention includes the one or more processors locating nearby vehicles during operation, where the nearby distance is predetermined or limited by connectivity technology. Vehicle-to-vehicle (V2V) communication technology can be used to locate vehicles, and GPS data can be used to determine the proximity of nearby vehicles to the host vehicle. For example, the one or more processors communicate with a plurality of other vehicles via V2V communication, and receive data from the plurality of vehicles of their respective GPS locations, and determine which vehicles are within a predetermined geographic distance from the host vehicle. The geographic distance (i.e., the geodetic distance) is the distance measured along the surface of the Earth. During the location activity of the host vehicle, the host vehicle and the plurality of other vehicles are in operation (i.e., in motion), which provides an advantage over current technology, namely, selecting candidate vehicles that are within a predetermined distance of the host vehicle, and enabling the sequence of forming and dissolving the dynamic vehicle network during operation and travel of the host vehicle and the candidate vehicles.

[0017] An advantageous aspect of some examples of the invention includes the one or more processors sending invitations to the located nearby vehicles to dynamically join the vehicle network. The one or more processors invite a plurality of vehicles within a predefined geographic distance to join the dynamic vehicle network, also referred to herein as the "vehicle network" or "network." The other nearby vehicles control whether they receive or block the invitation to join the dynamic vehicle network, or in some embodiments of the invention, the other nearby vehicles can choose not to participate in V2V communication, and thus are not located. The one or more processors initiate the invitation to a plurality of vehicles that are within the predetermined geographic distance and determined to be traveling in a direction and / or path similar to that of the host vehicle.

[0018] Advantageous aspects of some examples of the invention include one or more processors receiving a Vehicle Identifier Number (VIN) and confirmation that a nearby vehicle has accepted the sent invitation and joined the vehicle network. When a nearby vehicle joins the vehicle network, aspects of the invention assign an index to the joining vehicle such that the index provides a unique identifier for the joining vehicle as a “member vehicle” of the vehicle network, and this index is associated with EDR data and fragments and offsets of private keys distributed among all member vehicles in the vehicle network (discussed in detail below). In embodiments of the invention, the index can be a number, binary, character, string, or any combination thereof capable of clearly identifying a member vehicle within an instance of a dynamic vehicle network. Receipt of the VIN of the corresponding member vehicle joining the current dynamic vehicle network provides a clear identification of the member vehicle, and the allocation of the index information enables data to be assigned to the corresponding member vehicle for the current dynamic vehicle network, avoiding confusion of data sent to vehicles sequentially included in multiple dynamic vehicle networks.

[0019] In some embodiments, the VIN and index associated with a corresponding member vehicle of the dynamic vehicle network are sent to a remote data center, which is typically used as a data source for vehicle accident or incident investigations. An advantageous aspect of the invention includes one or more processors sending the VIN and index associated with a corresponding vehicle of the newly formed dynamic vehicle network to a central data repository, thereby enabling the identification of network member vehicles and which vehicle is associated with which index designation during the network's duration. In some embodiments, the VIN and index information is encrypted to protect the identity of member vehicles while allowing decryption in the event of an accident involving the primary vehicle. In some embodiments, the VIN and index information is sent to member vehicles for temporary storage during the duration of the dynamic vehicle network as a redundancy for sending information to the central data repository. The temporary duration of the dynamic vehicle network and its dissolution after the predetermined lifespan of the duration improve the practice of EDR data recording by enabling the recording and distribution of EDR data segments as a recoverable alternative source of EDR data in the event of corruption or loss of EDR data stored on the primary vehicle.

[0020] Advantages of some examples of the invention include a finite lifespan duration for the dynamic vehicle network, making each instance of the dynamic vehicle network temporary. The expiration of the dynamic vehicle network's lifespan duration can be initiated, for example, by criteria including a time function, travel distance, member vehicles of the network moving beyond a predetermined geographical distance, or the signal strength of the V2V connection dropping below a minimum threshold. After the lifespan duration of the vehicle network expires, one or more processors disband the current group of member vehicles as the current network and continue creating the next group of member vehicles to form the next dynamic vehicle network, while the master vehicle and nearby vehicles are actively operating.

[0021] Advantages of some examples of the present invention include one or more processors segmenting EDR data, wherein the data segments and timestamps associated with the data segments are encrypted and sent to at least one member vehicle of the dynamic vehicle network. The EDR data segments are distributed to the member vehicles of the dynamic vehicle network and associated with the timestamps and indices assigned to the respective member vehicles. By distributing segmented EDR data among multiple member vehicles of the dynamic vehicle network, advantages over current EDR data recording practices are achieved. The distribution of EDR data segments provides protection against data privacy issues because no single member vehicle includes all EDR data, and the data is sent in an encrypted format. Embodiments of the present invention are not limited to the segmentation type, as any segmentation algorithm can be used.

[0022] Advantageous aspects of some examples of the invention include one or more processors segmenting the EDR data using a private key used by the master vehicle or its owner to decrypt EDR data. The private key is used to decrypt EDR data segments sent to member vehicles in a dynamic vehicle network. By segmenting the private key and distributing the fragments of the private key, along with the location offsets associated with the private key fragments, among member vehicles in the dynamic vehicle network, no single member vehicle has sufficient private key information to decrypt the EDR data segment stored on its own. One aspect of the invention involves sending unencrypted private key fragments in text format. By identifying the member vehicle and obtaining the text-formatted fragments of the private key and their location offsets, the private key can be reconstructed and used by an investigator to recover and decrypt the distributed EDR data segments from the member vehicles and their associated timestamps. The offsets associated with the fragments of the private key provide the fragment's position within the reconstructed private key. The timestamps enable the reconstruction of the EDR data chronologically. Current practice provides the private key to the master vehicle owner for exclusive access, which creates a risk of EDR data being accessed and decrypted.

[0023] Advantages of some examples of the present invention include the ability of one or more processors to recover EDR data in situations where the primary vehicle has been involved in an accident and EDR data recovery is not possible and data cannot be decrypted directly from the primary vehicle and / or the vehicle owner. Embodiments of the present invention provide alternative means for recovering and decrypting EDR data in cases where the primary vehicle has been involved in an accident and the EDR data storage device is damaged (making EDR data unrecoverable from the primary vehicle) or where the private key for decrypting the EDR data is unavailable due to the condition of the vehicle owner (i.e., the driver of the primary vehicle at the time of the accident). Current practices cannot decrypt and analyze EDR data if the EDR data stored on the primary vehicle is damaged or inaccessible due to injury or incapacitation of the primary vehicle owner in an accident.

[0024] Advantageous aspects of some examples of the invention include one or more processors dissolving the dynamic vehicle network after a finite lifespan duration. The lifespan duration of the dynamic vehicle network is predetermined and can be based on a time function, the distance covered by the master and member vehicles, and / or the departure of member vehicles, and is not limited by factors determining the lifespan duration. Embodiments of the invention instruct member vehicles to delete received EDR data segments, as well as private key fragments and offsets, after initiating the dissolution of the current dynamic vehicle network. This aspect keeps the storage of EDR data, private key fragments, and shared VIN and index information temporary, thereby protecting privacy in the event of an incident during the lifespan of the dynamic vehicle network, while providing an alternative for recovering and reconstructing EDR data.

[0025] Advantageous aspects of some examples of the invention include one or more processors forming a next dynamic vehicle network after dissolving the current dynamic vehicle network. The primary vehicle repeatedly identifies and invites nearby vehicles as next candidate vehicles to join as a group of next member vehicles forming the next dynamic vehicle network. In some embodiments, a vehicle from the dissolved current dynamic vehicle network can rejoin as part of the next dynamic vehicle network, provided that the vehicle continues to operate within a predetermined geographical distance of the primary vehicle. Aspects of the invention establish a VIN and index designation for each member vehicle in the next dynamic vehicle network, and proceed to segmenting EDR data and distributing portions of the EDR data to the corresponding next member vehicles in the next dynamic vehicle network, as well as segmenting the private key and sending fragments and offsets of the private key to the corresponding next member vehicles.

[0026] According to another embodiment of the present invention, a computer system for distributing Event Data Recorder (EDR) data of a master vehicle is provided. The computer system includes a computer processor, at least one computer-readable storage medium, and program instructions stored on the at least one computer-readable storage medium and executed by the computer processor. The processor executes the program instructions to send index information that uniquely identifies a corresponding member vehicle of a dynamic vehicle network. Member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geographical distance of the master vehicle. The processor also executes program instructions to send fragments of a private key associated with the master vehicle's EDR data to the corresponding member vehicles located within the predetermined geographical distance of the master vehicle. The processor also executes instructions to distribute segments of copied EDR data from the master vehicle among the corresponding member vehicles. Each EDR data segment is associated with an index identifier of the corresponding member vehicle and includes a timestamp of the EDR data segment. The processor also executes program instructions to dissolve the dynamic vehicle network and initiate a next dynamic vehicle network including a set of subsequent candidate vehicles in response to the expiration of a predetermined lifecycle duration associated with the dynamic vehicle network and the absence of an accident involving the master vehicle.

[0027] Distributing segmented EDR data to local storage devices among multiple member vehicles in a dynamic vehicle network created during the operation of the master and member vehicles enables the reconstruction of the private key for decrypting the recovered EDR data even if the EDR data is corrupted or distorted after an accident involving the master vehicle. Sharing fragments of the private key among member vehicles in the dynamic vehicle network allows for the decryption of the recovered EDR data even if any vehicle cannot determine or reconstruct the private key. The identification of member vehicles in the dynamic vehicle network allows investigators to recover and reconstruct EDR data and decryption keys, even if locally recorded and stored EDR data is unrecoverable or remains encrypted due to an unavailable decryption key.

[0028] Advantages of some examples of the invention include the processor executing program instructions to locate nearby vehicles during operation, wherein the proximity distance is predetermined or limited by connectivity technology. Vehicle-to-vehicle (V2V) communication technology can be used to locate vehicles, and GPS data can be used to determine the proximity of nearby vehicles to the host vehicle. For example, the processor communicates with multiple other vehicles via V2V communication and receives data on their respective GPS locations from the multiple vehicles, and determines which vehicles are within a predetermined geographic distance from the host vehicle. Geographic distance (i.e., geodetic distance) is a distance measured along the Earth's surface. During the host vehicle's location activity, the host vehicle and multiple other vehicles are in operation (i.e., in motion), which provides advantages over current technologies, namely, the selection of candidate vehicles within the predetermined distance of the host vehicle, and the implementation of a sequence of forming and dissolving a dynamic vehicle network during the operation and travel of the host vehicle and candidate vehicles.

[0029] Advantages of some examples of the invention include the processor executing program instructions to send invitations to nearby vehicles to dynamically join a vehicle network. Multiple vehicles within a predefined geographical distance join the dynamic vehicle network, also referred to herein as a "vehicle network" or "network". Other nearby vehicles control whether they accept or block invitations to join the dynamic vehicle network, or in some embodiments of the invention, other nearby vehicles may choose not to participate in V2V communication and therefore not be located. Invitations are sent to multiple vehicles located within a predetermined geographical distance and identified as traveling in a direction and / or path similar to that of the master vehicle.

[0030] Advantages of some examples of the invention include the processor executing program instructions to receive a Vehicle Identifier Number (VIN) and confirmation that a nearby vehicle has accepted the sent invitation and joined the vehicle network. When a nearby vehicle joins the vehicle network, aspects of the invention assign an index to the joining vehicle such that the index provides a unique identifier for the joining vehicle as a “member vehicle” of the vehicle network, and this index is associated with EDR data and fragments and offsets of private keys distributed among all member vehicles in the vehicle network (discussed in detail below). In embodiments of the invention, the index can be a number, binary, character, string, or any combination thereof capable of clearly identifying a member vehicle within an instance of a dynamic vehicle network. Receipt of the VIN of the corresponding member vehicle joining the current dynamic vehicle network provides a clear identifier for the member vehicle, and the allocation of the index information enables data to be assigned to the corresponding member vehicle for the current dynamic vehicle network, avoiding confusion of data sent to vehicles sequentially included in multiple dynamic vehicle networks.

[0031] In some embodiments, the VIN and index associated with a corresponding member vehicle of the dynamic vehicle network are sent to a remote data center, which is typically used as a data source for vehicle accident or incident investigations. An advantageous aspect of the invention includes the processor executing program instructions to send the VIN and index associated with a corresponding vehicle of the newly formed dynamic vehicle network to a central data repository, thereby enabling the identification of network member vehicles and which vehicle is associated with which index designation during the network's duration. In some embodiments, the VIN and index information is encrypted to protect the identity of member vehicles while allowing decryption in the event of an accident involving the primary vehicle. In some embodiments, the VIN and index information is sent to member vehicles for temporary storage during the duration of the dynamic vehicle network as a redundancy for sending information to the central data repository. The temporary duration of the dynamic vehicle network and its dissolution after the predetermined lifespan of the duration improve the practice of EDR data recording by enabling the recording and distribution of EDR data segments as a recoverable alternative source of EDR data in the event of corruption or loss of EDR data stored on the primary vehicle.

[0032] Advantages of some examples of the invention include a finite lifespan duration for the dynamic vehicle network, making each instance of the dynamic vehicle network temporary. The expiration of the dynamic vehicle network's lifespan duration can be initiated, for example, by criteria including a time function, travel distance, member vehicles of the network moving beyond a predetermined geographical distance, or the signal strength of the V2V connection dropping below a minimum threshold. After the lifespan duration of the vehicle network expires, the processor executes program instructions to disband the current group of member vehicles as the current network and continues to create the next group of member vehicles to form the next dynamic vehicle network, while the master vehicle and nearby vehicles are actively operating.

[0033] Advantages of some examples of the invention include the processor executing program instructions to segment EDR data, wherein the data segments and timestamps associated with the data segments are encrypted and sent to at least one member vehicle of the dynamic vehicle network. The EDR data segments are distributed to member vehicles of the dynamic vehicle network and associated with timestamps and indices assigned to the respective member vehicles. By distributing segmented EDR data among multiple member vehicles of the dynamic vehicle network, advantages over current EDR data recording practices are achieved. The distribution of EDR data segments provides protection against data privacy issues because no single member vehicle includes all EDR data, and the data is sent in an encrypted format. Embodiments of the invention are not limited to the segmentation type, as any segmentation algorithm can be used.

[0034] Advantages of some examples of the invention include the processor executing program instructions to segment a private key used by the master vehicle or its owner to decrypt EDR data. The private key is used to decrypt EDR data segments sent to member vehicles in a dynamic vehicle network. By segmenting the private key and distributing the fragments of the private key, along with the associated location offsets, among member vehicles in the dynamic vehicle network, no single member vehicle has sufficient private key information to decrypt the EDR data segment stored on its own. One aspect of the invention involves sending unencrypted private key fragments in text format. By identifying the member vehicle and obtaining the text-formatted fragments of the private key and their location offsets, the private key can be reconstructed and used by an investigator to recover and decrypt the distributed EDR data segments from the member vehicles and their associated timestamps. The offsets associated with the fragments of the private key provide the fragment's position within the reconstructed private key. The timestamps enable the reconstruction of EDR data chronologically. Current practice provides the private key to the master vehicle owner for exclusive access, which creates a risk of EDR data being accessed and decrypted.

[0035] Advantages of some examples of the invention include the processor executing program instructions to recover EDR data in cases where the primary vehicle has been involved in an accident and EDR data recovery is not possible and data cannot be decrypted directly from the primary vehicle and / or the vehicle owner. Embodiments of the invention provide alternative means for recovering and decrypting EDR data in cases where the primary vehicle has been involved in an accident and the EDR data storage device is damaged (making EDR data unrecoverable from the primary vehicle) or where the private key for decrypting the EDR data is unavailable due to the condition of the vehicle owner (i.e., the driver of the primary vehicle at the time of the accident). Current practices cannot decrypt and analyze EDR data if the EDR data stored on the primary vehicle is damaged or inaccessible due to injury or incapacitation of the primary vehicle owner in an accident.

[0036] Advantages of some examples of the invention include the processor executing program instructions to dissolve the dynamic vehicle network after a finite lifespan duration. The lifespan duration of the dynamic vehicle network is predetermined and can be based on a time function, the distance covered by the master and member vehicles, and / or the departure of member vehicles, and is not limited by factors determining the lifespan duration. Embodiments of the invention instruct member vehicles to delete received EDR data segments, private key fragments, and offsets after initiating the dissolution of the current dynamic vehicle network. This aspect keeps the storage of EDR data, private key fragments, and shared VIN and index information temporary, thereby protecting privacy in the event of an incident during the lifespan of the dynamic vehicle network, while providing an alternative for recovering and reconstructing EDR data.

[0037] Advantageous aspects of some examples of the invention include the processor executing program instructions to form a next dynamic vehicle network after the current dynamic vehicle network is dissolved. The master vehicle repeatedly identifies and invites nearby vehicles as next candidate vehicles to join as a group of next member vehicles forming the next dynamic vehicle network. In some embodiments, a vehicle from the dissolved current dynamic vehicle network can rejoin as part of the next dynamic vehicle network, provided that the vehicle continues to operate within a predetermined geographical distance of the master vehicle. The aspects of the invention establish a VIN and index designation for each member vehicle in the next dynamic vehicle network, and proceed to segmenting the EDR data and distributing the portions of the EDR data to the corresponding next member vehicles in the next dynamic vehicle network, as well as segmenting the private key and sending fragments and offsets of the private key to the corresponding next member vehicles.

[0038] According to another embodiment of the present invention, a computer program product for distributing Event Data Recorder (EDR) data of a master vehicle is provided. The computer program product includes at least one computer-readable storage medium and program instructions stored on the at least one computer-readable storage medium. These program instructions include instructions to send index information uniquely identifying corresponding member vehicles of a dynamic vehicle network. Member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geographical distance of the master vehicle. These program instructions also include instructions to send a fragment of a private key associated with the master vehicle's EDR data to the corresponding member vehicle located within the predetermined geographical distance of the master vehicle. These program instructions also include instructions to distribute segments of copied EDR data from the master vehicle among the corresponding member vehicles. The EDR data segments are associated with the index identifier of the corresponding member vehicle and include a timestamp of the EDR data segment. These program instructions also include instructions to dissolve the dynamic vehicle network and initiate a next dynamic vehicle network including a set of subsequent candidate vehicles in response to the expiration of a predetermined lifecycle duration associated with the dynamic vehicle network and the absence of an accident involving the master vehicle.

[0039] Distributing segmented EDR data to local storage devices among multiple member vehicles in a dynamic vehicle network created during the operation of the master and member vehicles enables the reconstruction of the private key for decrypting the recovered EDR data even if the EDR data is corrupted or distorted after an accident involving the master vehicle. Sharing fragments of the private key among member vehicles in the dynamic vehicle network allows for the decryption of the recovered EDR data even if any vehicle cannot determine or reconstruct the private key. The identification of member vehicles in the dynamic vehicle network allows investigators to recover and reconstruct EDR data and decryption keys, even if locally recorded and stored EDR data is unrecoverable or remains encrypted due to an unavailable decryption key.

[0040] Advantageous aspects of some examples of the invention include program instructions for locating nearby vehicles during operation, wherein the proximity distance is predetermined or limited by the connectivity technology. Vehicle-to-vehicle (V2V) communication technology can be used to locate vehicles, and GPS data can be used to determine the proximity of nearby vehicles to the master vehicle. For example, the master vehicle communicates with multiple other vehicles via V2V communication and receives data on their respective GPS locations from the multiple vehicles, and determines which vehicles are within a predetermined geographic distance from the master vehicle. Geographic distance (i.e., geodetic distance) is a distance measured along the Earth's surface. During the master vehicle's location activities, the master vehicle and multiple other vehicles are in operation (i.e., in motion), which provides an advantage over current technologies, namely, the selection of candidate vehicles within the predetermined distance of the master vehicle, and the implementation of a sequence for forming and dissolving a dynamic vehicle network during the operation and travel of the master vehicle and candidate vehicles.

[0041] Advantageous aspects of some examples of the invention include programmatic instructions to send invitations to nearby vehicles to dynamically join a vehicle network. Multiple vehicles within a predefined geographical distance join the dynamic vehicle network, also referred to herein as a "vehicle network" or "network". Other nearby vehicles control whether they accept or block invitations to join the dynamic vehicle network, or, in some embodiments of the invention, other nearby vehicles may choose not to participate in V2V communication and therefore not be located. Invitations are sent to multiple vehicles located within a predetermined geographical distance and identified as traveling in a direction and / or path similar to that of the master vehicle.

[0042] Advantageous aspects of some examples of the invention include receiving a Vehicle Identifier Number (VIN) and procedural instructions confirming that a nearby vehicle accepts the sent invitation and joins the vehicle network. When a nearby vehicle joins the vehicle network, aspects of the invention assign an index to the joining vehicle such that the index provides a unique identifier for the joining vehicle as a "member vehicle" of the vehicle network, and this index is associated with EDR data and fragments and offsets of private keys distributed among all member vehicles in the vehicle network (discussed in detail below). In embodiments of the invention, the index can be a number, binary, character, string, or any combination thereof capable of clearly identifying a member vehicle within an instance of a dynamic vehicle network. Receiving the VIN of the corresponding member vehicle joining the current dynamic vehicle network provides a clear identifier for the member vehicle, and the allocation of index information enables data to be assigned to the corresponding member vehicle for the current dynamic vehicle network, avoiding confusion of data sent to vehicles sequentially included in multiple dynamic vehicle networks.

[0043] In some embodiments, the VIN and index associated with a corresponding member vehicle of the dynamic vehicle network are sent to a remote data center, which is typically used as a data source for vehicle accident or incident investigations. An advantageous aspect of the invention includes a processor executing program instructions to send the VIN and index associated with a corresponding vehicle of the newly formed dynamic vehicle network to a central data repository, thereby enabling the identification of network member vehicles and which vehicle is associated with which index designation during the network's duration. In some embodiments, the VIN and index information is encrypted to protect the identity of member vehicles while allowing decryption in the event of an accident involving the primary vehicle. In some embodiments, the VIN and index information is sent to member vehicles for temporary storage during the duration of the dynamic vehicle network as a redundancy for sending information to the central data repository. The temporary duration of the dynamic vehicle network and its dissolution after the predetermined lifespan of the duration improve the practice of EDR data recording by enabling the recording and distribution of EDR data segments as a recoverable alternative source of EDR data in the event of corruption or loss of EDR data stored on the primary vehicle.

[0044] Advantages of some examples of the invention include a finite lifespan duration for the dynamic vehicle network, making each instance of the dynamic vehicle network temporary. The expiration of the dynamic vehicle network's lifespan duration can be initiated, for example, by criteria including a time function, travel distance, member vehicles of the network moving beyond a predetermined geographical distance, or the signal strength of the V2V connection dropping below a minimum threshold. After the lifespan duration of the vehicle network expires, the processor executes program instructions to disband the current group of member vehicles as the current network and continues to create the next group of member vehicles to form the next dynamic vehicle network, while the master vehicle and nearby vehicles are actively operating.

[0045] Advantages of some examples of the present invention include program instructions for segmenting EDR data, wherein the data segments and timestamps associated with the data segments are encrypted and sent to at least one member vehicle of the dynamic vehicle network. The EDR data segments are distributed to the member vehicles of the dynamic vehicle network and associated with the timestamps and indices assigned to the respective member vehicles. By distributing segmented EDR data among multiple member vehicles of the dynamic vehicle network, advantages over current EDR data recording practices are achieved. The distribution of EDR data segments provides protection against data privacy issues because no single member vehicle includes all EDR data, and the data is sent in an encrypted format. Embodiments of the present invention are not limited to the segmentation type, as any segmentation algorithm can be used.

[0046] Advantageous aspects of some examples of the invention include program instructions for segmenting the private key used by the primary vehicle or its owner to decrypt EDR data. The private key is used to decrypt EDR data segments sent to member vehicles in a dynamic vehicle network. By segmenting the private key and distributing the fragments of the private key, along with the location offsets associated with the private key fragments, among member vehicles in the dynamic vehicle network, no single member vehicle has sufficient private key information to decrypt the EDR data segment stored on its own. One aspect of the invention involves sending unencrypted private key fragments in text format. By identifying the member vehicle and obtaining the text-formatted fragments of the private key and their location offsets, the private key can be reconstructed and used by an investigator to recover and decrypt the distributed EDR data segments from the member vehicles and their associated timestamps. The offsets associated with the fragments of the private key provide the fragment's position within the reconstructed private key. The timestamps enable the reconstruction of EDR data chronologically. Current practice provides the private key to the primary vehicle owner for exclusive access, which creates a risk of EDR data being accessed and decrypted.

[0047] Advantages of some examples of the invention include program instructions for recovering EDR data in cases where the primary vehicle has been involved in an accident and EDR data recovery is not possible, and data cannot be decrypted directly from the primary vehicle and / or the vehicle owner. Embodiments of the invention provide alternative means for recovering and decrypting EDR data in cases where the primary vehicle has been involved in an accident and the EDR data storage device is damaged (making EDR data unrecoverable from the primary vehicle) or where the private key for decrypting the EDR data is unavailable due to the condition of the vehicle owner (i.e., the driver of the primary vehicle at the time of the accident). Current practices cannot decrypt and analyze EDR data if the EDR data stored on the primary vehicle is damaged or inaccessible due to injury or incapacitation of the primary vehicle owner in an accident.

[0048] Advantageous aspects of some examples of the invention include program instructions to dissolve the dynamic vehicle network after the expiration of a finite lifespan duration. The lifespan duration of the dynamic vehicle network is predetermined and can be based on a time function, the distance covered by the master and member vehicles, and / or the departure of member vehicles, and is not limited by factors determining the lifespan duration. Embodiments of the invention instruct member vehicles to delete received EDR data segments, private key fragments, and offsets after initiating the dissolution of the current dynamic vehicle network. This aspect maintains the storage of EDR data, private key fragments, and shared VIN and index information as temporary, thereby protecting privacy in the event of an incident during the lifespan of the dynamic vehicle network, while providing an alternative for recovering and reconstructing EDR data.

[0049] Advantageous aspects of some examples of the invention include program instructions for forming the next dynamic vehicle network after the current dynamic vehicle network is dissolved. The master vehicle repeatedly identifies and invites nearby vehicles as next candidate vehicles to join as a group of next member vehicles forming the next dynamic vehicle network. In some embodiments, a vehicle from the dissolved current dynamic vehicle network may rejoin as part of the next dynamic vehicle network, provided that the vehicle continues to operate within a predetermined geographical distance of the master vehicle. The aspects of the invention establish a VIN and index designation for each member vehicle in the next dynamic vehicle network, and proceed to segmenting the EDR data and distributing the portions of the EDR data to the corresponding next member vehicles in the next dynamic vehicle network, as well as segmenting the private key and sending fragments and offsets of the private key to the corresponding next member vehicles.

[0050] The advantages described above are exemplary and do not represent all advantages. Furthermore, embodiments of this disclosure may include all, some, or none of the foregoing advantages, while still remaining within the scope of this disclosure.

[0051] Various aspects of this disclosure are described by means of explanatory text, flowcharts, block diagrams of computer systems, and / or block diagrams of machine logic included in embodiments of a computer program product (CPP). For any flowchart, operations may be performed in a different order than that shown in the given flowchart, depending on the art involved. For example, also according to the art involved, two operations shown in consecutive flowchart blocks may be performed in reverse order, as a single integrated step, simultaneously, or in a manner that at least partially overlaps in time.

[0052] The invention will now be described in detail with reference to the accompanying drawings. Figure 1 This is a functional block diagram illustrating a dynamic vehicle network (generally represented by 107) including distributed data processing according to an embodiment of the present invention. Figure 1 This illustration is merely for the purpose of providing one embodiment and does not imply any limitation on the environments in which different embodiments may be implemented. Those skilled in the art can make many modifications to the depicted environments without departing from the scope of the invention as set forth in the claims.

[0053] Figure 1A dynamic vehicle network 107 is depicted, in which Event Data Recorder (EDR) data is distributed over a limited lifespan. The dynamic vehicle network 107 includes a master vehicle 116, network member vehicles 120, 125, 130, and 135, and a data center 140 connected to the dynamic vehicle network 107 via a network 150. The dynamic vehicle network 107 is a local network between operating vehicles that communicates via vehicle-to-vehicle (V2V) technology and exchanges information including location, direction, speed, and other information. The dynamic vehicle network 107 forms dynamically as vehicles are in operation and includes vehicles invited by a master vehicle, such as master vehicle 116. Invited vehicles decide whether to "opt out" after receiving an invitation to join the network. The dynamic vehicle network is temporary and includes a limited lifespan that is predetermined and may expire based on time, distance traveled, and member vehicles leaving the network (e.g., leaving the master vehicle in a different direction or over a different distance). After the current dynamic vehicle network is disbanded, the next dynamic vehicle network can be formed, and the formation and disbanding can be carried out continuously as the master vehicle moves and discovers member vehicles to join the network.

[0054] The master vehicle 116 is an operational vehicle and includes a computing device 110 configured to run a data recovery program 200, and includes hardware and software enabling the EDR 118 to record event data. In an embodiment of the invention, the master vehicle 116 travels on a road / path toward a destination. The master vehicle 116 initiates invitations to other vehicles in the vicinity to join the dynamic vehicle network 107 via the data recovery program 200 running on the computing device 110. The vicinity is a predetermined distance and may be further limited to vehicles identified as operational and traveling in directions and paths similar to those of the master vehicle 116, such as those identified by Global Positioning System (GPS) data exchanged between vehicles via V2V communication. The master vehicle 116 is the issuer of an index serving as a unique identifier for the corresponding member vehicle of the dynamic vehicle network 107 via the data recovery program 200.

[0055] The computing device 110 operates on the host vehicle 116 and includes a data recovery program 200, and is communicatively connected to the EDR 118. In some embodiments, the computing device 110 may be an onboard computing device capable of sending, receiving, and processing data and instructions and communicating with network member vehicles 120, 125, 130, and 135, as well as communicating with the data center 140 via network 150. In some embodiments, the computing device 110 is structurally and functionally similar to... Figure 1 Terminal user equipment 103.

[0056] Data recovery program 200 provides recoverable EDR data distributed in segments among multiple member vehicles that have opted to join a dynamic vehicle network. Segmentation and distribution of the primary vehicle's EDR data supports post-accident investigations by enabling vehicle data recovery in the event of an accident in which the primary vehicle is damaged, destroyed, or otherwise rendered inaccurate or unavailable. EDR data captures vehicle condition and operational attributes immediately preceding, during, and following an accident such as an accident, collision, fire, loss of control, or other triggered vehicle actions.

[0057] Data recovery procedure 200 is initiated and sends invitations to join the vehicle network to candidate vehicles within a predetermined range of the master vehicle on which it operates. Data recovery procedure 200 communicates with nearby vehicles via V2V communication technology and receives confirmations from candidate vehicles selected to join the dynamic vehicle network as member vehicles, along with the corresponding member vehicle's VIN. Data recovery procedure 200 assigns an index to each member vehicle as a unique identifier within the network and sends the corresponding member vehicle's encrypted VIN and text-based index assignment identifier to a central data repository. Immediately after the dynamic vehicle network is formed and the VIN and assigned network index identifier are received, the encrypted VIN and text-based index information are sent to the central data storage device. In some embodiments, the member vehicle's VIN and / or index identifier are shared among the member vehicles of the dynamic vehicle network to enable vehicle and data identification in cases where access to the central storage data is unavailable. In some embodiments, the current network index identification information is periodically copied and sent to a remote central data storage device.

[0058] Data recovery procedure 200 performs segmentation of the private key of the master vehicle used to decrypt the EDR data. Data recovery procedure 200 creates fragments of the private key and distributes these fragments to each member vehicle in the dynamic vehicle network. The fragments are created using any existing method and distributed unencrypted in text format, including offsets of the fragments' positions within the reconstructed private key. Private key segmentation occurs immediately after network formation, and each fragment is stored on the corresponding member vehicle in the dynamic vehicle network. In some embodiments of the invention, after network formation and completion of segmentation and distribution, the segmented and offset data, along with the index identifiers of the corresponding member vehicles, are immediately sent to a remote central data storage device. The segmentation and distribution of the private key portion prevents member vehicles from decrypting the EDR data.

[0059] Data recovery procedure 200 copies and segments EDR data from the event data recording device. Data recovery procedure 200 distributes the segments to the corresponding member vehicles of the dynamic vehicle network, and in some embodiments, data recovery procedure 200 uses V2V communication technology for segment distribution. The EDR data segment of the master vehicle includes portions of vehicle control and operational data and is distributed to member vehicles in an encrypted format, thus protecting data privacy because no individual vehicle possesses the entire private key required to decrypt the data, and the VIN shared among member vehicles is in encrypted format. Member vehicles of the dynamic vehicle network do not consume or use the segmented data; instead, the segmented data is stored to provide redundant copies of the EDR data, which can be recovered and reconstructed for authorized agencies to conduct vehicle accident investigations.

[0060] The dynamic vehicle network created by data recovery program 200 is a temporary network with a finite lifespan. In some embodiments, the expiration of the dynamic vehicle network may be triggered by the duration of travel, while in other embodiments, the expiration may be triggered by the distance traveled. In other embodiments, the expiration of the dynamic vehicle network may occur due to one or more member vehicles leaving as member vehicles, changing direction, or exceeding a distance from the master vehicle. In some embodiments, all members of the vehicle network back up each other's EDR data (including the encrypted VIN of the respective vehicle) to ensure integrity and security.

[0061] If the data recovery procedure 200 does not detect an accident involving the primary vehicle, all segment data and private key fragments are deleted after the network expires. If an accident occurs, data segments sent to member vehicles in the dynamic vehicle network are retained for a predetermined period for potential recovery availability. After the storage period expires and no event is detected, the segmented EDR data, text-formatted private key fragments, and indexed and encrypted VIN information stored on the member vehicles during the finite lifespan of the dynamic vehicle network are deleted.

[0062] The EDR 118 is an event data logging device and includes data storage capacity to store vehicle control, operational, and performance data associated with the primary vehicle. For example, the EDR 118 records vehicle data such as speed, acceleration changes, passenger behavior (i.e., the number of passengers wearing seatbelts); driver inputs (steering, throttle, and braking); vehicle position, speed, and yaw angle; and other details such as the deployment of safety and passenger protection systems, and any potential impact forces. This data is combined with concurrent diagnostics of the vehicle's systems. In some cases, EDR data is considered sensitive and private and is protected by encryption using a unique public-private key pair. The private key is typically only available to the vehicle owner.

[0063] EDR 118 records event data when a sudden change is detected, thereby recording a relatively large amount of data over a very short period of time, including several seconds before the incident, several seconds during the incident, and several seconds after the incident. In some embodiments, EDR 118 may not share the recorded data with a central data repository (such as data center 140), and EDR 118 may be corrupted during the incident or tampered with after the incident, leaving fragmented copies of the EDR data as a surviving or accurate data source.

[0064] Network member vehicles 120, 125, 130, and 135 are vehicles operating within a predetermined distance from the host vehicle 116. Network member vehicles 120, 125, 130, and 135 receive invitations to join the dynamic vehicle network from a data recovery program 200 running on the computing device 110 of the host vehicle 116. Network member vehicles 120, 125, 130, and 135 respond to the invitation by "selecting to join" to join the vehicle network, or by "selecting to leave" or ignoring the invitation to not join the vehicle network. Network member vehicles 120, 125, 130, and 135 include VIN information in their respective "selecting to join" responses.

[0065] In response to joining the vehicle network, network member vehicles 120, 125, 130, and 135 receive a unique index identifying the corresponding vehicle within the network, and receive a fragment of the private key of the master vehicle 116 in text format, along with the index of the network member vehicle and encrypted VIN information. Network member vehicles 120, 125, 130, and 135 receive encrypted segments of the recorded EDR data from the master vehicle 116 and store these segments on local storage. If an accident involving the master vehicle 116 is detected, the segmented EDR data is stored on the respective network member vehicles 120, 125, 130, and 135 for a predetermined period of time until the EDR data is recovered (if necessary).

[0066] Data center 140 is a central storage facility used to store EDR data received from master vehicle 116 after an incident, provided that the incident did not damage EDR 118 or prevent the transmission of EDR data to data center 140. Data center 140 is communicatively connected to master vehicle 116 via network 150.

[0067] Network 150 provides a communication connection between computing devices 110 operating on the main vehicle 116 and data center 140. Network 150 can be, for example, a local area network (LAN), a telecommunications network, a wide area network (WAN) such as the Internet, a virtual local area network (VLAN), or any combination that may include wired, wireless, or optical connections. In some embodiments, network 150 may be... Figure 3The wide area network (WAN) 102 is depicted in the diagram. Typically, network 150 can be any combination of connections and protocols for data transmission and communication between computing device 110, which supports dynamic vehicle network 107, and data center 140.

[0068] Figure 2 A flowchart is depicted for a data recovery procedure 200 comprising a segmented distribution of a copy of the Event Data Recorder (EDR) data of the primary vehicle, according to an embodiment of the present invention. When EDR data has been damaged, corrupted, or tampered with due to an accident, the data recovery procedure 200 provides an alternative source of EDR data for the vehicle accident. The data recovery procedure 200 enables the recovery of segmented portions of EDR data distributed among member vehicles in a dynamic vehicle network by reconstructing the segmented private keys to identify member vehicles and decrypting the segmented data.

[0069] Data recovery procedure 200 sends invitations to candidate vehicles within a predetermined geographical distance of the master vehicle to join the dynamic vehicle network (step 210). Data recovery procedure 200 also sends requests to other vehicles within a predefined range / distance of the master vehicle to join a temporary network forming the vehicles to share distributed EDR data segments and other data, thereby enabling the recovery of EDR data if data stored on the master vehicle is corrupted, damaged, or inaccurate due to tampering. Invitations are sent as requests, and receiving vehicles voluntarily choose to join their own dynamic vehicle network. Acceptance of invitations is controlled by the candidate vehicles.

[0070] For example, data recovery program 200 sends invitation notifications to other vehicles operating within a predetermined geographical distance. This may include determining their distance from the primary vehicle 116, direction of travel, speed, and the location of candidate vehicles. Data recovery program 200 sends invitations to operating vehicles that appear to be traveling towards the same or similar destination as the primary vehicle 116. Data recovery program 200 sends invitations via V2V communication, which may include transmissions via network 150.

[0071] Data recovery procedure 200 receives the VIN of the corresponding member vehicle in response to a candidate vehicle joining the dynamic vehicle network (step 220). Candidate vehicles that "select to join" to join the dynamic vehicle network include their respective VINs and an indication of consent to join the network. The VIN provides identification for the member vehicle to facilitate on-demand recovery of EDR data. The dynamic vehicle network is formed between member vehicles and master vehicles.

[0072] For example, the data recovery program 200 running on the master vehicle 116 receives responses from candidate vehicles instructing them to "opt in" or "opt out" (or not to respond) to join the dynamic vehicle network 107. Vehicles that "opt in" are member vehicles of the network and provide their respective VINs to the data recovery program 200.

[0073] Data recovery procedure 200 assigns an index to identify the corresponding member vehicle within the dynamic vehicle network (step 230). Each member vehicle in the dynamic vehicle network is identified by an index assigned by data recovery procedure 200 within the dynamic vehicle network. This index is associated with the data distributed to the member vehicle to facilitate data recovery should the EDR data be unavailable for investigator analysis due to an accident involving the primary vehicle. Data recovery procedure 200 sends the index information and the encrypted VIN of the corresponding member vehicle to the member vehicles of the newly formed dynamic vehicle network. Data recovery procedure 200 sends the VIN and index information to the central data storage device immediately after the network is formed. The dynamic vehicle network is a temporary network with a limited lifespan. The local clusters of network vehicles are only built for a limited time and are deassociated after the lifespan expiration criteria are met. Subsequently, while the primary and candidate vehicles are in operation, the next dynamic vehicle network will be built. The list of member vehicle IDs and index information for the VIN are mapped to the corresponding set of member vehicles in the current dynamic vehicle network, which can be checked by the timestamp at which the member vehicle ID list was generated.

[0074] For example, data recovery program 200 assigns an index to each of the network member vehicles 120, 125, 130, and 135 (collectively referred to as member vehicles) in the dynamic vehicle network, and shares the index information and the encrypted VIN associated with the index with the member vehicles. Data recovery program 200 sends the index information and associated VIN to data center 140, for example, within the first few minutes of forming the dynamic vehicle network.

[0075] Data recovery procedure 200 sends a fragment of the private key used for decryption to the appropriate member of the network (step 240) in text format. Typically, only the primary vehicle owner has access to the private key to decrypt EDR data. With the primary vehicle owner's consent, data recovery procedure 200 segments the private key into multiple parts and distributes these fragments among member vehicles in the dynamic vehicle network. Embodiments of the invention use any segmentation algorithm that can be used to successfully segment and reconstruct the private key into its original state. Data recovery procedure 200 includes offsets along with the fragments to indicate the fragment's position in the reconstruction of the private key. These fragments are distributed to member vehicles unencrypted in text format. The segmentation and distribution of fragments occur rapidly after data recovery procedure 200 receives the consent of the member vehicles and forms a dynamic vehicle network. The fact that each member vehicle only has a fragment of the private key and cannot decrypt EDR data segments, and that the private key is distributed among multiple operating member vehicles, makes the reconstruction of the private key highly unlikely.

[0076] For example, data recovery program 200 uses a segmentation technique that divides the binary form of the private key into sub-component strings of 1s and 0s. Each segment is accompanied by an offset indicating its position within the original private key. Network member vehicles 120, 125, 130, and 135 each receive a segment of the private key and its offset. This segment is sent in text format as sub-components of the binary form of the private key. Data recovery program 200 identifies the specific segment and offset sent along with the index of the receiving member vehicle. Each member vehicle is unaware of which sub-components and offsets of the private key it received, or which segments and offsets were sent to other member vehicles.

[0077] Data recovery procedure 200 segments and distributes the copied EDR data from the master vehicle among the corresponding member vehicles, such that each segment is associated with the index of the corresponding member vehicle and includes a timestamp of the data segment (step 250). Data recovery procedure 200 copies the recorded EDR data segments and sends the corresponding segments to the corresponding member vehicles, associating them with the member vehicle's index and the timestamp of the EDR data segment. In this way, all EDR data is distributed segment by segment to the member vehicles of the dynamic vehicle network. Each segment is encrypted to protect the data contained within it and is stored locally on the member vehicle along with the timestamp and index information corresponding to the receiving member vehicle. When decrypted by reconstructing the private key of the segmented data, the segmented EDR data and timestamps are recovered and reconstructed in chronological order.

[0078] For example, the data recovery procedure 200 operating on the master vehicle 116 copies the first segment of the recorded EDR data and sends the segment, along with its timestamp, to the network member vehicle 130. Data segmentation continues, and the data recovery procedure 200 continues to send segments and corresponding timestamps to network member vehicles 120, 135, and 126, and may continue segmenting and distributing segments and timestamps until all EDR data has been sent. In some embodiments, the order in which EDR data segments are sent to member vehicles may change sequentially, and may include multiple consecutive segments to the same member vehicle.

[0079] Data recovery procedure 200, in response to the expiration of the network's lifecycle duration without an accident involving the primary vehicle, disbands the current dynamic vehicle network and initiates the next dynamic vehicle network (step 260). The current dynamic vehicle network has a finite lifecycle duration, which is predetermined and may include multiple expiration criteria. In the absence of a primary vehicle accident, the current dynamic vehicle network may be disbanded based on an elapsed time threshold, exceeding a distance threshold, a member vehicle leaving the current vehicle network, or due to a member vehicle's V2V signal strength dropping below a threshold level. Data recovery procedure 200 determines that no primary vehicle accident has occurred, detects a triggered expiration criterion, and initiates the disbandment of the current dynamic vehicle network by communicating with the member vehicle via V2V communication. Data recovery procedure 200 provides instructions to the member vehicle to delete received EDR data segments, as well as fragments and offsets of the private key. In some embodiments, the disbandment criteria may be included as instructions from data recovery procedure 200 to the member vehicle when the dynamic vehicle network is formed. In some embodiments, if a member vehicle loses contact with the master vehicle via V2V communication and data recovery procedure 200 for a predetermined period of time, a disbanding instruction is initiated, including instructions to delete segmented data, timestamps, shared VIN and index information, as well as private key fragments and offsets.

[0080] In some embodiments, after disbanding the current dynamic vehicle network and providing instructions to the member vehicles of the current dynamic vehicle network that is being disbanded, the data recovery procedure 200 initiates the next dynamic vehicle network by locating and inviting the next group of candidate vehicles to join the next dynamic vehicle network.

[0081] For example, network member vehicle 125 leaves the road on which the master vehicle 116 and network vehicles 120, 130, and 135 are traveling, and as network member vehicle 125 moves further away from the current dynamic vehicle network, the V2V communication signal strength drops below a predetermined threshold. Data recovery procedure 200 detects the expiration criterion and initiates the disbanding of the current dynamic vehicle network, sending instructions to member vehicles to delete segmented EDR data, timestamps, index information, shared encrypted VINs, and fragments and offsets of private keys. Network member vehicle 125 is outside the range of receiving V2V communication with data recovery procedure 200, but after a predetermined duration of no communication with the master vehicle, network member vehicle 125 initiates the deletion of received EDR data segments, timestamps, indexes, shared VINs, and fragments and offsets of private keys received by network member vehicle 125. After disbanding the current dynamic vehicle network, which includes network vehicles 120, 125, 130, and 135, the data recovery procedure 200 initiates the next dynamic vehicle network by locating a group of next candidate vehicles within a predetermined geographical distance and sending invitations to that group of next candidate vehicles to join the next dynamic vehicle network.

[0082] Data recovery procedure 200 identifies member vehicles in the network in response to an accident involving the primary vehicle, obtains private key fragments and offsets, recovers EDR data segments and timestamps, decrypts the segments with the reconstructed private key, and reconstructs the segmented EDR data in chronological order (step 270). In some embodiments, data recovery procedure 200 detects an accident involving the primary vehicle and sends instructions to the corresponding member vehicles to retain the stored EDR data segments. In some embodiments, data recovery procedure 200 performs post-detection of accidents involving the primary vehicle under the guidance of an investigation agency, and in some cases under the authorization of the investigation agency.

[0083] After detecting an accident involving the primary vehicle, the data recovery procedure 200 uses index information to identify member vehicles in the dynamic vehicle network and obtains the distributed private key fragments and corresponding offsets. The data recovery procedure 200 reconstructs the private key based on the offsets and fragments sent to the member vehicles in text format. The private key is reconstructed by applying the offset information accompanying the distribution of the private key fragments to the corresponding member vehicles. The data recovery procedure 200 uses the reconstructed private key to decrypt EDR data segments and timestamp information. The data recovery procedure 200 obtains the EDR data segments distributed among member vehicles in the dynamic vehicle network and their corresponding timestamps. The data recovery procedure 200 reconstructs the EDR data based on the obtained index information and timestamps of the EDR data segments.

[0084] In some embodiments, where the primary vehicle owner / driver has been severely incapacitated or killed due to an accident involving the primary vehicle, accident investigators may be unable to decrypt EDR data locally stored on the primary vehicle. Embodiments of the present invention provide alternative means of recovering and decrypting EDR data while providing security for distributed data.

[0085] For example, data recovery procedure 200 detects that the accident involves the primary vehicle 116 and sends instructions to member vehicles in the dynamic vehicle network to retain the received and stored EDR data segments. The investigation agency initiates data recovery procedure 200 to obtain fragments and offsets of the private keys distributed among network member vehicles 120, 125, 130, and 135, and reconstructs the private keys based on the offsets of each fragment's position within the original private key. Data recovery procedure 200 obtains the encrypted distributed EDR data segments and their corresponding timestamps. Using the reconstructed private key, data recovery procedure 200 decrypts the distributed segments and timestamps of the EDR data, and reconstructs the EDR data in an appropriate chronological order based on the decrypted timestamp information.

[0086] Another example of an embodiment of the invention involves vehicle A initiating a V2V vehicle local cluster by sending an invitation to join a first dynamic vehicle network. Vehicles B, C, D, and E respond with an "opt-in" confirmation, and data recovery procedure 200 assigns indices 1, 2, 3, and 4 to vehicles B, C, D, and E, respectively. The indices are sent to each vehicle and to data center 140 on a remote server. After network startup, the master vehicle (i.e., vehicle A) segments its private key into four parts (the segmentation algorithm can be any existing algorithm), and each corresponding segment is sent to the corresponding vehicle among B, C, D, and E based on the indices of member vehicles B, C, D, and E. After recording vehicle A's EDR data, data recovery procedure 200 periodically copies segments of vehicle A's encrypted EDR data to B, C, D, and E. The segmentation and distribution method is not limited to embodiments of the invention; the method can be cyclic copying, taking a consistent order based on vehicle index tags without repetition, or the distribution method can send EDR data segments with each pair of vehicles repeating once.

[0087] Each replicated EDR data segment includes a timestamp so that these segments can be merged chronologically during EDR data recovery. If, as determined during a health check at the end of the lifecycle duration, vehicle A has not been involved in an accident, vehicle A will issue an EDR data erase instruction to each of member vehicles B, C, D, and E to delete the replicated data. In the event of an accident involving vehicle A and damage to vehicle A including the loss of local EDR data, data sent to the remote data center server when the current dynamic vehicle network was formed indicates which vehicles were member vehicles of the current dynamic vehicle network prior to the accident, and replicated EDR data segments are obtained from these member vehicles.

[0088] Because the EDR data segments are encrypted, and each member vehicle possesses only a fragment of the private key, each member vehicle cannot decrypt the EDR data segment independently. Since the remote data center server contains identifiers for the complete set of member vehicles in the current dynamic vehicle network, only a commissioned investigator can obtain the data identifying the vehicles, reconstruct the private key fragments, and decrypt the sequentially assembled recovered EDR data segments. The local vehicle network is dynamically established periodically while the master vehicle is running, and the joining of member vehicles is largely random. Therefore, embodiments of the invention make it difficult to predefine dynamic vehicle network members before an accident occurs to the master vehicle, and thus minimize the exposure of encrypted EDR data.

[0089] Figure 3 A schematic diagram depicts exemplary network resources associated with the invention disclosed in practice. The invention can be implemented via the disclosed processor execution instruction stream. For example... Figure 3 As shown, computing environment 100 includes an example of an environment for executing at least some computer code relating to performing methods of the present invention, such as the method of data recovery program 200 in block 151, which is held in persistent storage device 113. In addition to block 151, computing environment 100 includes, for example, a computer 101, a wide area network (WAN) 102, an end-user equipment (EUD) 103, a remote server 104, a public cloud 105, a private cloud 106, and a data center 140 operating as a remote database 132 on remote server 104. In this embodiment, computer 101 includes processor group 109 (including processing circuitry 119 and cache 121), communication infrastructure 111, volatile memory 112, persistent storage device 113 (including operating system 122 and data recovery program 200 of block 151, as described above), and peripheral device group 114 (including user interface (UI) device group 123, storage device 124, and network module 115).

[0090] Remote server 104 includes remote database 132, which in some embodiments may resemble data center 140. Figure 1 The public cloud 105 includes a gateway 145, a cloud orchestration module 141, a host physical unit 142, a virtual machine unit 143, and a container unit 144.

[0091] Computer 101 may take the form of a desktop computer, laptop computer, tablet computer, smartphone, smartwatch or other wearable computer, mainframe computer, quantum computer, or any other form of computer or mobile device now known or to be developed in the future capable of running programs, accessing networks, or querying databases such as remote database 132. In some embodiments, computer 101 may take the form of a handheld device capable of receiving and sending data and executing computer instructions. In some embodiments, computer 101 may be configured and similar to Figure 1 The computing device 110 depicted operates and is carried out on the main vehicle 116. As is known in the field of computer technology, and depending on that technology, the execution of a computer-implemented method can be distributed among multiple computers and / or multiple locations. On the other hand, in this presentation of the computing environment 100, the detailed discussion focuses on a single computing device, in particular computer 101, to keep the presentation as simple as possible. Computer 101 can be located in the cloud, even... Figure 3 It is not shown to be in the cloud. On the other hand, computer 101 does not need to be in the cloud unless it can be definitively stated to any extent.

[0092] Processor group 109 includes one or more computer processors of any type now known or to be developed in the future. Processing circuitry 119 may be distributed across multiple packages, such as multiple coordinated integrated circuit chips. Processing circuitry 119 may implement multiple processor threads and / or multiple processor cores. Cache 121 is memory located within the processor chip package, typically used for data or code that the threads or cores running on processor group 109 should be able to access quickly. Cache memory is typically organized into multiple levels depending on its relative proximity to the processing circuitry. Alternatively, some or all of the processor group's cache may be located "off-chip". In some computing environments, processor group 109 may be designed to use qubits and perform quantum computing.

[0093] Computer-readable program instructions are typically loaded onto computer 101 to cause the processor assembly 109 of computer 101 to perform a series of operational steps to implement a computer-implemented method, such that the instructions executed in this way instantiate the method specified in the flowcharts and / or descriptions of the computer-implemented method contained herein (collectively, "the method of the present invention"). These computer-readable program instructions are stored in various types of computer-readable storage media, such as cache 121 and other storage media discussed below. The program instructions and associated data are accessed by processor assembly 109 to control and direct the execution of the method of the present invention. In computing environment 100, at least some of the instructions for performing the method of the present invention may be stored in data recovery program 200 in block 151 of persistent storage device 113.

[0094] Communication structure 111 is a signal transmission path that allows various components of computer 101 to communicate with each other. Typically, this structure consists of switches and conductive paths, such as switches and conductive paths forming buses, bridges, physical input / output ports, etc. Other types of signal communication paths can be used, such as fiber optic communication paths and / or wireless communication paths.

[0095] Volatile memory 112 is any type of volatile memory currently known or developed in the future. Examples include dynamically typed random access memory (RAM) or statically typed RAM. Typically, volatile memory 112 is characterized by random access, but this is not required unless explicitly indicated. In computer 101, volatile memory 112 is located in a single package and is internal to computer 101; however, optionally or additionally, volatile memory may be distributed across multiple packages and / or located externally relative to computer 101.

[0096] The persistent storage device 113 is any form of non-volatile storage device in a computer that is now known or to be developed in the future. The non-volatility of this storage device means that the stored data will be retained regardless of whether the computer 101 is powered or whether the persistent storage device 113 is directly powered. The persistent storage device 113 may be a read-only memory (ROM), but typically at least a portion of the persistent storage device allows data to be written, deleted, and rewritten. Some common forms of persistent storage devices include hard disks and solid-state storage devices. The operating system 122 can take many forms, such as various known proprietary operating systems or open-source portable operating system interface type operating systems employing a kernel. The code included in the representative data recovery block 200 typically includes at least some of the computer code involved in performing the methods of the present invention.

[0097] Peripheral device group 114 includes the peripheral device group of computer 101. Data communication connections between peripheral devices and other components of computer 101 can be implemented in various ways, such as Bluetooth connectivity, near field communication (NFC) connectivity, cable connections (e.g., Universal Serial Bus (USB) type cables), plug-in connections (e.g., Secure Digital (SD) cards), connections via local area networks, or even connections via wide area networks such as the Internet. In various embodiments, UI device group 123 may include components such as displays, speakers, microphones, wearable devices (e.g., goggles and smartwatches), keyboards, mice, printers, touchpads, game controllers, and haptic devices. Storage device 124 is an external storage device (e.g., an external hard drive) or a pluggable memory (e.g., an SD card). Storage device 124 may be persistent and / or volatile. In some embodiments, storage device 124 may take the form of a quantum computing storage device for storing data in the form of qubits. In embodiments where computer 101 requires a large amount of storage (e.g., computer 101 stores and manages a large database locally), the storage device may be provided by a peripheral storage device designed to store very large amounts of data, such as a storage area network (SAN) shared by multiple geographically dispersed computers.

[0098] Network module 115 is a collection of computer software, hardware, and firmware that allows computer 101 to communicate with other computers via WAN 102. Network module 115 may include hardware such as a modem or Wi-Fi transceiver, software for packetizing and / or depacketizing data for transmission over the communication network, and / or web browser software for transmitting data over the Internet. In some embodiments, the network control and network forwarding functions of network module 115 are performed on the same physical hardware device. In other embodiments (e.g., embodiments utilizing Software-Defined Networking (SDN)), the control and forwarding functions of network module 115 are performed on physically separate devices, such that the control functions manage multiple different network hardware devices. Computer-readable program instructions for performing the methods of the present invention can typically be downloaded to computer 101 from an external computer or external storage device via a network adapter card or network interface included in network module 115.

[0099] WAN 102 is any wide area network (such as the Internet) capable of transmitting computer data over non-local distances using any technology now known or to be developed in the future for transmitting computer data. In some embodiments, WAN 102 may be replaced and / or supplemented by a local area network (LAN), which is designed to transmit data between devices located in a local area such as a Wi-Fi network. WAN and / or LAN typically include computer hardware such as copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and edge servers.

[0100] End User Equipment (EUD) 103 is any computer system used and controlled by an end user (e.g., a customer of the enterprise operating computer 101) and can take any of the forms discussed above in conjunction with computer 101. EUD 103 typically receives helpful and useful data from the operation of computer 101. For example, assuming computer 101 is designed to provide advice to an end user, this advice is typically transmitted from network module 115 of computer 101 to EUD 103 via WAN 102. Thus, EUD 103 may display or otherwise present this advice to the end user. In some embodiments, EUD 103 may be a client device, such as a thin client, heavy client, mainframe, desktop, etc.

[0101] Remote server 104 is any computer system that provides at least some data and / or functionality to computer 101. Remote server 104 can be controlled and used by the same entity operating computer 101. Remote server 104 represents a machine used to collect and store useful data for use by other computers (such as computer 101). For example, in the hypothetical scenario where computer 101 is designed and programmed to provide recommendations based on historical data, this historical data can be provided to computer 101 from a remote database 132 of remote server 104.

[0102] Public cloud 105 is any computer system that can be used by multiple entities, providing on-demand availability of computer system resources and / or other computing capabilities (especially data storage (cloud storage) and computing power) without direct active management by the user. Cloud computing typically leverages resource sharing to achieve consistency and economies of scale. Direct active management of the computing resources of public cloud 105 is performed by the computer hardware and / or software of cloud orchestration module 141. The computing resources provided by public cloud 105 are typically implemented by virtual computing environments running on various computers constituting host physical group 142, which is the various physical computers in and / or available to public cloud 105. Virtual computing environments (VCEs) typically take the form of virtual machines from virtual machine group 143 and / or containers from container group 144. It is understood that these VCEs can be stored as images and can be transferred between various physical host machines as images or after VCE instantiation. Cloud orchestration module 141 manages the transfer and storage of images, deploys new instances of VCEs, and manages active instances of VCE deployments. Gateway 145 is a collection of computer software, hardware, and firmware that allows public cloud 105 to communicate via WAN 102.

[0103] Now, we will provide some further explanation of Virtualized Computing Environments (VCEs). A VCE can be stored as an "image." A new active instance of a VCE can be instantiated from an image. Two familiar types of VCEs are virtual machines and containers. A container is a VCE that uses operating system-level virtualization. This refers to an operating system feature where the kernel allows multiple isolated user-space instances (called containers) to exist. From the perspective of a program running within it, these isolated user-space instances typically behave like a real computer. A computer program running on a regular operating system can utilize all the resources of that computer, such as connected devices, files and folders, network shares, CPU power, and quantifiable hardware capabilities. However, a program running within a container can only use the contents of that container and the devices allocated to that container; this characteristic is called containerization.

[0104] Private cloud 106 is similar to public cloud 105, except that computing resources are available only to a single enterprise. While private cloud 106 is depicted as communicating with WAN 102, in other embodiments, private cloud may be completely disconnected from the internet and accessible only via a local / private network. Hybrid cloud is a combination of multiple clouds of different types (e.g., private, community, or public cloud types), typically implemented separately by different vendors.

[0105] Each of the multiple clouds remains a separate, discrete entity, but the larger hybrid cloud architecture is bound together through standardization or proprietary technologies, supporting orchestration, management, and / or data / application portability across the multiple component clouds. In this embodiment, both public cloud 105 and private cloud 106 are part of a larger hybrid cloud.

[0106] The programs described herein are based on applications for which these programs are implemented in specific embodiments of the invention. However, it should be understood that any specific procedural terminology used herein is for convenience only, and therefore the invention should not be limited to use only in any specific application identified and / or implied by such terminology.

[0107] This invention can be a system, method, and / or computer program product at any possible level of technical detail integration. The computer program product may include a computer-readable storage medium having computer-readable program instructions thereon for causing a processor to perform aspects of the invention.

[0108] Computer-readable storage media can be tangible devices capable of holding and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example, but not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable optical disc read-only memory (CD-ROM), digital versatile disc (DVD), memory sticks, floppy disks, mechanical encoding devices such as punch cards or recessed structures with instructions recorded thereon, and any suitable combination of the foregoing. As used herein, computer-readable storage media should not be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.

[0109] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a suitable computing / processing device, or downloaded via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network) to an external computer or external storage device. The network may include copper cables, optical fibers, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to a computer-readable storage medium within the suitable computing / processing device.

[0110] Computer-readable program instructions used to perform the operations of this invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, integrated circuit configuration data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​(e.g., Smalltalk, C++, etc.) and procedural programming languages ​​(e.g., the "C" programming language or similar programming languages). The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer may be connected to the user's computer via any type of network (including a local area network (LAN) or a wide area network (WAN)) or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, to perform aspects of this invention, electronic circuits, including, for example, programmable logic circuits, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), may execute computer-readable program instructions to personalize the electronic circuits by utilizing state information from the computer-readable program instructions.

[0111] Various aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0112] These computer-readable program instructions may be provided to a processor of a computer or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / actions specified in one or more blocks of a flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that can direct a computer, programmable data processing apparatus, and / or other devices to operate in a particular manner, such that the computer-readable storage medium in which the instructions are stored includes an article of writing comprising instructions for implementing aspects of the functions / actions specified in one or more blocks of a flowchart and / or block diagram.

[0113] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer-implemented process, such that the instructions, which execute on the computer, other programmable apparatus or other device, perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.

[0114] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions comprising one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions indicated in the blocks may occur in a different order than indicated in the figures. For example, two blocks shown consecutively may actually be implemented as a single step, executed simultaneously, substantially simultaneously, with partial or complete time overlap, or these blocks may sometimes be executed in reverse order, depending on the functions involved. It will also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented by a dedicated hardware-based system that performs the specified function or action or executes a combination of dedicated hardware and computer instructions.

[0115] Various embodiments of the invention have been described for illustrative purposes, but are not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope of the described embodiments. The terminology used herein is chosen to best explain the principles of the embodiments, their practical application, or technical improvements to existing technologies on the market, or to enable others skilled in the art to understand the embodiments disclosed herein.

[0116] Example embodiments of the present invention are set forth in the claims, and also include:

[0117] (1). A system for distributing copies of event data logger (EDR) data of a vehicle, the system comprising:

[0118] Computer processor;

[0119] At least one computer-readable storage medium and program instructions stored on the at least one computer-readable storage medium and executed by the computer processor, the program instructions comprising:

[0120] A program instruction is sent to uniquely identify the index information of the corresponding member vehicles of the dynamic vehicle network, wherein the member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geographical distance of the master vehicle.

[0121] A program instruction to send a fragment of the private key associated with the EDR data of the master vehicle to the corresponding member vehicle of the dynamic vehicle network, wherein the fragment is sent in text format and includes the position offset of the fragment of the private key;

[0122] Program instructions for distributing segments of copied EDR data from the master vehicle among the respective member vehicles, wherein the EDR data segment is associated with an index identifier of the respective member vehicle and includes a timestamp of the segment of the EDR data; and

[0123] In response to the expiration of a predetermined lifecycle duration associated with the dynamic vehicle network and the absence of an accident involving the primary vehicle, the dynamic vehicle network is disbanded and a program instruction is initiated to initiate a next dynamic vehicle network comprising a set of subsequent candidate vehicles.

[0124] (2). The computer system according to clause (1), wherein the program instructions for dissolving the dynamic vehicle network include: sending to the member vehicles of the dynamic vehicle network instructions to delete the segment of the encrypted copied EDR data, the segment of the private key and the location offset, the index information, and the vehicle identification number (VIN) of the corresponding member vehicle shared with the member vehicle.

[0125] (3). The computer system described in clause (1) further includes:

[0126] The one or more processors send invitations to candidate vehicles within a predetermined geographical distance of the master vehicle to join the dynamic vehicle network; and

[0127] In response to the candidate vehicle joining the dynamic vehicle network as a member vehicle, the one or more processors receive the vehicle identification number (VIN) of the corresponding member vehicle, wherein the invitation to join the dynamic vehicle network, the response from the candidate vehicle, and the formation of the dynamic vehicle network occur during the operation of the master vehicle and the candidate vehicle, and wherein the formed dynamic vehicle network includes a temporary predetermined lifecycle duration.

[0128] (4). The computer system according to clause (1), wherein, in response to detecting that the accident has occurred in the master vehicle, the copied EDR data distributed to the member vehicles in segments is saved to the local storage device of the respective member vehicle.

[0129] (5). The computer system according to clause (1), wherein the expiration of the predetermined lifecycle duration is initiated by detecting at least one criterion selected from the group consisting of: the expiration of a predetermined time period, exceeding a predetermined driving distance, and the V2V communication signal from at least one member vehicle of the dynamic vehicle network dropping below a signal strength threshold.

[0130] (6). The computer system according to clause (1), wherein, after the formation of the dynamic vehicle network and before the initiation of segmenting and sending EDR data to the member vehicles, the encrypted vehicle identification number (VIN) of the respective member vehicle and the index information are sent to a central data store for use in vehicle accident investigation.

[0131] (7). The computer system described in Clause (1) further includes:

[0132] In response to detecting that the master vehicle is involved in the accident, a program instruction is sent to the member vehicle to retain the stored EDR data segment and the corresponding timestamp;

[0133] The program instructions to obtain the fragment of the private key and the location offset of the corresponding member sent to the dynamic vehicle network from the corresponding member vehicle;

[0134] Program instructions for reconstructing the private key based on the index information and the position offset of the corresponding segment received from the member vehicle;

[0135] Program instructions to obtain a segment of the copied EDR data and its corresponding timestamp from the corresponding member vehicle of the dynamic vehicle network, wherein the segment of the copied EDR data and its corresponding timestamp are encrypted;

[0136] The program instructions for using the private key to decrypt the segments of the copied EDR data and the corresponding timestamps; and

[0137] Based on the corresponding timestamp and index information of the segments of the copied EDR data, program instructions are generated to generate the copied EDR data.

[0138] (8). A computer program product according to clause (7), wherein the program instructions for dissolving the dynamic vehicle network include: sending to the member vehicles of the dynamic vehicle network instructions to delete segments of the encrypted copied EDR data, segments of the private key and the location offset, the index information, and the vehicle identification number (VIN) shared with the member vehicles, and wherein the expiration of the predetermined lifecycle duration is initiated by detecting at least one criterion selected from the group consisting of: the expiration of a predetermined time period, exceeding a predetermined driving distance, and the V2V communication signal from at least one member vehicle of the dynamic vehicle network dropping below a signal strength threshold.

[0139] (9). The computer program product described in Clause (7) further includes:

[0140] In response to detecting that the master vehicle is involved in the accident, a program instruction is sent to the member vehicle to retain the stored EDR data segment and the corresponding timestamp;

[0141] The program instructions to obtain the fragment of the private key and the location offset of the corresponding member sent to the dynamic vehicle network from the corresponding member vehicle;

[0142] Program instructions for reconstructing the private key based on the index information and the position offset of the corresponding segment received from the member vehicle;

[0143] Program instructions to obtain a segment of the copied EDR data and its corresponding timestamp from the corresponding member vehicle of the dynamic vehicle network, wherein the segment of the copied EDR data and its corresponding timestamp are encrypted;

[0144] The program instructions for using the private key to decrypt the segments of the copied EDR data and the corresponding timestamps; and

[0145] Based on the corresponding timestamp and index information of the segments of the copied EDR data, program instructions are generated to generate the copied EDR data.

Claims

1. A computer-implemented method for distributing copies of event data recorder (EDR) data of a vehicle, the method comprising: sending, by one or more processors, index information uniquely identifying respective member vehicles of a dynamic vehicle network, wherein the member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geographic distance of a host vehicle; sending, by the one or more processors, a fragment of a private key associated with EDR data of the host vehicle to the respective member vehicles of the dynamic vehicle network, wherein the fragment is sent in a text format and includes a positional offset of the fragment of the private key; distributing, by the one or more processors, segments of replicated EDR data from the host vehicle among the respective member vehicles, wherein an EDR data segment is associated with an index identification of the respective member vehicle and includes a timestamp of the segment of the EDR data; and in response to expiration of a predetermined duration of a lifetime associated with the dynamic vehicle network and an absence of an accident of the host vehicle, dissolving, by the one or more processors, the dynamic vehicle network and initiating a next dynamic vehicle network including a next set of candidate vehicles.

2. The method of claim 1, wherein, Dissolving the dynamic vehicle network includes sending, to the member vehicles of the dynamic vehicle network, instructions to delete the segments of encrypted replicated EDR data, the fragment of the private key and the positional offset, the index information, and a vehicle identification number (VIN) of the respective member vehicle shared with the member vehicle.

3. The method of claim 1 or claim 2, further comprising: sending, by the one or more processors, an invitation to join the dynamic vehicle network to the candidate vehicles within the predetermined geographic distance of the host vehicle; and in response to the candidate vehicles joining the dynamic vehicle network as the member vehicles, receiving, by the one or more processors, a vehicle identification number (VIN) of the respective member vehicle, wherein the invitation to join the dynamic vehicle network, a response from the candidate vehicles, and formation of the dynamic vehicle network occur during operation of the host vehicle and the candidate vehicles. in response to detecting the accident of the host vehicle, saving the replicated EDR data distributed in segments to the member vehicles to local storage of the respective member vehicles.

4. The method according to any of the preceding claims, wherein, The dynamic vehicle network includes a temporary predetermined duration of a lifetime.

5. The method according to any one of the preceding claims, wherein, Expiration of the predetermined duration of the lifetime is initiated by detecting at least one criterion selected from the group consisting of: expiration of a predetermined period of time, exceeding a predetermined distance of travel, and a V2V communication signal from at least one member vehicle of the dynamic vehicle network falling below a signal strength threshold.

6. The method of claim 5, wherein, The member vehicles of the dynamic vehicle network include at least two member vehicles and the host vehicle.

7. The method according to any of the preceding claims, wherein, ​ 8. The method of any of the preceding claims, wherein, After the dynamic vehicle network is formed, and prior to initiating the segmentation and transmission of EDR data to the member vehicles, the encrypted vehicle identification number VIN and the index information of the respective member vehicles are transmitted to a central data repository for vehicle accident investigation.

9. The method according to any of the preceding claims, wherein, The EDR data segments and corresponding timestamps are encrypted using the private key.

10. The method of any of the preceding claims, further comprising: responsive to detecting that the host vehicle is involved in the accident, transmitting, by the one or more processors, instructions to the member vehicles to retain stored EDR data segments and corresponding timestamps; retrieving, by the one or more processors, from the respective member vehicles, the fragments of the private key and the location offsets transmitted to the respective members of the dynamic vehicle network; reconstructing, by the one or more processors, the private key based on the index information and the location offsets of the respective fragments received from the member vehicles; retrieving, by the one or more processors, from the respective member vehicles of the dynamic vehicle network, segments of the replicated EDR data and corresponding timestamps, wherein the segments of the replicated EDR data and the corresponding timestamps are encrypted; decrypting, by the one or more processors, the segments of the replicated EDR data and the corresponding timestamps using the private key; and generating, by the one or more processors, the replicated EDR data based on the corresponding timestamps of the segments of the replicated EDR data and the index information.

11. A system for distributing a copy of event data recorder (EDR) data of a vehicle, the system comprising: a computer processor; at least one computer-readable storage medium and program instructions stored on the at least one computer-readable storage medium for execution by the computer processor, the program instructions comprising: program instructions to transmit index information uniquely identifying respective member vehicles of a dynamic vehicle network, wherein the member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geographic distance of a host vehicle; program instructions to transmit fragments of a private key associated with EDR data of the host vehicle to the respective member vehicles of the dynamic vehicle network, wherein the fragments are transmitted in a text format and include a location offset of the fragment of the private key; program instructions to distribute segments of replicated EDR data from the host vehicle among the respective member vehicles, wherein an EDR data segment is associated with an index identification of the respective member vehicle and includes a timestamp of the segment of the EDR data; and program instructions to dissolve the dynamic vehicle network and initiate a next dynamic vehicle network including a next set of candidate vehicles in response to expiration of a predetermined duration of a lifetime associated with the dynamic vehicle network and an absence of an accident of the host vehicle.

12. The system of claim 11, wherein, Program instructions to dissolve the dynamic vehicle network include sending instructions to the member vehicles of the dynamic vehicle network to delete the encrypted segments of the replicated EDR data, the segments of the private key, and the location offsets, the index information, and the vehicle identification number, VIN, of the respective member vehicles shared with the member vehicles.

13. The system of claim 11 or claim 12, further comprising: sending, by the one or more processors, an invitation to join the dynamic vehicle network to the candidate vehicles within a predetermined geographic distance of the host vehicle; and in response to the candidate vehicles joining the dynamic vehicle network as the member vehicles, receiving, by the one or more processors, the vehicle identification number, VIN, of the respective member vehicles, wherein the invitation to join the dynamic vehicle network, the response from the candidate vehicles, and the formation of the dynamic vehicle network occur during operation of the host vehicle and the candidate vehicles, and wherein the dynamic vehicle network formed comprises a temporary predetermined lifetime duration.

14. The system of any one of claims 11 to 13, wherein, in response to detecting that the accident occurred to the host vehicle, saving the replicated EDR data distributed to the member vehicles in segments to local storage of the respective member vehicles.

15. The system of any one of claims 11 to 14, wherein, expiration of the predetermined lifetime duration is initiated by detecting at least one criterion selected from the group consisting of: expiration of a predetermined time period, exceeding a predetermined distance of travel, and a V2V communication signal from at least one member vehicle of the dynamic vehicle network falling below a signal strength threshold.

16. The system of any one of claims 11 to 15, wherein, after formation of the dynamic vehicle network, and prior to initiating distribution of EDR data segments and sending to the member vehicles, the encrypted vehicle identification number, VIN, of the respective member vehicles and the index information are sent to a central data repository for vehicle accident investigation.

17. The system of any one of claims 11 to 16, further comprising: program instructions to send instructions to the member vehicles to retain stored EDR data segments and corresponding time stamps in response to detecting that the host vehicle was involved in the accident; program instructions to retrieve from the respective member vehicles the segments of the private key and the location offsets of the private key sent to the respective members of the dynamic vehicle network; program instructions to reconstruct the private key based on the index information and the location offsets of the respective segments received from the member vehicles; program instructions to retrieve from the respective member vehicles of the dynamic vehicle network segments of the replicated EDR data and corresponding time stamps, wherein the segments of the replicated EDR data and the corresponding time stamps are encrypted; program instructions to decrypt the segments of the replicated EDR data and the corresponding time stamps using the private key; and program instructions to generate the replicated EDR data based on the corresponding time stamps of the segments of the replicated EDR data and the index information.

18. A computer program product for distributing a copy of event data recorder, EDR, data of a vehicle, the method comprising: At least one computer-readable storage medium, and program instructions stored on the at least one computer-readable storage medium, the program instructions comprising: program instructions to transmit index information uniquely identifying respective member vehicles of a dynamic vehicle network, wherein the member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geographic distance of a host vehicle; program instructions to transmit a segment of a private key associated with EDR data of the host vehicle to the respective member vehicles of the dynamic vehicle network, wherein the segment is transmitted in a text format and includes a location offset of the segment of the private key; program instructions to distribute segments of replicated EDR data from the host vehicle among the respective member vehicles, wherein an EDR data segment is associated with an index identification of the respective member vehicle and includes a timestamp of the segment of the EDR data; and program instructions to dissolve the dynamic vehicle network and initiate a next dynamic vehicle network including a next set of candidate vehicles in response to expiration of a predetermined lifetime duration associated with the dynamic vehicle network and an absence of an accident of the host vehicle.

19. The computer program product of claim 18, wherein, The program instructions to dissolve the dynamic vehicle network include program instructions to transmit instructions to the member vehicles of the dynamic vehicle network to delete the encrypted segments of the replicated EDR data, the segment of the private key and the location offset, the index information, and a vehicle identification number (VIN) shared with the member vehicles, and wherein the expiration of the predetermined lifetime duration is initiated by detecting at least one criterion selected from the group consisting of: expiration of a predetermined time period, exceeding a predetermined distance of travel, and a V2V communication signal from at least one member vehicle of the dynamic vehicle network falling below a signal strength threshold.

20. The computer program product of claim 18 or claim 19, further comprising: program instructions to transmit instructions to the member vehicles to retain the stored segments of EDR data and corresponding timestamps in response to detecting that the host vehicle was involved in the accident; program instructions to retrieve, from the respective member vehicles, the segment of the private key and the location offset transmitted to the respective members of the dynamic vehicle network; program instructions to reconstruct the private key based on the index information and the location offset of the respective segment received from the member vehicles; program instructions to retrieve, from the respective member vehicles of the dynamic vehicle network, segments of the replicated EDR data and corresponding timestamps, wherein the segments of the replicated EDR data and the corresponding timestamps are encrypted; program instructions to decrypt the segments of the replicated EDR data and the corresponding timestamps using the private key; and program instructions to generate the replicated EDR data based on the corresponding timestamps of the segments of the replicated EDR data and the index information.