A Framework for Privacy Policy Enforcement for Connected Automotive Systems
Anis Bkakria, Lydia Brika · 2023
The GDPR is a set of regulations designed to give users control over their personal data and applies to any connected object that processes such data. One of the most complex environments covered by the GDPR is the connected car, which has brought attention to the sensitive data processed by these vehicles. This data includes information about the driver or owner, the vehicle’s environment, and the vehicle itself. Given the varying sensitivity levels of this data, it is important to offer users control over their data and privacy. To address this, we propose an end-to-end privacy preserving framework that ensures the integrity, confidentiality, and traceability of data related to user privacy within a connected vehicle. This framework combines data tainting for data traceability, lightweight signature for data integrity, and attribute-based encryption for confidentiality and access control to effectively enforce privacy policies set by both vehicle users and manufacturers. This approach is the first to offer end-to-end privacy and confidentiality policy enforcement for connected vehicles, covering data generation by sensors to the Transmission Control Unit.