Telematics Data Privacy via Mobile Cloud Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Telematics data collected by vehicles often includes personally identifiable information (PII), which poses privacy concerns due to regulations like CalOPPA and GDPR, and existing security mechanisms are inadequate for protecting this data, especially in scenarios where users ride in various vehicles.
Innovation Solution
A system where a vehicle and a mobile device register with a cloud-based computing system to establish cryptographic keys, enabling the encryption and secure storage of telematics data, with the mobile device acting as a gateway to secure the data and the cloud system processing it to remove identifying aspects, associating it with a numeric identifier for secure storage and retrieval.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If telematics data is communicated to third parties for additional features and insights, then vehicle functionality and manufacturing benefits are improved, but user privacy and data security are compromised due to inclusion of PII
Solution Approach 1:
The system extracts and removes personally identifiable information from telematics data before communication to third parties. The PII filtering component specifically identifies and extracts PII elements such as GPS location data from start/end points and driving habits, separating them from the useful telematics data for analysis.
Solution Approach 2:
The patent introduces an intermediary processing system between data collection and third-party communication. This intermediary includes PII filtering and encryption components that mediate the data flow, allowing useful telematics data to be communicated while blocking or anonymizing PII elements.
2Reliability
If cryptographic encryption is implemented to secure telematics data, then data security is improved, but system complexity increases due to key management and encryption processes
Solution Approach 1:
The mobile device and vehicle system automatically perform cryptographic key generation, exchange, and management without requiring manual user intervention. The system self-manages the cryptographic infrastructure including generating keys, establishing secure channels, and handling encryption/decryption operations autonomously.
Solution Approach 2:
The patent introduces a cloud-based intermediary system that facilitates cryptographic key management between the vehicle and mobile device. This intermediary cloud system helps coordinate key exchange and management, reducing the burden on individual devices while maintaining security.
3Object-affected harmful factors
If PII data is filtered and anonymized before storage, then user privacy is protected, but data utility is reduced for analytical purposes
Solution Approach 1:
The system applies different processing treatments to different portions of telematics data based on their sensitivity. Useful operational data is retained in full detail for analysis, while only the specific PII portions are filtered or anonymized, preserving local quality of each data element according to its privacy requirements.
Solution Approach 2:
The patent segments telematics data into distinct categories: PII elements that require filtering/anonymization and non-PII operational data that can be fully utilized for analysis. This segmentation allows selective processing that protects privacy while preserving data utility for legitimate analytical purposes.
Data Source
AI summary
Systems, methods, and other embodiments described herein relate to securing personally identifiable information associated with riding in a vehicle. In one embodiment, a method includes, in response to receiving, in a mobile device from the vehicle, telematics data about a current trip of the vehicle, securing the telematics data according to at least a mobile cryptographic key associated with the mobile device to provide the telematics data as secured data that is obfuscated. The method includes generating, by the mobile device, a secure packet including at least the secured data and a signature from the vehicle associated with the secured data. The method includes communicating, by the mobile device, the secure packet to a remote computing device to cause the remote computing device to securely store the secured data without identifying a user associated with the mobile device.


