Displays the current state of the device depending on the privacy mode

By receiving device status information and presenting different states on different user devices according to the privacy mode, the problem of inconvenience in user control when protecting privacy is solved, and a balance between privacy protection and device control is achieved.

CN114402268BActive Publication Date: 2025-09-09SIGNIFY HOLDING BV
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202080067317.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-09-26
Filing Date
2020-09-23
Publication Date
2025-09-09
Estimated Expiration
2040-09-23

AI Technical Summary

Technical Problem

When existing technologies protect privacy-sensitive device status information, users may not be able to control the device and prevent data sharing at the same time, resulting in inconvenience in control.

Method used

By receiving the current status information of the device on the user device and deciding to present accurate status information on the first user device and accurate or inaccurate status information on the second user device based on the activation status of the privacy mode, the processor is used to control information transmission and device operation to ensure privacy protection.

Benefits of technology

This protects privacy-sensitive information from being known by others without affecting the user's control over the device, avoiding the risk of device status confusion and privacy mode being discovered.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114402268B_ABST
    Figure CN114402268B_ABST
Patent Text Reader

Abstract

A system (1) is configured to receive state information reflecting a current state of a device (33) and determine first state information (68, 69) for presentation on a first user device (1). The first state information reflects the current state of the device. The system is further configured to cause the first state information to be presented on the first user device and to cause second state information (78, 79) to be presented on a second user device. The second state information reflects the current state of the device depending on whether a privacy mode is active for the device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a system for receiving status information reflecting a current status of a device and causing first status information to be presented on a first user device and second status information to be presented on a second user device.

[0002] The invention further relates to a method of receiving status information reflecting a current status of a device and causing first status information to be presented on a first user device and second status information to be presented on a second user device.

[0003] The invention also relates to a computer program product enabling a computer system to perform such a method. Background Art

[0004] The number of connected 24 / 7 devices continues to grow. Many of these devices continuously collect data to support numerous services that benefit users or companies. Common services that use data include security, contextual awareness, and personalized recommendations, among others.

[0005] Connected products such as lighting use real-time and historical data to improve their behavior and provide personalized and intelligent services to users. As more and more devices are connected, the data collected becomes more precise and, as a result, can lead to undesirable privacy-related behaviors.

[0006] Limiting the collection and use of privacy-sensitive data is known. For example, EP2856845 A2 discloses a method and corresponding system for use in a networked lighting control system, whereby an individual can determine various privacy settings for the data collected related to the area being monitored. These settings include the individual's selection of which specific types of data may or may not be collected; whether the individual can link to the collected data; and restrictions on the purposes for which the data may be used.

[0007] A disadvantage of the method of EP2856845 A2 is that if a user does not wish to share certain data with others, he can disable the recording of this data, but then he himself will not have access to this data. This is particularly disadvantageous when the data helps the user control the device. Summary of the Invention

[0008] A first object of the present invention is to provide a system that allows a user to protect privacy-sensitive device state information in a manner that does not inconvenience the user's control over the device.

[0009] A second object of the present invention is to provide a method that allows a user to protect privacy-sensitive device state information in a manner that does not inconvenience the user's control over the device.

[0010] In a first aspect of the present invention, a system for receiving status information reflecting the current state of a device and causing first status information to be presented on a first user device and second status information to be presented on a second user device includes at least one input interface, at least one output interface, and at least one processor, the at least one processor being configured to use the at least one input interface to receive the status information reflecting the current state of the device, determine the first status information for presentation on the first user device, the first status information reflecting the current state of the device, use the at least one output interface to cause the first status information to be presented on the first user device, and use the at least one output interface to cause the second status information to be presented on the second user device, the second status information reflecting the current state of the device depending on whether the privacy mode is activated for the device.

[0011] By having accurate device status information presented on a first user device, and having accurate or inaccurate device status information presented on a second user device depending on whether privacy mode is activated for the device, a user can protect privacy-sensitive device status information from others without inconveniencing their control of the device. For example, they may not want others to know that a certain light is on, but still want to be able to check that the light is on. The device may be a lighting device, and the status may include, for example, at least one of a current on / off setting, a current light output level, and a current color setting.

[0012] The at least one processor can be configured to transmit the first state information to the first user device using the at least one output interface, determine the second state information, and transmit the second state information to the second user device using the at least one output interface. This is beneficial, for example, if the system is included in a bridge or an internet server.

[0013] Alternatively, the system may be included in the first user device, and the at least one processor may be configured to transmit a command to another device, the command instructing the other device to cause the second status information to be presented on the second user device. In this case, it is the first user device that notifies the second user device of the relevant status information and decides which status information to present on the second user device.

[0014] The at least one processor may be configured to receive a control command for controlling the device using the at least one input interface and, depending on whether the privacy mode is activated for the device, control the device according to the control command using the at least one output interface. When the privacy mode is activated for the device, this allows a user to be prohibited from controlling the device and not to see the current state of the device.

[0015] The at least one processor may be configured to determine the second state information such that the second state information does not reflect the current state or virtual state of the device and indicates that the privacy mode is activated for the device when determining that the privacy mode is activated for the device. This avoids confusion for the user of the second user device about the device state, but makes it impossible to hide the fact that the privacy mode is activated, which is a disadvantage if this fact itself is privacy-sensitive information.

[0016] The at least one processor may be configured to determine the second state information such that the second state information identifies the user who activated the privacy mode and / or the user device on which the privacy mode was activated. This makes it easier to find how to disable the privacy mode, if desired.

[0017] The at least one processor may be configured to determine a virtual current state of the device and include the virtual current state in the second state information when determining that the privacy mode is active for the device. For example, the virtual current state may be the last known state of the device before the privacy mode is activated for the device, the virtual current state may be determined randomly, or the virtual current state may be determined based on multiple previous states of the device. This allows the fact that the privacy mode is active to be hidden, which may be beneficial if this fact itself is privacy-sensitive information.

[0018] The privacy mode may have been activated on the first user device and / or by the user of the first user device. Thus, the user who activated the privacy mode is allowed to see the actual status information.

[0019] The first user device may be connected to the same local area network as the device, and the second user device may be connected to a different local area network than the device. For example, a user at home can see the actual status information, while another user who was given permission to control the device when visiting the user's home but is no longer at the user's home cannot see the actual status information.

[0020] The first user device may be used by a user identified in the first user information associated with the privacy mode, and / or the second user device may be used by a user identified in the second user information associated with the privacy mode. This makes it possible to identify a specific user who should be able to see the actual status information or a specific user who should not be able to see the actual status information when the privacy mode is activated.

[0021] The privacy mode can be automatically activated when a first light scene associated with the privacy mode is selected or when a first light control device associated with the privacy mode is used, and / or automatically deactivated when a second light scene not associated with the privacy mode is selected or when a second light control device not associated with the privacy mode is used. This eliminates the need for a user to manually activate and / or deactivate the privacy mode in certain situations. The light scene can be user-selected or automatically selected (e.g., time-based, sensor-triggered). The first and second light control devices can each include, for example, a specific physical interface (e.g., a dimmer switch) or a specific app (e.g., HueSync).

[0022] The privacy mode can be automatically activated or deactivated upon detecting the presence and / or absence of one or more specified persons and / or based on a user-specified schedule (e.g., from 8:00 PM to 12:00 AM). This eliminates the need for users to manually activate privacy mode in certain situations. For example, two users may have a control app for controlling lighting in their homes, and the first user may be able to specify that privacy mode be automatically activated when the first user is detected and the second user is not. Once the second user is detected, privacy mode can then be automatically deactivated.

[0023] In a second aspect of the present invention, a method for receiving state information reflecting a current state of a device and causing first state information to be presented on a first user device and second state information to be presented on a second user device comprises: receiving the state information reflecting the current state of the device, determining the first state information for presentation on the first user device, the first state information reflecting the current state of the device, causing the first state information to be presented on the first user device, and causing the second state information to be presented on the second user device, the second state information reflecting the current state of the device depending on whether a privacy mode is active for the device. The method may be performed by software running on a programmable device. The software may be provided as a computer program product.

[0024] Furthermore, a computer program for carrying out the methods described herein and a non-transitory computer-readable storage medium storing the computer program are provided.The computer program can, for example, be downloaded from or uploaded to an existing device, or stored when these systems are manufactured.

[0025] A non-transitory computer-readable storage medium stores at least one software code portion that, when executed or processed by a computer, is configured to perform executable operations for receiving state information reflecting a current state of a device and causing first state information to be presented on a first user device and second state information to be presented on a second user device.

[0026] The executable operations include receiving the state information reflecting the current state of the device, determining the first state information for presentation on the first user device, the first state information reflecting the current state of the device, causing the first state information to be presented on the first user device, and causing the second state information to be presented on the second user device, the second state information reflecting the current state of the device depending on whether a privacy mode is activated for the device.

[0027] As will be appreciated by those skilled in the art, aspects of the present invention may be embodied as devices, methods, or computer program products. Thus, aspects of the present invention may take the form of entirely hardware embodiments, entirely software embodiments (including firmware, resident software, microcode, etc.), or embodiments combining software and hardware aspects, which may all be generally referred to herein as "circuits," "modules," or "systems." The functions described in this disclosure may be implemented as algorithms executed by a processor / microprocessor of a computer. Furthermore, aspects of the present invention may take the form of a computer program product embodied in one or more computer-readable media having computer-readable program code embodied (e.g., stored) thereon.

[0028] Any combination of one or more computer-readable media may be utilized. A computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium may be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of the present invention, a computer-readable storage medium may be any tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0029] A computer-readable signal medium may include a propagated data signal having computer-readable program code embodied therein (e.g., in baseband or as part of a carrier wave). Such a propagated signal may take any of a variety of forms, including but not limited to electromagnetic, optical, or any suitable combination thereof. A computer-readable signal medium may be any computer-readable medium that is not a computer-readable storage medium and that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.

[0030] Program code embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, cable, RF, or any suitable combination thereof. The computer program code for implementing the operations of aspects of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages ​​(such as Java™, Smalltalk, or C++) and conventional procedural programming languages ​​(such as the "C" programming language or similar programming languages). The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0031] Aspects of the present invention are described below with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, as well as combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, particularly a microprocessor or central processing unit (CPU), to produce a machine such that instructions executed by the processor of the computer, other programmable data processing device, or other device create a device for implementing the functions / actions specified in the flowchart and / or one or more block diagram blocks.

[0032] These computer program instructions may also be stored in a computer-readable medium that can direct a computer, other programmable data processing apparatus, or other device to operate in a particular manner so that the instructions stored in the computer-readable medium produce an article of manufacture that includes instructions for implementing the functions / actions specified in the flowchart and / or one or more block diagram blocks.

[0033] The computer program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process, such that the instructions executed on the computer or other programmable apparatus provide a process for implementing the functions / actions specified in the flowchart and / or block diagram blocks.

[0034] The flowcharts and block diagrams in the various figures illustrate the architecture, functionality, and operation of possible implementations of devices, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of code that includes one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions described in the blocks may not appear in the order described in the figures. For example, two blocks shown in succession may in fact be executed substantially simultaneously, or the blocks may sometimes be executed in the opposite order depending on the functions involved. It will also be noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs the specified function or action, or a combination of dedicated hardware and computer instructions. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] These and other aspects of the invention are apparent from and will be further elucidated, by way of example, with reference to the accompanying drawings, in which:

[0036] Figure 1 is a block diagram of a first embodiment of the system;

[0037] Figure 2 is a block diagram of a second embodiment of the system;

[0038] Figure 3 is a block diagram of a third embodiment of the system;

[0039] Figure 4 is a flow chart of a first embodiment of the method;

[0040] Figure 5 is a flow chart of a second embodiment of the method;

[0041] Figure 6 showing a first example of a user interface shown on first and second user devices;

[0042] Figure 7 is a flowchart of a third embodiment of the method;

[0043] Figure 8 showing a second example of a user interface shown on first and second user devices;

[0044] Figure 9 is a flow chart of a first embodiment of a method for automatically activating and deactivating a privacy mode;

[0045] Figure 10 is a flow chart of a second embodiment of a method for automatically activating and deactivating a privacy mode; and

[0046] Figure 11 is a block diagram of an exemplary data processing system for executing the method of the present invention.

[0047] Corresponding elements in the drawings are denoted by the same reference numerals. DETAILED DESCRIPTION

[0048] Figure 1 A first embodiment of a system for receiving state information reflecting the current state of a device and causing first state information to be presented on a first user device and second state information to be presented on a second user device is shown. In this first embodiment, the system is mobile device 1, and mobile device 1 is also the first user device. The second user device is mobile device 35 or 36.

[0049] Mobile devices 1, 35, and 36 run an app for controlling lighting devices 31-33, which may be, for example, Hue lights. Lighting devices 31-33 communicate with (light) bridge 16 using, for example, Zigbee technology. Bridge 16 may be, for example, a Philips Hue bridge. Mobile devices 1 and 35 can control lighting devices 31-33 via wireless LAN access point 17 and bridge 16. Wireless LAN access point 17 is connected to the internet 11. Internet server 13 is also connected to the internet 11. Mobile device 36 can control lighting devices 31-33 via internet server 13.

[0050] Mobile device 1 includes a transceiver 3, a transmitter 4, a processor 5, a memory 7, and a display 9. Processor 5 is configured to receive status information reflecting the current status of one of lighting devices 31-33 from bridge 16 or internet server 13 using receiver 3, and determine first status information for presentation on mobile device 1. For example, the status of lighting device 31-33 may include a current on / off setting, a current light output level, and / or a current color setting. For example, the first status information reflects the current status of the device and may be the same as the status information received from bridge 16 or internet server 13.

[0051] Processor 5 is further configured to cause first status information to be presented on mobile device 1 using display 9 and second status information to be presented on mobile device 35 or 36 using transmitter 4. The second status information reflects the current status of the device depending on whether privacy mode is active for the device.

[0052] exist Figure 1 In the embodiment of the present invention, the processor 5 is configured to use the transmitter 4 to transmit a command to instruct the other device to cause the second state information to be presented on the second user device. The command can be transmitted to, for example, the mobile device 35 or 36, the bridge 16 or the Internet server 13.

[0053] For example, information about whether the privacy mode is activated for one lighting device or for all lighting devices can be obtained from the bridge 16 or the internet server 13. There are several possible reasons why the user of mobile device 1 is allowed to see the actual status information and why the user of mobile device 35 or 36 is not allowed to see the actual status information, such as:

[0054] Activation of privacy mode on the mobile device 1 and / or by the user of the mobile device 1 ;

[0055] Mobile device 1 is connected to the same local network as the device (which is one of lighting devices 31 - 33 ), and mobile device 36 is connected to a different local network than the device;

[0056] Mobile device 1 is used by a user identified in first user information associated with the privacy mode (e.g., a first list of user identifiers), and / or mobile device 35 or 36 is used by a user identified in second user information associated with the privacy mode (e.g., a second list of user identifiers).

[0057] When privacy mode is activated, one or more of the following restrictions may additionally apply:

[0058] The collected data is not shared with other smart home systems;

[0059] Use local processing of data whenever possible (e.g. for presence detection);

[0060] The collected data is either not stored, or is only stored temporarily using a limited buffer size, or at a low sampling rate;

[0061] The collected data is processed only for real-time behavior and is not used in any learning algorithms.

[0062] When privacy mode is activated, not only may the current state of one or more devices not be displayed on specific user devices, but the currently activated light scene, the last user action, and / or the presence sensor state may also not be displayed on those specific user devices. However, when presence is detected, the system will generally still behave in the same way, such as turning on a light. While the system does not share device states and data that may be collected by those devices with any other smart home systems (such as Amazon Echo or Google Home) in privacy mode, it may still allow those other smart home systems to control devices.

[0063] Activation of privacy mode can be triggered by the activation of a specific light scene (e.g., a relaxation scene) or a routine (e.g., a falling asleep routine). During the time that the light scene or routine is active, events detected by the associated connected devices (e.g., devices in the room or area where the relaxation scene is generating its effect) can be processed according to the limitations of privacy mode.

[0064] A selective privacy mode can be implemented, where privacy mode is activated only in a specific room (e.g., a bedroom), i.e., for devices in that room, and not throughout the entire house. Privacy mode can be automatically deactivated if the user changes scenes, at the end of a routine, or due to a timeout. Privacy mode can also be automatically deactivated when it is detected that the user has left their home.

[0065] Two different levels of privacy can be implemented:

[0066] 1. Explicit. In explicit mode, the system does not hide that it is in private mode (e.g., indicating that no device state information is available). This allows third-party integrations to adapt their functionality accordingly;

[0067] 2. Transparency. In transparent mode, the system mimics default system behavior (e.g., showing authentic but fictitious device states) so that privacy mode cannot be detected by third-party integrations or remote observers.

[0068] The implementer can choose one of these privacy levels, or can implement both privacy levels and allow the user or administrator to select the privacy level he wishes to use.

[0069] exist Figure 1 In the embodiment of mobile device 1 shown in FIG, mobile device 1 includes a processor 5. In alternative embodiments, mobile device 1 includes multiple processors. Processor 5 of mobile device 1 can be a general-purpose processor (e.g., from ARM or Qualcomm) or a dedicated processor. Processor 5 of mobile device 1 can run, for example, an Android or iOS operating system. Display 9 can include, for example, an LCD or OLED display panel. For example, display 9 can be a touchscreen. Processor 5 can use the touchscreen to provide a user interface. Memory 7 can include one or more memory units. For example, memory 7 can include solid-state memory.

[0070] The receiver 3 and transmitter 4 may communicate with the wireless LAN access point 17 using one or more wireless communication technologies, such as Wi-Fi (IEEE 802.11). In alternative embodiments, multiple receivers and / or multiple transmitters are used instead of a single receiver and a single transmitter. Figure 1 In the embodiment shown in , a separate receiver and a separate transmitter are used. In an alternative embodiment, the receiver 3 and the transmitter 4 are combined into a transceiver. The mobile device 1 may include other components typical for mobile devices, such as a battery and a power connector. The present invention may be implemented using a computer program running on one or more processors.

[0071] exist Figure 1 In the embodiment, lighting devices 31-33 are controlled by mobile devices 1 and 35 via bridge 16. In an alternative embodiment, one or more of lighting devices 31-33 are controlled by one or more of mobile devices 1 and 35 without a bridge, for example directly via Bluetooth. Figure 1In the embodiment of the present invention, the internet server 13 receives data from and transmits data to the lighting devices 31-33 via the bridge 16. In an alternative embodiment, the internet server 13 receives data from and transmits data to one or more of the lighting devices 31-33 without a bridge.

[0072] Figure 2 A second embodiment of a system for receiving status information reflecting the current status of a device and causing first status information to be presented on a first user device and second status information to be presented on a second user device is shown. In this second embodiment, the system is a computer 21, the first user device is a mobile device 34, and the second user device is a mobile device 35 or 36. Computer 21 is connected to the Internet 11 and acts as a server. Mobile devices 34-36 can control lighting devices 31-33 via computer 21.

[0073] Computer 21 includes a receiver 23, a transmitter 24, a processor 25, and a storage device 27. Processor 25 is configured to receive status information reflecting the current status of one of lighting devices 31-33 from bridge 16 using receiver 24, and determine first status information for presentation on mobile device 34. For example, the first status information reflects the current status of the device and may be the same as the status information received from bridge 16.

[0074] Processor 25 is further configured to use transmitter 24 to cause first status information to be presented on mobile device 34 and cause second status information to be presented on mobile device 35 or 36. The second status information reflects the current status of the device depending on whether privacy mode is active for the device.

[0075] exist Figure 2 In an embodiment of the present invention, the processor 25 is configured to use the transmitter 24 to transmit the first status information to the mobile device 34, for example, at the request of the mobile device 34, determine the second status information, and use the transmitter 24 to transmit the second status information to the mobile device 35 or 36, for example, at the request of the mobile device 35 or 36.

[0076] exist Figure 2In the embodiment of computer 21 shown in FIG, computer 21 includes a processor 25. In alternative embodiments, computer 21 includes multiple processors. Processor 25 of computer 21 can be a general-purpose processor (e.g., from Intel or AMD) or a dedicated processor. Processor 25 of computer 21 can run, for example, a Windows or Unix-based operating system. Storage device 27 can include one or more memory units. For example, storage device 27 can include one or more hard disks and / or solid-state memories. Storage device 27 can be used to store, for example, an operating system, applications, and application data.

[0077] For example, the receiver 23 and transmitter 24 may use one or more wired and / or wireless communication technologies, such as Ethernet and / or Wi-Fi (IEEE 802.11), to communicate with the wireless LAN access point 17. In alternative embodiments, multiple receivers and / or multiple transmitters are used instead of a single receiver and a single transmitter. Figure 2 In the embodiment shown in , a separate receiver and a separate transmitter are used. In an alternative embodiment, the receiver 23 and the transmitter 24 are combined into a transceiver. The computer 21 may include other components typical for a computer, such as a power connector. The present invention may be implemented using a computer program running on one or more processors.

[0078] exist Figure 2 In the embodiment of the present invention, computer 21 receives data from and transmits data to lighting devices 31-33 via bridge 16. In an alternative embodiment, computer 21 receives data from and transmits data to one or more of lighting devices 31-33 without a bridge.

[0079] Figure 3 A third embodiment of a system for receiving status information reflecting the current status of a device and causing first status information to be presented on a first user device and second status information to be presented on a second user device is shown. In this third embodiment, the system is a bridge 41, the first user device is a mobile device 34, and the second user device is a mobile device 35 or 36. Mobile devices 34 and 35 can control lighting devices 31-33 via wireless LAN access point 17 and bridge 16. Mobile device 36 can control lighting devices 31-33 via internet server 13.

[0080] The bridge 41 includes a receiver 43, a transmitter 44, a processor 45, and a memory 47. The processor 45 is configured to receive state information reflecting the current state of one of the lighting devices 31-33 from the device itself (i.e., one of the lighting devices 31-33) using the receiver 43, and determine first state information for presentation on the mobile device 34. For example, the state information reflects the current state of the device and may be the same as the state information received from the device.

[0081] Processor 45 is configured to use the transmitter to cause first status information to be presented on mobile device 34 and second status information to be presented on mobile devices 35 and 36. The second status information reflects the current status of the device depending on whether privacy mode is active for the device.

[0082] exist Figure 3 In the embodiment of FIG. 4 , processor 45 is configured to transmit the first status information to mobile device 34 using transmitter 44 , determine the second status information, and transmit the second status information to mobile device 35 or 36 using transmitter 44 .

[0083] exist Figure 3 In the embodiment of the bridge 41 shown in FIG, the bridge 41 includes a processor 45. In alternative embodiments, the bridge 41 includes multiple processors. The processor 45 of the bridge 41 can be a general-purpose processor (e.g., an ARM-based processor) or a dedicated processor. The processor 45 of the bridge 41 can run, for example, a Unix-based operating system. The memory 47 can include one or more memory units. For example, the memory 47 can include solid-state memory. For example, the memory 47 can be used to store a list of connected lights.

[0084] For example, the receiver 43 and transmitter 44 may use one or more wired or wireless communication technologies, such as Ethernet for communicating with the wireless LAN access point 17 and Zigbee for communicating with the lighting devices 31-33. In alternative embodiments, multiple receivers and / or multiple transmitters are used instead of a single receiver and a single transmitter. Figure 3 In the embodiment shown in , a separate receiver and a separate transmitter are used. In an alternative embodiment, the receiver 43 and the transmitter 44 are combined into a transceiver. The bridge 41 may include other components typical for network equipment, such as a power connector. The present invention may be implemented using a computer program running on one or more processors.

[0085] exist Figure 1-Figure 3 In some embodiments, the system of the present invention comprises a mobile device, a computer, or a bridge. In alternative embodiments, the system of the present invention is a different device. Figure 1-Figure 3In an embodiment, the system of the present invention comprises a single device. In an alternative embodiment, the system of the present invention comprises a plurality of devices. Figure 1-Figure 3 In the example of FIG. 5 , the user device is a mobile device, but other types of devices can also be used as the user device.

[0086] To enable privacy mode, the system can switch between privacy mode and normal mode, which is the mode in which privacy mode is not activated. For example, privacy mode can be set for all devices in the home or for a subset of devices in the home (for example, all devices in a room or a single device). For example, these devices could be lighting devices.

[0087] In privacy mode, a set of restrictions is applied to the system operation. These restrictions can be defined by the user or by the system. Typically, the operation of the system will include the following steps: (1) setup and configuration; (2) activation of privacy mode; (3) maintaining privacy mode with the set restrictions; (4) switching back to normal operation mode. Figure 9 and Figure 10 To explain steps 2 and 4. Figure 4 、 Figure 5 and Figure 7 Let's explain step 3.

[0088] Figure 4 A first embodiment of a method for receiving state information reflecting a current state of a device and causing first state information to be presented on a first user device and second state information to be presented on a second user device is shown in .Step 101 comprises receiving state information reflecting a current state of a device.

[0089] Step 103 includes determining first status information for presentation on the first user device. The first status information reflects the current status of the device and may be the same as the status information received in step 101. Step 105 includes causing the first status information to be presented on the first user device. Step 107 includes causing second status information to be presented on the second user device. The second status information reflects the current status of the device depending on whether a privacy mode is active for the device.

[0090] In addition to limiting the sharing of status information by preventing the device's current status from being displayed on certain user devices while in privacy mode, one or more additional restrictions can be applied while maintaining privacy mode:

[0091] Data collection is limited: no data is collected at all, or only for real-time processing maintenance, or only for a limited buffer of, for example, 5 minutes, or only for learning purposes and not for real-time behavior (the latter mode can be used when the collected data is only used to train the system and is not stored in its raw form; only aggregated data is stored);

[0092] Data processing: Data is not processed in any way (no data is collected), or data is processed only for real-time actions (e.g., presence detection) and not stored or used for learning, or data is used but processed locally, i.e., not sent to a remote server / cloud, or data is processed as part of a learning mechanism but not stored in its original form;

[0093] Limiting visualization of detected event details: Even if sensor events and their attributes are sent to other devices, the data sent can be labeled or classified as privacy-sensitive information, and based on this classification, the receiving device will not report the event details in the app, dashboard, portal, or any other user application.

[0094] Figure 5 A second embodiment of a method for receiving status information reflecting the current status of a device and causing the status information to be presented on a user device is shown in FIG. Figure 5 In the embodiment, Figure 4 Step 105 includes sub-step 111, and Figure 5 Step 107 includes sub-steps 113-119.

[0095] exist Figure 5 In an embodiment, the method is performed by a first device. In step 111, the first status information (determined in step 103) is presented on a display of the first device. The first sub-step of step 107 (i.e., step 113) includes checking whether the privacy mode is active for the device whose status information was received in step 101. If not, step 117 is performed. Step 117 includes determining second status information that is the same as the first status information determined in step 103.

[0096] If the privacy mode is activated, step 115 is performed. Step 115 includes determining the second state information so that the second state information does not reflect the current state or virtual state of the device and indicates that the privacy mode is activated for the device when it is determined that the privacy mode is activated for the device. Figure 5 In an embodiment, step 115 further comprises determining second status information such that the second status information identifies the user activating the privacy mode and / or the user device on which the privacy mode is activated. Step 119 comprises transmitting the second status information to the second user device.

[0097] Figure 6A first example of a user interface shown on first and second user devices is shown. The first user device 1 is used by a user named "Dan". The user's name is identified by a label 71 on the display 9 of the first user device 1. The second user device 35 is used by a user named "Laura". The user's name is identified by a label 72 on the display 39 of the second user device 35.

[0098] Both user devices are shown for controlling Figure 1 The user interface of the lighting devices 31-33 is shown in FIG. 6A. Panel 61 reflects the current state of the lighting device 31 and can be used to control the lighting device 31. Panel 64 reflects the current state of the lighting device 32 and can be used to control the lighting device 32. Panel 67 reflects the current state of the lighting device 33 and can be used to control the lighting device 33.

[0099] Each panel displays the name of the corresponding lighting fixture. For example, panels 67 and 77 display the name of lighting fixture 33. Furthermore, each panel has a color corresponding to the color rendered by the corresponding lighting fixture. Each panel also displays the dimming level using circles rendered on top of the bars (e.g., circles 63 and 69), and indicates whether the corresponding light is turned on or off using a switch (e.g., switches 62, 65, and 68). If the switch is off, as in panel 64, the panel is uncolored, and the bars and circles representing the dimming level are not displayed.

[0100] When privacy mode is activated for lighting device 33, panel 77 is shown. Figure 5 The status information displayed in panel 77 has already been determined in step 115 of . Status information for lighting device 33 is also shown in panel 77, but since privacy mode is active, the actual status is not shown to Laura. Instead, a message 79 including the text "Set to Private by Dan" is shown. Figure 6 In the example of , panel 77 shows who has activated privacy mode (a user named "Dan"), and when privacy mode is activated for lighting device 33, control of lighting device 33 is disabled, i.e. an empty oval 78 is shown instead of a switch.

[0101] Figure 7 A third embodiment of a method for receiving status information reflecting the current status of a device and causing the status information to be presented on a user device is shown in FIG. Figure 7 In the embodiment, step 105 includes replacing Figure 5 Sub-step 131 of sub-step 111, Figure 5 Step 115 is replaced by step 135 , and steps 121 and 123 are performed after step 107 .

[0102] exist Figure 7In an embodiment, the method is performed by a device different from the first device, such as a bridge or an internet server. In step 131, the first status information (determined in step 103) is transmitted to the first user device. After determining in step 113 that the privacy mode is active for the device whose status information was received in step 101, step 135 is performed.

[0103] Step 135 includes determining second state information by determining a virtual current state of the device, and including the virtual current state in the second state information when determining that the privacy mode is activated for the device. The virtual current state can be the last known state of the device before the privacy mode is activated for the device. For example, the virtual current state can be randomly determined, or the virtual current state can be determined based on multiple previous states of the device.

[0104] Step 121 includes receiving a control command from the second user device for controlling the device. Step 123 includes controlling the device according to the control command, depending on whether privacy mode is active for the device. If the user of the second user device is near the device, the user will know that privacy mode is active for the device if the device does not respond to the user's command. On the other hand, if the user of the second user device is near the device, the user may be aware of the device's actual current state and, therefore, also know that privacy mode is active for the device.

[0105] In step 121, the second state information may be updated to reflect the content of the control command. In this case, if the user of the second user device is located at a distance, he may get the impression that he can indeed control the device. Figure 7 Not shown.

[0106] Figure 8 A second example of a user interface shown on a first and a second user device is shown. Figure 8 In the example of FIG. 8 , a panel 87 is shown on the display 39 of the second user device 35 instead of Figure 6 The status information displayed in panel 87 is already in Figure 7 The switch 88 shown in the panel 87 indicates that the lighting device 33 is turned off, while the lighting device 33 is actually turned on, as shown in the panel 67 displayed on the first user device 1.

[0107] Before maintaining privacy mode, the user typically sets and configures the privacy mode. In a simple embodiment, the privacy mode is defined by the system itself, leaving the user with no control over what restrictions are enabled and how they are enabled. In another embodiment, the user can define whether the entire (lighting) system or just a portion of it should be restricted when privacy mode is activated, as well as how the mode should be restricted. Furthermore, the user can define how the mode is activated, including automatic activation when certain conditions are met. Furthermore, the user can define the visibility of the (lighting) system based on user access levels, including notifying the user when the system is in privacy mode.

[0108] Once privacy mode has been activated, it is maintained. The user can manually enable privacy mode. Alternatively, the user / system may define a set of rules when privacy mode is enabled. These rules may include: routines and schedules (e.g., privacy mode is activated on weekends or specific days defined in a schedule), association with system state (e.g., if a specific scene in the Hue lights is activated, privacy mode is also activated), association with the presence of specific devices or people (e.g., if person A is detected, the system automatically switches to privacy mode), presence-based activation may also include a combination of users and devices, including unknown devices and unknown people (e.g., if detected persons A and B, privacy mode is activated, while if detected persons A, B, and C, it is not activated).

[0109] In more advanced systems, the user can delegate activation to the system by instructing the system to switch to private mode when it detects an event that is likely to be privacy-sensitive according to the system, such as using a specific light control device or activating a specific system state (such as a streaming state). The system may also have learned from previous activations of privacy modes by the user themselves and (suggest) activation of privacy mode when similar conditions are detected.

[0110] Similar to activation, switching back to normal mode can be manual or based on predefined rules. If the conditions for privacy mode are no longer met, for example, if a timeout (timer expiration) occurs (for example, privacy mode can only be activated for a certain period of time and then needs to be reactivated again), or if certain conditions that override privacy mode are met (for example, an unknown person is detected and privacy mode is immediately turned off), the system can switch back to normal mode. If a (soft) security application is active (such as Hue outside the home), deactivating privacy mode may require user authentication.

[0111] Figure 9A first embodiment of a method for automatically activating and deactivating a privacy mode is shown. A privacy mode may relate to a single device or to multiple devices. A privacy mode may relate to one or more specified devices or to all devices in a location (e.g., a home). Figure 9 In an embodiment, each device can be individually set to a privacy mode. Figure 9 In an embodiment, the privacy mode is automatically activated if a scene associated with the privacy mode is selected or a timer (of a user-specified schedule) expires. Figure 9 In an embodiment, the privacy mode is automatically deactivated if a scene that is not associated with any privacy mode is selected or some other timer (of a user-specified schedule) expires.

[0112] Step 151 includes manually or automatically selecting a first scene associated with one or more lighting devices and associated with a privacy mode for the one or more lighting devices. Step 152 includes rendering the first scene on the one or more lighting devices. Step 161 is performed after step 152 and includes activating the privacy mode for the one or more lighting devices if the privacy mode is not already activated for the one or more lighting devices. Step 161 also includes recording the reason for activating the privacy mode, for example, by identifying the scene that was selected in step 151.

[0113] Step 157 includes manually or automatically selecting a second scene associated with the same one or more lighting devices, but not associated with privacy mode. Step 158 includes rendering the second scene on the one or more lighting devices. Step 163 is performed after step 158. Step 163 includes checking whether privacy mode is activated, and if so, whether the selection of the first scene is the sole reason for activating privacy mode.

[0114] If privacy mode is not activated, no further steps are performed. If privacy mode is activated and selection of the first scene is the only reason for activating privacy mode, then step 167 is performed. Step 167 includes deactivating privacy mode and removing the recorded reason for activating privacy mode. If privacy mode is activated and selection of the first scene is not the only reason for activating privacy mode, then step 165 is performed. Step 165 includes removing selection of the first scene as the recorded reason for automatically activating privacy mode. Another reason for automatically activating privacy mode may still remain recorded, such as the expiration of a timer for a user-specified schedule.

[0115] Step 154 ​​includes the expiration of a timer for a user-specified schedule. Step 155 includes determining whether the expired timer corresponds to the beginning or end of a privacy time window. If the timer corresponds to the beginning of a privacy time window, step 161 is executed. If the timer corresponds to the end of a privacy time window, step 163 is executed. In alternative embodiments, steps 154 and 155 or steps 151, 152, 157, and 158 are omitted.

[0116] Figure 10 A second embodiment of a method for automatically activating and deactivating a privacy mode is shown. Figure 10 In an embodiment, the privacy mode is automatically activated upon detecting the presence of one or more designated persons and / or the absence of one or more designated persons.

[0117] Step 181 includes identifying which people are present. For example, a camera can be used to perform the identification of people. Alternatively, people can be identified based on RF (e.g., Bluetooth or Wi-Fi) transmissions from their user devices.

[0118] Step 183 includes checking whether a person from group X is present. If the presence of such a person is detected, step 161 is performed and the privacy mode associated with the event is activated for one or more devices associated with the privacy mode, if not already activated. If the presence of such a person is not detected, step 163 is performed and, if the presence of this person was the only reason for activating the privacy mode, the privacy mode is deactivated.

[0119] Step 184 involves checking whether a person from group Y is present. If the presence of such a person is not detected, step 163 is performed, and if the presence of this person (combined with the presence of a person from group Z) is the only reason for activating the privacy mode, the privacy mode is deactivated. If the presence of such a person is detected, step 185 is performed.

[0120] Step 185 includes checking whether a person from group Z associated with the detected person from group Y is also present. If the presence of such a person is not detected, i.e., the person is detected as not present, then step 161 is performed and the privacy mode associated with this event is activated for one or more devices associated with the privacy mode, if not already activated. If the presence of such a person is detected in step 185, then no further steps are performed.

[0121] Step 185 is also performed after step 181. If it is determined that a person from group Z is present, then step 163 is performed, and if the absence of this person (combined with the presence of a person from group Y) is the only reason for activating privacy mode, then privacy mode is deactivated. A person can be in both group Y and group Z, but not in both group X and group Y or both group X and group Z.

[0122] In an example application, two users both have a control app for controlling lighting in their home, and the first user can specify that privacy mode is automatically activated when the first user (from group Y) is detected and the second user (from group Z) is not detected, and automatically deactivated again when the first user is no longer detected or the second user is detected. In an alternative embodiment, Figure 9 and Figure 10 The steps are combined.

[0123] Figure 11 Depicted instructions can be executed as reference Figure 4 、 Figure 5 、 Figure 7 、 Figure 9 and Figure 10 A block diagram of an exemplary data processing system for the described methods.

[0124] like Figure 11 As shown in , data processing system 300 may include at least one processor 302 coupled to memory element 304 via system bus 306. In this way, the data processing system may store program code in memory element 304. Further, processor 302 may execute program code accessed from memory element 304 via system bus 306. In one aspect, the data processing system may be implemented as a computer suitable for storing and / or executing program code. However, it should be appreciated that data processing system 300 may be implemented in the form of any system including a processor and memory capable of performing the functions described in this specification.

[0125] Memory element 304 may include one or more physical memory devices, such as, for example, local memory 308 and one or more mass storage devices 310. Local memory may refer to random access memory or other non-persistent storage device(s) typically used during the actual execution of program code. Mass storage devices may be implemented as hard drives or other persistent data storage devices. Processing system 300 may also include one or more cache memories (not shown) that provide temporary storage of at least some program code in order to reduce the number of times program code must be retrieved from mass storage device 310 during execution. For example, if processing system 300 is part of a cloud computing platform, processing system 300 may also be able to use memory elements of another processing system.

[0126] Optionally, input / output (I / O) devices, depicted as input device 312 and output device 314, may be coupled to the data processing system. Examples of input devices may include, but are not limited to, a keyboard, a pointing device such as a mouse, or a microphone (e.g., for voice and / or speech recognition). Examples of output devices may include, but are not limited to, a monitor or display, or speakers. Input and / or output devices may be coupled to the data processing system directly or through intervening I / O controllers.

[0127] In an embodiment, the input and output devices may be implemented as a combined input / output device (in Figure 11 314). An example of such a combined device is a touch-sensitive display, sometimes also referred to as a "touch screen display" or simply a "touch screen." In such an embodiment, input to the device can be provided by movement of a physical object (such as, for example, a user's finger or a stylus) on or near the touch screen display.

[0128] Network adapter 316 may also be coupled to data processing system 300 to enable it to couple to other systems, computer systems, remote network devices, and / or remote storage devices through intervening private or public networks. Network adapters may include data receivers for receiving data transmitted to data processing system 300 by the systems, devices, and / or networks, as well as data transmitters for transmitting data from data processing system 300 to the systems, devices, and / or networks. Modems, cable modems, and Ethernet cards are examples of different types of network adapters that may be used with data processing system 300.

[0129] like Figure 11As shown in FIG, memory element 304 can store application programs 318. In various embodiments, application programs 318 can be stored in local memory 308, one or more mass storage devices 310, or separate from local memory and mass storage devices. It should be appreciated that data processing system 300 can further execute an operating system (OS) that can facilitate the execution of application programs 318. Figure 11 ). Application 318, implemented in the form of executable program code, may be executed by data processing system 300 (eg, by processor 302). In response to executing the application, data processing system 300 may be configured to perform one or more operations or method steps described herein.

[0130] Figure 11 Input device 312 and output device 314 are shown as being separate from network adapter 316. However, additionally or alternatively, input may be received via network adapter 316, and output may be transmitted via network adapter 316. For example, data processing system 300 may be a cloud server. In this case, input may be received from a user device acting as a terminal, and output may be transmitted to a user device acting as a terminal.

[0131] Various embodiments of the present invention may be implemented as a program product for use with a computer system, wherein the program(s) of the program product define functionality of the embodiments (including the methods described herein). In one embodiment, the program(s) may be embodied on various non-transitory computer-readable storage media, where, as used herein, the term "non-transitory computer-readable storage medium" includes all computer-readable media with the sole exception of transitory propagated signals. In another embodiment, the program(s) may be embodied on various transitory computer-readable storage media. Illustrative computer-readable storage media include, but are not limited to: (i) non-writable storage media on which information is permanently stored (e.g., read-only memory devices within a computer, such as CD-ROM disks readable by a CD-ROM drive, ROM chips, or any type of solid-state non-volatile semiconductor memory); and (ii) writable storage media on which information is stored that can be altered (e.g., flash memory, a floppy disk within a floppy disk drive or hard drive, or any type of solid-state random-access semiconductor memory). The computer program(s) may be executed on the processor 302 described herein.

[0132] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the present invention. As used herein, the singular forms "a" or "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that when used in this specification, the terms "comprise" and / or "comprising" specify the presence of stated features, parts, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, parts, steps, operations, elements, components and / or groups thereof.

[0133] The corresponding structures, materials, actions, and equivalents of all means or step plus function elements in the following claims are intended to include any structure, material, or action for performing a function in combination with other claimed elements as specifically claimed. The description of the embodiments of the present invention has been presented for illustrative purposes, but is not intended to be exhaustive or limited to the embodiments in the disclosed form. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the invention. The embodiments are selected and described in order to best explain the principles of the invention and some practical applications, and to enable others of ordinary skill in the art to understand the invention for various embodiments with various modifications suitable for the particular use under consideration.

Claims

1. A system for receiving status information reflecting a current status of a device and causing first status information to be presented on a first user device and second status information to be presented on a second user device, wherein the device is a lighting device, the system comprising: at least one input interface; at least one output interface; and At least one processor configured to: - receiving, using said at least one input interface, said status information reflecting said current status of said device, - determining first state information for presentation on the first user device, the first state information reflecting the current state of the device, - causing the first status information to be presented on the first user equipment using the at least one output interface, and - causing second state information to be presented on the second user device using the at least one output interface, the second state information reflecting the current state of the device depending on whether a privacy mode is active for the device, Wherein the at least one processor is configured to determine a virtual current state of the device and include the virtual current state in the second state information when the privacy mode is active for the device.

2. The system of claim 1 , wherein the at least one processor is configured to: - transmitting the first state information to the first user equipment using the at least one output interface, - determining the second state information, and - transmitting the second state information to the second user equipment using the at least one output interface.

3. The system according to claim 1 or 2, wherein the at least one processor is configured to: - using the at least one input interface to receive control commands for controlling the device, and - controlling the device according to the control command using the at least one output interface, depending on whether the privacy mode is activated for the device.

4. A system according to claim 1 or 2, wherein the at least one processor is configured to, when determining that the privacy mode is activated for the device, determine the second state information, so that the second state information does not reflect the current state or virtual state of the device and indicates that the privacy mode is activated for the device.

5. The system of claim 4, wherein the at least one processor is configured to determine the second state information such that the second state information identifies a user activating the privacy mode and / or a user device on which the privacy mode is activated.

6. A system according to claim 1 or 2, wherein the virtual current state is the last known state of the device before the privacy mode is activated for the device, the virtual current state has been randomly determined, or the virtual current state has been determined based on multiple previous states of the device.

7. The system of claim 1 or 2, wherein the privacy mode is activated on the first user device and / or by a user of the first user device.

8. The system of claim 1 or 2, wherein the first user device is connected to the same local area network as the device, and the second user device is connected to a different local area network than the device.

9. A system according to claim 1 or 2, wherein the first user device is used by a user identified in first user information associated with the privacy mode, and / or the second user device is used by a user identified in second user information associated with the privacy mode.

10. A system according to claim 1 or 2, wherein the privacy mode is automatically activated when a first light scene associated with the privacy mode is selected or when a first light control device associated with the privacy mode is used, and / or is automatically deactivated when a second light scene not associated with the privacy mode is selected or when a second light control device not associated with the privacy mode is used.

11. The system of claim 1 or 2, wherein the privacy mode is automatically activated or deactivated upon detecting the presence of one or more specified persons and / or the absence of one or more specified persons and / or based on a user-specified schedule.

12. The system of claim 1 or 2, wherein the device is a lighting device and the state comprises at least one of a current on / off setting, a current light output level, and a current color setting.

13. A method for receiving status information reflecting a current status of a device and causing first status information to be presented on a first user device and second status information to be presented on a second user device, wherein the device is a lighting device, the method comprising: - receiving said status information reflecting said current status of said device; - determining first state information for presentation on the first user device, the first state information reflecting the current state of the device; - determining a virtual current state of the device and including the virtual current state in the second state information when a privacy mode is activated for the device; - causing the first status information to be presented on the first user equipment; as well as - causing second state information to be presented on the second user device, when the privacy mode is active for the device, the second state information reflecting the virtual current state.

14. A computer program product comprising at least one software code portion configured for performing the method of claim 13 when run on a computer system of the system according to claim 1.

Citation Information

Patent Citations

  • A method for providing privacy protection in networked lighting control systems

    EP2856845A2

  • Privacy filtering of requested user data and context activated privacy modes

    CN105917349A

  • Cognitive widgets and UI components for preserving privacy and security

    CN110020545A