A privacy protection method and system for vehicle data
By using digital twin technology and local differential privacy protection technology, connected vehicle data is continuously collected and processed, solving the problems of insufficient privacy and availability in traditional technologies and improving data stability and privacy.
Patent Information
- Application Number
- CN202410754754.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-12
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2044-06-12
AI Technical Summary
Traditional data privacy protection technologies are insufficient in terms of privacy and usability in the continuous privacy release of connected vehicle data, making it difficult to guarantee the privacy and security of user vehicle data.
By continuously collecting mobile user data from vehicles using digital twin technology, privacy-preserving preprocessing is performed using local differential privacy protection technology, a sliding window is set and noise is added for perturbation calculation, and the optimal user privacy data is determined.
This approach ensures data availability while enhancing vehicle data privacy, preventing malicious attacks, and guaranteeing data stability and privacy.
Smart Images

Figure CN118797717B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of data privacy protection, and in particular to a vehicle data privacy protection method and system. BACKGROUND
[0002] With the emergence and rapid development of emerging technologies such as mobile Internet and cloud computing, data within different industries is also continuously accumulating. At present, the number of networked vehicles is increasing rapidly, and networked vehicles also use big data thinking mode to bring more perfect and accurate services to users. Under this background, the demand of different social organizations for user data is continuously increasing, and the value of vehicle data is self-evident, such as traffic estimation, crowd perception, user interest location analysis, and even intelligent recommendation combined with multi-modal big models, which all need to obtain application through vehicle data.
[0003] Networked vehicles upload vehicle data to servers to meet the business support for users, and in order to better protect privacy, continuous privacy publishing of vehicle data is needed. However, with the accumulation of data, the risk of leakage of vehicle data related to user privacy is greatly improved, which brings great privacy security risks to users. Once the server is attacked, attackers can obtain a large amount of real information of users. Traditional data privacy protection technology has weak privacy, and there are certain deficiencies in the usability of continuous privacy publishing, and it is difficult to find a trusted data collector in reality, so it is difficult to guarantee the privacy and security of user vehicle data. SUMMARY
[0004] In view of this, in order to solve the problems of insufficient privacy and usability when continuously publishing vehicle data of networked vehicles through traditional data privacy protection technology, the embodiments of the present application provide a vehicle data privacy protection method and system.
[0005] A vehicle data privacy protection method, the method comprising:
[0006] continuously collecting flow user data of a vehicle by using digital twin technology;
[0007] determining to-be-disturbed privacy data by performing privacy protection preprocessing on the flow user data;
[0008] determining optimal user privacy data by performing disturbance operation on the to-be-disturbed privacy data;
[0009] The optimal user privacy data is determined based on a statistical quantity of the user privacy data closest to the statistical quantity of the privacy protection.
[0010] In a possible embodiment, the continuously collecting flow user data of a vehicle by using digital twin technology comprises:
[0011] obtaining a unique identifier of the vehicle;
[0012] determining a corresponding twin vehicle of the vehicle according to the unique identification by using a digital twin technology;
[0013] continuously collecting the flow user data in the twin vehicle within a preset period of time;
[0014] The flow user data includes location information, license plate information, and driving path information.
[0015] In a possible embodiment, the privacy protection preprocessing of the flow user data determines to-be-disturbed privacy data, including:
[0016] determining a first quantity of the flow user data of the vehicle at present;
[0017] determining a second quantity of the flow user data by using a local differential privacy protection technology for privacy publishing of the first quantity of the flow user data;
[0018] performing similarity calculation on the first quantity and the second quantity to output a similarity value;
[0019] When the similarity value is less than or equal to a preset similarity value, the second quantity of the flow user data is determined as the to-be-disturbed privacy data.
[0020] In a possible embodiment, the disturbance operation on the to-be-disturbed privacy data further determines optimal user privacy data, including:
[0021] setting a sliding window for the to-be-disturbed privacy data, and setting a privacy budget ∈ of the sliding window;
[0022] calculating the privacy budget ∈ of the sliding window at a current timestamp based on a privacy budget allocation strategy i , ∈ i < ∈;
[0023] adding noise to the privacy budget ∈ i for disturbance operation to further determine the optimal user privacy data.
[0024] In a possible embodiment, the moving direction of the sliding window includes forward and backward, and the calculating the privacy budget ∈ of the sliding window at the current timestamp based on the privacy budget allocation strategy i , ∈ i < ∈, includes:
[0025] allocating the privacy budget ∈ to a forward sliding window and a backward sliding window;
[0026] calculating the privacy budget ∈ of the forward sliding window at the current timestamp based on the privacy budget allocation strategy i,fThe privacy budget ∈ of the forward sliding window i,b ;
[0027] The privacy budget ∈ of the forward sliding window i,f The privacy budget ∈ of the backward sliding window i,b The smaller one is taken as the privacy budget ∈ of the sliding window at the current timestamp i .
[0028] In a possible embodiment, the privacy budget ∈ of the forward sliding window i,f is calculated as follows:
[0029] k = ω - r + 1
[0030]
[0031] where k is the remaining timestamp in the forward sliding window; ω is the total timestamp of the sliding window; r is the timestamp at which the forward sliding window starts; is the remaining privacy budget in the forward sliding window; ∈ / 2 is the privacy budget allocated to the forward sliding window by the privacy budget ∈; ∈ r is the privacy budget at which the forward sliding window starts.
[0032] In a possible embodiment, the privacy budget ∈ of the backward sliding window i,b is calculated as follows:
[0033] j = i - ω + 1
[0034]
[0035] where j is the remaining timestamp in the backward sliding window; i is the current timestamp; ω is the total timestamp of the sliding window; is the remaining privacy budget in the backward sliding window; ∈ / 2 is the privacy budget allocated to the backward sliding window by the privacy budget ∈; ∈ j is the privacy budget at which the backward sliding window starts.
[0036] In a possible embodiment, the method further comprises:
[0037] When the similarity value is greater than the preset similarity value, the second quantity of the streaming user data is uploaded to the server as user privacy data without privacy budget in the privacy protection preprocessing of the streaming user data.
[0038] In a possible embodiment, the privacy budget ∈ i is added with noise for disturbance calculation as follows:
[0039] c' i = c i + Lap(1 / ∈ i )
[0040] wherein c' i is the optimal user privacy data, c i is the privacy data to be disturbed, and Lap(1 / ∈ i ) is noise added to the privacy budget ∈ i .
[0041] Based on the same concept, the embodiment of the present application provides a privacy protection system for vehicle data, comprising:
[0042] a collection module configured to continuously collect flow user data of a vehicle by using digital twin technology;
[0043] a processing module configured to determine the privacy data to be disturbed by performing privacy protection preprocessing on the flow user data;
[0044] a disturbance module configured to determine the optimal user privacy data by performing disturbance operation on the privacy data to be disturbed.
[0045] The optimal user privacy data is determined based on the statistical quantity of the user privacy data closest to the quantity of the privacy protection.
[0046] In the embodiment of the present application, the flow user data of the vehicle is continuously collected by using digital twin technology; thus, the vehicle data can be continuously published, ensuring the availability of the vehicle data, and then the flow user data is preprocessed for privacy protection to determine the privacy data to be disturbed; the privacy data to be disturbed is operated for disturbance to determine the optimal user privacy data; wherein the optimal user privacy data is determined based on the statistical quantity of the user privacy data closest to the quantity of the privacy protection; thus, the availability is ensured while meeting the demand for privacy of the vehicle data. BRIEF DESCRIPTION OF DRAWINGS
[0047] The drawings constituting a part of the specification of the present application are used to provide further understanding of the present application, the illustrative embodiments of the present application and the description thereof are used to explain the present application, and do not constitute improper limitation on the present application. In the drawings:
[0048] Figure 1 an embodiment flow chart of a privacy protection method for vehicle data provided by the embodiment of the present application;
[0049] Figure 2 an embodiment flow chart of another privacy protection method for vehicle data provided by the embodiment of the present application;
[0050] Figure 3A flowchart illustrating another embodiment of a vehicle data privacy protection method provided by the present invention;
[0051] Figure 4 A flowchart illustrating another embodiment of a vehicle data privacy protection method provided by the present invention;
[0052] Figure 5 A schematic diagram of privacy budget for a sliding window in perturbation calculation provided in an embodiment of the present invention;
[0053] Figure 6 This is a schematic diagram of the architecture of a vehicle data privacy protection system provided in an embodiment of the present invention. Detailed Implementation
[0054] The present invention will now be described in detail with reference to the accompanying drawings and embodiments. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.
[0055] The following detailed description is exemplary and intended to provide further detailed explanation of the invention. Unless otherwise specified, all technical terms used in this invention have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in this invention is for describing particular embodiments only and is not intended to limit the scope of exemplary embodiments according to the invention.
[0056] See Figure 1 The above is a flowchart illustrating an embodiment of a vehicle data privacy protection method provided by the present invention. Figure 1 As shown, the process may include the following steps:
[0057] Step 101: Continuously collect mobile user data of vehicles using digital twin technology.
[0058] In this embodiment, vehicles may include cars, buses, trucks, vans, motorcycles, etc. Mobile user data may include location information, license plate information, and travel route information. Specifically, location information may include frequently visited location information. Travel route information may include traffic volume estimates, traffic light status, pedestrian flow, and multiple routes to the destination, etc., without limitation.
[0059] In practice, vehicle user data can be directly obtained from data storage providers, but this method cannot provide real-time access to the data. This makes it difficult to protect the privacy of real-time vehicle user data, thus requiring continuous data collection. However, this method cannot meet the need for continuous publishing, resulting in certain usability limitations. Alternatively, vehicle user data can be obtained from untrusted data collectors, but this method also cannot simultaneously satisfy both privacy and usability requirements.
[0060] This embodiment takes the continuous collection of vehicle flow user data by digital twin technology as an example for illustration. In the case of using digital twin technology, even under the condition of untrusted data collection, continuous publication and privacy protection of data can be ensured.
[0061] In an embodiment, the vehicle can be uniquely identified by using digital twin technology. The unique identification here can be the license plate number of the vehicle, or a randomly generated identification, which is not limited here. Then, the corresponding twin vehicle of the vehicle is determined according to the unique identification, and the continuous collection of the flow user data in the twin vehicle within a preset period is obtained. The real-time flow user data of the vehicle is recorded in the twin vehicle. Without affecting the operation of other devices of the vehicle, the flow user data of the vehicle can be continuously collected, while the privacy and usability are ensured.
[0062] Step 102, privacy protection preprocessing of the flow user data to determine the to-be-disturbed privacy data.
[0063] In an embodiment, the privacy protection is performed by using the local differential privacy protection technology. First, the amount of the flow user data collected in step 101 is counted, and then the similarity between the amount and the amount published by the local differential privacy protection technology is determined, so as to determine the data to be disturbed, i.e., the to-be-disturbed privacy data, thereby improving the amount of the vehicle flow user data published by the privacy protection. The specific implementation can be achieved by the embodiment flowchart shown in Figure 2 The embodiment flowchart shown in Figure 2 The embodiment flowchart shown in
[0064] Step 201, determining a first amount of the current flow user data of the vehicle.
[0065] Step 202, performing privacy publication on the first amount of the flow user data by using the local differential privacy protection technology to determine a second amount of the flow user data.
[0066] Step 203, performing similarity calculation on the first amount and the second amount to output a similarity value.
[0067] Step 204, when the similarity value is less than or equal to a preset similarity value, determining the second amount of the flow user data as the to-be-disturbed privacy data.
[0068] The steps 201 to 204 are uniformly described as follows:
[0069] In one embodiment, the method for determining the amount of execution data can be calculated using a decision algorithm, and there are no limitations on this. Specifically, it can be done in the following way: taking the current location information of the vehicle's mobile user data as an example in this embodiment, the similarity value is calculated using a random response mechanism as an example:
[0070] T i =c i -c r ′
[0071] v i =(T i >T) Determine T i Is it greater than T?
[0072] In the formula, c i c is a statistical measure of the current location information. r ′ For the final privacy release volume, T i This represents the similarity value.
[0073] In another embodiment, not only can similarity be used to determine perturbed privacy data, but the probability of similarity can also be further tested to determine whether the output vehicle data needs to be perturbed, thereby improving the accuracy of similarity. Specifically, based on the judgment T... i Whether the similarity is greater than T is determined by a similarity score of 1 if the score is true and 0 if the score is false, as shown below:
[0074]
[0075] In the formula, v i ′ This represents the probability value of similarity.
[0076] When the similarity probability value is positive, the second number of mobile user data is determined as privacy data to be disturbed.
[0077] Step 103: Perform perturbation calculations on the privacy data to be perturbed to determine the optimal user privacy data.
[0078] Among them, the optimal user privacy data is determined based on the statistical measure that best approximates the amount of privacy protection.
[0079] In one embodiment, as the vehicle data containing the privacy data to be disturbed involves more information, malicious access or malicious attacks will also increase. When attackers continuously access and raise questions, the stability of the privacy data to be disturbed will decrease due to the increase in the number of attacks, and even the privacy will be reduced. Therefore, perturbation operations can be performed on the privacy data to be disturbed to improve data stability.
[0080] For example, the attacker sends a question to the server: "Have you ever been to Peace Road?" Assuming that the server data shows that he has been to Peace Road, when the attacker asks the question, the server can output the correct answer or an incorrect answer. When the server outputs the correct answer, the privacy of the to-be-disturbed private data is destroyed. If the attacker asks several times, the privacy is destroyed more. Therefore, it can be known that the disturbance operation on the to-be-disturbed private data is beneficial to improving the stability and privacy of the to-be-disturbed private data. As to how to perform the disturbance operation on the to-be-disturbed private data and then determine the optimal user private data, the embodiment flowchart shown in FIG. 1 can be used to implement. Figure 3 As shown in FIG. 2, the embodiment flowchart of another vehicle data privacy protection method provided by the embodiment of the application is shown. The flowchart can include the following steps. Figure 3 As shown in FIG. 3, the embodiment flowchart of still another vehicle data privacy protection method provided by the embodiment of the application is shown. The flowchart can include the following steps.
[0081] In step 301, a sliding window is set for the to-be-disturbed private data, and a privacy budget ∈ of the sliding window is set.
[0082] In step 302, the privacy budget ∈ of the sliding window at a current timestamp is calculated based on a privacy budget allocation strategy. i i < ∈.
[0083] The steps 301 to 302 are uniformly described as follows.
[0084] In an embodiment, continuing the example in step 103, if the attacker asks several times, the to-be-disturbed private data will be gradually attacked and thus the privacy is lost. Therefore, the reliability of transmission can be required for the to-be-disturbed private data to guarantee the privacy. Alternatively, the efficiency and reliability of data transmission can be improved by setting a sliding window for the to-be-disturbed private data.
[0085] To further determine the number of attacks before the privacy is lost at the server, thereby avoiding the loss of privacy, the privacy budget ∈ can be set for the sliding window. Then, the privacy budget ∈ of the sliding window at a current timestamp is calculated based on a privacy budget allocation strategy. i Here, the privacy budget ∈ of any timestamp is less than the privacy budget set for the sliding window. i In this way, the privacy of the to-be-disturbed private data can be guaranteed not to be attacked, and problems such as data loss and data out-of-order caused by network congestion or other conditions can be avoided. As to how to calculate the privacy budget ∈ of the sliding window at a current timestamp based on a privacy budget allocation strategy, the embodiment flowchart shown in FIG. 4 can be used to implement. As shown in FIG. 5, the embodiment flowchart of still another vehicle data privacy protection method provided by the embodiment of the application is shown. The flowchart can include the following steps. i Figure 4 As shown in FIG. 6, the embodiment flowchart of still another vehicle data privacy protection method provided by the embodiment of the application is shown. The flowchart can include the following steps. Figure 4 As shown in FIG. 7, the embodiment flowchart of still another vehicle data privacy protection method provided by the embodiment of the application is shown. The flowchart can include the following steps.
[0086] Step 401, the moving direction of the sliding window includes: forward, backward, and the privacy budget ∈ is allocated to the forward sliding window and the backward sliding window.
[0087] Step 402, the privacy budget ∈ of the forward sliding window at the current timestamp is calculated based on the privacy budget allocation strategy i,f , and the privacy budget ∈ of the backward sliding window i,b .
[0088] Step 403, the size of the privacy budget ∈ of the forward sliding window i,f and the privacy budget ∈ of the backward sliding window i,b is compared, and the smaller one is taken as the privacy budget ∈ of the sliding window at the current timestamp i .
[0089] The following is a unified description of steps 401 to 403:
[0090] Referring to Figure 5 , a privacy budget diagram of a sliding window in a perturbation operation is provided for an embodiment of the present application, as shown in Figure 5 , the size of the sliding window is ω, and the range of the privacy budget ∈ belongs to (∈ i-ω+1 , …, ∈ i-1 ); c i ′ is the optimal user privacy data, c i is the privacy data to be perturbed, c i-ω+1 is the privacy data to be perturbed at timestamp i-ω+1, c r+ω-1 is the privacy data to be perturbed at timestamp r+ω-1, ∈ i-ω+1 is the privacy budget at timestamp i-ω+1.
[0091] In an embodiment, the privacy budget ∈ is allocated to the forward sliding window and the backward sliding window based on the privacy budget allocation strategy. As shown in Figure 5 , the privacy budget ∈ i is allocated at each timestamp. Here, the maximum privacy budget allocated to timestamp i is estimated from two angles: the forward sliding window and the backward sliding window. The backward sliding window starts at timestamp i-ω+1, and the forward sliding window starts at the timestamp r of the last privacy release. The size of the two sliding windows is ω. Here, the privacy budget is calculated from the perspective of the two windows, and the minimum value of the two values is selected to avoid the depletion of the privacy budget. Specifically, the following program can be executed.
[0092] Input: (∈1, …, ∈ i-1 )
[0093] Output: the allocated privacy budget ∈ of the current timestampi
[0094] Identify the last privacy release c r
[0095] / / Forward privacy budget estimation
[0096] 1 Calculate the remaining timestamp k = ω - r + 1 in the forward sliding window
[0097] 2 Calculate the remaining privacy budget in the forward sliding window
[0098] 3 Calculate the estimated privacy budget of the forward sliding window
[0099] / / Backward privacy budget estimation
[0100] 4 Calculate the remaining privacy budget j = i - ω + 1 of the backward sliding window
[0101] 5 Calculate the remaining privacy budget of the backward sliding window
[0102] 6 Calculate the estimated privacy budget of the backward sliding window
[0103] 7 Return the minimum value ∈ of the two estimated budgets i = min(∈ i,f ,∈ i,b )
[0104] In the formula, k is the remaining timestamp in the forward sliding window; ω is the total timestamp of the sliding window; r is the timestamp at which the forward sliding window starts; is the remaining privacy budget in the forward sliding window; ∈ / 2 is the privacy budget allocated to the forward sliding window by the privacy budget ∈; ∈ r is the privacy budget at which the forward sliding window starts; is the remaining privacy budget in the backward sliding window; ∈ j is the privacy budget at which the backward sliding window starts.
[0105] Step 303, add noise to the privacy budget ∈ i to determine the optimal user privacy data.
[0106] In an embodiment, noise can be added to make the privacy data to be disturbed more stable, and when attacked maliciously, the privacy and usability of the privacy data to be disturbed can be guaranteed. The noise here can be Laplace noise, Gaussian noise, etc. Here, only the Laplace noise is taken as an example. The privacy budget ∈ i= 0 is expected, the perturbation operation is performed on the perturbed private data, and the following procedure can be executed.
[0107] 1 if v' i = 1 then
[0108] 2 Calculate the privacy budget ∈ at the current timestamp by the privacy budget allocation strategy i
[0109] 3 c' i = c i + Lap(1 / ∈ i );
[0110] / / Add Laplace noise to the calculated privacy budget ∈ i
[0111] else
[0112] 4 Let the current privacy budget ∈ i = 0
[0113] 5 c' i = c' r
[0114] / / The last privacy release is the approximate value of the current release
[0115] end
[0116] In the formula, c' i is the optimal user private data, c i is the private data to be perturbed, and Lap(1 / ∈ i ) is the noise added to the privacy budget ∈ i .
[0117] In addition, the optimal user private data determined after perturbation can be uploaded to the server through the communication terminal. In addition to the case in step 204, when the similarity value is greater than the preset similarity value and when the probability value of the similarity is negative, the second number of the flow user data is uploaded to the server as the user private data without privacy budget.
[0118] Here, direct upload to the server can be uploaded to the server through the communication terminal. The communication terminal here can use a TBOX communication terminal in the vehicle, and the server can be a TSP (Telematics Service Provider) automotive remote service provider, which is not limited here.
[0119] In the embodiment of the present application, the flowing user data of the vehicle is continuously collected by using the digital twin technology; thus, the vehicle data can be continuously published, ensuring the availability of the vehicle data, and then the flowing user data is preprocessed for privacy protection to determine the privacy data to be disturbed; the privacy data to be disturbed is operated for disturbance to determine the optimal user privacy data; wherein the optimal user privacy data is determined based on the statistical quantity of the privacy protection quantity closest to the user privacy data; thus, the availability is ensured while meeting the demand for privacy of the vehicle data.
[0120] Referring to Figure 6 , a schematic diagram of the architecture of a vehicle data privacy protection system provided by the embodiment of the present application is shown. Figure 6 As shown, it comprises:
[0121] The collection module is configured to continuously collect the flowing user data of the vehicle by using the digital twin technology.
[0122] The processing module is configured to preprocess the flowing user data for privacy protection to determine the privacy data to be disturbed.
[0123] The disturbance module is configured to operate the privacy data to be disturbed for disturbance to determine the optimal user privacy data.
[0124] The optimal user privacy data is determined based on the statistical quantity of the privacy protection quantity closest to the user privacy data.
[0125] In a possible embodiment, the collection module comprises (not shown in the figure):
[0126] The identification acquisition submodule is configured to acquire the unique identification of the vehicle.
[0127] The vehicle corresponding submodule is configured to determine the twin vehicle corresponding to the vehicle according to the unique identification by using the digital twin technology.
[0128] The data acquisition submodule is configured to continuously collect the flowing user data in the twin vehicle within a preset time period.
[0129] The flowing user data comprises: location information, license plate information, and driving path information.
[0130] In a possible embodiment, the processing module comprises (not shown in the figure):
[0131] The first quantity determination submodule is configured to determine the first quantity of the flowing user data of the vehicle.
[0132] The publishing submodule is configured to determine the second quantity of the flowing user data by using the local differential privacy protection technology to publish the first quantity of the flowing user data for privacy.
[0133] a similarity sub-module, configured to perform similarity calculation on the first quantity and the second quantity to output a similarity value;
[0134] a to-be-disturbed data sub-module, configured to determine the second quantity of the flow user data as the to-be-disturbed privacy data when the similarity value is less than or equal to a preset similarity value.
[0135] In a possible embodiment, the disturbance module comprises (not shown in the figure):
[0136] a window setting sub-module, configured to set a sliding window for the to-be-disturbed privacy data, and set a privacy budget ∈ of the sliding window;
[0137] a current budget sub-module, configured to calculate the privacy budget ∈ of the sliding window at a current timestamp based on a privacy budget allocation strategy i , ∈ i < ∈.
[0138] an optimal data sub-module, configured to disturb the to-be-disturbed privacy data by adding noise to the privacy budget ∈ i and determine optimal user privacy data.
[0139] In a possible embodiment, the moving direction of the sliding window comprises: forward and backward; and the current budget sub-module comprises (not shown in the figure):
[0140] an allocation unit, configured to allocate the privacy budget ∈ to a forward sliding window and a backward sliding window;
[0141] a budget calculation unit, configured to calculate the privacy budget ∈ of the forward sliding window and the privacy budget ∈ of the backward sliding window at the current timestamp based on a privacy budget allocation strategy i,f and i,b .
[0142] a budget comparison unit, configured to compare the size of the privacy budget ∈ of the forward sliding window i,f and the privacy budget ∈ of the backward sliding window i,b , and take the smaller one as the privacy budget ∈ of the sliding window at the current timestamp i .
[0143] In a possible embodiment, the budget comparison unit comprises (not shown in the figure):
[0144] the privacy budget ∈ of the forward sliding window i,f is calculated as follows:
[0145] k = ω - r + 1
[0146]
[0147] where k is the remaining timestamp in the forward sliding window; ω is the total timestamp of the sliding window; r is the timestamp at which the forward sliding window starts; is the remaining privacy budget in the forward sliding window; ∈ / 2 is the privacy budget allocated to the forward sliding window from the privacy budget ∈; ∈ r is the privacy budget at which the forward sliding window starts.
[0148] In a possible embodiment, the budget comparison unit further comprises (not shown in the figure):
[0149] The privacy budget ∈ of the backward sliding window i,b is calculated as follows:
[0150] j = i - ω + 1
[0151]
[0152] where j is the remaining timestamp in the backward sliding window; i is the current timestamp; ω is the total timestamp of the sliding window; is the remaining privacy budget in the backward sliding window; ∈ / 2 is the privacy budget allocated to the backward sliding window from the privacy budget ∈; ∈ j is the privacy budget at which the backward sliding window starts.
[0153] In a possible embodiment, it further comprises (not shown in the figure):
[0154] The direct uploading module is configured to, when the similarity value is greater than the preset similarity value, upload the second quantity of the mobile user data as user privacy data without privacy budget to the server during the privacy protection preprocessing of the mobile user data.
[0155] In a possible embodiment, the optimal data submodule comprises (not shown in the figure):
[0156] The privacy budget ∈ is added with noise for disturbance operation. i The calculation formula is as follows:
[0157] c' i = c i + Lap(1 / ∈ i )
[0158] where c' i is the optimal user privacy data, c i is the privacy data to be disturbed, and Lap(1 / ∈ i ) is the noise added to the privacy budget ∈ i .
[0159] It is apparent that the application can be implemented in a variety of other forms, without departing from the spirit or essential characteristics thereof. The disclosed embodiments are to be considered in all respects only as illustrative and not restrictive. The scope of the application is indicated by the appended claims rather than by the foregoing description, and all changes which come within the meaning and range of equivalency of the claims are intended to be embraced therein.
[0160] Those skilled in the art will appreciate that embodiments of the application can be devised for a method, a system, or a computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) embodying computer readable program code.
[0161] The present application is described in reference to the flowchart illustrations and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processing system or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams block or blocks. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks.
[0162] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart illustrations and / or block diagrams block or blocks. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks.
[0163] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart illustrations and / or block diagrams block or blocks. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks.
[0164] It should be pointed out finally that the above embodiments are only used to illustrate the technical solutions of the present application but not to limit it. Although the present application has been described in detail with reference to the above embodiments, it should be understood by those skilled in the art that the specific embodiments of the present application can be modified or replaced equivalently without departing from the spirit and scope of the present application, and any modification or equivalent replacement without departing from the spirit and scope of the present application should be covered in the protection scope of the claims of the present application.
Claims
1. A method for protecting the privacy of vehicle data, characterized in that, include: Utilize digital twin technology to continuously collect mobile user data for vehicles; The mobile user data is preprocessed for privacy protection to determine the privacy data to be disturbed; The privacy data to be perturbed is subjected to perturbation calculations to determine the optimal user privacy data. The optimal user privacy data is determined based on the statistical measure that best approximates the amount of privacy protection. The method of continuously collecting mobile user data of vehicles using digital twin technology includes: Obtain the vehicle's unique identifier; Using digital twin technology, the unique identifier is used to determine the twin vehicle corresponding to the vehicle; The mobile user data in the twin vehicles is continuously collected within a preset time period; The mobile user data includes: location information, license plate information, and travel route information; The step of performing privacy-preserving preprocessing on the mobile user data to determine the privacy data to be disturbed includes: Determine the first quantity of the current mobile user data for the vehicle; Using local differential privacy protection technology, a second number of mobile user data are determined by privacy-publishing a first number of the mobile user data. Calculate the similarity between the first quantity and the second quantity, and output the similarity value; When the similarity value is less than or equal to a preset similarity value, a second quantity of the mobile user data is determined as the privacy data to be disturbed; The step of performing perturbation calculations on the privacy data to be perturbed in order to determine the optimal user privacy data includes: Set a sliding window for the privacy data to be disturbed, and set a privacy budget for the sliding window. ; Calculate the privacy budget for the sliding window at the current timestamp based on the privacy budget allocation strategy. ; Regarding the privacy budget Noise is added to perform perturbation calculations to determine the optimal user privacy data; The sliding window moves in two directions: forward and backward; the privacy budget for the sliding window at the current timestamp is calculated based on the privacy budget allocation strategy. ,include: Privacy Budget Assign to the forward sliding window and the backward sliding window; The privacy budget for the forward sliding window at the current timestamp is calculated based on the privacy budget allocation strategy. Privacy budget for backsliding windows ; Compare the privacy budget of the forward sliding window and the privacy budget of the backward sliding window The size of the privacy budget is used, with the smaller value being the privacy budget for the sliding window at the current timestamp. ; Privacy budget for the forward sliding window The calculation formula is as follows: = [ ] In the formula, k is the remaining timestamp in the forward sliding window; The total timestamp of the sliding window; The timestamp of the start of the forward sliding window; The remaining privacy budget in the forward sliding window; For privacy budget Privacy budget allocated to the forward sliding window; Privacy budget for the initial step in the forward sliding window; Privacy budget for the backward sliding window The calculation formula is as follows: [ ] In the formula, The remaining timestamps in the backward sliding window; The current timestamp; The total timestamp of the sliding window; The remaining privacy budget in the backward sliding window; For privacy budget Privacy budget allocated to the backward sliding window; Privacy budget starts in the backward sliding window.
2. The method according to claim 1, characterized in that, Also includes: When performing privacy protection preprocessing on the mobile user data, if the similarity value is greater than the preset similarity value, a second number of the mobile user data will be uploaded to the server as user privacy data without privacy budget.
3. The method according to claim 1, characterized in that, The privacy budget The calculation formula for adding noise to the perturbation operation is shown below: In the formula, For optimal user privacy data, For privacy data to be disturbed, For privacy budget Added noise.
4. A vehicle data privacy protection system, characterized in that, include: The data acquisition module is used to continuously collect mobile user data of vehicles using digital twin technology; The processing module is used to perform privacy protection preprocessing on the mobile user data to determine the privacy data to be disturbed; The perturbation module is used to perform perturbation calculations on the privacy data to be perturbed in order to determine the optimal user privacy data; The optimal user privacy data is determined based on the statistical measure that best approximates the amount of privacy protection. The method of continuously collecting mobile user data of vehicles using digital twin technology includes: Obtain the vehicle's unique identifier; Using digital twin technology, the unique identifier is used to determine the twin vehicle corresponding to the vehicle; The mobile user data in the twin vehicles is continuously collected within a preset time period; The mobile user data includes: location information, license plate information, and travel route information; The step of performing privacy-preserving preprocessing on the mobile user data to determine the privacy data to be disturbed includes: Determine the first quantity of the current mobile user data for the vehicle; Using local differential privacy protection technology, a second number of mobile user data are determined by privacy-publishing a first number of the mobile user data. Calculate the similarity between the first quantity and the second quantity, and output the similarity value; When the similarity value is less than or equal to a preset similarity value, a second quantity of the mobile user data is determined as the privacy data to be disturbed; The step of performing perturbation calculations on the privacy data to be perturbed in order to determine the optimal user privacy data includes: Set a sliding window for the privacy data to be disturbed, and set a privacy budget for the sliding window. ; Calculate the privacy budget for the sliding window at the current timestamp based on the privacy budget allocation strategy. ; Regarding the privacy budget Noise is added to perform perturbation calculations to determine the optimal user privacy data; The sliding window moves in two directions: forward and backward; the privacy budget for the sliding window at the current timestamp is calculated based on the privacy budget allocation strategy. ,include: Privacy Budget Assign to the forward sliding window and the backward sliding window; The privacy budget for the forward sliding window at the current timestamp is calculated based on the privacy budget allocation strategy. Privacy budget for backsliding windows ; Compare the privacy budget of the forward sliding window and the privacy budget of the backward sliding window The size of the privacy budget is used, with the smaller value being the privacy budget for the sliding window at the current timestamp. ; Privacy budget for the forward sliding window The calculation formula is as follows: = [ ] In the formula, k is the remaining timestamp in the forward sliding window; The total timestamp of the sliding window; The timestamp of the start of the forward sliding window; The remaining privacy budget in the forward sliding window; For privacy budget Privacy budget allocated to the forward sliding window; Privacy budget for the initial step in the forward sliding window; Privacy budget for the backward sliding window The calculation formula is as follows: [ ] In the formula, The remaining timestamps in the backward sliding window; The current timestamp; The total timestamp of the sliding window; The remaining privacy budget in the backward sliding window; For privacy budget Privacy budget allocated to the backward sliding window; Privacy budget starts in the backward sliding window.
Citation Information
Patent Citations
Intelligent traffic path planning method based on federated learning and digital twinning
CN112700639A
Infinite data flow real-time privacy protection method and system based on dynamic budget allocation
CN114417423A