Vehicle incident data recovery using distributed vehicle event data
Patent Information
- Application Number
- JP2025574122
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-07-07
- Filing Date
- 2024-06-11
- Publication Date
- 2026-09-08
Smart Images

Figure 2026530286000001_ABST
Abstract
Description
[[Background Art]]
[0001] The present invention relates to recovery of vehicle event data, and more specifically to distribution of recorded event data to member vehicles of a dynamic vehicle network.
[0002] Modern transportation vehicles incorporate a growing array of technological and automation complements, such as global positioning systems (GPS), edge computing communications, and vehicle-to-vehicle (V2V) communications. In V2V communication, information regarding vehicle operation, such as the speed and position of surrounding vehicles, can be exchanged. V2V communication allows vehicles to broadcast and receive omnidirectional messages up to 10 times per second, establishing 360-degree awareness of nearby vehicles. In addition to the current use of radar and cameras for detecting potential threats during vehicle operation, V2V communication technology enhances threat avoidance by providing warnings, or in some cases automatic responses.
[0003] Vehicles may be configured to include an event data recorder (EDR), which records and stores on-board a plurality of vehicle conditions and attributes when triggered by an event such as acceleration, a sudden change in direction, or deployment of a safety function. In some cases, an EDR device can continuously record vehicle operation data in a loop manner, and overwrite previous data after one loop of recording is completed. An EDR device typically records and stores data during a set period from before, during and after the detection of a vehicle incident. EDR data may include combinations of occupant behavior (i.e., number of people in the vehicle, seatbelt wearers); driver inputs (steering, accelerator and brake); vehicle position, speed, and yaw rate; and other details such as deployment of safety and occupant protection systems, and the force of any impact that may have occurred, combined with vehicle system diagnostics acquired during the same period.
[0004] EDR data is often used in the reconstruction and investigation of vehicle incidents, such as failures, loss of control, collisions, fires, vehicle malfunctions, and other events often referred to as accidents. The data also contains information about the performance of vehicle functions, systems, and safety features, which can contribute to identifying design issues or discrepancies between specifications and performance. Such information and feedback can be used to further improve incident avoidance, vehicle function performance, and safety features that protect drivers and passengers. In some jurisdictions (i.e., states), EDR data is considered part of the vehicle's property and therefore the property of the vehicle owner. In such jurisdictions, access to EDR data by anyone other than the owner requires permission. In some cases, EDR data is protected by encryption, and the owner's private key is required to access and view / analyze the recorded data. In other cases, across different jurisdictions, EDR data may be transmitted to a central data center used to facilitate vehicle incident investigations, but the availability and usefulness of centralized data storage may be limited by data volume, transmission delays, and / or interference. Conversely, EDR data may be compromised as a result of vehicle incidents such as collisions, fires, theft, or malfunctions of vehicle functions (e.g., unexpected airbag deployment, ABS system failure, autonomous vehicle malfunction, etc.). [Overview of the project]
[0005] According to various embodiments of the present invention, a computer implementation method, a computer program product, and a computer system are provided for distributing copies of event data recorder (EDR) data of a host vehicle. The computer implementation method comprises the step of one or more processors transmitting index information that uniquely identifies each member vehicle of a dynamic vehicle network. The member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geodesic distance from the host vehicle. The computer implementation method further comprises the step of one or more processors transmitting to each of the member vehicles located within a predetermined geodesic distance from the host vehicle a fragment of a secret key associated with the host vehicle's EDR data. The computer implementation method further comprises the step of one or more processors distributing segments of the EDR data replicated from the host vehicle among the respective member vehicles. The segments of the EDR data are associated with the index identification information of each member vehicle and include a timestamp of the segment of the EDR data. The computer implementation method further comprises the step of one or more processors dissolving the dynamic vehicle network and starting a new dynamic vehicle network including the next set of candidate vehicles in response to the expiration of a predetermined lifecycle duration associated with the dynamic vehicle network and the absence of an incident in the host vehicle. [Brief explanation of the drawing]
[0006] [Figure 1] This is a functional block diagram showing a gas separation cell according to one embodiment of the present invention.
[0007] [Figure 2] A flowchart illustrating a data recovery program, including the distribution of copies of event data recorder (EDR) data from a host vehicle, according to one embodiment of the present invention, is shown.
[0008] [Figure 3]A block diagram of the components of a computing system, including a computing device configured to run the data recovery program shown in Figure 2, according to one embodiment of the present invention, is shown. [Modes for carrying out the invention]
[0009] Embodiments of the present invention recognize that many modern vehicles are equipped with technological devices designed to detect the occurrence of vehicle incidents and to record and store vehicle-related data before, during, and after such incidents. Vehicle incidents may include, among other things, accidents involving collisions, loss of vehicle control, fires, and malfunctions of vehicle functions, and these are recorded and stored on event data recorder (EDR) devices, which have been included in the manufacture of certain vehicles for many years and may be provided as aftermarket accessories.
[0010] Existing use of EDR data can be compromised as a result of an incident experienced by a vehicle, or if the vehicle owner is injured and the secret key to decrypt the EDR data on that vehicle is otherwise unknown or unavailable. To improve the availability of accurate data after a vehicle incident, a solution is needed to securely recover vehicle data from an incident even if the vehicle's local storage is corrupted. Secure availability of event data recorder data is also valuable for semi-autonomous or fully autonomous vehicles to understand the actions taken before, during, and after an incident, as well as the state of the driver and vehicle. For example, whether the driver was able to override vehicle controls, or whether safety features responded as expected.
[0011] The embodiments recognize that EDR data is intended to be read-only data stored in the vehicle's local storage in the event of a vehicle incident, and that in many cases this data can only be retrieved by the vehicle owner (i.e., the holder of the private key to decrypt the EDR data). The embodiments recognize that there is a possibility that the data may be distorted or otherwise affected in order to avoid unfavorable incident investigation results, which suggests that EDR data may be frequently transmitted to a verification center. The embodiments also recognize that a vehicle incident may generate a large amount of data in a short period of time, requiring local storage, but that in a serious incident, the local storage of the data may be corrupted or destroyed.
[0012] In certain jurisdictions, the embodiment recognizes that EDR data is considered part of the vehicle owner's property, and therefore access to such data is protected, and that the owner may be required to access such EDR data or to grant permission to others to access such EDR data. As part of the protection of EDR data, records are typically encrypted and stored locally, so that a private key is required to decrypt the data, and such private key may only be available to the vehicle owner. In serious incidents where stored data is corrupted or the vehicle owner (as the driver) is seriously injured, the decryption private key may not be provided or may be unavailable. If the owner is unable to provide the private key for decrypting the EDR data due to incapacitation or unwillingness, decryption of the EDR data related to the incident may be impossible, and the investigation may remain incomplete. Accessing EDR data associated with vehicle incidents provides valuable insights into the moments immediately before, during, and after a vehicle incident, and can offer even greater value to incidents involving semi-autonomous and fully autonomous vehicles as they become more common and numerous.
[0013] Because vehicle incident EDR data can provide an accurate and unbiased account of driver actions, vehicle condition, performance, conditions, and occupant information, the ability to recover EDR data that would otherwise be unavailable can provide clarity to the contributing factors of an incident and offer valuable information for the continuous improvement of vehicle operation and safety features.
[0014] According to one embodiment of the present invention, a computer implementation method for distributing event data recorder (EDR) data of a host vehicle is provided. The computer implementation method comprises the step of one or more processors transmitting index information that uniquely identifies each member vehicle of a dynamic vehicle network. The member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geodesic distance from the host vehicle. The computer implementation method further comprises the step of one or more processors transmitting a fragment of a secret key associated with the EDR data of the host vehicle to each of the member vehicles located within a predetermined geodesic distance from the host vehicle. The computer implementation method further comprises the step of one or more processors distributing segments of EDR data replicated from the host vehicle among the respective member vehicles. The segments of EDR data are associated with the index identification information of each member vehicle and include a timestamp of the segment of EDR data. The computer implementation method further comprises a step in which, in response to the expiration of a predetermined lifecycle duration associated with the dynamic vehicle network and the absence of an incident in the host vehicle, one or more processors dissolve the dynamic vehicle network and start a new dynamic vehicle network including the next set of candidate vehicles, thereby enabling the reconstruction of the secret key for decryption of the retrieved EDR data.
[0015] By distributing segmented EDR data to local storage across multiple member vehicles of a dynamic vehicle network created during the operation of the host and member vehicles, it becomes possible to reconstruct the secret key for decrypting recovered EDR data if the EDR data is corrupted or distorted after an incident in the host vehicle. By sharing fragments of the secret key among member vehicles of the dynamic vehicle network, it becomes possible to decrypt recovered EDR data even if one vehicle cannot identify or reconstruct the secret key. By identifying member vehicles of the dynamic vehicle network, investigators can recover and reconstruct EDR data and decryption keys even in cases where locally recorded and stored EDR data is unrecoverable or remains encrypted due to the unavailability of the decryption key.
[0016] Advantageous embodiments of some examples of the present invention may include one or more processors locating nearby vehicles during operation in which proximity distances are predetermined or limited by connectivity technology. Vehicle-to-vehicle (V2V) communication technology may be used to locate vehicles, and GPS data may be used to determine the proximity of nearby vehicles to a host vehicle. For example, one or more processors communicate with several other vehicles via V2V communication, receive data from these vehicles regarding their respective GPS locations, and determine which vehicles are within a predetermined geodetic distance from the host vehicle. Geodetic distance (i.e., geodetic distance) is the distance measured along the surface of the Earth. The fact that the host vehicle and several other vehicles are operating (i.e., driving) during the location activity by the host vehicle provides advantages over current technology with respect to the selection of candidate vehicles within a predetermined distance from the host vehicle, and enables the formation and dissolution of a series of dynamic vehicle networks while the host vehicle and candidate vehicles are operating and driving.
[0017] In some advantageous aspects of the present invention, one or more processors send invitations to located nearby vehicles to dynamically join a vehicle network. The one or more processors invite a number of vehicles within a predefined geodesic distance to join a dynamic vehicle network, also referred to herein as the “vehicle network” or “network.” Other nearby vehicles have control over whether to accept or block the invitation to join the dynamic vehicle network, or, in some embodiments of the present invention, the other nearby vehicles may choose not to participate in V2V communication and, as a result, may not be located. The one or more processors initiate invitations to a number of vehicles that are located within a predefined geodesic distance and are determined to be traveling in a direction and / or route similar to that of the host vehicle.
[0018] In some advantageous embodiments of the present invention, one or more processors receive a vehicle identification number (VIN) along with confirmation from a nearby vehicle that it has accepted the transmitted invitation and joined the vehicle network. As a nearby vehicle joins the vehicle network, embodiments of the present invention assign an index to the joining vehicle, thereby providing the joining vehicle with unique identification information as a “member vehicle” of the vehicle network, and the index is associated with EDR data and a fragment and offset of a secret key distributed among all member vehicles of the vehicle network (discussed in detail below). In embodiments of the present invention, the index may be a number, a binary number, a character, a string, or any combination that can be used to clearly identify a member vehicle within an instance of a dynamic vehicle network. By receiving the VIN of each member vehicle joining the current dynamic vehicle network, clear identification of member vehicles is provided, and by assigning index information, data assignment to each member vehicle in the current dynamic vehicle network is made possible, thus avoiding confusion of data transmitted to vehicles that are successively included in multiple dynamic vehicle networks.
[0019] In some embodiments, the VINs and indices associated with each member vehicle of a dynamic vehicle network are transmitted to a remote data center typically used as a data source for vehicle incident or accident investigations. An advantageous aspect of the present invention includes one or more processors transmitting the VINs and indices associated with each vehicle of a newly formed dynamic vehicle network to a central data store, enabling the identification of network member vehicles and which vehicles are associated with which index designations for the lifetime of the network. In some embodiments, the VIN and index information is encrypted to protect the identification information of member vehicles, while enabling decryption in the event of an incident in a host vehicle. In some embodiments, the VIN and index information is transmitted to member vehicles to be temporarily stored for the lifetime of the dynamic vehicle network as redundancy for the transmission of information to the central data store. The temporary lifetime of the dynamic vehicle network, in conjunction with dissolving the dynamic vehicle network after the expiration of a predetermined lifecycle lifetime, improves EDR data recording practices by enabling the recording and distribution of segments of EDR data as a recoverable alternative source of EDR data in the event that EDR data stored in host vehicles is corrupted or lost.
[0020] Some advantageous embodiments of the present invention include a limited lifecycle duration for a dynamic vehicle network, with each instance of the dynamic vehicle network being transient. The expiration of the lifecycle duration in a dynamic vehicle network may be initiated, for example, by a criterion including a function of time, distance traveled, etc., when a member vehicle of the network moves outside a predetermined geodesic distance, or when the signal strength of a V2V connection falls below a minimum threshold. After the expiration of the lifecycle duration of the vehicle network, one or more processors dissolve the current set of member vehicles as the current network and proceed to create the next set of member vehicles to form the next dynamic vehicle network while the host vehicle and localized neighbor vehicles are actively operating.
[0021] Advantageous aspects of some examples of the present invention include one or more processors segmenting EDR data, where the data segments and the timestamps associated with the data segments are encrypted and transmitted to at least one member vehicle of a dynamic vehicle network. The EDR data segments are distributed to the member vehicles of the dynamic vehicle network and associated with timestamps and indices assigned to each member vehicle. Distributing the segmented EDR data among multiple member vehicles of the dynamic vehicle network provides advantages over current EDR data recording practices. The distribution of EDR data segments ensures that no single member vehicle contains all of the EDR data, and since the data is transmitted in encrypted form, protection against data privacy concerns is provided. Embodiments of the present invention are not limited by the type of segmentation, as any segmentation algorithm can be used.
[0022] Some advantageous embodiments of the present invention involve one or more processors fragmenting a secret key used by a host vehicle or the owner of a host vehicle to decrypt EDR data. The secret key is used to decrypt segments of EDR data transmitted to member vehicles of a dynamic vehicle network. By fragmenting the secret key and distributing the fragments of the secret key, along with the location offsets associated with the fragments, no single member vehicle possesses sufficient secret key information to decrypt the segments of EDR data stored in its respective member vehicle. Embodiments of the present invention transmit unencrypted secret key fragments in text format. By identifying member vehicles and retrieving the text fragments and location offsets of the secret key, the secret key can be reconstructed, which an investigator can then use to recover and decrypt the distributed segments of EDR data and associated timestamps from the member vehicles. The offsets associated with the secret key fragments provide the location of the fragments within the reconstructed secret key. The timestamps enable a chronological reconstruction of the EDR data. Current practices provide private keys for exclusive access by the host vehicle owner, creating vulnerabilities (exposure) to access and decrypt EDR data.
[0023] In some advantageous aspects of the present invention, one or more processors recover EDR data when an incident occurs in a host vehicle and the EDR data cannot be recovered directly from the host vehicle and / or the vehicle owner, and the data cannot be decrypted. In cases where an incident occurs in a host vehicle and the EDR data storage device is damaged, making the EDR data unrecoverable from the host vehicle, or where the secret key for decrypting the EDR data is unavailable due to the state of the vehicle owner (i.e., as the driver of the host vehicle at the time the incident occurred), embodiments of the present invention provide alternative means for recovering and decrypting the EDR data. If the EDR data stored in the host vehicle is damaged, or if the host vehicle owner is injured or otherwise incapacitated in the incident, current practice makes it impossible to decrypt and analyze the EDR data.
[0024] Some advantageous embodiments of the present invention include one or more processors dissolving a dynamic vehicle network after the expiration of a limited lifecycle lifetime. The lifecycle lifetime of the dynamic vehicle network is predetermined and may be based on a function of time, the distance covered by host vehicles and member vehicles, and / or the departure of member vehicles, and is not limited by the factors determining the lifecycle lifetime. Embodiments of the present invention instruct member vehicles to delete segments of received EDR data, and fragments and offsets of private keys, after the commencement of dissolution of the current dynamic vehicle network. In this embodiment, privacy is protected while providing alternative means for recovering and reconstructing EDR data in the event of an incident during the lifecycle of the dynamic vehicle network by making the storage of EDR data, private key fragments, and shared VIN and index information temporary.
[0025] An advantageous aspect of some examples of the present invention comprises one or more processors forming a next dynamic vehicle network after disbanding a current dynamic vehicle network. The host vehicle repeatedly locates and invites neighboring vehicles as next candidate vehicles that will join as a set of next member vehicles forming the next dynamic vehicle network. In some embodiments, a vehicle from the disbanded current dynamic vehicle network may rejoin as a member of the next dynamic vehicle network if the vehicle continues to operate within a predefined geodesic distance from the host vehicle. Aspects of the present invention proceed to establishing a vehicle identification number and indexing for each of the next member vehicles of the next dynamic vehicle network, segmenting event data recorder data, distributing a portion thereof to each respective next member vehicle of the next dynamic vehicle network, fragmenting a secret key, and transmitting the fragment and an offset thereof to each respective next member vehicle.
[0026] According to another embodiment of the present invention, a computer system is provided for distributing event data recorder (EDR) data of a host vehicle. The computer system comprises a computer processor, at least one computer-readable storage medium, and program instructions stored on the at least one computer-readable storage medium, which are executed by the computer processor. The processor executes program instructions for transmitting index information that uniquely identifies each member vehicle of a dynamic vehicle network. The member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geodesic distance from the host vehicle. The processor further executes program instructions for transmitting a fragment of a secret key associated with the host vehicle's EDR data to each of the member vehicles located within the predetermined geodesic distance from the host vehicle. The processor further executes program instructions for distributing segments of the EDR data replicated from the host vehicle among the respective member vehicles. The segments of the EDR data are associated with the index identification information of each member vehicle and include a timestamp of the segment of the EDR data. The processor further executes program instructions to dissolve the dynamic vehicle network and start a new dynamic vehicle network, which includes the next set of candidate vehicles, in response to the expiration of a predetermined lifecycle duration associated with the dynamic vehicle network and the absence of an incident in the host vehicle.
[0027] By distributing segmented EDR data to local storage among a plurality of member vehicles of a dynamic vehicle network created during operation of a host vehicle and member vehicles, reconstruction of a secret key for decrypting recovered EDR data becomes possible if the EDR data is damaged or corrupted after an incident involving the host vehicle. By sharing fragments of the secret key among the member vehicles of the dynamic vehicle network, decryption of recovered EDR data becomes possible in a state where no single vehicle can identify or reconstruct the secret key. By identifying the member vehicles of the dynamic vehicle network, investigators can recover and reconstruct EDR data and decryption keys even in cases where locally recorded and stored EDR data is unrecoverable, or remains encrypted due to an unavailable decryption key.
[0028] An advantageous aspect of some examples of the present invention includes a processor executing program instructions for identifying the position of neighboring vehicles during operation in which the proximity distance is predetermined or restricted by connection technology. Vehicle-to-vehicle (V2V) communication technology may be used to identify vehicle positions, and GPS data may be used to determine the proximity of a neighboring vehicle relative to the host vehicle. For example, the processor communicates with a plurality of other vehicles via V2V communication, receives data relating to their respective GPS positions from the plurality of vehicles, and determines which vehicles are within a predetermined geodetic distance from the host vehicle. Geodetic distance is a distance measured along the surface of the Earth. The fact that the host vehicle and the plurality of other vehicles are operating (i.e., traveling) during the position identification activity performed by the host vehicle provides advantages over existing technologies in terms of selection of candidate vehicles within a predetermined distance from the host vehicle, and also enables a series of formations and dissolutions of a dynamic vehicle network during operation and traveling of the host vehicle and the candidate vehicles.
[0029] In some advantageous aspects of the present invention, a processor executes a program instruction to send an invitation to a localized nearby vehicle to dynamically join a vehicle network. The processor invites a number of vehicles within a predefined geodesic distance to join a dynamic vehicle network, also referred to herein as the “vehicle network” or “network.” Other nearby vehicles have control over whether to accept or block the invitation to join the dynamic vehicle network, or, in some embodiments of the present invention, the other nearby vehicles may choose not to participate in V2V communication and, as a result, may not be localized. Invitations are sent to a number of vehicles that are located within a predefined geodesic distance and are determined to be traveling in a direction and / or route similar to that of the host vehicle.
[0030] In some advantageous embodiments of the present invention, the processor executes a program instruction to receive a Vehicle Identification Number (VIN) along with confirmation from a nearby vehicle that it accepts the transmitted invitation and joins the vehicle network. As a nearby vehicle joins the vehicle network, embodiments of the present invention assign an index to the joining vehicle, thereby providing the joining vehicle with unique identification information as a “member vehicle” of the vehicle network, and the index is associated with EDR data and a fragment and offset of a secret key distributed among all member vehicles of the vehicle network (discussed in detail below). In embodiments of the present invention, the index may be a number, a binary number, a character, a string, or any combination that can be used to clearly identify a member vehicle within an instance of a dynamic vehicle network. By receiving the VIN of each member vehicle joining the current dynamic vehicle network, clear identification of member vehicles is provided, and by assigning index information, data assignment to each member vehicle in the current dynamic vehicle network is made possible, thus avoiding confusion of data transmitted to vehicles that are consecutively included in multiple dynamic vehicle networks.
[0031] In some embodiments, the VINs and indices associated with each member vehicle of a dynamic vehicle network are transmitted to a remote data center typically used as a data source for vehicle incident or accident investigations. An advantageous aspect of the present invention includes a processor executing program instructions to transmit the VINs and indices associated with each vehicle of a newly formed dynamic vehicle network to a central data store, enabling the identification of network member vehicles and which vehicles are associated with which index designations for the lifetime of the network. In some embodiments, the VIN and index information is encrypted to protect the identification information of member vehicles, while enabling decryption in the event of an incident at a host vehicle. In some embodiments, the VIN and index information is transmitted to member vehicles to be temporarily stored for the lifetime of the dynamic vehicle network as redundancy for the transmission of information to the central data store. The temporary lifetime of the dynamic vehicle network, in conjunction with dissolving the dynamic vehicle network after the expiration of a predetermined lifecycle lifetime, improves EDR data recording practices by enabling the recording and distribution of segments of EDR data as a recoverable alternative source of EDR data in the event that EDR data stored at a host vehicle is corrupted or lost.
[0032] Some advantageous embodiments of the present invention include a limited lifecycle duration for a dynamic vehicle network, with each instance of the dynamic vehicle network being transient. The expiration of the lifecycle duration in a dynamic vehicle network may be initiated, for example, by a criterion including a function of time, distance traveled, etc., when a member vehicle of the network moves outside a predetermined geodesic distance, or when the signal strength of a V2V connection falls below a minimum threshold. After the expiration of the lifecycle duration of the vehicle network, the processor executes program instructions to dissolve the current set of member vehicles as the current network and proceed to create the next set of member vehicles to form the next dynamic vehicle network while the host vehicle and localized neighbor vehicles are actively operating.
[0033] In some advantageous embodiments of the present invention, a processor executes program instructions for segmenting EDR data, where the data segments and the timestamps associated with those data segments are encrypted and transmitted to at least one member vehicle of a dynamic vehicle network. The EDR data segments are distributed to the member vehicles of the dynamic vehicle network and associated with timestamps and indices assigned to each member vehicle. Distributing the segmented EDR data among multiple member vehicles of the dynamic vehicle network provides advantages over current EDR data recording practices. The distribution of EDR data segments ensures that no single member vehicle contains all of the EDR data, and since the data is transmitted in encrypted form, protection against data privacy concerns is provided. Embodiments of the present invention are not limited by the type of segmentation, as any segmentation algorithm can be used.
[0034] Some advantageous embodiments of the present invention include a processor executing program instructions for fragmenting a secret key used by a host vehicle or the owner of a host vehicle to decrypt EDR data. The secret key is used to decrypt segments of EDR data transmitted to member vehicles of a dynamic vehicle network. By fragmenting the secret key and distributing the fragments of the secret key, along with the position offsets associated with the fragments, no single member vehicle possesses sufficient secret key information to decrypt the segments of EDR data stored in its respective member vehicle. Embodiments of the present invention transmit unencrypted fragments of the secret key in text form. By identifying member vehicles and retrieving the text fragments and position offsets of the secret key, the secret key can be reconstructed, and an investigator can use it to recover and decrypt the distributed segments of EDR data and associated timestamps from the member vehicles. The offsets associated with the fragments of the secret key provide the position of the fragments within the reconstructed secret key. The timestamps enable a chronological reconstruction of the EDR data. Current practices provide private keys for exclusive access by the host vehicle owner, creating vulnerabilities to access and decrypt EDR data.
[0035] In some advantageous aspects of the present invention, a processor executes program instructions for recovering EDR data when an incident occurs in a host vehicle and the EDR data cannot be recovered directly from the host vehicle and / or the vehicle owner, and the data cannot be decrypted. In cases where an incident occurs in a host vehicle and the EDR data storage device is damaged, making the EDR data unrecoverable from the host vehicle, or where the secret key for decrypting the EDR data is unavailable due to the state of the vehicle owner (i.e., as the driver of the host vehicle at the time the incident occurred), embodiments of the present invention provide alternative means for recovering and decrypting the EDR data. If the EDR data stored in the host vehicle is damaged, or if the host vehicle owner is injured or otherwise incapacitated in the incident, current practice makes it impossible to decrypt and analyze the EDR data.
[0036] Some advantageous embodiments of the present invention include a processor executing program instructions for dissolving a dynamic vehicle network after the expiration of a limited lifecycle lifetime. The lifecycle lifetime of a dynamic vehicle network is predetermined and may be based on a function of time, the distance covered by host vehicles and member vehicles, and / or the departure of member vehicles, and is not limited by the factors determining the lifecycle lifetime. Embodiments of the present invention instruct member vehicles to delete segments of received EDR data, and fragments and offsets of private keys, after the commencement of dissolution of the current dynamic vehicle network. In this embodiment, privacy is protected while providing alternative means for recovering and reconstructing EDR data in the event of an incident during the lifecycle of the dynamic vehicle network by making the storage of EDR data, private key fragments, and shared VIN and index information temporary.
[0037] Some advantageous embodiments of the present invention include a process of executing program instructions to form a next dynamic vehicle network after dissolving the current dynamic vehicle network. The host vehicle repeatedly locates and invites nearby vehicles as the next candidate vehicles to join as the next set of member vehicles forming the next dynamic vehicle network. In some embodiments, a vehicle from the dissolved current dynamic vehicle network may rejoin as a member of the next dynamic vehicle network if the vehicle continues to operate within a predefined geodesic distance from the host vehicle. Embodiments of the present invention proceed to establish a VIN and index designation for each of the next member vehicles of the next dynamic vehicle network, segment the EDR data and distribute a portion thereof to each of the next member vehicles of the next dynamic vehicle network, and fragment the secret key and transmit the fragment and offset to each next member vehicle.
[0038] According to another embodiment of the present invention, a computer program product is provided for distributing event data recorder (EDR) data of a host vehicle. The computer program product comprises at least one computer-readable storage medium and program instructions stored on the at least one computer-readable storage medium. The program instructions include instructions for transmitting index information that uniquely identifies each member vehicle of a dynamic vehicle network. The member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geodesic distance from the host vehicle. The program instructions further include instructions for transmitting a fragment of a secret key associated with the host vehicle's EDR data to each of the member vehicles located within a predetermined geodesic distance from the host vehicle. The program instructions further include instructions for distributing segments of EDR data replicated from the host vehicle among the respective member vehicles. The segments of EDR data are associated with the index identification information of each member vehicle and include a timestamp of the segment of the EDR data. The program instructions further include instructions for disbanding the dynamic vehicle network and initiating a new dynamic vehicle network, which includes the next set of candidate vehicles, in response to the expiration of a predetermined lifecycle duration associated with the dynamic vehicle network and the absence of an incident in the host vehicle.
[0039] By distributing segmented EDR data to local storage across multiple member vehicles of a dynamic vehicle network created during the operation of the host and member vehicles, it becomes possible to reconstruct the secret key for decrypting recovered EDR data if the EDR data is corrupted or distorted after an incident in the host vehicle. By sharing fragments of the secret key among member vehicles of the dynamic vehicle network, it becomes possible to decrypt recovered EDR data even if one vehicle cannot identify or reconstruct the secret key. By identifying member vehicles of the dynamic vehicle network, investigators can recover and reconstruct EDR data and decryption keys even in cases where locally recorded and stored EDR data is unrecoverable or remains encrypted due to the unavailability of the decryption key.
[0040] Advantageous embodiments of some examples of the present invention include program instructions for locating a nearby vehicle during operation in which the proximity distance is predetermined or limited by the connection technology. Vehicle-to-vehicle (V2V) communication technology may be used to locate the vehicle, and GPS data may be used to determine the proximity of a nearby vehicle to a host vehicle. For example, a host vehicle communicates with several other vehicles via V2V communication, receives data from these vehicles regarding their respective GPS locations, and determines which vehicles are within a predetermined geodetic distance from the host vehicle. Geodetic distance is the distance measured along the surface of the Earth. The fact that the host vehicle and several other vehicles are operating (i.e., driving) during the location activity by the host vehicle provides advantages over current technology in selecting candidate vehicles within a predetermined distance from the host vehicle, and allows for the formation and dissolution of a series of dynamic vehicle networks while the host vehicle and candidate vehicles are operating and driving.
[0041] Some advantageous embodiments of the present invention include a program instruction for sending an invitation to a localized nearby vehicle to dynamically join a vehicle network. The program instruction includes inviting a number of vehicles within a predefined geodesic distance to join a dynamic vehicle network, also referred to herein as the “vehicle network” or “network.” Other nearby vehicles may control whether to accept or block the invitation to join the dynamic vehicle network, or, in some embodiments of the present invention, such other nearby vehicles may choose not to participate in V2V communication and, as a result, may not be localized. Invitations are sent to a number of vehicles that are located within a predefined geodesic distance and are determined to be traveling in a direction and / or route similar to that of the host vehicle.
[0042] Some advantageous embodiments of the present invention include a program instruction for receiving a Vehicle Identification Number (VIN) along with confirmation by a nearby vehicle that it accepts the transmitted invitation and joins the vehicle network. As a nearby vehicle joins the vehicle network, embodiments of the present invention assign an index to the joining vehicle, thereby providing the joining vehicle with unique identification information as a “member vehicle” of the vehicle network, and the index is associated with EDR data and a fragment and offset of a secret key distributed among all member vehicles of the vehicle network (discussed in detail below). In embodiments of the present invention, the index may be a number, a binary number, a character, a string, or any combination that can be used to clearly identify a member vehicle within an instance of a dynamic vehicle network. By receiving the VIN of each member vehicle joining the current dynamic vehicle network, clear identification of member vehicles is provided, and by assigning index information, data assignment to each member vehicle in the current dynamic vehicle network is made possible, thus avoiding confusion of data transmitted to vehicles that are consecutively included in multiple dynamic vehicle networks.
[0043] In some embodiments, the VINs and indices associated with each member vehicle of a dynamic vehicle network are transmitted to a remote data center typically used as a data source for vehicle incident or accident investigations. An advantageous aspect of the present invention includes a processor executing program instructions to transmit the VINs and indices associated with each vehicle of a newly formed dynamic vehicle network to a central data store, enabling the identification of network member vehicles and which vehicles are associated with which index designations for the lifetime of the network. In some embodiments, the VIN and index information is encrypted to protect the identification information of member vehicles, while enabling decryption in the event of an incident at a host vehicle. In some embodiments, the VIN and index information is transmitted to member vehicles to be temporarily stored for the lifetime of the dynamic vehicle network as redundancy for the transmission of information to the central data store. The temporary lifetime of the dynamic vehicle network, in conjunction with dissolving the dynamic vehicle network after the expiration of a predetermined lifecycle lifetime, improves EDR data recording practices by enabling the recording and distribution of segments of EDR data as a recoverable alternative source of EDR data in the event that EDR data stored at a host vehicle is corrupted or lost.
[0044] Some advantageous embodiments of the present invention include a limited lifecycle duration for a dynamic vehicle network, with each instance of the dynamic vehicle network being transient. The expiration of the lifecycle duration in a dynamic vehicle network may be initiated, for example, by a criterion including a function of time, distance traveled, etc., when a member vehicle of the network moves outside a predetermined geodesic distance, or when the signal strength of a V2V connection falls below a minimum threshold. After the expiration of the lifecycle duration of the vehicle network, the processor executes program instructions to dissolve the current set of member vehicles as the current network and proceed to create the next set of member vehicles to form the next dynamic vehicle network while the host vehicle and localized neighbor vehicles are actively operating.
[0045] Advantageous aspects of some examples of the present invention include program instructions for segmenting EDR data, where the data segments and the timestamps associated with the data segments are encrypted and transmitted to at least one member vehicle of a dynamic vehicle network. The EDR data segments are distributed to the member vehicles of the dynamic vehicle network and associated with timestamps and indices assigned to each member vehicle. Distributing segmented EDR data among multiple member vehicles of a dynamic vehicle network provides advantages over current EDR data recording practices. The distribution of EDR data segments ensures that no single member vehicle contains all of the EDR data, and since the data is transmitted in encrypted form, protection against data privacy concerns is provided. Embodiments of the present invention are not limited by the type of segmentation, as any segmentation algorithm can be used.
[0046] Some advantageous embodiments of the present invention include program instructions for fragmenting a secret key used by a host vehicle or the owner of a host vehicle to decrypt EDR data. The secret key is used to decrypt segments of EDR data transmitted to member vehicles of a dynamic vehicle network. By fragmenting the secret key and distributing the fragments of the secret key, along with the location offsets associated with the fragments, no single member vehicle possesses sufficient secret key information to decrypt the segments of EDR data stored in its respective member vehicle. Embodiments of the present invention transmit unencrypted fragments of the secret key in text form. By identifying member vehicles and retrieving the text fragments and location offsets of the secret key, the secret key can be reconstructed, and an investigator can use it to recover and decrypt the distributed segments of EDR data and associated timestamps from the member vehicles. The offsets associated with the fragments of the secret key provide the location of the fragments within the reconstructed secret key. The timestamps enable the chronological reconstruction of the EDR data. Current practice provides the secret key for exclusive access by the host vehicle owner, creating vulnerabilities to access and decryption of EDR data.
[0047] Some advantageous embodiments of the present invention include program instructions for recovering EDR data when an incident occurs in a host vehicle and the EDR data cannot be recovered directly from the host vehicle and / or the vehicle owner, and the data cannot be decrypted. In cases where an incident occurs in a host vehicle and the EDR data storage device is damaged, making the EDR data unrecoverable from the host vehicle, or where the secret key for decrypting the EDR data is unavailable due to the state of the vehicle owner (i.e., as the driver of the host vehicle at the time the incident occurred), embodiments of the present invention provide alternative means for recovering and decrypting the EDR data. If the EDR data stored in the host vehicle is damaged, or if the host vehicle owner is injured or otherwise incapacitated in the incident, current practice makes it impossible to decrypt and analyze the EDR data.
[0048] Some advantageous embodiments of the present invention include program instructions for dissolving a dynamic vehicle network after the expiration of a limited lifecycle duration. The lifecycle duration of a dynamic vehicle network is predetermined and may be based on a function of time, the distance covered by host and member vehicles, and / or the departure of member vehicles, and is not limited by the factors determining the lifecycle duration. Embodiments of the present invention instruct member vehicles to delete segments of received EDR data, and fragments and offsets of private keys, after the commencement of dissolution of the current dynamic vehicle network. In this embodiment, privacy is protected by making the storage of EDR data, private key fragments, and shared VIN and index information temporary, while providing alternative means for recovering and reconstructing EDR data in the event of an incident during the lifecycle of the dynamic vehicle network.
[0049] Some advantageous embodiments of the present invention include program instructions for forming a next dynamic vehicle network after dissolving the current dynamic vehicle network. The host vehicle repeatedly locates and invites nearby vehicles as the next candidate vehicles to join as the next set of member vehicles forming the next dynamic vehicle network. In some embodiments, a vehicle from the dissolved current dynamic vehicle network may rejoin as a member of the next dynamic vehicle network if the vehicle continues to operate within a predefined geodesic distance from the host vehicle. Embodiments of the present invention proceed to establish a VIN and index designation for each of the next member vehicles of the next dynamic vehicle network, segment the EDR data and distribute a portion thereof to each of the next member vehicles of the next dynamic vehicle network, and fragment the secret key and transmit the fragment and offset to each next member vehicle.
[0050] The advantages described above are illustrative advantages, and not all advantages are discussed. Furthermore, embodiments of this disclosure may exist that remain within the scope of this disclosure but include all, some, or none of the advantages described above.
[0051] Various aspects of this disclosure are described by explanatory text, flowcharts, block diagrams of computer systems, and / or block diagrams of machine logic included in embodiments of computer program products (CPPs). With respect to any flowchart, depending on the technology involved, operations may be performed in a different order than those shown in a given flowchart. For example, again, depending on the technology involved, two operations shown in consecutive blocks of a flowchart may be performed in reverse order, as a single integrated step, simultaneously, or with at least partial time overlap.
[0052] The present invention will now be described in detail with reference to the figures. Figure 1 is a functional block diagram showing a dynamic vehicle network including distributed data processing, generally designated as 107, according to one embodiment of the present invention. Figure 1 provides only an example of one implementation and does not imply any limitation with respect to the environment in which different embodiments may be implemented. Many modifications to the illustrated environment can be made by those skilled in the art without departing from the scope of the present invention enumerated by the claims.
[0053] Figure 1 shows a dynamic vehicle network 107 to which event data recorder (EDR) data is distributed over a limited lifecycle. The dynamic vehicle network 107 includes a host vehicle 116, network member vehicles 120, 125, 130, and 135, and a data center 140 connected to the dynamic vehicle network 107 via network 150. The dynamic vehicle network 107 is a local network between operating vehicles, communicating via vehicle-to-vehicle (V2V) technology and exchanging information that may include location, direction, speed, and other information. The dynamic vehicle network 107 is formed dynamically while vehicles are operating and includes vehicles invited by host vehicles such as the host vehicle 116. Invited vehicles decide whether to "opt in" after receiving an invitation to join the network. A dynamic vehicle network is temporary and has a limited lifecycle duration, which is predetermined and may expire based on time, mileage, and when a member vehicle leaves the network (e.g., leaves in a different direction from the host vehicle or moves too far away from the host vehicle). The next dynamic vehicle network may be formed after the dissolution of the current dynamic vehicle network, and such formation and dissolution may occur continuously as host vehicles are in operation and member vehicles to join the network are found.
[0054] The host vehicle 116 is a vehicle in motion and comprises a computing device 110 having hardware and software to enable event data recording by the EDR 118 and to run a data recovery program 200. In embodiments of the present invention, the host vehicle 116 is traveling on a roadway / route toward a destination. The host vehicle 116 initiates an invitation to other nearby vehicles to join the dynamic vehicle network 107 via the data recovery program 200 running on the computing device 110. The nearby area is a predetermined distance and may be further limited to vehicles that are determined to be in motion and traveling in a similar direction and route to the host vehicle 116, as determined by global positioning system (GPS) data exchanged between vehicles via V2V communication. The host vehicle 116 is the issuer of an index, which serves as a unique identifier for each member vehicle of the dynamic vehicle network 107, via the data recovery program 200.
[0055] The computing device 110 operates on the host vehicle 116, includes a data recovery program 200, and is communicatively connected to the EDR 118. In some embodiments, the computing device 110 may be a vehicle-mounted computing device capable of transmitting, receiving, and processing data and instructions, communicating with network member vehicles 120, 125, 130, and 135, and communicating with the data center 140 via the network 150. In some embodiments, the computing device 110 is structurally and functionally similar to the end-user device 103 in Figure 1.
[0056] The data recovery program 200 provides recoverable EDR data distributed in segments among multiple member vehicles that have accepted membership in the dynamic vehicle network. The segmentation and distribution of host vehicle EDR data supports post-incident investigations by enabling the recovery of vehicle data in the event of an incident in the host vehicle that destroys, corrupts, or otherwise renders the EDR data on the host vehicle inaccurate or unavailable. The EDR data captures vehicle state and operational attributes immediately before, during, and after an incident such as an accident, collision, fire, loss of control, or other triggered vehicle action.
[0057] The data recovery program 200 is started and sends an invitation to join the vehicle network to candidate vehicles within a predetermined range of the host vehicle on which the data recovery program 200 is running. The data recovery program 200 communicates with nearby vehicles via V2V communication technology and receives confirmation from candidate vehicles that have accepted to join the dynamic vehicle network as member vehicles, as well as the VIN of each member vehicle. The data recovery program 200 assigns an index to each member vehicle as a unique identifier within the network and sends the encrypted VIN and the assigned text-based index identifier of each member vehicle to the central data storage repository. The transmission of the encrypted VIN and text-based index information to the central data storage occurs promptly after the formation of the dynamic vehicle network, the reception of the VINs, and the assignment of network index identification information. In some embodiments, the VINs and / or index identifiers of member vehicles are shared among member vehicles of the dynamic vehicle network to enable identification of vehicles and data when access to the central storage data is unavailable. In some embodiments, the current network index identification information is periodically replicated and sent to remote central data storage.
[0058] The data recovery program 200 performs fragmentation of the host vehicle's private key used to decrypt EDR data. The data recovery program 200 creates fragments of the private key and distributes them to each member vehicle of the dynamic vehicle network. The fragments are created using any existing method, distributed in unencrypted text format, and include the offset of the fragment's position within the reconstructed private key. The private key fragmentation is performed promptly after the network is formed, and each fragment is stored in each member vehicle of the dynamic vehicle network. In some embodiments of the present invention, the fragmented and offset data, along with the index identification information of each member vehicle, is transmitted to a remote central data storage promptly after the network is formed and the fragmentation and distribution are completed. By fragmenting and distributing multiple parts of the private key, decryption of the EDR data by member vehicles is prevented.
[0059] The data recovery program 200 replicates and segments the EDR data from the event data recording device. The data recovery program 200 distributes the segments to each member vehicle of the dynamic vehicle network, and in some embodiments, the data recovery program 200 uses V2V communication technology for segment distribution. The segment of the host vehicle's EDR data includes a portion of the vehicle control and operation data and is distributed to member vehicles in encrypted form. As a result, individual vehicles do not possess the entire secret key required to decrypt the data, and the privacy of the data is protected because the VIN shared among member vehicles is in encrypted form. Member vehicles of the dynamic vehicle network do not consume or use the segmented data, but rather store it and provide redundant copies of the EDR data that can be recovered and reconstructed for vehicle incident investigations by authorized authorities.
[0060] The dynamic vehicle network created by the data recovery program 200 is a temporary network with a limited lifecycle. In some embodiments, the expiration of the dynamic vehicle network may be triggered by elapsed time (time duration), while in other embodiments, the expiration of the network may be triggered by mileage. In yet another embodiment, the expiration of the dynamic vehicle network may occur when one or more member vehicles leave the network due to a change of direction or exceeding a certain distance from the host vehicle. In some embodiments, all members of the vehicle network back up each other's EDR data, including the encrypted VIN of each vehicle, to ensure integrity and security.
[0061] If the data recovery program 200 does not detect an incident in the host vehicle, all segmented data and private key fragments are deleted at the end of the network's lifecycle. If an incident occurs, data segments sent to member vehicles of the dynamic vehicle network are stored for a predetermined period so that they may be available for potential recovery. After the storage lifecycle expires and no incident is detected, segmented EDR data, text-formatted private key fragments, and indexed and encrypted VIN information stored in member vehicles during the limited lifecycle of the dynamic vehicle network are deleted.
[0062] The EDR118 is an event data recording device with data storage capacity for storing vehicle control, operation, and performance data associated with the host vehicle. For example, the EDR118 records vehicle data such as speed, acceleration changes, and occupant behavior (i.e., number of people in the vehicle, seatbelt wearers); driver input (steering, accelerator, and brakes); vehicle position, speed, and yaw angle; and other details such as the deployment of safety and occupant protection systems, as well as the force of any impacts that may occur, in combination with diagnostics of the vehicle's systems acquired during the same period. In some cases, EDR data is considered highly sensitive confidential data and is protected by encryption using a unique public-private key pair. The private key is typically only available to the vehicle owner.
[0063] The EDR118 records event data when a sudden change is detected, recording a relatively large amount of data in a very short time, including the seconds before, during, and after an incident. In some embodiments, the EDR118 cannot share the recorded data with a central data storage repository such as a data center 140, and the EDR118 may be corrupted during or after an incident, leaving a segmented copy of the EDR data as a surviving or accurate data source.
[0064] Network member vehicles 120, 125, 130, and 135 are vehicles operating within a predetermined distance from the host vehicle 116. Network member vehicles 120, 125, 130, and 135 receive an invitation to join the dynamic vehicle network from the data recovery program 200 running on the computing device 110 of the host vehicle 116. Network member vehicles 120, 125, 130, and 135 respond to the invitation by "accepting" to join the vehicle network, or by "rejecting" or ignoring the invitation in order not to join the vehicle network. Network member vehicles 120, 125, 130, and 135 include VIN information in their respective "acceptance" responses.
[0065] In response to joining the vehicle network, network member vehicles 120, 125, 130, and 135 receive a unique index that identifies each vehicle within the network, and receive a fragment of the host vehicle 116's private key in text format, along with the network member vehicle index and encrypted VIN information. Network member vehicles 120, 125, 130, and 135 receive encrypted segments of EDR data recorded from host vehicle 116 and store these segments in local storage. If an incident is detected for host vehicle 116, the segmented EDR data is stored in each network member vehicle 120, 125, 130, and 135 for a predetermined period of time, if necessary, while waiting for the EDR data to be recovered.
[0066] Data center 140 is a centralized repository that stores EDR data received from host vehicle 116 after an incident occurs, in cases where EDR 118 is not damaged by the incident, or where the incident prevents EDR data from being sent to data center 140. Data center 140 is communicably connected to host vehicle 116 via network 150.
[0067] Network 150 provides communication connectivity between computing devices 110 operating on the host vehicle 116 and the data center 140. Network 150 may be any combination of, for example, a local area network (LAN), a telecommunications network, a wide area network (WAN) such as the Internet, a virtual local area network (VLAN), or wired, wireless, or optical connectivity. In some embodiments, network 150 may be a wide area network (WAN) 102 as shown in Figure 3. Generally, network 150 may be any combination of connectivity and protocols that support data transmission and communication between computing devices 110 and the data center 140 of the dynamic vehicle network 107.
[0068] Figure 2 shows a flowchart of a data recovery program 200 according to one embodiment of the present invention, which includes segmented distribution of a copy of event data recorder (EDR) data from a host vehicle. The data recovery program 200 provides an alternative source of EDR data for a vehicle incident if the EDR data is corrupted, destroyed, or tampered with as a result of the incident. The data recovery program 200 makes the EDR data recoverable from segmented portions of the EDR data distributed among member vehicles in a dynamic vehicle network by reconstructing the fragmented secret key to identify member vehicles and decrypting the segmented data.
[0069] The data recovery program 200 sends an invitation to candidate vehicles within a predetermined geodetic distance from the host vehicle to join the dynamic vehicle network (step 210). The data recovery program 200 also sends requests to other vehicles within a predefined range / distance from the host vehicle to join the formation of a temporary network of vehicles for sharing distributed segments of EDR data and other data, enabling the recovery of EDR data if the data stored in the host vehicle has become inaccurate due to destruction, corruption, or tampering. The invitation is sent as a request, and the receiving vehicles voluntarily choose to join the dynamic vehicle network of their own volition. Acceptance of the invitation is controlled by the candidate vehicles.
[0070] For example, the data recovery program 200 may send an invitation notification to another vehicle in motion within a predetermined geodetic distance, which may include determining the distance from the host vehicle 116, the direction of travel, the speed, and the location of the candidate vehicle. The data recovery program 200 sends an invitation to a vehicle in motion that appears to be traveling toward the same or a similar destination as the host vehicle 116. The data recovery program 200 sends the invitation via V2V communication, which may include transmission over the network 150.
[0071] The data recovery program 200 receives the VINs of each member vehicle in response to a candidate vehicle joining the dynamic vehicle network (step 220). Candidate vehicles that "accept" joining the dynamic vehicle network include their respective VINs along with their consent to join the network. The VINs provide identification information of the member vehicles to assist in the recovery of EDR data as needed. The dynamic vehicle network is formed between member vehicles and host vehicles.
[0072] For example, a data recovery program 200 running on a host vehicle 116 receives responses from candidate vehicles indicating whether they "accept" or "reject" (or do not respond to) joining the dynamic vehicle network 107. Vehicles that "accept" are member vehicles of the network and provide their respective VINs to the data recovery program 200.
[0073] The data recovery program 200 assigns an index to identify each member vehicle in the dynamic vehicle network (step 230). Each member vehicle in the dynamic vehicle network is identified by the data recovery program 200 assigning an index designation within the dynamic vehicle network. The index is associated with the data distributed to the member vehicles to facilitate data recovery in the event of an incident in the host vehicle and EDR data is unavailable for analysis by investigators. The data recovery program 200 transmits the index information and encrypted VIN of each member vehicle to the member vehicles of the newly formed dynamic vehicle network. The data recovery program 200 transmits the VIN and index information to the central data storage as soon as the network is formed. The dynamic vehicle network is a temporary network with a limited lifecycle lifetime. Local clusters of network vehicles are built only for their lifetime and are disconnected after the lifecycle expiration criteria are met. Subsequently, the next dynamic vehicle network will be built while the host vehicle and candidate vehicles are running. The member vehicle ID list in the VIN and index information is mapped to the corresponding set of member vehicles in the current dynamic vehicle network, which can be verified by the timestamp when the member vehicle ID list was generated.
[0074] For example, the data recovery program 200 assigns an index to each of the network member vehicles 120, 125, 130, and 135 (collectively referred to as member vehicles) of the dynamic vehicle network, and shares the index information and the encrypted VIN associated with that index with the member vehicles. The data recovery program 200 transmits the index information and associated VIN to the data center 140, for example, within the first few minutes after the dynamic vehicle network is formed.
[0075] The data recovery program 200 transmits fragments of the secret key used for decryption to each member of the network by sending the fragments in text format (step 240). Typically, the host vehicle owner has sole access to the secret key for decrypting the EDR data. With the consent of the host vehicle owner, the data recovery program 200 fragments the secret key into multiple parts and distributes the fragments among the member vehicles of the dynamic vehicle network. Embodiments of the present invention use any fragmentation algorithm that can be used to successfully fragment the secret key and reconstruct it to its original state. The data recovery program 200 includes the fragments along with offsets to indicate the location of the fragments in the reconstruction of the secret key. The fragments are distributed to the member vehicles in unencrypted text format. Fragmentation and distribution of fragments are performed promptly after the data recovery program 200 receives consent from the member vehicles and forms the dynamic vehicle network. Each member vehicle only possesses fragments of the secret key and cannot decrypt segments of the EDR data, and the probability of reconstructing the secret key is very low due to the fact that the secret key is distributed among multiple operating member vehicles.
[0076] For example, the data recovery program 200 uses a fragmentation technique that fragments the binary form of the private key into a string of subcomponents of 1s and 0s. Each fragment is accompanied by an offset indicating the fragment's position within the original private key. Each of the network member vehicles 120, 125, 130, and 135 receives a fragment and offset of the private key. The fragment is transmitted in text form as a subcomponent of the binary form of the private key. The data recovery program 200 identifies the specific fragment and offset transmitted along with the index of the receiving member vehicle. Each member vehicle is unaware of which subcomponents and offsets of the private key it has received, nor is it aware of the fragments and offsets transmitted to other member vehicles.
[0077] The data recovery program 200 segments and distributes the EDR data replicated from the host vehicle among the member vehicles, so that each segment is associated with the index of each member vehicle and includes the timestamp of the data segment (step 250). The data recovery program 200 replicates the segments of the recorded EDR data and sends each segment to the respective member vehicle, where it is associated with the index of the member vehicle and the timestamp of the EDR data segment. In this way, all EDR data is distributed segment by segment to the member vehicles of the dynamic vehicle network. Each segment is encrypted to protect the data contained in the segment and stored locally in the member vehicle along with the timestamp and index information corresponding to the receiving member vehicle. When decrypted by reconstructing the fragmented secret key, the segmented EDR data and timestamps are recovered and reconstructed chronologically.
[0078] For example, a data recovery program 200 running on a host vehicle 116 duplicates a first segment of the recorded EDR data and transmits that segment, along with the timestamp of the data segment, to a network member vehicle 130. As data segmentation continues, the data recovery program 200 proceeds to transmit segments and corresponding timestamps to network member vehicles 120, 135, and 125, and may continue segmentation and distribution of segments and timestamps until all EDR data has been transmitted. In some embodiments, the order in which segments of EDR data are transmitted to member vehicles may change continuously and may include multiple consecutive segments to the same member vehicle.
[0079] The data recovery program 200 dissolves the current dynamic vehicle network in response to the expiration of the network's lifecycle duration without any incident occurring to the host vehicle, and initiates the next dynamic vehicle network (step 260). The current dynamic vehicle network has a predetermined limited lifecycle duration and may have multiple expiration criteria. If no incident has occurred to the host vehicle, the current dynamic vehicle network may be dissolved based on the exceedance of an elapsed time threshold, a distance threshold, the departure of a member vehicle from the current vehicle network, or because the strength of a member vehicle's V2V signal falls below a threshold level. The data recovery program 200 determines that no incident has occurred to the host vehicle, detects a triggering expiration criterion, and initiates the dissolution of the current dynamic vehicle network by communicating with the member vehicle via V2V communication. The data recovery program 200 provides the member vehicle with instructions to delete the received EDR data segment, and the secret key fragment and offset. In some embodiments, when a dynamic vehicle network is formed, the dissolution criteria may be included as instructions from the data recovery program 200 to the member vehicle. In some embodiments, if communication between a member vehicle and the data recovery program 200 via V2V communication from the host vehicle is lost for a predetermined duration, a dissolution command is initiated, which includes instructions for deleting segmented data, timestamps, shared VIN and index information, and private key fragments and offsets.
[0080] In some embodiments, after the current dynamic vehicle network is disbanded and commands are provided to the member vehicles of the current dynamic vehicle network during disbanding, the data recovery program 200 starts the next dynamic vehicle network by identifying the location of the next set of candidate vehicles and inviting them to join the next dynamic vehicle network.
[0081] For example, if network member vehicle 125 leaves the roadway where host vehicle 116 and network vehicles 120, 130, and 135 are traveling, and network member vehicle 125 moves further away from the current dynamic vehicle network, the V2V communication signal strength falls below a predetermined threshold. The data recovery program 200 detects the expiration criterion and initiates the dissolution of the current dynamic vehicle network, sending an instruction to the member vehicle to delete the segmented EDR data, timestamps, index information, shared encrypted VIN, and private key fragments and offsets. Network member vehicle 125 is out of range of V2V communication with the data recovery program 200, but has not received communication with the host vehicle for a predetermined lifetime, then network member vehicle 125 begins deleting the segments, timestamps, index, and shared VIN of the received EDR data, as well as the private key fragments and offsets received by network member vehicle 125. After the dissolution of the current dynamic vehicle network, which included network vehicles 120, 125, 130, and 135, the data recovery program 200 identifies the location of the next group of candidate vehicles within a predetermined geodetic distance and initiates the next dynamic vehicle network by sending an invitation to that group of candidate vehicles to join the next dynamic vehicle network.
[0082] The data recovery program 200, in response to an incident in a host vehicle, identifies member vehicles of the network, retrieves fragments and offsets of the secret key, recovers segments and timestamps of the EDR data, decrypts the segments using the reconstructed secret key, and reconstructs the segmented EDR data in chronological order (step 270). In some embodiments, the data recovery program 200 detects an incident involving a host vehicle and sends a command to each member vehicle to retain the stored segments of the EDR data. In some embodiments, after detecting an incident involving a host vehicle, the data recovery program 200 operates under the direction of, and in some cases under the authority of, an investigative agency.
[0083] When the data recovery program 200 detects an incident in a host vehicle, it uses index information to identify member vehicles in the dynamic vehicle network and retrieves the distributed secret key fragments and their corresponding offsets. The data recovery program 200 reconstructs the secret key based on the offsets and fragments sent to the member vehicles in text format. The secret key is reconstructed by applying the offset information associated with the distribution of secret key fragments to each member vehicle. The data recovery program 200 uses the reconstructed secret key to decrypt the EDR data segments and timestamp information. The data recovery program 200 retrieves the EDR data segments and their corresponding timestamps distributed among the member vehicles in the dynamic vehicle network. The data recovery program 200 reconstructs the EDR data based on the index information and the timestamps of the retrieved EDR data segments.
[0084] In some embodiments, in situations where the host vehicle owner / driver is severely disabled or dies as a result of an incident in the host vehicle, it may be impossible for incident investigators to decrypt EDR data stored locally in the host vehicle. Embodiments of the present invention provide alternative means for recovering and decrypting EDR data while providing security for distributed data.
[0085] For example, the data recovery program 200 detects that the host vehicle 116 is involved in an incident and sends a command to the member vehicles of the dynamic vehicle network to retain the received stored EDR data segments. The investigation agency starts the data recovery program 200 to retrieve the fragments and offsets of the secret key distributed among the network member vehicles 120, 125, 130, and 135, and reconstructs the secret key based on the offsets of the positions of each fragment in the original secret key. The data recovery program 200 retrieves the distributed segments of the encrypted EDR data and their corresponding timestamps. Using the reconstructed secret key, the data recovery program 200 decrypts the distributed segments and timestamps of the EDR data and reconstructs the EDR data in the appropriate time chronological order based on the decrypted timestamp information.
[0086] One further example of one embodiment of the present invention includes vehicle A initializing a vehicle V2V local cluster by sending an invitation to join a first dynamic vehicle network. Vehicles B, C, D, and E respond with an "acceptance" acknowledgment, and the data recovery program 200 assigns indices 1, 2, 3, and 4 to vehicles B, C, D, and E, respectively. These indices are sent to each vehicle and to the data center 140 on the remote server. After the network is started, the host vehicle, vehicle A, fragments its private key into four parts (the segmentation algorithm may be any existing algorithm), and each fragment is sent to the corresponding vehicle, B, C, D, and E, based on the index of the member vehicles B, C, D, and E. After recording the EDR data of vehicle A, the data recovery program 200 periodically replicates segments of the encrypted EDR data of vehicle A to B, C, D, and E. The segmentation and distribution method is not limited to the embodiments of the present invention. The method may be a round-robin replication method performed in a consistent and non-repeated order based on the vehicle's index tag, or a distribution method in which one segment of EDR data is transmitted to two vehicles with one instance of duplication.
[0087] Each replicated EDR data segment includes a timestamp so that the segments can be merged chronologically during EDR data recovery. If, during a health check at the end of the lifecycle, it is determined that no incident occurred in vehicle A, vehicle A issues an EDR data erasure command to member vehicles B, C, D, and E to delete the replicated data. If an incident occurs in vehicle A, and the damage to vehicle A includes the loss of local EDR data, the data sent to the remote data center server when the current dynamic vehicle network was formed indicates which vehicles were member vehicles of the current dynamic vehicle network before the incident occurred, and the replicated EDR data segments are retrieved from those member vehicles.
[0088] The EDR data segments are encrypted, and each member vehicle possesses only one fragment of the secret key; therefore, no single member vehicle can decrypt the EDR data segment independently. The remote data center server contains identification information for the complete set of member vehicles in the current dynamic vehicle network; therefore, only authorized investigators can retrieve the data identifying the vehicles, reconstruct the secret key fragments, and decrypt the recovered EDR data segments, configured in order. The local vehicle network is dynamically built as the host vehicle operates, and the member vehicles that join are largely random. Thus, embodiments of the present invention make it difficult to pre-define the members of the dynamic vehicle network before an incident occurs in the host vehicle, thereby minimizing the vulnerability of the encrypted EDR data.
[0089] Figure 3 shows a schematic diagram of exemplary network resources associated with carrying out the disclosed invention. The invention may be carried out by the disclosed processor which executes instruction streams. As shown in Figure 3, the computing environment 100 includes an example of an environment for executing at least a portion of computer code involved in carrying out the methods of the invention, such as the method of a data recovery program 200 in block 151 held in persistent storage 113. In addition to block 151, the computing environment 100 includes, for example, a computer 101, a wide area network (WAN) 102, an end-user device (EUD) 103, a remote server 104, a public cloud 105, a private cloud 106, and a data center 140 operating as a remote database 132 on the remote server 104. In this embodiment, the computer 101 includes a processor set 109 (including processing circuits 119 and a cache 121), a communication fabric 111, volatile memory 112, persistent storage 113 (including an operating system 122 and a data recovery program 200 for the block 151 identified above), a peripheral device set 114 (including a user interface (UI)), a device set 123, storage 124, and a network module 115.
[0090] The remote server 104 includes a remote database 132 that, in some embodiments, can operate similarly to a data center 140 (Figure 1). The public cloud 105 includes a gateway 145, a cloud orchestration module 141, a host physical machine set 142, a virtual machine set 143, and a container set 144.
[0091] Computer 101 may take the form of a desktop computer, laptop computer, tablet computer, smartphone, smartwatch, or other wearable computer, mainframe computer, quantum computer, or any other form of computer or mobile device, currently known or to be developed in the future, capable of running programs, accessing networks, or querying databases such as remote database 132. In some embodiments, computer 101 may take the form of a handheld device capable of receiving and transmitting data and executing computer instructions. In some embodiments, computer 101 may be configured and operate similarly to computing device 110 shown in Figure 1, operating on a host vehicle 116. As is well understood in the field of computer technology, and depending on the technology, the execution of a computer implementation method may be distributed among multiple computers and / or multiple locations. On the other hand, in this presentation of the computing environment 100, in order to keep the presentation as simple as possible, the detailed discussion focuses on a single computing device, specifically computer 101. Although computer 101 is not shown in the cloud in Figure 3, it may be located in the cloud. On the other hand, computer 101 is not required to reside in the cloud, except to any extent that can be definitively indicated.
[0092] The processor set 109 includes one or more computer processors of any type currently known or to be developed in the future. The processing circuitry 119 may be distributed across multiple packages, for example, multiple coordinated integrated circuit chips. The processing circuitry 119 may implement multiple processor threads and / or multiple processor cores. The cache 121 is memory located within the processor chip package and is typically used for data or code that should be available for high-speed access by threads or cores running on the processor set 109. The cache memory is typically organized into multiple levels depending on its relative proximity to the processing circuitry. Alternatively, some or all of the cache for the processor set may be located "off-chip". In some computing environments, the processor set 109 may operate using qubits and be designed to perform quantum computing.
[0093] Computer-readable program instructions are typically loaded onto computer 101, causing the processor set 109 of computer 101 to execute a series of operational steps, thereby enabling the computer implementation method. As a result, the instructions thus executed instantiate the method specified in the flowcharts and / or descriptions of the computer implementation method contained herein (collectively referred to as the "Method of the Invention"). These computer-readable program instructions are stored in various types of computer-readable storage media, such as cache 121 and other storage media discussed below. The program instructions and associated data are accessed by the processor set 109 to control and direct the execution of the Method of the Invention. In computing environment 100, at least some of the instructions for executing the Method of the Invention may be stored in a data recovery program 200 in block 151 of persistent storage 113.
[0094] The communication fabric 111 is a signal conduction path that enables various components of the computer 101 to communicate with one another. Typically, this fabric is made up of switches and conductive paths, such as buses, bridges, physical input / output ports, and similar components. Other types of signal communication paths, such as optical fiber communication paths and / or wireless communication paths, may be used.
[0095] Volatile memory 112 is any type of volatile memory currently known or to be developed in the future. Examples include dynamic random access memory (RAM) or static RAM. Typically, volatile memory 112 is characterized by random access, but this is not required unless explicitly stated. In computer 101, volatile memory 112 is located in a single package and resides inside computer 101, but alternatively or additionally, volatile memory may be distributed across multiple packages and / or located externally to computer 101.
[0096] The persistent storage 113 is any form of non-volatile storage for a computer that is currently known or may be developed in the future. The non-volatility of this storage means that the stored data is maintained regardless of whether power is supplied directly to the computer 101 and / or to the persistent storage 113. The persistent storage 113 may be read-only memory (ROM), but typically at least a portion of the persistent storage allows for writing, deleting, and rewriting of data. Some well-known forms of persistent storage include magnetic disks and solid-state storage devices. The operating system 122 can take multiple forms, such as various known proprietary operating systems or open-source portable operating system interface type operating systems employing a kernel. The code contained in a representative block of the data recovery program 200 typically includes at least a portion of the computer code involved in executing the method of the present invention.
[0097] The peripheral device set 114 includes a set of peripheral devices for the computer 101. Data communication connections between the computer 101's peripheral devices and other components can be implemented in various ways, including Bluetooth connections, Near-Field Communication (NFC) connections, connections made by cables (such as universal serial bus (USB) type cables), insertable connections (e.g., secure digital (SD) cards), connections made through local area communication networks, and even connections made through wide area networks such as the internet. In various embodiments, the UI device set 123 may include components such as a display screen, speaker, microphone, wearable devices (such as goggles and smartwatches), keyboard, mouse, printer, touchpad, game controller, and haptic devices. Storage 124 is external storage such as an external hard drive, or insertable storage such as an SD card. Storage 124 may be persistent and / or volatile. In some embodiments, storage 124 may take the form of a quantum computing storage device for storing data in the form of qubits. In embodiments where computer 101 is required to have a large amount of storage (for example, when computer 101 locally stores and manages a large database), this storage may be provided by peripheral storage devices designed to store very large amounts of data, such as a storage area network (SAN) shared by multiple geographically distributed computers.
[0098] The network module 115 is a collection of computer software, hardware, and firmware that enables computer 101 to communicate with other computers via the WAN 102. The network module 115 may include hardware such as a modem or Wi-Fi signal transceiver, software for packetizing and / or depacketizing data for communication network transmission, and / or web browser software for communicating data over the Internet. In some embodiments, the network control and network forwarding functions of the network module 115 are performed on the same physical hardware device. In other embodiments (e.g., embodiments utilizing Software-Defined Networking (SDN)), the control and forwarding functions of the network module 115 are performed on physically separate devices, such that the control function manages multiple different network hardware devices. Computer-readable program instructions for performing the method of the present invention can typically be downloaded to computer 101 from an external computer or external storage device via a network adapter card or network interface included in the network module 115.
[0099] WAN102 is any wide area network (e.g., the Internet) capable of transmitting computer data over non-local distances using any currently known or future-developed technology for transmitting computer data. In some embodiments, WAN102 may be replaced and / or supplemented by a local area network (LAN), such as a Wi-Fi network, designed to transmit data between devices located in a local area. WANs and / or LANs typically include computer hardware such as copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and edge servers.
[0100] An end-user device (EUD) 103 is any computer system used and controlled by an end-user (e.g., an enterprise customer operating computer 101) and can take any of the forms discussed above in relation to computer 101. EUD 103 typically receives useful and valuable data from the operation of computer 101. For example, in a hypothetical case where computer 101 is designed to provide recommendations to an end-user, these recommendations would typically be communicated from computer 101's network module 115 to EUD 103 via WAN 102. In this way, EUD 103 can display or otherwise present the recommendations to the end-user. In some embodiments, EUD 103 may be a client device such as a thin client, heavy client, mainframe computer, desktop computer, and the like.
[0101] The remote server 104 is any computer system that provides at least some data and / or functionality to computer 101. The remote server 104 may be controlled and used by the same entity that operates computer 101. The remote server 104 represents a machine that collects and stores useful and valuable data for use by other computers, such as computer 101. For example, in a hypothetical case where computer 101 is designed and programmed to provide recommendations based on historical data, this historical data may be provided to computer 101 from the remote database 132 of the remote server 104.
[0102] The public cloud 105 is any computer system available for use by multiple entities, providing on-demand availability of computer system resources and / or other computer functions, particularly data storage (cloud storage) and computing power, without direct active management by the user. Cloud computing typically leverages resource sharing to achieve coherence and economies of scale. Direct active management of the computing resources of the public cloud 105 is performed by the computer hardware and / or software of the cloud orchestration module 141. The computing resources provided by the public cloud 105 are typically implemented by virtual computing environments running on various computers that make up the host physical machine set 142, which is the universe of physical computers within and / or available to the public cloud 105. The virtual computing environment (VCE) typically takes the form of virtual machines from the virtual machine set 143 and / or containers from the container set 144. These VCEs can be stored as images and transferred between various physical machine hosts, either as images or after VCE instantiation. The cloud orchestration module 141 manages the transfer and storage of images, deploys new VCE instantiations, and manages active instantiations of VCE deployments. The gateway 145 is a collection of computer software, hardware, and firmware that enables the public cloud 105 to communicate through the WAN 102.
[0103] Here, some further explanation of virtualized computing environments (VCEs) is provided. A VCE can be stored as an "image." A new active instance of a VCE can be instantiated from an image. Two well-known types of VCEs are virtual machines and containers. A container is a VCE that uses operating system-level virtualization. This refers to an operating system feature where the kernel allows for the existence of multiple isolated user-space instances called containers. These isolated user-space instances typically behave like actual computers in terms of the programs running within them. Computer programs running on a normal operating system can utilize all of that computer's resources, including connected devices, files and folders, network shares, CPU power, and quantifiable hardware capabilities. However, programs running inside a container can only use the contents of the container and the devices allocated to that container; this feature is known as containerization.
[0104] A private cloud 106 is similar to a public cloud 105, except that its computing resources are available for use by a single enterprise only. While private cloud 106 is shown as being in communication with the WAN 102, in other embodiments, a private cloud may be completely isolated from the internet and accessible only through a local / private network. A hybrid cloud is a combination of multiple clouds of different types (e.g., private cloud, community cloud, or public cloud types), often implemented by different vendors.
[0105] Each of the multiple clouds remains a separate, discrete entity, but the larger hybrid cloud architecture is bound together by standardized or proprietary technologies that enable orchestration, management, and / or data / application portability between the multiple configuration clouds. In this embodiment, both the public cloud 105 and the private cloud 106 are part of the larger hybrid cloud.
[0106] The programs described herein are identified based on the applications in which they are implemented in particular embodiments of the present invention. However, it should be understood that any specific program names used herein are for convenience only, and therefore the present invention should not be limited to use in any particular application identified and / or suggested by such names.
[0107] The present invention may be a system, method, and / or computer program product in an integration of any possible level of technical detail. The computer program product may include a computer-readable storage medium (or multiple mediums) having computer-readable program instructions for causing a processor to perform an aspect of the present invention.
[0108] A computer-readable storage medium can be a tangible device capable of holding and storing instructions for use by an instruction execution device. A computer-readable storage medium may be, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any preferred combination of those described above. A non-exclusive list of more specific examples of computer-readable storage media includes: portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital multipurpose disks (DVDs), memory sticks, floppy disks, mechanically encoded devices such as punch cards or grooved raised structures on which instructions are recorded, and any preferred combination of those described above. As used herein, a computer-readable storage medium should not be construed as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a pulse of light passing through an optical fiber cable), or a transient signal itself, such as an electrical signal transmitted through a wire.
[0109] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to each computing / processing device, or to an external computer or external storage device via a network such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface within each computing / processing device receives computer-readable program instructions from the network and transfers such instructions for storage in a computer-readable storage medium within the respective computing / processing device.
[0110] The computer-readable program instructions that perform the operation of the present invention may be assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, configuration data for integrated circuits, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, or similar, and procedural programming languages such as the C programming language or similar. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or wide area network (WAN), or this connection may be to an external computer (for example, through the Internet using an Internet service provider). In some embodiments, for example, an electronic circuit including a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA) may be personalized by executing computer-readable program instructions by utilizing state information of computer-readable program instructions in order to perform an aspect of the present invention.
[0111] Aspects of the present invention are described herein with reference to flowcharts and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the present invention. It will be understood that each block in the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.
[0112] These computer-readable program instructions may be provided to a computer processor or other programmable data processing device to generate a machine, which in turn creates means for instructions executed via the processor of the computer or other programmable data processing device to implement functions / operations specified in one or more blocks of a flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium on which the instructions are stored, which can instruct a computer, a programmable data processing device, and / or other device to function in a particular manner, such that the storage medium has a product containing instructions that implements the modes of functions / operations specified in one or more blocks of a flowchart and / or block diagram.
[0113] Computer-readable program instructions may also be loaded into a computer, other programmable data processing device, or other device to execute a series of operational steps on the computer, other programmable device, or other device, thereby generating a computer implementation process in which the instructions executed on the computer, other programmable device, or other device implement the functions / operations specified in one or more blocks of a flowchart and / or block diagram.
[0114] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of instructions containing one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions described in the blocks may occur in an order different from the order shown in the drawings. For example, two blocks shown consecutively may actually be implemented as a single step, executed simultaneously, substantially simultaneously, partially or entirely, with overlapping timelines, or blocks may, in some cases, be executed in reverse order depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs a specified function or operation, or a combination of dedicated hardware and computer instructions.
[0115] The descriptions of various embodiments of the present invention are presented for illustrative purposes only and are not intended to be comprehensive or limitless to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope of the embodiments described. The terminology used herein has been selected to best describe the principles of the embodiments, their practical applications, or technical improvements to the art found in the market, or to enable other persons skilled in the art to understand the embodiments disclosed herein.
[0116] Exemplary embodiments of the present invention are described in the claims and further include: (1). A system for distributing copies of vehicle event data recorder (EDR) data, wherein the method is: Computer processor; At least one computer-readable storage medium, and program instructions stored on the at least one computer-readable storage medium that are executed by the computer processor The program instructions are: A program instruction for transmitting index information that uniquely identifies each member vehicle of a dynamic vehicle network, wherein the member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geodetic distance from a host vehicle; A program instruction for transmitting a fragment of a secret key associated with the host vehicle's EDR data to each of the member vehicles of the dynamic vehicle network, wherein the fragment is transmitted in text format and includes a positional offset of the fragment of the secret key; Program instructions for distributing segments of EDR data replicated from the host vehicle among the respective member vehicles, wherein each segment of EDR data is associated with an index identification information of the respective member vehicle and includes a timestamp of the segment of the EDR data; and Program instructions to disband the dynamic vehicle network and start the next dynamic vehicle network, which includes the next set of candidate vehicles, in response to the expiration of a predetermined lifecycle duration associated with the dynamic vehicle network and the absence of an incident in the host vehicle. A system that has (2) The computer system according to item (1), wherein a program instruction for dissolving the dynamic vehicle network includes sending an instruction to the member vehicles of the dynamic vehicle network to delete the encrypted replicated EDR data segment, the fragment of the secret key and the position offset, the index information and the vehicle identification number (VIN) of each member vehicle shared with the member vehicles. (3) A procedure for one or more processors to send an invitation to a candidate vehicle located within a predetermined geodetic distance from the host vehicle to join the dynamic vehicle network; and In response to the candidate vehicle joining the dynamic vehicle network as a member vehicle, the procedure involves one or more processors receiving the vehicle identification number (VIN) of each of the member vehicles, wherein the invitation to join the dynamic vehicle network, the response from the candidate vehicle, and the formation of the dynamic vehicle network occur while the host vehicle and the candidate vehicle are operating, and the formed dynamic vehicle network includes a predetermined temporary lifecycle duration. The computer system described in item (1), further comprising the features described in item (1). (4) The computer system according to item (1), which, in response to detecting that the incident has occurred in the host vehicle, stores the replicated EDR data distributed to the member vehicles in segment units in the local storage of each member vehicle. (5) The computer system according to item (1), wherein the expiration of the predetermined lifecycle duration is initiated by the detection of at least one criterion selected from the group consisting of the expiration of the predetermined period, the exceedance of a predetermined mileage, and the V2V communication signal from at least one member vehicle of the dynamic vehicle network falling below a signal strength threshold. (6) The computer system described in item (1), wherein the encrypted vehicle identification number (VIN) and index information of each of the member vehicles are transmitted to a central data repository for vehicle incident investigation after the formation of the dynamic vehicle network and before the segmentation of EDR data and transmission to the member vehicles begin. (7) A program instruction to send to the member vehicle an instruction to retain a segment of stored EDR data and a corresponding timestamp, in response to the detection of the host vehicle's involvement in the incident; Program instructions for retrieving the fragment of the secret key and the position offset transmitted to each member vehicle of the dynamic vehicle network from each member vehicle; A program instruction for reconstructing the secret key based on the index information and the position offset of each fragment received from the member vehicle; Program instructions for retrieving the replicated EDR data segment and the corresponding timestamp from each of the member vehicles of the dynamic vehicle network, wherein the replicated EDR data segment and the corresponding timestamp are encrypted; Program instructions for decrypting the replicated EDR data segment and the corresponding timestamp using the secret key; and Program instructions for generating the replicated EDR data based on the corresponding timestamp and index information of the replicated EDR data segment. The computer system described in item (1), further comprising the features described in item (1). (8) The computer program product according to item (7), wherein the program instructions for disbanding the dynamic vehicle network include sending instructions to the member vehicles of the dynamic vehicle network to delete the encrypted replicated EDR data segment, the fragment of the secret key and the position offset, and the index information and the vehicle identification number (VIN) shared with the member vehicles, and the expiration of the predetermined lifecycle lifetime is initiated by the detection of at least one criterion selected from the group consisting of the expiration of the predetermined period, the exceedance of a predetermined mileage, and the V2V communication signal from at least one member vehicle of the dynamic vehicle network falling below a signal strength threshold. (9) A program instruction to send to the member vehicle an instruction to retain a segment of stored EDR data and a corresponding timestamp, in response to the detection of the host vehicle's involvement in the incident; Program instructions for retrieving the fragment of the secret key and the position offset transmitted to each member vehicle of the dynamic vehicle network from each member vehicle; A program instruction for reconstructing the secret key based on the index information and the position offset of each fragment received from the member vehicle; Program instructions for retrieving the replicated EDR data segment and the corresponding timestamp from each of the member vehicles of the dynamic vehicle network, wherein the replicated EDR data segment and the corresponding timestamp are encrypted; Program instructions for decrypting the replicated EDR data segment and the corresponding timestamp using the secret key; and Program instructions for generating the replicated EDR data based on the corresponding timestamp and index information of the replicated EDR data segment. A computer program product as described in item (7), further comprising the features described therein.
Claims
1. A computer implementation method for distributing copies of vehicle event data recorder (EDR) data, comprising: The step in which one or more processors transmit index information that uniquely identifies each member vehicle of the dynamic vehicle network, wherein the member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geodetic distance from the host vehicle; The step of one or more processors transmitting to each of the member vehicles of the dynamic vehicle network a fragment of a secret key associated with the host vehicle's EDR data, wherein the fragment is transmitted in text format and includes a positional offset of the fragment of the secret key; The step of one or more processors distributing segments of EDR data replicated from the host vehicle among the respective member vehicles, wherein each segment of EDR data is associated with an index identification information of the respective member vehicle and includes a timestamp of the segment of the EDR data; and In response to the expiration of a predetermined lifecycle duration associated with the dynamic vehicle network and the absence of an incident in the host vehicle, one or more processors dissolve the dynamic vehicle network and initiate a new dynamic vehicle network including the next set of candidate vehicles. A computer implementation method comprising the following:
2. The method according to claim 1, wherein the dissolution of the dynamic vehicle network comprises sending an instruction to the member vehicles of the dynamic vehicle network to delete the encrypted replicated EDR data segment, the fragment of the secret key and the position offset, the index information and the vehicle identification number (VIN) of each member vehicle shared with the member vehicles.
3. The step of one or more processors sending an invitation to a candidate vehicle located within a predetermined geodetic distance from the host vehicle to join the dynamic vehicle network; and In response to the candidate vehicle joining the dynamic vehicle network as a member vehicle, one or more processors receive the vehicle identification number (VIN) of each of the member vehicles, where the invitation to join the dynamic vehicle network, the response from the candidate vehicle, and the formation of the dynamic vehicle network occur during the operation of the host vehicle and the candidate vehicle. The method according to claim 1 or claim 2, further comprising the above.
4. The method according to any one of the preceding claims, wherein, in response to detection that the incident has occurred in the host vehicle, the replicated EDR data distributed to the member vehicles in segment units is stored in the local storage of each member vehicle.
5. The method according to any one of the above claims, wherein the dynamic vehicle network includes a temporary predetermined lifecycle duration.
6. The method according to claim 5, wherein the expiration of the predetermined lifecycle duration is initiated by the detection of at least one criterion selected from the group consisting of the expiration of a predetermined period, the exceedance of a predetermined mileage, and the V2V communication signal from at least one member vehicle of the dynamic vehicle network falling below a signal strength threshold.
7. The method according to any one of the above claims, wherein the member vehicles of the dynamic vehicle network include at least two member vehicles and the host vehicle.
8. The method according to any one of the preceding claims, wherein the encrypted vehicle identification number (VIN) and index information of each of the member vehicles are transmitted to a central data repository for vehicle incident investigation after the formation of the dynamic vehicle network and before the segmentation of EDR data and transmission to the member vehicles begin.
9. The method according to any one of the above claims, wherein the segment of the EDR data and the corresponding timestamp are encrypted using the secret key.
10. In response to detecting the host vehicle's involvement in the incident, one or more processors send an instruction to the member vehicle to hold a stored segment of EDR data and a corresponding timestamp; The step of one or more processors retrieving the fragment of the secret key and the position offset transmitted to each member vehicle of the dynamic vehicle network from each member vehicle; The step of one or more processors reconstructing the secret key based on the index information and the position offset of each fragment received from the member vehicle; The step involves one or more processors retrieving the replicated EDR data segments and corresponding timestamps from each of the member vehicles of the dynamic vehicle network, wherein the replicated EDR data segments and corresponding timestamps are encrypted; The step of one or more processors decrypting the replicated EDR data segment and the corresponding timestamp using the secret key; and The step in which one or more processors generate the replicated EDR data based on the corresponding timestamp and index information of the replicated EDR data segments. The method according to any one of the preceding claims, further comprising:
11. A system for distributing copies of vehicle event data recorder (EDR) data: Computer processor; At least one computer-readable storage medium, and program instructions stored on the at least one computer-readable storage medium that are executed by the computer processor. The program instructions are: A program instruction for transmitting index information that uniquely identifies each member vehicle of a dynamic vehicle network, wherein the member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geodetic distance from a host vehicle; A program instruction for transmitting to each of the member vehicles of the dynamic vehicle network a fragment of a secret key associated with the host vehicle's EDR data, wherein the fragment is transmitted in text format and includes a positional offset of the fragment of the secret key; Program instructions for distributing segments of EDR data replicated from the host vehicle among the respective member vehicles, wherein each segment of EDR data is associated with an index identification information of the respective member vehicle and includes a timestamp of the segment of the EDR data; and Program instructions to disband the dynamic vehicle network and start the next dynamic vehicle network, which includes the next set of candidate vehicles, in response to the expiration of a predetermined lifecycle duration associated with the dynamic vehicle network and the absence of an incident in the host vehicle. A system that has
12. The system according to claim 11, wherein a program instruction for disbanding the dynamic vehicle network includes transmitting an instruction to the member vehicles of the dynamic vehicle network to delete the encrypted segment of the replicated EDR data, the fragment of the secret key and the position offset, the index information and the vehicle identification number (VIN) of each member vehicle shared with the member vehicles.
13. A procedure in which one or more processors transmit an invitation to a candidate vehicle located within a predetermined geodetic distance from the host vehicle to join the dynamic vehicle network; and In response to the candidate vehicle joining the dynamic vehicle network as a member vehicle, the procedure involves one or more processors receiving the vehicle identification number (VIN) of each of the member vehicles, wherein the invitation to join the dynamic vehicle network, the response from the candidate vehicle, and the formation of the dynamic vehicle network occur while the host vehicle and the candidate vehicle are operating, and the formed dynamic vehicle network includes a predetermined temporary lifecycle duration. The system according to claim 11 or claim 12, further comprising the above.
14. The system according to any one of claims 11 to 13, wherein, in response to detection that the incident has occurred in the host vehicle, the replicated EDR data distributed to the member vehicles in segment units is stored in the local storage of each member vehicle.
15. The system according to any one of claims 11 to 14, wherein the expiration of the predetermined lifecycle duration is initiated by the detection of at least one criterion selected from the group consisting of the expiration of a predetermined period, the exceedance of a predetermined mileage, and the V2V communication signal from at least one member vehicle of the dynamic vehicle network falling below a signal strength threshold.
16. The system according to any one of claims 11 to 15, wherein the encrypted vehicle identification number (VIN) and index information of each member vehicle are transmitted to a central data repository for vehicle incident investigation after the formation of the dynamic vehicle network and before the segmentation of EDR data and transmission to the member vehicles begin.
17. A program instruction to send to the member vehicle an instruction to retain a stored segment of EDR data and a corresponding timestamp, in response to the detection of the host vehicle's involvement in the incident; Program instructions for retrieving the fragment of the secret key and the position offset transmitted to each member vehicle of the dynamic vehicle network from each member vehicle; A program instruction for reconstructing the secret key based on the index information and the position offset of each fragment received from the member vehicle; Program instructions for retrieving the replicated EDR data segment and the corresponding timestamp from each of the member vehicles of the dynamic vehicle network, wherein the replicated EDR data segment and the corresponding timestamp are encrypted; Program instructions for decrypting the replicated EDR data segment and the corresponding timestamp using the secret key; and Program instructions for generating the replicated EDR data based on the corresponding timestamp and index information of the replicated EDR data segments. The system according to any one of claims 11 to 16, further comprising:
18. A computer program product for distributing copies of vehicle event data recorder (EDR) data, wherein the method is: At least one computer-readable storage medium, and program instructions stored on the at least one computer-readable storage medium The program instructions are: A program instruction for transmitting index information that uniquely identifies each member vehicle of a dynamic vehicle network, wherein the member vehicles of the dynamic vehicle network include candidate vehicles located within a predetermined geodetic distance from a host vehicle; A program instruction for transmitting to each of the member vehicles of the dynamic vehicle network a fragment of a secret key associated with the host vehicle's EDR data, wherein the fragment is transmitted in text format and includes a positional offset of the fragment of the secret key; Program instructions for distributing segments of EDR data replicated from the host vehicle among the respective member vehicles, wherein each segment of EDR data is associated with an index identification information of the respective member vehicle and includes a timestamp of the segment of the EDR data; and Program instructions to disband the dynamic vehicle network and start the next dynamic vehicle network, which includes the next set of candidate vehicles, in response to the expiration of a predetermined lifecycle duration associated with the dynamic vehicle network and the absence of an incident in the host vehicle. A computer program product that has [certain characteristics].
19. The computer program product according to claim 18, wherein the program instruction for dissolving the dynamic vehicle network includes transmitting an instruction to the member vehicles of the dynamic vehicle network to delete the encrypted replicated EDR data segment, the fragment of the secret key and the position offset, and the index information and the vehicle identification number (VIN) shared with the member vehicles, and the expiration of the predetermined lifecycle lifetime is initiated by the detection of at least one criterion selected from the group consisting of the expiration of the predetermined period, the exceedance of a predetermined mileage, and the V2V communication signal from at least one member vehicle of the dynamic vehicle network falling below a signal strength threshold.
20. A program instruction to send to the member vehicle an instruction to retain a stored segment of EDR data and a corresponding timestamp, in response to the detection of the host vehicle's involvement in the incident; Program instructions for retrieving the fragment of the secret key and the position offset transmitted to each member vehicle of the dynamic vehicle network from each member vehicle; A program instruction for reconstructing the secret key based on the index information and the position offset of each fragment received from the member vehicle; Program instructions for retrieving the replicated EDR data segment and the corresponding timestamp from each of the member vehicles of the dynamic vehicle network, wherein the replicated EDR data segment and the corresponding timestamp are encrypted; Program instructions for decrypting the replicated EDR data segment and the corresponding timestamp using the secret key; and Program instructions for generating the replicated EDR data based on the corresponding timestamp and index information of the replicated EDR data segments. A computer program product according to claim 18 or claim 19, further comprising the above.