As How You Drive

I have been discussing Pay As You Drive (PAYD) insurance schemes on this blog for nearly ten years.

The simplest version of the concept varies your insurance premium according to the quantity of driving – Pay As How Much You Drive. But for obvious reasons, insurance companies are also interested in the quality of driving – Pay As How Well You Drive – and several companies now offer a discount for “safe” driving, based on avoiding events such as hard braking, sudden swerves, and speed violations.

Researchers at the University of Washington argue that each driver has a unique style of driving, including steering, acceleration and braking, which they call a “driver fingerprint”. They claim that drivers can be quickly and reliably identified from the braking event stream alone.

Bruce Schneier posted a brief summary of this research on his blog without further comment, but a range of comments were posted by his readers. Some expressed scepticism about the reliability of the algorithm, while others pointed out that driver behaviour varies according to context – people drive differently when they have their children in the car, or when they are driving home from the pub.

“Drunk me drives really differently too. Sober me doesn’t expect trees to get out of the way when I honk.”

Although the algorithm produced by the researchers may not allow for this kind of complexity, there is no reason in principle why a more sophisticated algorithm couldn’t allow for it. I have long argued that JOHN-SOBER and JOHN-DRUNK should be understood as two different identities, with recognizably different patterns of behaviour and risk. (See my post on Identity Differentiation.)

However, the researchers are primarily interested in the opportunities and threats created by the possibility of using the “driver fingerprint” as a reliable identification mechanism.

  • Insurance companies and car rental companies could use “driver fingerprint” data to detect unauthorized drivers.
  • When a driver denies being involved in an incident, “driver fingerprint” data could provide relevant evidence.
  • The police could remotely identify the driver of a vehicle during an incident.
  • “Driver fingerprint” data could be used to enforce safety regulations, such as the maximum number of hours driven by any driver in a given period.

While some of these use cases might be justifiable, the researchers outline various scenarios where this kind of “fingerprinting” would represent an unjustified invasion of privacy, observe how easy it is for a third party to obtain and abuse driver-related data, and call for a permission-based system for controlling data access between multiple devices and applications connected to the CAN bus within a vehicle. (CAN is a low-level protocol, and does not support any security features intrinsically.)


Sources

Miro Enev, Alex Takakuwa, Karl Koscher, and Tadayoshi Kohno, Automobile Driver Fingerprinting Proceedings on Privacy Enhancing Technologies; 2016 (1):34–51

Andy Greenberg, A Car’s Computer Can ‘Fingerprint’ You in Minutes Based on How You Drive (Wired, 25 May 2016)

Bruce Schneier, Identifying People from their Driving Patterns (30 May 2016)

See also John H.L. Hansen, Pinar Boyraz, Kazuya Takeda, Hüseyin Abut, Digital Signal Processing for In-Vehicle Systems and Safety. Springer Science and Business Media, 21 Dec 2011

Wikipedia: CAN bus, Vehicle bus


Related Posts

Identity Differentiation (May 2006)

Pay As You Drive (October 2006) (June 2008) (June 2009)

Evolution Architecture

Caoilte O’Connor is a developer at ITV, the UK’s largest Commercial Terrestrial TV Network. Here’s a short  (~2 min) clip from Domain Service Aggregators: A Structured Approach to Microservice Composition . In this clip he describes how …

Keys to Enterprise Architecture Success

By Stuart Macgregor, CEO, Real IRM Solutions and The Open Group South Africa Avoiding the perils on the way to successful Enterprise Architecture Enterprise architecture (EA) is more relevant today than ever before – considering the accelerating pace of technology … Continue reading

Enterprise Architecture – four meanings

It sounds like a simple question when someone asks – “what is enterprise architecture?”. But if you have been on the responding end of this question, it isn’t always easy to come up with a clear and succinct answer! After 40 or so years, you would think that the answer was simple, but… I’ve found it…

Barriers to Innovation

  Is innovation inevitable? Greger Wikstrand and I have been trading blog posts on innovation since last November. In his latest post, “Credit card fraud and stalled innovation”, Greger discusses the relatively slow pace of innovation in credit card security. Those best placed to increase security neglect it because they don’t own the risk (a […]

Towards a whole-enterprise architecture standard – Worked-example

For a viable enterprise ­architecture [EA], now and into the future, we need frameworks, methods and tools that can support the EA discipline’s needs. This is a follow-on to a six-part series on proposals towards an enterprise-architecture framework and standard for whole-of-enterprise architecture: Introduction

New FREE EA course on Udemy

Free Enterprise Architecture courseMy brand new EA course What is Enterprise Architecture? is now available on Udemy. It’s a simple and straightforward introduction which explains what Enterprise Architecture is. Although it is an introduction to the subject, it includes material that will be useful to anyone involved in Enterprise Architecture. Click here for free enrolment in this course. All you need…

technology knowledge premise

As technology is everywhere, it’s important for everyone to have a basic understanding of technology matters, in the same way people should understand societal, political and financial matters. To understand how the world works, how we fit in, how to instigate or participate in change, or create what’s next.  — me, 6.19.2015 [lifted from my 100Stickmen […]

The Curse of Knowledge

[Originally published in my 100Stickmen Tech musings notebook. Before it was 100Stickmen Tech.] The main cause of incomprehensible prose is the difficulty of imagining what it’s like for someone else not to know what you know. – Steven Pinker, The Sense of Style From The Sense of Style: The Curse of Knowledge: a difficulty in […]