In-Vehicle Measurement Data Encryption for Campaign Access Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for collecting measurement data from motor vehicles using cloud storage allow unauthorized access to sensitive data, compromising privacy and security, as service providers can gain insights into vehicle-related or personal data.
Innovation Solution
A method and system that uses a central computer system to generate campaign-specific cryptographic keys, encrypting measurement data with symmetrical encryption in the vehicle before transmission, and decrypting it only for authorized campaign operators, ensuring data isolation and security throughout the communication and storage process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If measurement data is stored in centralized cloud storage, then data collection efficiency is improved, but data security and privacy protection deteriorate as service providers can access and evaluate the measurement data
Solution Approach 1:
The patent segments the centralized storage system into distributed edge storage nodes within the service provider's network. Measurement data is divided and stored across multiple edge nodes rather than in a single centralized location, reducing the security risk exposure while maintaining collection efficiency. Each edge node stores only specific portions of data, limiting the impact of potential security breaches.
Solution Approach 2:
The patent introduces an intermediary encryption layer between the measurement data and the storage system. Data is encrypted using cryptographic keys before being transmitted to and stored in the cloud storage infrastructure. This intermediary encryption mechanism allows efficient centralized storage while protecting data from unauthorized access by service providers and intermediaries.
2Reliability
If measurement data is encrypted with vehicle-specific keys, then data security is improved, but key management complexity and system complexity increase
Solution Approach 1:
The patent implements a universal key hierarchy where a small number of master keys at the service provider level can derive and manage multiple vehicle-specific keys. This universal key management system allows secure encryption of data from multiple vehicles using a standardized key structure, reducing the operational complexity of managing individual keys for each vehicle while maintaining strong security.
Solution Approach 2:
The patent performs preliminary key establishment and distribution before actual measurement data collection begins. Vehicle-specific cryptographic keys are pre-configured in vehicles during manufacturing or initial setup, and corresponding public keys are pre-distributed to the service provider's key management system. This preliminary action eliminates the need for complex real-time key generation and distribution during data collection operations.
3Quantity of substance
If all measurement data from multiple campaigns is stored together, then storage efficiency is improved, but data isolation and access control deteriorate as operators can access data from campaigns they should not see
Solution Approach 1:
The patent applies local quality encryption where different cryptographic parameters and access controls are applied to different portions of the stored data based on campaign-specific requirements. While all data is physically stored together in the same infrastructure, each campaign's data is encrypted with campaign-specific key material and metadata, ensuring that operators can only decrypt and access data from campaigns they are authorized to view, maintaining logical isolation within physical consolidation.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a method for carrying out measurement campaigns by means of motor vehicles (12). A key derivation module (43) is operated by a central computer system (11), which key derivation module generates a campaign-specific cryptographic key (44) for the respective measurement campaign, and control software (15) is provided in the motor vehicles (12), which control software is executed in a respective local computer system (14) in the respective motor vehicle (12) and is set up a) for carrying out measurements (16) of measurement data (17) in accordance with campaign configuration data (26) of the respective measurement campaign and b) for encrypting the measured measurement data (17) in the local computer system (14) by means of the campaign-specific cryptographic key (44) using a predetermined symmetrical encryption method (45) and c) for transmitting the encrypted measurement data (17) to the central computer system (11).