Autonomous / semi-autonomous driving method and apparatus with trusted data collection, retention and / or sharing

By introducing management systems and cloud server data management in autonomous/semi-autonomous vehicles, the concerns of passengers and drivers about data privacy are addressed, reliable data collection and sharing are achieved, and user trust is enhanced.

CN110741323BActive Publication Date: 2025-09-09INTEL CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201780091436.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2017-06-30
Publication Date
2025-09-09
Estimated Expiration
2037-06-30

AI Technical Summary

Technical Problem

In autonomous/semi-autonomous driving systems, passengers’ and drivers’ concerns about data privacy have not been effectively addressed, which has affected the widespread application of autonomous/semi-autonomous vehicles.

Method used

By introducing a management system in autonomous/semi-autonomous vehicles, including a reservation subsystem, an access control subsystem, and a data collection and sharing subsystem, it is ensured that data collection, retention, and sharing comply with the privacy requirements of passengers or drivers, and cloud servers are used for authentication and data management to generate expected passwords to establish trust.

Benefits of technology

It enables the trusted collection, retention and sharing of passenger and driver data in autonomous/semi-autonomous driving systems, enhances data privacy protection, and improves the trust of passengers and drivers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN110741323B_ABST
    Figure CN110741323B_ABST
Patent Text Reader

Abstract

Disclosed herein are apparatuses, methods, and computer-readable media associated with autonomous / semi-autonomous driving. In one embodiment, the apparatus for autonomous / semi-autonomous driving may include a management system for provision in an autonomous / semi-autonomous vehicle. The management system may include a reservation subsystem for receiving a passenger or driver's reservation for an autonomous or semi-autonomous vehicle from a cloud server; and an access control subsystem for controlling access to the autonomous or semi-autonomous vehicle, the access control subsystem including a trust function for gaining the passenger's or driver's trust that their data privacy requirements will be met when the passenger or driver attempts to execute the reservation. Other embodiments may be disclosed or claimed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of autonomous / semi-autonomous driving. In particular, the present disclosure relates to autonomous / semi-autonomous driving devices and methods with trusted data collection, retention, and / or sharing between an autonomous / semi-autonomous vehicle and its passengers / drivers. Background Art

[0002] The background description provided herein is for the purpose of generally presenting the context of the disclosure. Unless otherwise indicated herein, the materials described in this section are not prior art to the claims in this application and are not admitted to be prior art by inclusion in this section.

[0003] The key value proposition of autonomous / semi-autonomous vehicles is to achieve the benefits of a personalized commuting experience as a service without the need for vehicle ownership. For companies to offer this service at an affordable cost, they will likely want to collect a comprehensive amount of data about both passengers and / or drivers for their own use and to sell it to third parties such as insurance companies (e.g., to adjust premium payments to reward good drivers), transportation departments (e.g., to identify driver and passenger route usage for maintenance and infrastructure planning), and vehicle manufacturers (e.g., to identify driver and passenger preferred infotainment features, etc.). The collected data may include location information, points of interest, routes, usage time, etc.

[0004] Because the shared data is sensitive and personal to passengers and drivers, for this model to work, passengers and drivers will likely need assurances about some or all of the following key concerns:

[0005] 1- Is the company collecting my personal data trustworthy?

[0006] 2- What type of data will be captured?

[0007] 3- Who will have access to my data?

[0008] 4-Once I share my data, how long will my data be retained?

[0009] If the above data privacy concerns are not addressed, the “personalized commuting as a service” model using future autonomous / semi-autonomous vehicles will not be groundbreaking, and the transportation industry, the public, and the environment will not be able to fully benefit. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] The embodiments will be readily understood by the following detailed description in conjunction with the accompanying drawings. For ease of description, identical reference numerals are used to indicate identical structural elements. In each of the accompanying drawings, the embodiments are illustrated by way of example and not by way of limitation.

[0011] Figure 1 An overview of an autonomous / semi-autonomous driving system with trusted data collection, retention, and / or sharing is illustrated, according to various embodiments.

[0012] Figure 2 An example operational flow for checking in a passenger / driver is illustrated, according to some embodiments.

[0013] Figure 3 An example interface for a passenger / driver to specify data privacy preferences is illustrated, according to various embodiments.

[0014] Figure 4 An example operational flow for reserving an autonomous / semi-autonomous vehicle is illustrated, according to some embodiments.

[0015] Figure 5 An example operational flow for performing a subscription with trusted receipt collection and / or sharing is illustrated in accordance with some embodiments.

[0016] Figure 6 The diagram illustrates an example apparatus suitable for use as an onboard system of a hosted memory management system, as a cloud server, or as a client device, in accordance with various embodiments.

[0017] Figure 7 An example computer-readable medium having instructions configured to enable an onboard system, a cloud server, or a client device to implement aspects of the present disclosure is illustrated, according to various embodiments. DETAILED DESCRIPTION

[0018] Disclosed herein are apparatuses, methods, and computer-readable media associated with autonomous / semi-autonomous driving. The present disclosure provides methods and apparatuses for autonomous / semi-autonomous driving that establish and empower passengers and drivers with a straightforward way to designate what type of information the vehicle and mobility service provider can capture during a ride, with whom the data can be shared, and for how long the data is allowed to be retained, based on mutual trust.

[0019] In an embodiment, an apparatus for autonomous / semi-autonomous driving may include a management system for provision in an autonomous / semi-autonomous vehicle. The management system may include: a reservation subsystem for receiving a passenger's or driver's reservation for an autonomous or semi-autonomous vehicle from a cloud server; and an access control subsystem for controlling access to the autonomous or semi-autonomous vehicle, the access control subsystem including a trust function for gaining the passenger's or driver's trust that their data privacy requirements will be met when the passenger or driver attempts to execute the reservation.

[0020] In an embodiment, a cloud server may include: a communication subsystem for communicating with a passenger or driver and an autonomous or semi-autonomous vehicle; a reservation subsystem coupled to the communication subsystem for managing reservations of the passenger or driver for the autonomous or semi-autonomous vehicle, wherein the management includes generating and providing a desired password for the passenger or driver for the corresponding reservation for use by the autonomous or semi-autonomous vehicle to establish trust with the passenger or driver regarding the satisfaction of the passenger's or driver's data privacy requirements; and a user management subsystem coupled to the communication subsystem for managing the passenger's or driver's data privacy requirements, wherein the management includes providing the passenger's or driver's data privacy requirements to the corresponding reserved autonomous or semi-autonomous vehicle. The corresponding reserved autonomous or semi-autonomous vehicle uses the provided data privacy requirements to regulate the collection and sharing of data associated with the passenger or driver.

[0021] In an embodiment, a client device for autonomous or semi-autonomous driving may include: a processor; and a reservation client operated by the processor to provide data privacy preferences of a passenger or driver to a cloud server.

[0022] These and other aspects will be further described below. In the following description, reference is made to the accompanying drawings which form a part hereof, wherein like reference numerals throughout the drawings indicate like parts, and wherein illustrative embodiments are shown by way of illustration. It should be understood that other embodiments may be utilized and that structural or logical changes may be made without departing from the scope of this disclosure. Therefore, the following detailed description should not be taken in a limiting sense, and the scope of the embodiments is defined by the appended claims and their equivalents.

[0023] The operations of the various methods may be described sequentially as multiple discrete actions or operations in a manner that is most helpful in understanding the claimed subject matter. However, the order of description should not be interpreted as implying that the operations are necessarily order-dependent. Specifically, the operations may not be performed in the order presented. The described operations may be performed in an order different from that of the described embodiments. In additional embodiments, various additional operations may be performed and / or the described operations may be omitted, split, or combined.

[0024] For purposes of this disclosure, the phrase "A and / or B" means (A), (B), or (A and B). For purposes of this disclosure, the phrase "A, B, and / or C" means (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C). The specification may use the phrases "in an embodiment" or "in multiple embodiments," which may each refer to one or more of the same or different embodiments. Furthermore, the terms "comprising," "including," "having," and the like as used with respect to the embodiments of the present disclosure are synonymous. The terms "motor" and "engine" are synonymous unless the context clearly indicates otherwise.

[0025] As used hereinafter (including in the claims), the term "autonomous / semi-autonomous vehicle" may refer to any of an assisted parking vehicle, an autonomous driving and parking vehicle, or a fully automated navigation / parking vehicle. An assisted parking vehicle may be a current generation vehicle with an advanced driver assistance system (ADAS) with driver assistance functionality (also known as computer-assisted driving). An autonomous driving and parking vehicle may be a current or future generation vehicle with an ADAS that has autonomous driving or self-driving capabilities (i.e., without a human driver), and a fully automated navigation / parking vehicle may be a future generation vehicle with an ADAS that has autonomous driving capabilities in which passengers can be dropped off at a destination and the vehicle can park itself.

[0026] The term "module" may refer to, may be part of, or may include an application specific integrated circuit (ASIC) that executes one or more software or firmware programs having one or more machine instructions (generated from an assembler or from a high-level language compiler), an electronic circuit, a programmable combinatorial logic circuit (such as a field programmable gate array (FPGA)), a processor (shared, dedicated, or group) and / or memory (shared, dedicated, or group), and / or other suitable components that provide the described functionality.

[0027] Now refer to Figure 1 , which illustrates an overview of an autonomous / semi-autonomous driving system with trusted data collection, retention, and / or sharing, according to various embodiments. As shown, the autonomous / semi-autonomous driving system 100 may include one or more autonomous / semi-autonomous vehicles 104 and one or more cloud servers 108 communicatively coupled to each other via a network 106. A passenger (in a fully autonomous embodiment) or a driver 102 (in a semi-autonomous embodiment) may interact with the autonomous / semi-autonomous vehicle(s) 104 and the cloud server(s) 108 via a passenger or driver device 103 (hereinafter also referred to as a client device 103). In embodiments, the passenger or driver 102 may also interact, at least partially, directly with the autonomous / semi-autonomous vehicle(s) 104. In embodiments, the operator(s) of the cloud server(s) 108 may be the provider(s) of the autonomous / semi-autonomous vehicle(s) 104. In other embodiments, the operator(s) of the cloud server(s) 108 and the provider(s) of the autonomous / semi-autonomous vehicle(s) 104 may be different parties.

[0028] The autonomous / semi-autonomous vehicle(s) 104 and the cloud server(s) 108 can be combined with the autonomous / semi-autonomous driving technology of the present disclosure, which includes trusted data collection, retention, and sharing. That is, the autonomous / semi-autonomous vehicle(s) 104 and the cloud server(s) 108 can be combined with the autonomous / semi-autonomous driving technology of the present disclosure, which collects, retains, and / or shares data in accordance with the data privacy requirements of the passengers / drivers 102. Furthermore, the autonomous / semi-autonomous vehicle(s) 104 and the cloud server(s) 108 can be combined with the autonomous / semi-autonomous driving technology of the present disclosure, which enables the passengers / drivers 102 of the autonomous / semi-autonomous vehicle(s) 104 to trust that their data privacy requirements regarding data collection, retention, and sharing will be met / complied with by the autonomous / semi-autonomous vehicle(s) 104 and the cloud server(s) 108.

[0029] In an embodiment, the autonomous / semi-autonomous vehicle 104 may include a management system 112, which may include a reservation subsystem 122, an access control subsystem 124, and a data collection and sharing subsystem 126. The reservation subsystem 122 may be configured to facilitate a passenger / driver 102 (directly or via a client device 103) to make a reservation for an autonomous / semi-autonomous vehicle 104 that hosts the management system 112 (i.e., an autonomous / semi-autonomous vehicle 104 in which the management system 112 is provided onboard). The access control subsystem 124 may be configured to control access to the host autonomous / semi-autonomous vehicle 104. In an embodiment, the access control subsystem 124 may include a trust function configured to gain the passenger or driver 102's trust that the passenger's or driver's data privacy requirements will be met / adhered to when the passenger or driver 102 attempts to make a reservation using the host autonomous / semi-autonomous vehicle 104. The data collection and sharing subsystem 126 may be configured to collect, maintain, and share data associated with a passenger or driver's use of the host autonomous / semi-autonomous vehicle 104 in compliance with the passenger or driver's 102 data privacy requirements.

[0030] In an embodiment, the reservation subsystem 122 may be configured to receive reservations for the passenger / driver 102 to host the autonomous / semi-autonomous vehicle 104 from the cloud server(s) 108. Each reservation may include data related to the destination of the particular reservation, the time of the particular reservation, the pickup location of the particular reservation, the duration of the particular reservation, and / or a reference identifier for the particular reservation.

[0031] In an embodiment, the trust function of the access control subsystem 124 can be configured to generate an expected password in response to a passenger / driver's attempt to make a reservation and provide the expected password to the passenger / driver 102. The expected password can be unique to a particular reservation. Generating and providing the expected password to the passenger / driver 102 demonstrates to the passenger / driver 102 that the autonomous / semi-autonomous vehicle 104 can be trusted to meet or comply with the passenger / driver's 102 data privacy requirements.

[0032] In an embodiment, the reservation subsystem 122 may be further configured to provide the unique signature of the host autonomous / semi-autonomous vehicle 104 to the cloud server(s) 108 when the passenger / driver 102 makes a reservation for the host autonomous / semi-autonomous vehicle 104. The unique signature of the host autonomous / semi-autonomous vehicle 104 may be used by the cloud server(s) 108 when generating an expected password to be provided by the host autonomous / semi-autonomous vehicle 104 when the passenger / driver 102 makes a reservation and providing the expected password to the passenger / driver 102 to prove to the passenger / driver 102 that the autonomous / semi-autonomous vehicle 104 can be trusted to meet the data privacy requirements of the passenger / driver 102.

[0033] In an embodiment, the access control subsystem 124 may be further configured to collect biometric data of the passenger / driver 102 making a reservation for the host autonomous / semi-autonomous vehicle 104 and provide the biometric data to the cloud server(s) 108 to facilitate confirmatory identification of the passenger / driver 102 by the cloud server(s) 108.

[0034] In an embodiment, the data collection and sharing subsystem 126 may be configured to receive a data privacy profile of a passenger / driver 102 who is making a reservation for a host autonomous / semi-autonomous vehicle 104 from the cloud server(s) 108. The data privacy profile may be provided by the cloud server(s) 108 in response to confirming the identity of the passenger / driver 102 based at least in part on the received biometric data of the passenger / driver 102. In an embodiment, the biometric data may include a photograph, fingerprint, voice print, etc. of the passenger / driver 102.

[0035] In an embodiment, the reservation subsystem 122, the access control subsystem 124, and the data collection and sharing subsystem 126 may be implemented in hardware, software, or a combination thereof. Hardware implementations may include application-specific integrated circuits (ASICs), programmable circuits such as field-programmable gate arrays (FPGAs), and the like. For software implementations, the management system 112 may further include a processor having one or more cores, memory, and other associated circuits (not shown), and the reservation subsystem 122, the access control subsystem 124, and / or the data collection and sharing subsystem 126 may be implemented in an assembler language supported by the processor, or any programmable language that can be compiled into machine code executable by the processor.

[0036] In an embodiment, as shown, the autonomous / semi-autonomous vehicle 104 may further include: a communication subsystem 114 for communicating with (multiple) cloud servers 108; and one or more input / output (I / O) devices 116 for facilitating interaction with the passenger / driver 102 directly or via (multiple) client devices 103. The communication subsystem 114 and the I / O devices 116 may be operatively coupled to the management system 112. The communication subsystem 114 may be one or more of a wide range of communication subsystems known in the art, including but not limited to: a WiFi communication subsystem, a 4G / 5G / LTE cellular communication subsystem, a satellite communication subsystem, Communication subsystem, near field communication (NFC) subsystem, etc. The I / O device 116 may include, for example, one or more display screens (e.g., touch-sensitive display screens). The I / O device 116 may further include a camera, a fingerprint reader, or a voice recorder for capturing a photo, fingerprint, or voice print of the passenger / driver 102, respectively.

[0037] In embodiments, autonomous / semi-autonomous vehicle 104 may be equipped with other components (eg, a navigation system, a global positioning system (GPS), etc. (not shown)).

[0038] Continue to refer Figure 1In an embodiment, the cloud server(s) 108 may (collectively) include a reservation subsystem 132, a user management subsystem 134, and a communication subsystem 136, which is communicatively coupled to the reservation subsystem 132 and the user management subsystem 134. The reservation subsystem 132 may be configured to manage reservations for autonomous / semi-autonomous vehicles 104 by passengers / drivers 102. Specifically, the reservation subsystem 132 may be configured to maintain a database (not shown) of autonomous / semi-autonomous vehicles, including types of autonomous / semi-autonomous vehicles (e.g., compact, standard, sport utility, etc.), associated signatures, reservations, availability, usage, maintenance, etc. Furthermore, the reservation subsystem 132 may be configured to generate an expected password (for the cloud server(s) 108 ) to be provided by the reserved autonomous / semi-autonomous vehicle 104 when the passenger / driver 102 makes their reservation and provide the expected password to the passenger / driver 102 , thereby allowing the passenger / driver 102 to trust that their data privacy requirements will be met by the autonomous / semi-autonomous vehicle 104 and the cloud server(s) 108 .

[0039] In an embodiment, the reservation subsystem 132 may also be configured to receive biometric data of the passenger / driver 102 making the reservation for the autonomous / semi-autonomous vehicle 104 to determine the identity of the passenger / driver 102. In an embodiment, the reservation subsystem 132 may be further configured to provide the data privacy profile of the passenger / driver 102 to the autonomous / semi-autonomous vehicle 104 (for use in the cloud server(s) 108) upon confirming the identity of the passenger / driver 102.

[0040] In an embodiment, the user management subsystem 134 may be configured to register the passenger / driver 102. The user management subsystem 134 may facilitate the collection and storage of details related to the passenger / driver 102, such as their name, address, demographics, credit card and / or banking information, photos, fingerprints, voiceprints, etc. The user management subsystem 134 may create, maintain, and terminate accounts for the passenger / driver 102. In an embodiment, the user management subsystem 134 may also be configured to collect data privacy requirements of the passenger / driver 102 and maintain a data privacy profile based on the collected data privacy requirements. In an embodiment, the user management subsystem 134 may also be configured to collect, maintain, and / or share data related to the vehicle usage of the passenger / driver 102.

[0041] In embodiments, data privacy requirements may include whether certain data associated with the passenger / driver 102 may be collected, accessed, and / or shared. Examples of such data may include, but are not limited to, demographic data, in-cabin visual data, in-cabin audio data, location and route data, in-cabin infotainment usage data, and / or in-cabin comfort preferences. Examples of access that may or may not be allowed may include, but are not limited to, access by the service provider(s) of the autonomous / semi-autonomous vehicle 104. Examples of sharing that may or may not be allowed may include, but are not limited to, sharing with vehicle manufacturers, transportation departments, academic institutions, research institutions, and the like. In embodiments, data privacy requirements may further include a validity period for the collection, access, and / or sharing authorization, i.e., the duration for which the collected data may be maintained and made available. (See also Figure 3 , to be further described.)

[0042] In an embodiment, the communication subsystem 136 may be configured to facilitate communications with the autonomous / semi-autonomous vehicle 104 and the client device(s) 103. Similar to the communication subsystem 114, the communication subsystem 136 may be one or more of a wide range of communication subsystems known in the art, including but not limited to: a WiFi communication subsystem, a 4G / 5G / LTE cellular communication subsystem, a satellite communication subsystem, and the like.

[0043] In an embodiment, each cloud server 108 may further include a processor having one or more cores, a memory, and other associated circuitry (e.g., a hardware accelerator) (not shown), and the reservation subsystem 132 and the user management subsystem 126 may be implemented in software with or without hardware acceleration. More specifically, the reservation subsystem 132 and the user management subsystem 126 may be implemented in an assembler language supported by the processor, or any programmable language that can be compiled into machine code executable by the processor, and / or a bitstream for programming the hardware accelerator (if employed). Examples of hardware accelerators may include, but are not limited to, FPGAs.

[0044] In an embodiment, the subscription subsystem 132 and the user management subsystem 134 may be provided from (a cluster of) public cloud servers 108 operated by a common operator. In alternative embodiments, the subscription subsystem 132 and the user management subsystem 134, or even portions of the functionality, may be provided from (clusters of) different cloud servers 108 operated by different operators.

[0045] Still refer to Figure 1In an embodiment, each client device 103 may include a subscription client 142. In some embodiments, such as where the client device 103 is a computing tablet, laptop, or desktop computer having a processor with one or more cores, memory, and associated circuitry (not shown), the subscription client 142 may be a general-purpose agent such as a browser. In other embodiments, such as where the client device 103 is a wearable device or smartphone also having a processor with one or more cores, memory, and associated circuitry (not shown), the subscription client 142 may be a downloaded application.

[0046] In an embodiment, the network 106 may be any of several public / private, wired / wireless, LAN and / or WAN networks known in the art, including the Internet, having several routers, switches, gateways, base stations, etc. coupled to each other.

[0047] Now refer to Figure 2 , which illustrates an example operational flow for registering a passenger / driver according to some embodiments. As shown, process 200 for registering a passenger / driver may include operations 202 through 218. The operations may be performed, for example, by client device 103 (specifically, reservation client 142) and cloud server(s) 108 (specifically, user management subsystem 134). In alternative embodiments, some of the operations may be combined, decomposed, or performed in a different order.

[0048] Process 200 may begin at 202. At 202, a request to create a user account and register the passenger / driver may be submitted from a client device 103 of a passenger / driver 102 to a cloud server(s) 108. The request may include various data of the passenger / driver 102, such as name, home or business address, email address, phone number, credit card or bank account information, etc. The request may be sent from the client device 103 to the cloud server(s) 108 in one or more messages. Upon receiving the various data of the passenger / driver 102, at 204, the cloud server(s) 108 may create a user account and store the user information.

[0049] When the account is created, other users (e.g., family members or coworkers) may optionally be added to the account as additional passengers / drivers at 206. At 208, upon receiving information about the additional users (passengers / drivers), the user account may be updated by the cloud server(s) 108.

[0050] Similarly, when creating an account, data collection, retention, and sharing preferences may be specified for the primary user (passenger / driver) at 210. Upon receiving the primary user's (passenger / driver) data collection, retention, and sharing preferences at 212, the user account may be updated by the cloud server(s) 108 with the stored provided preferences.

[0051] Likewise, when creating an account, data collection, retention, and sharing preferences may be specified for other users (passengers / drivers) of the account at 214. Upon receiving the data collection, retention, and sharing preferences of the other users (passengers / drivers) of the account at 216, the user account may be updated by the cloud server(s) 108 with the stored provided preferences.

[0052] Finally, at 218 , the passenger / driver may log out and terminate the check-in session.

[0053] Now refer to Figure 3 , which illustrates an example interface for a passenger / driver to specify data privacy preferences according to various embodiments. As shown, the example interface 300 for specifying passenger / driver data privacy preferences may include three screen instances 302-306. Screen instance 302 may allow the passenger / driver to specify whether to share (anonymous) demographic data associated with the passenger / driver, in-cabin visual data, in-cabin audio data, location and route data, in-cabin infotainment usage data, in-cabin comfort preference data, and the like. Screen instance 304 may allow the passenger / driver to specify whether the service provider of the autonomous / semi-autonomous vehicle 104, the vehicle manufacturer, transportation authorities, academic institutions, and the like may have authorization to access the collected information—in other words, whether the collected data may be shared with these entities. Screen instance 306 may allow the passenger / driver to specify the duration of access to the collected data (e.g., only during the ride, one month, three months, indefinitely (until authorization is revoked), or for a specific date range), in other words, the duration for which the collected data may be retained (and therefore, shared).

[0054] Now refer to Figure 4 , which illustrates an example operational flow for reserving an autonomous / semi-autonomous vehicle according to some embodiments. As shown, process 400 for reserving an autonomous / semi-autonomous vehicle may include operations 402-422. For example, the operations may be performed by autonomous / semi-autonomous vehicle 104 (specifically, management system 112), client device 103 (specifically, reservation client 142), and cloud server(s) 108 (specifically, reservation subsystem 132). In alternative embodiments, some of the operations may be combined, decomposed, or performed in a different order.

[0055] Process 400 may begin at 402. At 402, a request for an autonomous / semi-autonomous vehicle may be submitted from a client device 103 to cloud server(s) 108. In embodiments, the request may include a destination, a date / time when the vehicle is needed, a pickup location, and the like.

[0056] At 404, the availability of autonomous / semi-autonomous vehicles that can satisfy the request can be checked by the cloud server(s) 108. At 406, upon identifying an available autonomous / semi-autonomous vehicle 104 suitable for satisfying the request, a request for a unique signature of the autonomous / semi-autonomous vehicle 104 can be sent from the cloud server(s) 108 to the autonomous / semi-autonomous vehicle 104. In an embodiment, the unique signature of the autonomous / semi-autonomous vehicle 104 can be a unique firmware signature.

[0057] At 408, upon receiving the request, the unique signature may be retrieved or generated by the autonomous / semi-autonomous vehicle 104. In an embodiment, the unique firmware signature is generated securely. At 410, upon retrieval or generation, the unique signature may be sent by the autonomous / semi-autonomous vehicle 104 to the cloud server(s) 108.

[0058] At 412, upon receiving the unique signature from the autonomous / semi-autonomous vehicle 104, the cloud server(s) 108 may verify the unique signature. At 414, upon verification of the received signature, the reservation may be transmitted by the cloud server(s) 108 to the autonomous / semi-autonomous vehicle 104. The reservation may include data such as the destination, the pick-up time and location, a reservation / booking reference, and the like.

[0059] At 416, upon receiving the reservation, the autonomous / semi-autonomous vehicle 104 may store the received reservation. In an embodiment, the autonomous / semi-autonomous vehicle 104 (equipped with a navigation system) may also pre-plan a route from the pickup location to the destination. At 418, the autonomous / semi-autonomous vehicle 104 may acknowledge (confirm) the acceptance of the reservation allocation.

[0060] At 420, the cloud server(s) 108 may generate an expected password for the autonomous / semi-autonomous vehicle 104 to prove to the passenger / driver 102 its trustworthiness regarding compliance with the passenger / driver's 102 data privacy requirements. The expected password may be generated in any of several challenge-response authentication mechanisms (CRAMs), such as Challenge-Handshake Authentication Protocol (CHAP), Extensible Authentication Protocol with Pre-Shared Keys (EAP-PSK), and the like. In an embodiment, the expected password is generated based at least in part on a unique signature and subscription of the autonomous / semi-autonomous vehicle 104. At 422, the expected password may be provided to the client device 103 by the cloud server(s) 108.

[0061] Now refer to Figure 5 , which illustrates an example operational flow for performing a reservation with trusted receipt collection, retention, and / or sharing according to some embodiments. For example, operations may be performed by client device 103 (specifically, reservation client 142), cloud server 108 (specifically, user management subsystem 134), and autonomous / semi-autonomous vehicle 104 (specifically, access control subsystem 124). In alternative embodiments, some of the operations may be combined, decomposed, or performed in a different order.

[0062] Process 500 may begin at 502. At 502, a request for access may be provided to an autonomous / semi-autonomous vehicle 104. The request may be provided to the autonomous / semi-autonomous vehicle 104 from a client device 103 or directly to the autonomous / semi-autonomous vehicle 104 if a passenger / driver 102 interacts with an I / O device 116 of the autonomous / semi-autonomous vehicle 104.

[0063] At 504, in response to the request for access, the autonomous / semi-autonomous vehicle 104 (e.g., the trust function of the access control subsystem 123) may generate a password desired by the passenger / driver 102 to demonstrate that the autonomous / semi-autonomous vehicle 104 can be trusted to comply with the data privacy requirements of the passenger / driver 102. In an embodiment, the trust function of the access control subsystem 123 may be configured with password generation logic that is complementary to the password generation logic of the cloud server 108.

[0064] At 506, the generated expected passcode may be provided to the passenger / driver 102. In an embodiment, the generated expected passcode may be transmitted to and displayed on the client device 103. In other embodiments, the generated expected passcode may be displayed on the I / O device 116 of the autonomous / semi-autonomous vehicle 104.

[0065] At 508, the passenger / driver may determine whether the autonomous / semi-autonomous vehicle 104 provided the correct passcode to demonstrate its trustworthiness. At 510, confirmation of the passenger / driver's trustworthiness may be provided to the autonomous / semi-autonomous vehicle 104. In some embodiments, the autonomous / semi-autonomous vehicle 104 may provide a confirmation request along with the generated expected passcode. For these embodiments, the confirmation may be provided in the form of a requested confirmation.

[0066] Next, at 512, biometric data (such as a photo, fingerprint, voiceprint, etc.) of the passenger / driver 102 may be collected by a corresponding camera, fingerprint reader, or voice recorder of the autonomous / semi-autonomous vehicle 104. At 514, the collected biometric data and the reservation / booking reference may be sent from the autonomous / semi-autonomous vehicle 104 to the cloud server(s) 108.

[0067] At 516, upon receiving the biometric data, the cloud server(s) 108 (e.g., the user management subsystem 134) may access its passenger / driver database to confirm the identity of the passenger / driver and confirm that the person is indeed a registered passenger / driver. Upon confirming the identity of the passenger / driver (and optionally, their current registration status), the data privacy profile of the passenger / driver 102 may be retrieved. At 518, an acknowledgment message and the data privacy profile of the passenger / driver 102 may be provided (sent) from the cloud server(s) 108 to the autonomous / semi-autonomous vehicle 104.

[0068] At 520, upon receiving the data privacy profile of the passenger / driver 102, the autonomous / semi-autonomous vehicle 104 may configure itself (e.g., the data collection and sharing subsystem 126) accordingly to ensure that it operates in a manner that complies with the data privacy requirements specified in the data privacy profile of the passenger / driver 102. Additionally, at 522, the passenger / driver 102 may be granted access to the autonomous / semi-autonomous vehicle 104. Furthermore, in an embodiment, a generic or personalized greeting may be generated or output for welcoming the passenger / driver 102.

[0069] Now refer to Figure 6 , which illustrates a block diagram of a computer system suitable for use as an onboard system for a main memory management system, as a cloud server, or as a client device to implement the present disclosure, according to various embodiments. As shown, computer device 600 may include one or more processors 602 and system memory 604. Each processor 602 may include one or more processor cores. System memory 604 may include any known volatile or non-volatile memory.

[0070] In addition, the computer device 600 may include (multiple) mass storage devices 606 (such as solid-state drives), input / output device interfaces 608 (for interfacing with various input / output devices, such as a mouse, cursor control, display devices (including touch-sensitive screens), etc.), and communication interfaces 610 (such as a network interface card, a modem, etc.). In embodiments, the communication interface 610 may support wired or wireless communications, including near-field communications. These elements may be coupled to each other via a system bus 612, which may represent one or more buses. In the case of multiple buses, they may be bridged by one or more bus bridges (not shown).

[0071] Each of these elements can perform its conventional functions as known in the art. Specifically, if the computer system 600 is used to implement an onboard system for an autonomous / semi-autonomous vehicle 104, the system memory 604 and the mass storage device(s) 606 can be used to store a working copy and a permanent copy of the executable code of the programming instructions for the management system 112 (including the reservation subsystem 122, the access control subsystem 124, and the data collection and sharing subsystem 126); or if the computer system 600 is used as a cloud server 108, the system memory 604 and the mass storage device(s) 606 can be used to store a working copy and a permanent copy of the executable code of the programming instructions for the reservation subsystem 132 and the user management subsystem 134. In other embodiments, if the computer system 600 is used as a client device 103, the system memory 604 and the mass storage device(s) 606 can be used to store a working copy and a permanent copy of the executable code of the programming instructions for the reservation client 142. The programming instructions may include assembler instructions supported by processor(s) 602 or a high-level language (such as, for example, C) that can be compiled into such instructions.

[0072] A permanent copy of the executable code of the programming instructions may be placed into permanent mass storage device(s) 606 in the factory or in the field via, for example, a distribution medium (not shown) such as a compact disk (CD), or via communications interface 610 from a distributed server (not shown).

[0073] The number, capabilities, and / or capacity of these elements 610-612 may vary depending on the intended use of the example computer device 600, such as whether the example computer device 600 is used as an onboard system of an autonomous / semi-autonomous vehicle 104, as a cloud server 108, or as a client device 103. Otherwise, the composition of these elements 510-512 is known and accordingly will not be described further.

[0074] Figure 7The diagram illustrates an example non-transitory computer-readable medium having instructions configured to implement all or selected ones of the previously described operations associated with the management system 112 (including the reservation subsystem 122, access control subsystem 124, and data collection and sharing subsystem 126) of the autonomous / semi-autonomous vehicle 104, the reservation subsystem 132 and user management subsystem 134 of the cloud server(s) 108, or the reservation client 142 of the client device 103, according to various embodiments. As shown, the non-transitory computer-readable medium 702 may include a plurality of programming instructions 704. The programming instructions 704 may be configured to enable a device (e.g., an onboard system in the vehicle 104, the cloud server 108, or the client device 103) to perform the various operations previously described in response to execution of the programming instructions. In alternative embodiments, the programming instructions 704 may alternatively be provided on a plurality of non-transitory computer-readable storage media 702. In still other embodiments, the programming instructions 704 may be encoded in a transitory computer-readable signal.

[0075] Also refer to Figure 6 For some embodiments, the processor 602 may be packaged with a computer-readable medium having programming instructions 704 configured to implement all or selected aspects of the beverage dispensing-related operations previously described. For one embodiment, the processor 602 may be packaged with the computer-readable medium having programming instructions 704 to form a system-in-package (SiP). For one embodiment, the processor 602 may be integrated with the computer-readable medium having programming instructions 704 on the same die. For one embodiment, the processor 602 may be packaged with the computer-readable medium having programming instructions 704 to form a system-on-chip (SoC).

[0076] Thus, apparatus, methods, and computer-readable media associated with autonomous / semi-autonomous driving with trusted data collection, retention, and / or sharing have been described. While the trusted data collection, retention, and / or sharing techniques for autonomous / semi-autonomous driving have been described for ease of understanding, the techniques may also be implemented using a conventional, non-autonomous, manual vehicle equipped with the described onboard systems.

[0077] Example 1 may be an apparatus for autonomous or semi-autonomous driving, comprising: a management system for being set in an autonomous or semi-autonomous vehicle, wherein the management system may include: a reservation subsystem for receiving a passenger or driver's reservation for the autonomous or semi-autonomous vehicle from a cloud server; and an access control subsystem for controlling access to the autonomous or semi-autonomous vehicle, the access control subsystem including a trust function for obtaining the passenger's or driver's trust that the passenger's or driver's data privacy requirements will be met when the passenger or driver attempts to execute the reservation.

[0078] Example 2 may be example 1, wherein the received reservation may include data about the destination, reservation time, and reservation reference.

[0079] Example 3 may be Example 1, wherein the reservation subsystem may further generate and provide a signature of the autonomous or semi-autonomous vehicle and provide the signature to the cloud server in response to a request from the cloud server before receiving the reservation.

[0080] Example 4 may be example 1, wherein the trust function may generate and provide the expected password to the passenger or driver in response to the passenger or driver attempting to perform a reservation.

[0081] Example 5 may be example 4, wherein the trust function may generate the expected cryptogram based at least in part on a reservation time and a unique signature of the autonomous or semi-autonomous vehicle.

[0082] Example 6 may be any one of Examples 1-5, wherein the access control subsystem may further obtain biometric data of the passenger or driver and provide the biometric data of the passenger or driver to the cloud server.

[0083] Example 7 may be example 6, wherein the biometric data of the passenger or driver may include a photograph, fingerprint, or voiceprint of the passenger or driver.

[0084] Example 8 can be Example 6, wherein the access control subsystem may also receive a data privacy profile of the passenger or driver from the cloud server in response to providing the biometric data of the passenger or driver when the provided biometric data matches the biometric data of the passenger or driver known to the cloud server.

[0085] Example 9 may be Example 8, wherein the management system may further include a data collection and sharing subsystem for collecting and sharing data related to the passenger or driver and the passenger or driver's use of the autonomous or semi-autonomous vehicle based at least in part on the passenger's or driver's data privacy profile provided by the cloud server.

[0086] Example 10 may be Example 8, wherein the data privacy profile may include one or more specifications indicating whether collection or sharing of demographic data associated with a passenger / driver, in-cabin visual data, in-cabin audio data, location and route data, in-cabin infotainment usage data, or in-cabin comfort preference data is permitted.

[0087] Example 11 may be example 8, wherein the data privacy profile may include one or more specifications indicating whether to allow sharing of collected data associated with a passenger or driver with a service provider of an autonomous or non-autonomous vehicle, a vehicle manufacturer, a transportation department, or an academic institution.

[0088] Example 12 may be a method for autonomous or semi-autonomous driving, comprising: receiving, by an autonomous or semi-autonomous vehicle, a reservation for the autonomous or semi-autonomous vehicle by a passenger or driver from a cloud server; and controlling, by the autonomous or semi-autonomous vehicle, access to the autonomous or semi-autonomous vehicle, the control comprising: obtaining trust from the passenger or driver that the passenger's or driver's data privacy requirements will be met when the passenger or driver attempts to execute the reservation.

[0089] Example 13 may be example 12, further comprising: in response to the passenger or driver attempting to perform the reservation, generating, by the autonomous or semi-autonomous vehicle, an expected code and providing the expected code to the passenger or driver.

[0090] Example 14 may be example 13, wherein generating the expected password may include generating the expected password based at least in part on a reservation time and a unique signature of the autonomous or semi-autonomous vehicle.

[0091] Example 15 can be any of Examples 12-14, further comprising: obtaining biometric data of a passenger or driver by the autonomous or semi-autonomous vehicle; and providing the biometric data of the passenger or driver to a cloud server.

[0092] Example 16 can be example 15, further including: receiving, by the autonomous or semi-autonomous vehicle, a data privacy profile of the passenger or driver from the cloud server in response to providing the biometric data of the passenger or driver, when the provided biometric data matches the biometric data of the passenger or driver known to the cloud server.

[0093] Example 17 may be Example 15, further including: collecting, maintaining, or sharing, by the autonomous or semi-autonomous vehicle, data related to the passenger or driver and the passenger or driver's use of the autonomous or semi-autonomous vehicle based at least in part on the passenger's or driver's data privacy profile provided by the cloud server.

[0094] Example 18 may be one or more computer-readable storage media (CRMs) comprising a plurality of instructions that, in response to execution of the instructions by a processor of a device for autonomous or semi-autonomous driving provided in an autonomous or semi-autonomous vehicle, cause the operations management system to: receive a passenger or driver's reservation for an autonomous or semi-autonomous vehicle from a cloud server; and control access to the autonomous or semi-autonomous vehicle, the control including: obtaining the passenger's or driver's trust that the passenger's or driver's data privacy requirements will be met when the passenger or driver attempts to execute the reservation.

[0095] Example 19 may be example 18, wherein the device may be further caused to generate and provide the expected password to the passenger or driver in response to the passenger or driver attempting to perform the reservation.

[0096] Example 20 may be example 19, wherein the apparatus is caused to generate the expected password based at least in part on a reservation time and a unique signature of the autonomous or semi-autonomous vehicle.

[0097] Example 21 can be any of Examples 18-20, wherein the device is caused to obtain biometric data of the passenger or driver and provide the biometric data of the passenger or driver to the cloud server.

[0098] Example 22 may be Example 21, wherein the apparatus may be further configured to receive a data privacy profile of the passenger or driver from the cloud server in response to providing the biometric data of the passenger or driver when the provided biometric data matches the biometric data of the passenger or driver known to the cloud server.

[0099] Example 23 may be example 22, wherein the device may be further enabled to collect, maintain, or share data related to the passenger or driver and the passenger or driver's use of the autonomous or semi-autonomous vehicle based at least in part on a data privacy profile of the passenger or driver provided by a cloud server.

[0100] Example 24 may be an apparatus for autonomous or semi-autonomous driving, comprising: a management system for being set in an autonomous or semi-autonomous vehicle, wherein the management system may include: a reservation device for receiving a passenger or driver's reservation for the autonomous or semi-autonomous vehicle from a cloud server, and an access control device for controlling access to the autonomous or semi-autonomous vehicle, the access control device including a trust device for obtaining the passenger's or driver's trust that the passenger's or driver's data privacy requirements will be met when the passenger or driver attempts to execute the reservation.

[0101] Example 25 may be example 24, wherein the trusted device may include means for generating and providing the expected password to the passenger or driver in response to the passenger or driver attempting to perform the reservation.

[0102] Example 26 may be example 25, wherein the trusted device may include means for generating the expected cryptogram based at least in part on a reservation time and a unique signature of the autonomous or semi-autonomous vehicle.

[0103] Example 27 may be any of Examples 24-26, wherein the access control device may include a device for obtaining biometric data of the passenger or driver and providing the biometric data of the passenger or driver to the cloud server.

[0104] Example 28 can be Example 27, wherein the access control device may further include a device for receiving a data privacy profile of the passenger or driver from the cloud server in response to providing the biometric data of the passenger or driver when the provided biometric data matches the biometric data of the passenger or driver known to the cloud server.

[0105] Example 29 may be Example 28, wherein the management system may further include a data collection and sharing device for collecting and sharing data related to the passenger or driver and the passenger or driver's use of the autonomous or semi-autonomous vehicle based at least in part on the passenger's or driver's data privacy profile provided by the cloud server.

[0106] Example 30 may be a server device for autonomous or semi-autonomous driving, comprising: a communication subsystem for communicating with a passenger or driver and an autonomous or semi-autonomous vehicle; a reservation subsystem coupled to the communication subsystem for managing reservations of passengers or drivers for autonomous or semi-autonomous vehicles, the management of which may include: generating and presetting an expected password for the passenger or driver for the corresponding reservation for use by the autonomous or semi-autonomous vehicle to establish trust with the passenger or driver about meeting the data privacy requirements of the passenger or driver; and a user management subsystem for managing the data privacy requirements of the passenger or driver, the management of which may include: providing the data privacy requirements of the passenger or driver to the corresponding reserved autonomous or semi-autonomous vehicle; wherein the corresponding reserved autonomous or semi-autonomous vehicle uses the provided data privacy requirements to regulate the collection, retention or sharing of data associated with the passenger or driver.

[0107] Example 31 may be example 30, wherein the reservation subsystem may generate an expected password for the passenger or driver's reservation based at least in part on a unique signature of the autonomous or semi-autonomous vehicle being reserved.

[0108] Example 32 may be example 30, wherein the user management subsystem may, in response to receiving biometric data of a passenger or driver from an autonomous or semi-autonomous vehicle, provide a data privacy profile of the passenger or driver having the data privacy requirements of the passenger or driver to the autonomous or semi-autonomous vehicle reserved for the passenger or driver.

[0109] Example 33 may be any of Examples 30-32, wherein the user management subsystem may further register the passenger or driver and receive the data privacy preferences of the passenger or driver.

[0110] Example 34 may be a method for autonomous or semi-autonomous driving, comprising: managing, by a cloud server, reservations for autonomous or semi-autonomous vehicles by a passenger or driver, the management may include: generating and providing an expected password for the passenger or driver for the corresponding reservation for use by the autonomous or semi-autonomous vehicle to establish trust with the passenger or driver regarding meeting the passenger's or driver's data privacy requirements; and managing, by the cloud server, the passenger's or driver's data privacy requirements, the management may include: providing the passenger's or driver's data privacy requirements to the corresponding reserved autonomous or semi-autonomous vehicle; wherein the corresponding reserved autonomous or semi-autonomous vehicle uses the provided data privacy requirements to regulate the collection, retention, or sharing of data associated with the passenger or driver.

[0111] Example 35 may be example 34, wherein an expected password is generated for the passenger or driver's reservation based at least in part on a unique signature of the autonomous or semi-autonomous vehicle being reserved.

[0112] Example 36 may be example 34, further comprising: providing, by the cloud server, in response to receiving biometric data of a passenger or driver from the autonomous or semi-autonomous vehicle, a data privacy profile of the passenger or driver having the data privacy requirements of the passenger or driver to the autonomous or semi-autonomous vehicle reserved for the passenger or driver.

[0113] Example 37 may be any of Examples 34-36, further comprising: registering a passenger or driver, and receiving data privacy preferences of the passenger or driver.

[0114] Example 38 may be one or more computer-readable storage media (CRMs) comprising a plurality of instructions that, in response to execution of the instructions by a processor of a device, cause a cloud server for autonomous or semi-autonomous driving to: manage reservations for autonomous or semi-autonomous vehicles by passengers or drivers, the management of which may include: generating and providing an expected password for the passenger or driver for the corresponding reservation for use by the autonomous or semi-autonomous vehicle to establish trust with the passenger or driver about satisfying the data privacy requirements of the passenger or driver; and managing the data privacy requirements of the passenger or driver, the management of which may include: providing the data privacy requirements of the passenger or driver to the corresponding reserved autonomous or semi-autonomous vehicle; wherein the corresponding reserved autonomous or semi-autonomous vehicle uses the provided data privacy requirements to regulate the collection, retention, or sharing of data associated with the passenger or driver.

[0115] Example 39 may be example 38, wherein the cloud server is caused to generate an expected password for the passenger or driver's reservation based at least in part on a unique signature of the autonomous or semi-autonomous vehicle being reserved.

[0116] Example 40 may be example 38, wherein the cloud server is caused to provide a data privacy profile of the passenger or driver having the data privacy requirements of the passenger or driver to the autonomous or semi-autonomous vehicle reserved for the passenger or driver in response to receiving biometric data of the passenger or driver from the autonomous or semi-autonomous vehicle.

[0117] Example 41 may be any of Examples 38-40, wherein the cloud server may be further caused to register the passenger or driver and receive the data privacy preferences of the passenger or driver.

[0118] Example 42 may be an example apparatus for autonomous or semi-autonomous driving, comprising: a device for managing reservations for a passenger or driver for an autonomous or semi-autonomous vehicle, which may include a device for generating and providing an expected password for the passenger or driver for the corresponding reservation for use by the autonomous or semi-autonomous vehicle thereby establishing trust with the passenger or driver that the passenger's or driver's data privacy requirements are met; and a device for managing the passenger's or driver's data privacy requirements, which may include a device for providing the passenger's or driver's data privacy requirements to the corresponding reserved autonomous or semi-autonomous vehicle; wherein the corresponding reserved autonomous or semi-autonomous vehicle uses the provided data privacy requirements to regulate the collection, retention, or sharing of data associated with the passenger or driver.

[0119] Example 43 may be example 42, wherein the means for generating may include means for generating an expected cryptogram for the passenger or driver's reservation based at least in part on a unique signature of the autonomous or semi-autonomous vehicle being reserved.

[0120] Example 44 may be example 42, further comprising means for providing a data privacy profile of the passenger or driver having the data privacy requirements of the passenger or driver to an autonomous or semi-autonomous vehicle reserved for the passenger or driver in response to receiving biometric data of the passenger or driver from the autonomous or semi-autonomous vehicle.

[0121] Example 45 can be any of Examples 42-44, further comprising means for registering a passenger or driver, and means for receiving data privacy preferences of the passenger or driver.

[0122] Example 46 may be an example apparatus for autonomous or semi-autonomous driving, comprising: a processor; and a reservation client operated by the processor for providing data privacy preferences of a passenger or driver to a cloud server; wherein the cloud server, in response to biometric data of the passenger or driver provided by the autonomous or semi-autonomous vehicle, provides the data privacy preferences to the autonomous or semi-autonomous vehicle upon confirming the identity of the passenger or driver; wherein when the passenger or driver makes a reservation for the autonomous or semi-autonomous vehicle, the biometric data of the passenger or driver is provided to the cloud server by the autonomous or semi-autonomous vehicle in response to the passenger or driver attempting to obtain access to the autonomous or semi-autonomous vehicle; wherein the autonomous or semi-autonomous vehicle collects, maintains, or shares data associated with the passenger or driver in accordance with the data privacy preferences.

[0123] Example 47 may be example 46, wherein the reservation client may be further operated by the processor to contact the cloud server to reserve an autonomous or semi-autonomous vehicle for the passenger or driver; and wherein the reservation client may receive an expected password from the cloud server for the autonomous or semi-autonomous vehicle to gain trust from the passenger or driver that the data privacy preferences of the passenger or driver will be complied with; wherein the autonomous or semi-autonomous vehicle may also provide the same password to the passenger or driver when the passenger or driver attempts to access the autonomous or semi-autonomous vehicle when making the reservation.

[0124] Example 48 may be a method for autonomous or semi-autonomous driving, comprising: a reservation agent operated by a processor of a client device providing data privacy preferences of a passenger or driver to a cloud server; and the reservation agent, in conjunction with the cloud server, reserving an autonomous or semi-autonomous vehicle for the passenger or driver; wherein, in response to biometric data of the passenger or driver provided by the autonomous or semi-autonomous vehicle, the cloud server provides the data privacy preferences to the autonomous or semi-autonomous vehicle upon confirming the identity of the passenger or driver; wherein, when the passenger or driver performs a reservation for the autonomous or semi-autonomous vehicle, in response to the passenger or driver attempting to gain access to the autonomous or semi-autonomous vehicle, the autonomous or semi-autonomous vehicle provides the biometric data of the passenger or driver to the cloud server; wherein the autonomous or semi-autonomous vehicle collects, maintains, or shares data associated with the passenger or driver in accordance with the data privacy preferences.

[0125] Example 49 may be example 48, further comprising: receiving, by the reservation agent, an expected password from the cloud server for the autonomous or semi-autonomous vehicle to gain trust from the passenger or driver that the passenger's or driver's data privacy preferences will be complied with; wherein the autonomous or semi-autonomous vehicle may also provide the same password to the passenger or driver when the passenger or driver attempts to access the autonomous or semi-autonomous vehicle when executing the reservation.

[0126] Example 50 may be one or more computer-readable media (CRM) having a plurality of instructions that, in response to execution of the instructions by a client device, cause the client device to implement a reservation client to provide a passenger's or driver's data privacy preferences to a cloud server; wherein, in response to biometric data of the passenger or driver provided by the autonomous or semi-autonomous vehicle, upon confirming the identity of the passenger or driver, the cloud server provides the data privacy preferences to the autonomous or semi-autonomous vehicle; wherein, when the passenger or driver makes a reservation for the autonomous or semi-autonomous vehicle, in response to the passenger or driver attempting to gain access to the autonomous or semi-autonomous vehicle, the biometric data of the passenger or driver is provided to the cloud server by the autonomous or semi-autonomous vehicle; wherein the autonomous or semi-autonomous vehicle collects, maintains, or shares data associated with the passenger or driver in accordance with the data privacy preferences.

[0127] Example 51 may be example 50, wherein the reservation client may further contact the cloud server to reserve an autonomous or semi-autonomous vehicle for the passenger or driver; and wherein the reservation client may receive an expected password from the cloud server for the autonomous or semi-autonomous vehicle to gain trust from the passenger or driver that the data privacy preferences of the passenger or driver will be complied with; wherein the autonomous or semi-autonomous vehicle may also provide the same password to the passenger or driver when the passenger or driver attempts to access the autonomous or semi-autonomous vehicle when making the reservation.

[0128] Example 52 may be an apparatus for autonomous or semi-autonomous driving, comprising: a device for providing data privacy preferences of a passenger or driver to a cloud server; and a device for reserving an autonomous or semi-autonomous vehicle for the passenger or driver in conjunction with the cloud server; wherein, in response to biometric data of the passenger or driver provided by the autonomous or semi-autonomous vehicle, upon confirming the identity of the passenger or driver, the cloud server provides the data privacy preferences to the autonomous or semi-autonomous vehicle; wherein when the passenger or driver performs a reservation for the autonomous or semi-autonomous vehicle, in response to the passenger or driver attempting to gain access to the autonomous or semi-autonomous vehicle, the biometric data of the passenger or driver is provided to the cloud server by the autonomous or semi-autonomous vehicle; wherein the autonomous or semi-autonomous vehicle collects, maintains, or shares data associated with the passenger or driver in accordance with the data privacy preferences.

[0129] Example 53 may be example 52, further comprising means for receiving an expected passcode from a cloud server for the autonomous or semi-autonomous vehicle to gain the passenger's or driver's trust that the passenger's or driver's data privacy preferences will be complied with; wherein the autonomous or semi-autonomous vehicle may also provide the same passcode to the passenger or driver when the passenger or driver attempts to access the autonomous or semi-autonomous vehicle when making a reservation.

[0130] Although certain embodiments have been illustrated and described for purposes of illustration, a wide variety of alternative and / or equivalent embodiments or implementations calculated to achieve the same purpose may be substituted for the embodiments shown and described without departing from the scope of the present disclosure. This application is intended to cover any modifications or variations of the embodiments discussed herein. It is expressly intended, therefore, that the embodiments described herein be limited solely by the claims.

[0131] Where the disclosure recites "a" or "first" element or its equivalent, such disclosure includes one or more such elements, and neither requires nor excludes two or more such elements. Furthermore, the ordinal indicators (e.g., first, second, or third) of identified elements are used to distinguish between elements and do not indicate or imply a required or limited number of such elements, nor do they indicate a specific position or order of such elements, unless specifically stated otherwise.

Claims

1. A device for autonomous or semi-autonomous driving, comprising: A management system for use in an autonomous or semi-autonomous vehicle, wherein the management system comprises: a reservation subsystem for receiving a passenger or driver's reservation for the autonomous or semi-autonomous vehicle from a cloud server, and an access control subsystem for controlling access to the autonomous or semi-autonomous vehicle, the access control subsystem including a trust function for gaining trust from the passenger or driver that the passenger's or driver's data privacy requirements will be met when the passenger or driver attempts to execute the reservation, wherein to gain the trust, the trust function is for generating an expected cryptogram based at least in part on a unique signature of the autonomous or semi-autonomous vehicle and providing the expected cryptogram to the passenger or driver for verification of a trust relationship with the autonomous or semi-autonomous vehicle.

2. The apparatus of claim 1, wherein the received reservation comprises data regarding a destination, a reservation time and a reservation reference.

3. The apparatus of claim 1 , wherein the reservation subsystem is further configured to: generate and provide a signature for the autonomous or semi-autonomous vehicle; and provide the signature to the cloud server in response to a request from the cloud server before receiving the reservation.

4. The apparatus of claim 1 , wherein the trust function is responsive to the passenger or driver attempting to perform the reservation to generate and provide the expected password to the passenger or driver.

5. The apparatus of claim 4, wherein the trust function is to generate the expected password based further at least in part on a scheduled time for the autonomous or semi-autonomous vehicle.

6. The apparatus according to any one of claims 1 to 5, wherein the access control subsystem is configured to: further acquire biometric data of the passenger or driver; and provide the biometric data of the passenger or driver to the cloud server.

7. The apparatus of claim 6, wherein the biometric data of the passenger or driver comprises a photograph, fingerprint, or voice print of the passenger or driver.

8. An apparatus as described in claim 6, wherein the access control subsystem is used to: when the provided biometric data matches the biometric data of the passenger or driver known to the cloud server, in response to providing the biometric data of the passenger or driver, further receive a data privacy profile of the passenger or driver from the cloud server.

9. The apparatus of claim 8 , wherein the management system further comprises a data collection and sharing subsystem for collecting and sharing data related to the passenger or driver and the passenger or driver's use of the autonomous or semi-autonomous vehicle based at least in part on the data privacy profile of the passenger or driver provided by the cloud server.

10. The apparatus of claim 8, wherein the data privacy profile includes one or more specifications indicating whether collection or sharing of demographic data, in-cabin visual data, in-cabin audio data, location and route data, in-cabin infotainment usage data, or in-cabin comfort preference data associated with the passenger / driver is permitted.

11. The apparatus of claim 8, wherein the data privacy profile includes one or more specifications indicating whether the collected data associated with the passenger or driver is allowed to be shared with a service provider of the autonomous or non-autonomous vehicle, a vehicle manufacturer, a transportation department, or an academic institution.

12. A method for autonomous or semi-autonomous driving, comprising: receiving, by the autonomous or semi-autonomous vehicle, a reservation for the autonomous or semi-autonomous vehicle by a passenger or driver from a cloud server; as well as controlling access to the autonomous or semi-autonomous vehicle by the autonomous or semi-autonomous vehicle, including: gaining trust from the passenger or driver that data privacy requirements of the passenger or driver will be met when the passenger or driver attempts to execute the reservation, Wherein controlling access to the autonomous or semi-autonomous vehicle further comprises generating an expected password based at least in part on a unique signature of the autonomous or semi-autonomous vehicle and providing the expected password to the passenger or driver for verification of a trust relationship with the autonomous or semi-autonomous vehicle.

13. The method of claim 12, further comprising: In response to the passenger or driver attempting to execute the reservation, the expected code is generated by the autonomous or semi-autonomous vehicle and provided to the passenger or driver.

14. The method of claim 13, wherein generating the expected password comprises: The expected passcode is further generated based at least in part on a scheduled time for the autonomous or semi-autonomous vehicle.

15. The method of claim 12, further comprising: The autonomous or semi-autonomous vehicle obtains biometric data of the passenger or driver; and the autonomous or semi-autonomous vehicle provides the biometric data of the passenger or driver to the cloud server.

16. The method of claim 15, further comprising: In response to providing the biometric data of the passenger or driver, a data privacy profile of the passenger or driver is received by the autonomous or semi-autonomous vehicle from the cloud server when the provided biometric data matches biometric data of the passenger or driver known to the cloud server.

17. The method of claim 15, further comprising: Data related to the passenger or driver and the passenger or driver's use of the autonomous or semi-autonomous vehicle is collected, maintained, or shared by the autonomous or semi-autonomous vehicle based at least in part on the passenger or driver's data privacy profile provided by the cloud server.

18. A server device for autonomous or semi-autonomous driving, comprising: a communication subsystem for communicating with passengers or drivers, and the autonomous or semi-autonomous vehicle; a reservation subsystem coupled to the communication subsystem, the reservation subsystem for managing reservations for the passenger or driver with the autonomous or semi-autonomous vehicle, wherein managing reservations for the passenger or driver with the autonomous or semi-autonomous vehicle comprises: generating an expected password for the passenger or driver for a corresponding reservation based at least in part on a unique signature of the autonomous or semi-autonomous vehicle and providing the expected password for use by the autonomous or semi-autonomous vehicle, thereby establishing trust with the passenger or driver that data privacy requirements of the passenger or driver are met; and A user management subsystem, configured to manage the data privacy requirements of the passenger or driver, wherein managing the data privacy requirements of the passenger or driver includes: providing the data privacy requirements of the passenger or driver to a corresponding reserved autonomous or semi-autonomous vehicle; Wherein the corresponding reserved autonomous or semi-autonomous vehicle uses the provided data privacy requirements to regulate the collection, retention or sharing of data associated with the passenger or driver.

19. The apparatus of claim 18 , wherein the user management subsystem is configured to, in response to receiving biometric data of a passenger or driver from an autonomous or semi-autonomous vehicle, provide a data privacy profile of the passenger or driver having the data privacy requirements of the passenger or driver to an autonomous or semi-autonomous vehicle reserved for the passenger or driver.

20. The apparatus according to any one of claims 18-19, wherein the user management subsystem is configured to: further register the passenger or driver; and receive data privacy preferences of the passenger or driver.

21. A device for autonomous or semi-autonomous driving, comprising: processor; as well as a booking client operated by the processor for providing the data privacy preferences of the passenger or driver to the cloud server; wherein in response to biometric data of the passenger or driver provided by the autonomous or semi-autonomous vehicle, upon confirming the identity of the passenger or driver, the cloud server provides the data privacy preferences to the autonomous or semi-autonomous vehicle; wherein the autonomous or semi-autonomous vehicle collects, maintains, or shares data associated with the passenger or driver in compliance with the data privacy preferences; and wherein when the passenger or driver performs the reservation, the autonomous or semi-autonomous vehicle obtains trust from the passenger or driver that the data privacy preferences of the passenger or driver will be complied with, wherein to obtain the trust, the autonomous or semi-autonomous vehicle is operable to generate an expected password based at least in part on a unique signature of the autonomous or semi-autonomous vehicle and provide the expected password to the passenger or driver for verification of the trust relationship with the autonomous or semi-autonomous vehicle.

22. The apparatus of claim 21 , wherein when the passenger or driver makes a reservation for the autonomous or semi-autonomous vehicle, the biometric data of the passenger or driver is provided by the autonomous or semi-autonomous vehicle to the cloud server in response to the passenger or driver attempting to gain access to the autonomous or semi-autonomous vehicle.

23. The apparatus of claim 21 , wherein the reservation client is further operated by the processor to contact the cloud server to reserve the autonomous or semi-autonomous vehicle for the passenger or driver; and wherein the reservation client is configured to: receive the expected password from the cloud server for the autonomous or semi-autonomous vehicle to gain the passenger's or driver's trust that the data privacy preferences of the passenger or driver will be complied with; The autonomous or semi-autonomous vehicle is configured to provide the same password to the passenger or driver when the passenger or driver attempts to access the autonomous or semi-autonomous vehicle when making the reservation.

Citation Information

Patent Citations

  • Vehicle delivery through a mobile computing device

    US20170091856A1

  • Systems for learning user preferences and generating recommendations to make settings at connected vehicles and interfacing with cloud systems

    US9288270B1