Vehicle information processing device and method of operating the same
By preprocessing, standardizing, de-identifying, and encrypting vehicle data, the problems of insufficient security and data leakage in existing vehicle information collection systems are solved, and secure data transmission and flexible use are achieved.
Patent Information
- Application Number
- CN202010490106.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-06-02
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2040-06-02
AI Technical Summary
Existing vehicle information collection systems suffer from insufficient security during data transmission, a high risk of personal information leakage, and an inability to flexibly adapt to the needs of various data users.
The vehicle data is preprocessed, standardized, de-identified, and encrypted using a computing device, and then encrypted second-processed data is transmitted to the data collection server.
It improves the security of vehicle data, reduces the risk of data leakage, supports the needs of various data users, and enhances the flexibility and control of data use.
Smart Images

Figure CN113752963B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to a technology of a vehicle information processing apparatus and an operating method thereof. BACKGROUND
[0002] Vehicle information can include a variety of information about a vehicle acquired in a vehicle information collection apparatus embodied in a vehicle. For example, the vehicle information can be vehicle fault codes, vehicle speed, engine revolutions, coolant temperature, and the like, which are data of a vehicle state, which can be acquired through a vehicle electronic control unit (ECU). In particular, a telematics service based on vehicle information can implement a variety of convergence services such as maintenance reservation and emergency dispatch by diagnosing a remote vehicle, a premium differential application of each vehicle driving information, and the like.
[0003] Vehicle information is received through a telematics terminal, is delivered to a telematics server, and is finally provided to a telematics user through an information processing procedure. In this case, communication of an in-vehicle network with the telematics terminal uses an in-vehicle network such as a controller area network (CAN), a K-line, and the like, and communication of the telematics terminal with the server uses a conventional public network such as code division multiple access (CDMA), wideband code division multiple access (WCDMA), a wireless network using wireless broadband access service (Wibro), a wireless local area network (WLAN), and the like. Also, the telematics server provides a service to the telematics user by performing appropriate analysis, processing, and machining.
[0004] On the other hand, with the advent of a connected car and an autonomous vehicle era, the importance and value of vehicle information have come to the surface, and a variety of industries and government agencies collect vehicle information to use it. SUMMARY
[0005] The present application proposes a vehicle information collection system that can improve the security of vehicle data by using a computing device.
[0006] The vehicle information collection system of the present application embodiment has the effect that vehicle data is processed using a computing device and is utilized, and thus the security of the vehicle data can be improved.
[0007] Also, the vehicle information collection system of the embodiment of the present application has the effect that, in the case where external intrusion occurs in the process of directly transferring vehicle data to the server, the risk of data leakage can be reduced.
[0008] According to an aspect of the present disclosure, there is provided a vehicle information processing apparatus, characterized by comprising: a preprocessing and standardization section that receives vehicle data from a vehicle data collection apparatus provided in a vehicle, and generates first processed data by preprocessing and standardizing the vehicle data; a de-identification section that generates second processed data by de-identifying the first processed data; and a final encryption processing section that encrypts the second processed data, and transmits the encrypted second processed data to a data collection server.
[0009] According to another aspect of the present disclosure, there is provided an operation method of a vehicle information processing apparatus, characterized by comprising: a step of receiving vehicle data from a vehicle data collection apparatus provided in a vehicle, and generating first processed data by preprocessing and standardizing the vehicle data; a step of generating second processed data by de-identifying the first processed data; and a step of encrypting the second processed data, and transmitting the encrypted second processed data to a data collection server. BRIEF DESCRIPTION OF DRAWINGS
[0010] Figure 1 A block diagram is shown to illustrate a conventional vehicle information collection system.
[0011] Figure 2 A block diagram is shown to illustrate a vehicle information collection system of an embodiment of the present application.
[0012] Figure 3 A diagram is shown to illustrate a detailed block diagram of a computing apparatus of an embodiment of the present application.
[0013] Figure 4 A diagram is shown to illustrate a process in which a computing apparatus of an embodiment of the present application stores permission information in a permission management server.
[0014] Figure 5 A diagram is shown to illustrate the operation of a data collection server of an embodiment of the present application.
[0015] Figure 6a A diagram is shown to illustrate an example in which data is de-identified in an embodiment of the present application.
[0016] Figure 6b A diagram is shown to illustrate an example in which data is de-identified in another embodiment of the present application.
[0017] Figure 6c A diagram is shown to illustrate an example in which data is de-identified in another embodiment of the present application.
[0018] Figure 7aA diagram illustrating the process by which a computing device of an embodiment of the present invention issues a key in relation to a data collection entity.
[0019] Figure 7b A diagram illustrating the process of verifying the data collection subject using a computing device according to an embodiment of the present invention.
[0020] Figure 8 This diagram illustrates the operation between a data collection entity, a computing device, and a data user server according to an embodiment of the present invention.
[0021] Figure 9 To illustrate an embodiment of the present invention Figure 8 The diagram shows an example of the user interface for the task.
[0022] Figure 10 This diagram illustrates the operation between a data collection entity, a computing device, and a data user entity server, according to another embodiment of the present invention.
[0023] Figure 11 To illustrate another embodiment of the invention Figure 10 The diagram shows an example of the user interface for the task.
[0024] Figure 12 A flowchart illustrating the operation method of the computing device according to an embodiment of the present invention.
[0025] Figure 13 To illustrate embodiments of the present invention Figure 12 The flowchart shows the specific working method of step S110.
[0026] Explanation of reference numerals in the attached figures
[0027] 100: Data collection entity; 300: Vehicle data collection device
[0028] 400: Data user server; 500, 501, 502: Data user entity
[0029] 600: Computing device; 610: Preprocessing and standardization unit; 620: De-identification unit; 630: Final encryption processing unit.
[0030] 700: Data Collection Server Detailed Implementation
[0031] The present disclosure will now be described with reference to the accompanying drawings. The present disclosure can have various changes and can have various embodiments, and a specific embodiment is illustrated in the drawings and described in detail. However, it is not intended to limit the present disclosure to the specific embodiment, but to include all changes, and / or equivalent and / or alternative technical solutions within the idea and technical scope of the present disclosure. With regard to the description of the drawings, similar reference numerals are used for similar structural elements.
[0032] In the present disclosure, the expression "include" or "may include" and the like means the presence of the disclosed corresponding function, action or structural element, and one or more functions, actions or structural elements are added without limitation. Also, in the present disclosure, the term "include" or "have" and the like is used to specify the presence of the features, numbers, steps, actions, structural elements, components or combinations thereof described in the specification, and does not exclude the presence or addition of one or more other features, numbers, steps, actions, structural elements, components or combinations thereof in advance.
[0033] In the present disclosure, the expression "or" and the like includes any or all combinations of the words listed together. For example, "A or B" can mean that A can be included, B can be included, or both A and B can be included.
[0034] In the present disclosure, the expression "first", "second", "first" or "second" and the like can modify various structural elements of the present disclosure, but does not limit the corresponding structural elements. For example, the above expression does not limit the order and / or importance of the corresponding structural elements. The above expression is used to distinguish between two structural elements. For example, the first user device and the second user device are both user devices, and represent different user devices. For example, without exceeding the scope of protection of the present disclosure, the first structural element can be named as the second structural element, and similarly, the second structural element can be named as the first structural element.
[0035] When referring to one structural element "connected" or "coupled" to another structural element, it can be directly connected or coupled to other structural elements, or other structural elements can be present in the middle. In contrast, when referring to one structural element "directly connected" or "directly coupled" to another structural element, it can be understood that there are no other structural elements in the middle.
[0036] The terms used in the present disclosure are only used to describe specific embodiments, and are not intended to limit the present disclosure. As long as there is no explicit indication in the context, the singular expression includes the plural expression.
[0037] The meaning of all the terms used herein, including technical or scientific terms, can be the same as commonly understood by one of ordinary skill in the art to which the present disclosure pertains, unless otherwise defined. The meaning of terms commonly used in dictionaries is the same as the meaning in the context of the relevant art, unless otherwise defined in the present disclosure, and cannot be interpreted as an unusual or overly formal meaning.
[0038] With the advent of the era of connected cars and autonomous vehicles, the importance and value of vehicle data are gradually emerging, and various industries and government agencies collect and utilize vehicle data.
[0039] Figure 1 To show a block diagram of a conventional vehicle information collection system.
[0040] Referring to Figure 1 , the vehicle information collection system can include a data collection subject 100, a vehicle 200, a vehicle data collection device 300, a data use subject server 400, and a data use subject 500.
[0041] The data collection subject 100 can be one of a driver who drives the vehicle 200 and a passenger who rides in the vehicle 200.
[0042] The vehicle data collection device 300 is a device located inside the vehicle 200 for collecting vehicle data. The vehicle data collection device 300 can include at least one of an on board diagnostics (OBD) device 310, a digital tachograph (DTG) device 320, a vehicle-to-everything (V2X) device 330, a mobile device 340, and an operator monitoring device 350.
[0043] The vehicle data collection device 300 can transmit the collected vehicle data to the data use subject server 400.
[0044] The data use subject server 400 directly transmits the vehicle data transmitted from the vehicle data collection device 300 to the data use subject 500, or processes the vehicle data transmitted from the vehicle data collection device 300 and transmits the processed vehicle data to the data use subject 500.
[0045] The conventional vehicle information collection system mainly collects data through the data use subject 500, and thus the vehicle data is directly transmitted to the data use subject server 400 in its original form, and the vehicle information is processed in the data use subject server 400.
[0046] However, the vehicle data contains the location information of the vehicle, personal information of a new person who gets on the vehicle, etc., and the sovereignty thereof exists in the data collection subject 100, and thus the security of the conventional vehicle information collection system is not complete, and the flowing personal information cannot be processed.
[0047] That is, in the conventional vehicle information collection system, even if the vehicle data contains the personal information of the data collection subject 100, the collection setting cannot be implemented, and thus there is a problem in that all data occurring in the vehicle is collected in any case.
[0048] Also, in the conventional vehicle information collection system, in the process in which the vehicle data is transmitted to the server, when external intrusion occurs, the vehicle data will directly flow out.
[0049] Also, in the conventional vehicle information collection system, the vehicle data that can be used for various purposes can be collected only through one system, and thus the usability of the vehicle data is also reduced.
[0050] The collected vehicle data can be transmitted only to the server 400 of the initially set data use subject 500, and when there is another use subject that needs similar data, there can be an inconvenience in which a new collection device needs to be designed.
[0051] Figure 2 FIG. 1 is a block diagram of a vehicle information collection system according to an embodiment of the present application.
[0052] Referring to Figure 2 , instead of the data use subject server 400 of Figure 1 , the vehicle information collection system according to an embodiment of the present application can include a computing device 600 and a data collection server 700.
[0053] The computing device 600 processes the vehicle data received from the vehicle data collection device 300 according to a setting, and can transmit the processed vehicle data through encryption and de-identification operations to the data collection server 700.
[0054] After that, at least one of the data use first subject 501 and the data use second subject 502 requests the processed vehicle data from the data collection server 700, and can use the processed vehicle data.
[0055] The computing device 600 is a device such as a smartphone or an in-vehicle infotainment (IVI) for a vehicle that is synchronized with a subject (for example, a vehicle user) who collects data through a verification process, is operated by a data use subject, and can itself calculate and communicate.
[0056] According to an embodiment, the computing device 600 can include at least one of a tablet personal computer, a mobile phone, a video phone, an e-book reader, a desktop personal computer, a laptop personal computer, a netbook computer, a personal digital assistant (PDA), a portable multimedia player (PMP), a mobile medical device, a camera, or a wearable device.
[0057] The computing device 600 can perform the following 1) to 10) functions in a process of collecting data within a vehicle to transmit the data to a server.
[0058] 1) Synchronizing with a verification process of a data collection subject
[0059] 2) Receiving data occurring in a vehicle through a plurality of devices and performing a first processing of the data
[0060] 3) Receiving a request of a data use subject who needs to collect data and delivering the request to a data collection subject
[0061] 4) Setting a form (a file form and a format of a unit of data, etc.) to be provided to each use subject of each data
[0062] 5) Setting an encryption and de-identification level to be provided to each use subject of each data
[0063] 6) Performing an encryption and de-identification process of data
[0064] 7) Collecting and merging data to be provided so that a data use subject can browse
[0065] 8) Transmitting data on a key to interpret encrypted data to a server of a data use subject as needed
[0066] 9) Changing the setting matters mentioned in the above step 4) and step 5) in real time
[0067] 10) Determining whether to collect current and future data in real time, stopping the collection of data at a point in time when the data is not needed to be collected, and requesting deletion of past data to a server
[0068] In the present application, the vehicle data collected by the vehicle data collection device 300 can include at least one of vehicle driving information, safety information, management information, vehicle state information, driver identification information, driving environment information, and driver state information.
[0069] The above-mentioned vehicle driving information can include at least one of vehicle position, vehicle speed, vehicle gear, accumulated distance, accelerator information, brake information, tire speed information, acceleration information.
[0070] The above-mentioned safety information can include at least one of vehicle interior part state information, vehicle consumable state information of cooling water, engine oil, etc., vehicle seat belt state information, tire pressure information, battery state information.
[0071] The above-mentioned management information can include at least one of business detail information, fuel consumption information, fuel economy information, vehicle path information, fuel reduction information, other transportation-related variable information (for example, taxi: business state, cargo transportation: cargo state, etc.).
[0072] The above-mentioned vehicle state information can include at least one of vehicle model, vehicle year, accident record information, repair record information, part state information, driver history information.
[0073] The above-mentioned driver identification information can include at least one of driver name, driver age, driver health-related information, driver driving history information, driving trip information.
[0074] The above-mentioned driving environment information can include at least one of road-related information, road state, speed limit information, weather information, humidity information, wind direction information, traffic information.
[0075] The above-mentioned driver state information can include at least one of the degree of blinking of the driver, the heart rate of the driver, the blood pressure of the driver, whether the driver's smartphone is working, concentration degree information of the driver.
[0076] Figure 3 FIG. 1 is a diagram illustrating a detailed block diagram of a computing device according to an embodiment of the present application.
[0077] Referring to Figure 2 to Figure 3 , the computing device 600 can include a pre-processing and normalization unit 610, a de-identification unit 620, and a final encryption processing unit 630.
[0078] The pre-processing and normalization unit 610 can receive vehicle data from the vehicle data collection device 300 provided in the vehicle, and generate first processed data by pre-processing and normalizing the vehicle data.
[0079] The preprocessing and normalization unit 610 can unify the data form of the above-described vehicle data or process the above-described vehicle data into an easy-to-use form.
[0080] The de-identification unit 620 can generate second processed data by de-identifying the above-described first processed data.
[0081] The de-identification unit 620 can include a data classification unit 621, a personal information processing unit 623, an other information processing unit 625, a de-identification processing unit 627, and an encryption processing unit 629.
[0082] The data classification unit 621 can classify the above-described first processed data according to a set reference. In this case, the data classification reference can be set in advance or changed according to the needs of a data user.
[0083] The personal information processing unit 623 can process (or process) personal information included in the classified first processed data through the data classification unit 621. For example, the personal information processing unit 623 can extract personal information included in the classified first processed data.
[0084] The other information processing unit 625 can process (or process) other information included in the classified first processed data through the data classification unit 621. For example, the other information processing unit 625 can extract other information included in the classified first processed data.
[0085] The above-described other information can be information other than the personal information included in the classified first processed data. According to an embodiment, the classification reference of the above-described other information and the above-described personal information can be changed according to the degree of needs of a data user.
[0086] The de-identification processing unit 627 can perform de-identification processing on the above-described first processed data based on the above-described personal information and the above-described other information.
[0087] According to an embodiment, the de-identification method applicable to the de-identification processing unit 627 can be at least one of a pseudonymization method, an aggregation method, a data reduction method, a data suppression method, and a data masking method.
[0088] In this case, the pseudonym processing method is a method of changing the name of the subject of personal information into another name, the total processing method is a method of processing the identifier value by summation or average, the data deletion method is a method of deleting all or part of the identifier information, the data classification method is a method of processing a specific value of the identifier in a range, and the data masking method is a method of changing a part of the value of the identifier into *** or OOO.
[0089] The encryption processing section 629 can perform encryption processing on the first processed data based on the above-mentioned personal information and the above-mentioned other information.
[0090] The de-identification section 620 can generate second processed data by performing de-identification and encryption processing on the first processed data provided from the preprocessing and normalization section 610, and can transmit the second processed data to the final encryption processing section 630.
[0091] The final encryption processing section 630 can perform encryption on the second processed data, and can transmit the encrypted second processed data to the data collection server 700.
[0092] The key management server 800 can store a decoding key capable of decoding data encrypted by the computing device 600.
[0093] According to an embodiment, the computing device 600 can transmit a first decoding key related to encryption of the first processed data performed in the encryption processing section 629 to the key management server 800. The key management server 800 can store the above-mentioned first decoding key in an in-server database.
[0094] According to an embodiment, the computing device 600 can transmit a second decoding key related to encryption of the second processed data performed in the final encryption processing section 630 to the key management server 800. The key management server 800 can store the above-mentioned second decoding key in an in-server database.
[0095] Figure 4 A diagram for showing a process in which the computing device of an embodiment of the present application stores permission information in a permission management server.
[0096] Referring to Figure 4 , the computing device 600 can include a permission management section 640 that transmits permission information of each data use subject to the permission management server 900 in response to a request from the data collection subject 100.
[0097] The permission management server 900 can store the permission information transmitted from the permission management section 640 in a database.
[0098] Figure 5 A diagram for showing an operation of the data collection server of an embodiment of the present application.
[0099] Referring to Figure 5 , the data collection server 700 can store encrypted data 710. Among them, the encrypted data 710 can include at least one of encrypted personal data 711, de-identified personal data 713, and other data 715.
[0100] Referring to Figure 5 , the data usage subject 500 can request data browsing to the data collection server 700, and in response to the above data browsing request, the data collection server 700 can request permission information to the data usage subject 500.
[0101] The data usage subject 500 can browse data that complies with the permission on the data collection server 700. The data usage subject 500 can request the transmission of authentication and permission information to the permission management server 900.
[0102] The permission management server 900 can request a decoding key that complies with the permission to the key management server 800, and the key management server 800 can transmit the requested decoding key to the permission management server 900.
[0103] After that, the permission management server 900 can transmit the permission and the decoding key to the data collection server 700.
[0104] Figure 6a An example diagram in which data is de-identified according to an embodiment of the present application.
[0105] Referring to Figure 2 to Figure 6a , the computing device can perform de-identification by changing the disclosure range related to at least one data within the vehicle data.
[0106] For example, Figure 6a In the location information of the vehicle, the part of "Yongsan-gu Yeouido-dong 111-11" displayed will gradually become dark according to the setting of the disclosure range of each data.
[0107] Figure 6b An example diagram in which data is de-identified according to another embodiment of the present application.
[0108] Referring to Figure 2 to Figure 6b , the computing device can perform de-identification by performing pseudonymization on at least one data within the vehicle data.
[0109] Figure 6b In the vehicle data, the computing device can perform pseudonymization on the name, date of birth, gender, location information of the driver of the vehicle, display, and perform de-identification.
[0110] For example, Figure 6bIn this case, the name of the vehicle driver is anonymized from "Hong Gidong" to "Hong ACJD", the date of birth of the vehicle driver is anonymized from "April 22, 1978" to "19XX, XX, XX", and the gender of the vehicle driver is anonymized from "Male" to "????", and the location information of the vehicle is anonymized from "Seoul Yeongdeungpo-gu, Yeouido-dong 111-11" to "Seoul ****".
[0111] Figure 6c An example diagram for illustrating data de-identified according to another embodiment of the present application.
[0112] Referring to Figure 2 to Figure 6c , the computing device can perform de-identification by anonymizing at least one of the vehicle data.
[0113] Figure 6c In this case, the computing device anonymizes the name, the date of birth, the gender, and the location information of the vehicle driver in the vehicle data, and thus can perform de-identification.
[0114] In this case, the degree of anonymization (or the degree of disclosure range) can be changed according to a K value set by a data collection subject (K-Anonymity).
[0115] For example, Figure 6c In this case, according to a first K value, the name of the vehicle driver can be anonymized from "Hong Gidong" to "Hong", the date of birth of the vehicle driver can be anonymized from "April 22, 1978" to "Born between 1970 and 1980", the gender of the vehicle driver can be anonymized from "Male" to "Male or Female", and the location information of the vehicle can be anonymized from "Seoul Yeongdeungpo-gu, Yeouido-dong 111-11" to "Seoul Yeongdeungpo-gu".
[0116] For example, Figure 6c In this case, according to a second K value, the name of the vehicle driver can be anonymized from "Hong Gidong" to "Kim, Lee, Park, Hong", the date of birth of the vehicle driver can be anonymized from "April 22, 1978" to "Born between 1950 and 1990", the gender of the vehicle driver can be anonymized from "Male" to "Male or Female", and the location information of the vehicle can be anonymized from "Seoul Yeongdeungpo-gu, Yeouido-dong 111-11" to "Seoul Yeongdeungpo-gu, Mapo-gu, Gangnam-gu".
[0117] Figure 7a A diagram for illustrating a process in which the computing device issues a secret key related to a data collection subject according to an embodiment of the present application.
[0118] Referring to Figure 2 to Figure 7aThe data collection subject 100 can input personal identification information on the computing device 600. The computing device 600 issues a verification key for the data collection subject 100 in response to the personal identification information input and can generate a password.
[0119] Figure 7b A diagram showing the process of the computing device verifying the data collection subject according to an embodiment of the present application.
[0120] Referring to Figure 2 to Figure 7b The data collection subject 100 can input an access request on the computing device 600. The computing device 600 can perform a verification request for the data collection subject 100 in response to the access request.
[0121] If the data collection subject 100 inputs the verification key issued in the Figure 7a and the generated password on the computing device 600, the computing device 600 can transmit a verification result.
[0122] Figure 8 A diagram showing the operation between the data collection subject, the computing device, and the data usage subject server according to an embodiment of the present application.
[0123] Referring to Figure 8 The data usage subject server 400 can transmit a data collection request to the computing device 600, and the computing device 600 can deliver the data collection request to the data collection subject 100.
[0124] The data collection subject 100 can set the collected data and the data disclosure range of each usage subject. According to an embodiment, the data and the data disclosure range of each usage subject setting can be embodied by automation.
[0125] According to an embodiment, the data collection subject 100 can set whether to provide each data, or set the de-identification level of each data, or can set the encryption level of each data.
[0126] The computing device 600 can transmit the data based on the set range to the data usage subject server 400.
[0127] The data collection subject 100 can provide the data usage subject server 400 with information on the encryption interpretation key based on the set range.
[0128] Figure 9 An example diagram of a user interface showing the operation of the data collection subject, the computing device, and the data usage subject server according to an embodiment of the present application. Figure 8
[0129] Referring to Figure 8 and Figure 9 If a data user (e.g., A) makes a data collection request, a “Data collection request of A” will be displayed on the display provided on the computing device 600, and “Approval” or “Rejection” flags may be generated so that the data collection user 100 responds to the data collection request.
[0130] If the data collection entity 100 approves the above data collection request, it can set information such as data extension, data transmission cycle, data encryption, data de-identification, and detailed data settings.
[0131] According to an embodiment, the settings for data extension, data transmission period, data encryption, data de-identification, and detailed data can be set by preset values set by the data user (e.g., A).
[0132] According to another embodiment, the settings for data extension, data transmission cycle, data encryption, data de-identification, and detailed data can be set by the data collection entity 100 to values different from preset values.
[0133] Subsequently, if detailed data is set, it is possible to identify the representation of each data type (A, B, C, D, E, F, etc.) and whether or not data is provided for each data type.
[0134] Figure 10 This diagram illustrates the operation between a data collection entity, a computing device, and a data user entity server, according to another embodiment of the present invention.
[0135] Reference Figure 10 The data collection entity 100 can set the corresponding time and past data collection in real time on the computing device 600. The data collection entity 100 can set whether to collect each type of data based on time, and can execute past data deletion requests.
[0136] Then, the computing device 600 can transmit data and requests that conform to the settings to the data user server 400.
[0137] Figure 11 To illustrate another embodiment of the invention Figure 10 The diagram shows an example of the user interface for the task.
[0138] Reference Figure 10 and Figure 11 The data collection entity 100 configures data collection in real time on a display provided on the computing device 600. The data collection entity 100 can configure whether or not to collect overall data, or whether or not to collect personal information.
[0139] The data collection subject 100 can set real-time data collection for each subject on the display provided on the computing device 600. For example, the data collection subject 100 can set whether to collect real-time data for at least one of the data use subject A, the data use subject B, the data use subject C, the data use subject D, the data use subject E, and the data use subject F.
[0140] Also, the data collection subject 100 can add a new schedule on the display provided on the computing device 600, or set whether to collect data for a specific date and time.
[0141] Also, the data collection subject 100 can constitute a data collection schedule for each time on the display provided on the computing device 600. The data collection subject 100 can set whether to collect data for the whole data or personal information for a specific date and time. The data collection subject 100 can set real-time data collection for each use subject on the display provided on the computing device 600. For example, the data collection subject 100 can set whether to collect real-time data for at least one of the data use subject A, the data use subject B, the data use subject C, the data use subject D, the data use subject E, and the data use subject F.
[0142] Referring to Figure 2 to Figure 11 The vehicle data collection system of the computing device according to the embodiment of the present application can perform encryption and de-identification for the first time in the process of transmitting and receiving data, thereby enhancing the integrity and security of data.
[0143] Also, the vehicle data collection system of the computing device according to the embodiment of the present application does not transmit data occurring in a vehicle directly from each collection device, but collects and merges data for the first time to perform standardization and then transmits, thereby transmitting data merged with a server at one time without a data transmission device attached to each device.
[0144] Also, when an additional data use subject occurs, the vehicle data collection system of the computing device according to the embodiment of the present application can collect data even without constructing a new system.
[0145] Also, in the vehicle data collection system of the computing device according to the embodiment of the present application, a data collection subject having sovereignty of personal information can control his or her own information, and thus the security of personal information will be enhanced.
[0146] Figure 12 A flowchart showing the operation method of the computing device according to the embodiment of the present application.
[0147] Referring to Figure 1 to Figure 12The computing device of the embodiment of the present application receives vehicle data from a vehicle data collection device provided in a vehicle, and generates first processed data by preprocessing and normalizing the vehicle data (step S100).
[0148] The computing device can generate second processed data by de-identifying the first processed data (step S110).
[0149] The computing device can encrypt the second processed data and transmit the encrypted second processed data to a data collection server (step S120).
[0150] Figure 13 To show the specific working method of step S110 of the embodiment of the present application. Figure 12 The flow chart of the specific working method of step S110 is shown.
[0151] The computing device of the embodiment of the present application can classify the first processed data generated by preprocessing and normalizing the vehicle data (step S111).
[0152] The computing device can process personal information contained in the classified first processed data, and can process other information contained in the classified first processed data (step S113).
[0153] The computing device can de-identify and encrypt the first processed data based on the personal information and the other information (step S115).
[0154] The method of the above embodiment can be formulated by a computer executable program, and the secret key can be embodied in a general purpose digital computer when the program is operated, using a computer readable recording medium. Also, the data structure, program instruction or data file used in the embodiment of the present application can be recorded in a computer readable recording medium by various units. The computer readable recording medium can include all kinds of storage devices storing data readable by a computer system.
[0155] As examples of the computer-readable recording medium, there can be included a magnetic medium such as a hard disk, a floppy disk, and a magnetic tape, an optical recording medium such as a CD-ROM and a DVD, a magneto-optical medium such as a floptical disk, and a hard disk device specially configured to store and execute program instructions in the form of a ROM, a RAM, a flash memory, and the like. Also, the computer-readable recording medium can be a transmission medium that transmits a signal in which a program instruction, a data structure, and the like are specified. As examples of the program instruction, there can be included a machine code formed by a compiler and a high-level language code that is executed in a computer using an interpreter and the like.
[0156] The embodiments disclosed in the present specification and drawings are disclosed for the purpose of simply explaining the gist of the present application and helping to understand the present application, and the scope of the present application is not limited thereto. Therefore, the scope of the present application includes all modified or altered forms derived on the basis of the technical idea of the present application in addition to the embodiments disclosed herein.
Claims
1. A computing device for processing vehicle information in a vehicle information collection system, characterized in that, The vehicle data collection device includes at least one of an on-board diagnostic device, a digital driving recorder, a vehicle-to-everything device, a mobile device, and an operator monitoring device. The vehicle data includes at least one of vehicle driving information, safety information, management information, vehicle state information, driver identification information, driving environment information, and driver state information. The computing device further includes a permission management unit that transmits permission information of each data usage subject to the permission management server in response to a request from a data collection subject. The de-identification unit changes a disclosure range of each data included in the first processed data, or performs at least one of pseudonym processing on data included in the first processed data or anonymization processing on at least one of the data included in the first processed data. The computing device issues an authentication key and a password matching the data collection subject in response to input of personal identification information of the data collection subject. The computing device requests authentication of the data collection subject in response to an access request of the data collection subject, and transmits an authentication result to the data collection subject in response to input of the authentication key and the password of the data collection subject. The vehicle data collection device includes at least one of an on-board diagnostic device, a digital driving recorder, a vehicle-to-everything device, a mobile device, and an operator monitoring device. The vehicle data includes at least one of vehicle driving information, safety information, management information, vehicle state information, driver identification information, driving environment information, and driver state information. The computing device further includes a permission management unit that transmits permission information of each data usage subject to the permission management server in response to a request from a data collection subject. The de-identification unit changes a disclosure range of each data included in the first processed data, or performs at least one of pseudonym processing on data included in the first processed data or anonymization processing on at least one of the data included in the first processed data. The computing device issues an authentication key and a password matching the data collection subject in response to input of personal identification information of the data collection subject.
2. The computing device for processing vehicle information in a vehicle information collection system according to claim 1, wherein, The computing device requests authentication of the data collection subject in response to an access request of the data collection subject, and transmits an authentication result to the data collection subject in response to input of the authentication key and the password of the data collection subject.
3. The computing device for processing vehicle information in a vehicle information collection system of claim 1, wherein, The vehicle data collection device includes at least one of an on-board diagnostic device, a digital driving recorder, a vehicle-to-everything device, a mobile device, and an operator monitoring device.
4. The computing device for processing vehicle information in a vehicle information collection system of claim 1, wherein, The vehicle data includes at least one of vehicle driving information, safety information, management information, vehicle state information, driver identification information, driving environment information, and driver state information.
5. The computing device for processing vehicle information in a vehicle information collection system of claim 1, wherein, The computing device further includes a permission management unit that transmits permission information of each data usage subject to the permission management server in response to a request from a data collection subject.
6. The computing device for processing vehicle information in a vehicle information collection system of claim 1, wherein, The de-identification unit changes a disclosure range of each data included in the first processed data, or performs at least one of pseudonym processing on data included in the first processed data or anonymization processing on at least one of the data included in the first processed data.
7. The computing device for processing vehicle information in a vehicle information collection system according to claim 6, wherein, The computing device issues an authentication key and a password matching the data collection subject in response to input of personal identification information of the data collection subject.
8. A method for operating a computing device for processing vehicle information in a vehicle information collection system, characterized by, The computing device requests authentication of the data collection subject in response to an access request of the data collection subject, and transmits an authentication result to the data collection subject in response to input of the authentication key and the password of the data collection subject. a step of transmitting, to the key management server, a first decoding key related to encryption of the first processed data; and a step of transmitting, to the key management server, a second decoding key related to encryption of the second processed data, wherein the step of generating the second processed data includes: a step of classifying the first processed data; a step of processing personal information contained in the classified first processed data; a step of processing other information contained in the classified first processed data; a step of de-identifying the first processed data based on the personal information and the other information; and a step of encrypting the first processed data based on the personal information and the other information, wherein the key management server transmits the first decoding key and the second decoding key to the data collection server through an authority management server, and a data user requests authentication to the authority management server and requests transmission of authority information.
9. The method for operating a computing device for processing vehicle information in a vehicle information collection system according to claim 8, wherein the vehicle data collection device includes at least one of an on-board diagnostic device, a digital drive recorder, a car-to-x device, a mobile device, and an operator monitoring device, the vehicle data includes at least one of vehicle travel information, safety information, management information, vehicle state information, driver identification information, driving environment information, and driver state information.
10. The method for operating a computing device for processing vehicle information in a vehicle information collection system according to claim 8, wherein, further comprising: a step of changing a disclosure range of each data contained in the first processed data; or a step of performing pseudonym processing on at least one of the data contained in the first processed data; or a step of performing anonymization processing on at least one of the data contained in the first processed data.
11. A computer-readable recording medium, characterized by a program for causing a computer to function as means for executing the method described in claim 8.
Citation Information
Patent Citations
Intelligent network connection vehicle data privacy protection system and method independent of trusted party
CN110309675A
User data privacy management method and device and electronic equipment
CN110363025A