[论文解读] In-vehicle data recording, storage and access management in autonomous vehicles
本文提出了面向自动驾驶的事件数据记录仪(EDR/AD),作为自动驾驶与协同智能交通系统(C-ITS)中安全、保护隐私的车载系统,用于记录、存储和管理车辆数据。该系统通过CAN网络、OBD-II端口及自组织通信方式集成数据访问,利用密码学认证与全局可发现性,确保数据完整性、来源可追溯性及符合新兴监管标准,使EDR/AD成为实现法律合规、安全与社会可接受的自动驾驶的关键推动者。
Transport sector is in the process of being rapidly and fundamentally reshaped by autonomous and collaborative driving technologies. This reshaping promises huge economic and social benefits as well as challenges in terms of developing and deploying secure and safe transportations systems, their smooth integration to social fabric. We have employed Policy Scan and Technology Strategy Design methodology in order to identify concrete societal expectations and problems and map them with mitigating technological availabilities in the domain of autonomous driving and smart mobility. Event Data Recorder for Autonomous Driving (EDR/AD) is an envisioned subsystem of a vehicular Controller Area Network which ensures the confidentiality, integrity and availability of data related to operation of a vehicle in order to permit recovery of exact situation following the occurrence of an event or on demand. The exact technical and regulatory requirements for the device are still in the development internationally, but it is clear that it will be included into vehicle type-approval requirements at UNECE level. We present an analysis of the context of the usage of the EDR/AD in collaborative intelligent transport systems, related security, data provenance and privacy, other regulatory and technical issues considering many interest groups and stakeholders involved. We present a concrete proposal for developing a EDR/AD proof of the concept prototype with clear market deployment potential and urge security researchers, vehicle manufacturers, and component suppliers to form a collaboration towards implementing important technology for making future autonomous vehicles more socially acceptable and legally compliant. Furthermore, EDR/AD technology, apart from its immediate use in autonomous driving and smart mobility domain has a potential to be extended to general autonomous robot and AI applications.
研究动机与目标
- 为应对自动驾驶部署带来的日益增长的社会与监管挑战,特别是安全、责任归属与数据透明性方面的问题。
- 识别一种具体的技术解决方案——EDR/AD,以弥合自动驾驶中社会期望与技术能力之间的差距。
- 确保在协同智能交通系统(C-ITS)中,通过多个接入点(外部服务器、OBD-II、自组织网络)实现数据完整性、机密性与可用性。
- 通过汽车制造商、安全研究人员与零配件供应商之间的协作,推动开发可市场化、安全且符合标准的EDR/AD原型。
- 将EDR/AD的适用范围从自动驾驶车辆扩展至更广泛的自主机器人与人工智能系统,确保其长期社会与监管契合性。
提出的方法
- 采用政策扫描与技术战略设计方法,迭代识别自动驾驶领域中的社会问题与技术解决方案。
- 将EDR/AD作为控制器局域网络(CAN)的子系统提出,以确保事件发生期间及之后的数据机密性、完整性与可用性。
- 集成三种数据接入点:与外部服务器通信、通过OBD-II端口进行诊断访问,以及与其他车辆和基础设施的自组织通信。
- 应用PKI或伪名证书等密码学机制,实现全局可发现性,确保数据来源可追溯性与隐私合规性。
- 设计系统以支持“被遗忘的权利”,并通过端到端认证与访问控制防止数据篡改。
- 提出具备市场部署潜力的概念验证原型,强调产业界与安全研究人员之间的协作。
实验结果
研究问题
- RQ1如何设计车载数据记录与访问管理机制,以确保在自动驾驶与协同智能交通系统(C-ITS)中数据的完整性与安全性?
- RQ2在部署EDR/AD过程中,面对汽车制造商、监管机构与基础设施提供商等多元利益相关方,其关键监管、隐私与技术挑战是什么?
- RQ3EDR/AD如何在保障用户隐私的同时,支持数据来源可追溯性与全局可发现性,并实现与数据保护法律的合规?
- RQ4EDR/AD在实现自动驾驶车辆决策的法律问责与透明化方面发挥何种作用,特别是在事故重建与保险理赔中的应用?
- RQ5产业界、研究人员与监管机构之间的协作框架,如何加速安全、标准化EDR/AD系统的开发与部署?
主要发现
- EDR/AD被认定为具有明确市场与监管部署潜力的关键技术解决方案,有望成为UNECE法规下车辆型式认证的强制要求。
- 在外部服务器、OBD-II端口与自组织通信三种数据接入点中整合EDR/AD,需要统一的子系统以维护数据完整性并防止篡改。
- PKI或伪名证书等密码学机制对于实现全局可发现性、确保数据来源可追溯性,同时支持如“被遗忘的权利”等隐私原则至关重要。
- 车载网络当前缺乏安全与防篡改机制,亟需开发EDR/AD以支持安全且合法合规的自动驾驶车辆运行。
- 所提出的EDR/AD架构不仅适用于自动驾驶车辆,还可拓展至更广泛的自主机器人与人工智能系统应用,提升其长期适用性。
- 汽车制造商、安全研究人员与零配件供应商之间的协作,是开发安全、符合标准且可市场化EDR/AD原型的关键。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。