Information processing device, information processing method, and program

By designing a processing circuit in automotive accident investigation, setting the encryption level according to the time or type of sensor data and performing encryption processing, the difficulties of privacy protection and accident cause investigation are solved, and efficient and secure data storage and recovery are achieved.

CN119998807APending Publication Date: 2025-05-13SONY SEMICON SOLUTIONS CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202380070764.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-11-07
Filing Date
2023-09-26
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

It is difficult for the prior art to achieve privacy protection and accident cause investigation at the same time in automotive accident investigations, especially in the issue of privacy protection of image data and automatic erasing of audio data.

Method used

An information processing device is designed, and its processing circuit sets the encryption level according to the time or type of data generated by the sensor and performs encryption processing of the data. Specifically, the data is set to different levels in different time periods, and is encrypted and decrypted using different encryption keys.

Benefits of technology

It realizes the recording and storing of necessary data while protecting privacy in car accident investigations, ensuring that public institutions can freely recover data when needed to verify the cause of the accident, reducing the probability of data corruption and improving the efficiency of data encryption and recording.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119998807A_ABST
    Figure CN119998807A_ABST
Patent Text Reader

Abstract

[Problem] To achieve both privacy protection and accident cause investigation. [Solution] An information processing device is provided with a processing circuit. The processing circuit sets a level for data generated by a sensor mounted on a vehicle based on a time elapsed from generation of the data or a type of the data, and performs encryption processing of the data based on the set level.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing device, an information processing method, and a program. Background Art

[0002] In the event of a car accident, the cause can be investigated by referring to the video recorded by a dashcam, a sensor camera, etc. The dashcam, the sensor camera, etc. mainly have the function of recording the sensor data acquired by the vehicle-mounted sensor. On the other hand, from the perspective of privacy protection, it is generally problematic for others to view the sensor data acquired by the vehicle-mounted sensor.

[0003] Research and development of an in-vehicle device that can record necessary data while paying attention to privacy protection is conducted by detecting events such as collisions, sudden acceleration, or sudden steering wheel by using signals output from acceleration sensors, and retaining video or audio recordings of these events for self-verification.

[0004] However, technology in which privacy protection for image data is considered has not yet been achieved, and there is also a problem that audio data is automatically erased when a period of time has passed since the incident occurred, and it is still difficult to achieve privacy protection and accident cause investigation at the same time. Citation list Patent Literature

[0005] Patent Document 1: Japanese Patent Application Publication No. 2022-028858 Summary of the invention Technical Problems to be Solved by the Invention

[0006] Therefore, one of the non-limiting problems to be solved by the embodiments of the present disclosure is to achieve privacy protection and accident cause investigation at the same time. As some further non-limiting examples, the problems to be solved by the embodiments of the present disclosure may also be problems corresponding to the effects described in the embodiments. That is, the present disclosure can solve a problem corresponding to at least one of any effects described in the description of the embodiments of the present disclosure. Solutions to technical problems

[0007] According to one embodiment, an information processing device includes processing circuitry. The processing circuit sets a level for data generated by a sensor mounted on the vehicle based on a time elapsed since the data was generated or a type of the data, and The processing circuit performs encryption processing of the data based on the set level.

[0008] A storage unit may also be included, and The processing circuit may store the encrypted data in the storage unit.

[0009] The processing circuit may set the data until a first predetermined time elapses after the data is acquired to a first level, and The processing circuit may store the data of the first level in the storage section without encryption.

[0010] The processing circuit may set the data after the first predetermined time has passed since the data was acquired until a second predetermined time has passed, to the second level, and The processing circuit may encrypt the data of the second level using a first encryption key and store the data in the storage section.

[0011] The processing circuit may set the data after the second predetermined time has passed since the data was acquired until a third predetermined time has passed, to a third level, and The processing circuit may encrypt the data of the third level using a second encryption key and store the data in the storage section.

[0012] When the data set to the second level and encrypted is set to the third level after the second predetermined time has elapsed, the processing circuit may perform decryption corresponding to the first encryption key and then encrypt the data using the second encryption key.

[0013] After the first predetermined time has elapsed, the processing circuit may encrypt the data using a third encryption key, encrypt a key for decrypting the data encrypted using the third encryption key using the first encryption key, and store the encrypted key in association with the data encrypted using the third encryption key, and After the second predetermined time has elapsed, the processing circuit may encrypt a key for decrypting the data encrypted using the third encryption key using the second encryption key, and store the encrypted key in association with the data encrypted using the third encryption key.

[0014] The processing circuit may generate the third encryption key as a random key, and The processing circuit may update the third encryption key at every predetermined occasion.

[0015] After the third predetermined time has passed since the data was acquired, the processing circuit may discard the data or upload the data to an external server or storage.

[0016] The data may include one or more frames of data.

[0017] The data may include data having images and audio.

[0018] After the first predetermined time has elapsed since the data was acquired, the processing circuit may set the first type of data in the data to a second level and the second type of data in the data to a third level, The processing circuit may encrypt the data set to the second level using a first encryption key, The processing circuit may encrypt the data set to the third level using a second encryption key, and The processing circuit may store the encrypted data in the storage unit.

[0019] According to one embodiment, an electronic device includes a vehicle-mounted sensor and an information processing device according to any one of the above items. The processing circuit of the information processing device encrypts and stores the data sensed and generated by the vehicle-mounted sensor.

[0020] The vehicle-mounted sensor may include a camera unit.

[0021] The vehicle-mounted sensor may include a sound collecting unit.

[0022] According to one embodiment, an information processing method includes: Through the processing circuit, setting a level for data generated by a sensor mounted on the vehicle based on a time elapsed since the data was generated; and The encryption process of the data is performed based on the set level.

[0023] According to one embodiment, the program causes the processing circuit to perform an information processing method, the information processing method comprising: setting a level for data generated by a sensor mounted on the vehicle based on a time elapsed since the data was generated; and The encryption process of the data is performed based on the set level.

[0024] According to one embodiment, an information processing device includes processing circuitry. The processing circuit sets a level for data generated by the sensor based on a time elapsed since the data was generated or a type of the data, and The processing circuit performs encryption processing of the data based on the set level.

[0025] According to one embodiment, an information processing device includes a first encryption section, a second encryption section, and a data storage section. The first encryption unit encrypts data from a time after a first predetermined time has elapsed since the data was acquired until a second predetermined time has elapsed, based on a first encryption key. The second encryption unit encrypts data acquired after the second predetermined time has elapsed from acquisition of the data based on a second encryption key. The data storage unit stores data encrypted by the first encryption unit and the second encryption unit.

[0026] The encryption described in any of the above items may include encryption that implements at least one of the following: encryption that controls data access, and encryption that prevents data tampering. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 is a block diagram schematically showing an example of an electronic device according to the embodiment. Figure 2 is a flowchart showing a processing example of the information processing apparatus according to the embodiment. Figure 3 is a diagram showing an example of data storage according to an embodiment. Figure 4 is a block diagram schematically showing an example of an electronic device according to the embodiment. Figure 5 is a flowchart showing a processing example of the information processing apparatus according to the embodiment. Figure 6 is a diagram showing an example of data storage according to an embodiment. Figure 7 is a flowchart showing a processing example of the information processing apparatus according to the embodiment. Figure 8 is a diagram showing an example of data storage according to an embodiment. Fig. 9 is a block diagram showing an example of a schematic configuration of a vehicle control system. Fig.10 1 is an explanatory diagram showing an example of the installation positions of the vehicle exterior information detection unit and the imaging unit. DETAILED DESCRIPTION

[0028] The embodiments of the present disclosure are described below with reference to the accompanying drawings. The accompanying drawings are for illustration purposes, and the shapes and sizes of each structure in an actual device, the size ratios with other structures, etc. are not necessarily as shown in the drawings. In addition, since the accompanying drawings are shown in a simplified manner, in addition to what is shown in the accompanying drawings, structures required for implementation are also appropriately provided.

[0029] In addition, in the present disclosure, expressions such as "until a certain time has passed" and "after a certain time has passed" can be used as expressions indicating time, but whether the moment of the time is included in "until the time has passed" or "after the time has passed" can also be arbitrarily set according to the implementation form. That is, "until the time has passed" can be replaced with "before the time has passed", and "after the time has passed" can be replaced with "after the time has passed".

[0030] (First Implementation Method) Figure 1 1 is a block diagram schematically showing an electronic device 1 according to an embodiment. The electronic device 1 is, for example, a device including a sensor mounted on a car, and includes an on-vehicle sensor 10 and an information processing device 20. The electronic device 1 is a device capable of protecting the privacy of a person in the car, etc. by encrypting appropriate data, and outputting appropriate accident investigation data.

[0031] The vehicle-mounted sensor 10 acquires various information inside and outside the vehicle. The vehicle-mounted sensor 10 includes, for example, a sensor unit 100 and a data generation unit 102. In addition, although not shown, the vehicle-mounted sensor 10 may include a storage unit that stores data required for processing or processed data (such as sensing data required for data generation and generated data, etc.).

[0032] For example, it is desirable that the sensor unit 100 includes at least an imaging unit. The imaging unit included in the sensor unit 100 acquires optically acquired information inside and outside the vehicle. In addition, it is desirable that the sensor unit 100 includes a sound collecting unit. The sound collecting unit included in the sensor unit 100 acquires audio information inside and outside the vehicle.

[0033] The data generation unit 102 converts the information acquired by the sensor unit 100 into appropriate information, and generates data that can be confirmed by a person. For example, the data generation unit 102 can generate image data based on the information acquired from the camera unit (hereinafter, the concept including video data is referred to as image data). In addition, for example, the data generation unit 102 can generate audio data based on the information acquired from the sound collection unit. In the case where both the camera unit and the sound collection unit are provided, the data generation unit 102 can generate data in which image data generated from the data from the camera unit and audio data generated from the data from the sound collection unit are associated with each other.

[0034] The data generation unit 102 may be formed by a dedicated analog and / or digital electronic circuit, or may be implemented in a general-purpose processor, etc., in the form of information processing that specifically implements software using hardware resources. In the case of implementation by software, a program or execution file related to the software may be stored in a storage unit (not shown).

[0035] Furthermore, the data generating section 102 may be included in the information processing device 20 described below. In this case, data acquired by the vehicle-mounted sensor 10 may be transmitted to the information processing device 20, and data may be generated in the information processing device 20.

[0036] In addition, at least some functions of the vehicle-mounted sensor 10 and the information processing device 20 may be mounted on the same semiconductor substrate. For example, the sensor portion 100 may be an upper semiconductor layer, and at least a portion of the constituent elements of the data generation portion 102 and the information processing device 20 may be a lower semiconductor layer, and the electronic device 1 may include stacked semiconductor layers. These semiconductor layers may be formed separately and bonded by an appropriate method. In this case, the sensor portion 100 may be provided as a part of the information processing device 20. That is, as the electronic device 1, the information processing device 20 including the vehicle-mounted sensor 10 may be formed.

[0037] The information processing device 20 is a device that appropriately processes and stores information acquired by a sensor. The information processing device 20 includes a data storage unit 200 , a first encryption unit 202 , a second encryption unit 204 , a key storage unit 206 , a data control unit 208 , and an output I / F 210 .

[0038] The information processing device 20 includes, for example, a processing circuit and a storage circuit for realizing the above-mentioned configuration, and the processing circuit sets a privacy level for the data generated by the vehicle-mounted sensor 10 based on the time elapsed since the data was generated, and the processing circuit encrypts and stores the data based on the privacy level. Similar to the data generating unit 102, these processes may be realized by a dedicated electronic circuit, or may be realized in the form of information processing that specifically realizes software using hardware resources. In the case of executing the process by software, the program or execution file related to the software may be stored in the storage circuit.

[0039] The data storage section 200 stores data acquired and generated by the vehicle-mounted sensor 10. For example, the data is the data itself output from the vehicle-mounted sensor 10, or data encrypted at an appropriate privacy level at an appropriate timing.

[0040] For example, the following privacy levels are uniquely set in the data stored in the data storage unit 200. The first level is set for the data generated by the data generation unit 102 at this timing. The second level is set as the privacy level of the data after the first predetermined time has passed after the data generation unit 102 has generated the data. The third level is set as the privacy level of the data after the second predetermined time has passed after the data generation unit 102 has generated the data.

[0041] This level setting can be performed by a level setting unit (not shown), or each configuration can read the level through a timestamp stored in a storage unit. In addition, a mode can be adopted in which different storage methods are implemented for each piece of data by checking the time when the data was generated without setting the level.

[0042] Regarding the data of the first level, the data storage section 200 stores the data generated by the data generation section 102 .

[0043] Note that in the above description, the privacy level is set based on the time when the data generating section 102 generates data, but the present invention is not limited thereto, and the privacy level may be set based on the time when the sensor section 100 performs sensing (eg, scanning).

[0044] The first encryption unit 202 performs encryption processing on the data set to the second level for which a first predetermined time has passed since the acquisition of the data using the first encryption key, and stores the data in the data storage unit 200. At this time, the unencrypted data is deleted from the data storage unit 200. This data deletion may be performed by the first encryption unit 202, or may be performed by the data control unit 208.

[0045] The second encryption unit 204 performs encryption processing on the data set to the third level that has passed the second predetermined time since the acquisition of the data using the second encryption key, and stores the data in the data storage unit 200. As an example, the second encryption unit 204 decrypts the data using the first decryption key corresponding to the first encryption key (the key may be the same as or different from the first encryption key), and then encrypts the data using the second encryption key. As another example, at this time, the first encryption unit 202 or the decryption unit (not shown) decrypts the corresponding data using the first decryption key, and the second encryption unit 204 encrypts the corresponding data using the second encryption key.

[0046] At this time, similarly to the above, the data subjected to the first encryption process before the second encryption unit 204 or the data control unit 208 performs the second encryption process is deleted from the data storage unit 200, or the decrypted data subjected to the first encryption process is deleted.

[0047] The key storage unit 206 stores the first encryption key used for encryption by the first encryption unit 202 and the second encryption key used for encryption by the second encryption unit 204. In addition, the key storage unit 206 may store the first decryption key together with the second decryption key corresponding to the second encryption key. As another form, the decryption key may be a form that can be obtained from each encryption key. In this case, the predetermined component may also generate the decryption key at a necessary timing.

[0048] For example, the first encryption key is a key that can be decrypted by a public institution such as a police station. The first encryption unit 202 encrypts the second-level data using the key so that the public institution can decrypt the data after the first predetermined time has passed since acquisition until the second predetermined time has passed. For example, the first encryption key may be a key set when a product including the information processing device 20 of the present disclosure is shipped.

[0049] For example, the second encryption key is a key that can be decrypted by a user such as a driver or a car owner. For example, the second encryption key can be set by the user, or can be generated based on the user's biometric information. The second encryption unit 204 uses the key to encrypt the third level data so that after a second predetermined time has passed since acquisition, only the user or only a person who has obtained the user's permission can decrypt the data. For example, the second encryption key can be a key that can be set by the user when using a product including the information processing device 20 of the present disclosure, or a key generated by acquiring the user's biometric information.

[0050] In the figure, the data storage section 200 and the key storage section 206 are shown as different configurations, but this is shown as a non-limiting example. For example, the data storage section 200 and the key storage section 206 may be installed in a storage section (not shown) in the information processing device 20.

[0051] The data control section 208 discards the data stored in the data storage section 200, or outputs the data to the outside via the output I / F 210. For example, the data control section 208 may discard the data stored in the data storage section 200 for which a third predetermined time longer than the second predetermined time has passed. In addition, for example, the data control section 208 may discard the data for which the third predetermined time has passed from the data storage section 200, and transmit the data to the outside via the output I / F 210. As an example, the data control section 208 may upload the data after the third predetermined time has passed to an external server or storage.

[0052] The output I / F 210 is an interface for outputting data to the outside of the information processing device 20. The output I / F 210 may have any interface for appropriately outputting data to the outside, such as MIPI (registered trademark), USB, or a network interface.

[0053] Figure 2 2 is a flowchart showing the processing of the information processing device 20 according to the embodiment. For example, the flowchart shows the processing for the case where an event such as a traffic accident occurs.

[0054] The occurrence of an event can be detected by various sensors, for example, provided separately from the electronic device 1 or including the on-board sensor 10. For example, the sensor can be a sensor such as an acceleration sensor, a torque sensor, or a gyroscope sensor. The electronic device 1 can obtain data from these sensors via, for example, a controller area network (CAN) or the like to obtain event information. In addition, at least one of these sensors can be provided in the electronic device 1.

[0055] The information processing device 20 starts recording data (S100). According to the data input thereafter, appropriate encryption and data storage processing is performed.

[0056] The vehicle-mounted sensor 10 acquires data through sensing, converts the data into an appropriate format, and generates data to be recorded ( S200 ).

[0057] For data set to the first level until a first predetermined time has passed from data acquisition or data generation, the information processing device 20 stores data acquired from the vehicle-mounted sensor 10 in the data storage unit 200 without encrypting the data ( S102 ).

[0058] The first encryption unit 202 encrypts the data set to the second level after the first predetermined time has passed since the data acquisition or data generation until the second predetermined time has passed using the first encryption key, and stores the encrypted data in the data storage unit 200 (S104). For example, the first encryption unit 202 extracts the unencrypted data set to the second level stored in the data storage unit 200, and encrypts the data using the first encryption key. For example, after encryption, the data control unit 208 can discard the unencrypted data from the data storage unit 200.

[0059] The second encryption unit 204 uses the second encryption key to encrypt data set to the third level after the second predetermined time has passed since the data was acquired or generated until the third predetermined time has passed, and stores the encrypted data in the data storage unit 200 (S106). For example, the second encryption unit 204 extracts data stored in the data storage unit 200 that is not encrypted using the second encryption key and is set to the third level, and encrypts the data using the second encryption key. At this time, since the data is encrypted using the first encryption key, the data encrypted using the first encryption key can be decrypted and can be encrypted using the second encryption key. As another example, the data encrypted using the first encryption key can be further encrypted using the second encryption key.

[0060] For data for which a third predetermined time has elapsed from data acquisition or data generation, the data control section 208 may transmit the data to the outside and / or discard the data from the data storage section 200 ( S108 ).

[0061] In the case where no event occurs (S110: No), the information processing device 20 repeats the processing from S102 to S108. By this repetition, the information processing device 20 can record the data until the first predetermined time after the data is acquired or generated without encryption, record the data from the first predetermined time to the second predetermined time by the first encryption, record the data from the second predetermined time to the third predetermined time by the second encryption, and discard the data that has passed a certain time from the third predetermined time to ensure capacity. Note that in the case where the capacity of the data storage section 200 becomes insufficient, for example, the processing of S102 can be stopped, or in the case where the output I / F 210 is operating normally, data can be transmitted to the external server or the like in sequence starting from the old data.

[0062] In the case where an event has occurred (S110: Yes), the information processing device 20 continues the processing of S102 and stops other processing (S112). By performing processing in this manner, when data after the first predetermined time before the occurrence of an event (e.g., a traffic accident) is set to be accessible to anyone for accident verification, etc., a public agency can decrypt data before the first predetermined time before the occurrence of the accident while protecting privacy. In addition, data before the second predetermined time before the time that the public agency can decrypt can be stored in the data storage unit 200 as data that can be referenced with the user's permission.

[0063] The first predetermined time, the second predetermined time and the third predetermined time can be determined arbitrarily. For example, the first predetermined time can be set to 10 seconds, the second predetermined time can be set to 30 seconds, and the third predetermined time can be set to 3 minutes. Of course, these are given as non-limiting examples, and do not exclude setting shorter or longer times.

[0064] Note that S102 to S108 can be processed in parallel. Furthermore, the timing of S110 is not limited to the flowchart, and can be operated as an exception process.

[0065] Figure 3 : is a diagram showing an example of data stored according to the flowchart. Assume a current time t0, a first predetermined time t1, a second predetermined time t2, and a third predetermined time t3.

[0066] Data acquired between time t0-t1 and time t0, i.e., data before the first predetermined time has passed, is stored without encryption. Data acquired between time t0-t2 and time t0-t1, i.e., data after the first predetermined time has passed but before the second predetermined time has passed, is encrypted by the first encryption key and stored. Data acquired between time t0-t3 and time t0-t2, i.e., data after the second predetermined time has passed but before the third predetermined time has passed, is encrypted by the second encryption key and stored. Data acquired before time t0-t3, i.e., data after the third predetermined time has passed, is transmitted and / or discarded from the data storage unit 200 in a state encrypted by the second encryption key.

[0067] When an event such as a traffic accident occurs at time t0, data before t0 is stored in the data storage section 200 in this state, and on the other hand, newly acquired data is continuously stored in the data storage section 200 without being encrypted.

[0068] Here, the data may be, for example, data including image data and audio data, or may be image data or audio data. For example, the data may be data of one frame or a plurality of frames.

[0069] For example, in the case where the data is image data, encryption may be performed sequentially in each frame of the image according to a level set according to the predetermined time that has passed. As another example, for example, for each piece of image data of multiple frames, encryption may be performed frame by frame in sequence according to a level set according to the head or tail of the multiple frames, or data of an arbitrarily set predetermined frame number exceeding a predetermined time. The same applies to audio data or a combination of image data and audio data.

[0070] That is, the size of the data block to be encrypted can be set arbitrarily. However, for example, a data group exceeding the first predetermined time has little meaning in the present disclosure, so it is desirable that the size of the data group is smaller than the size of the data group that can be acquired within the first predetermined time. Similarly, it is desirable to encrypt data in units of a size smaller than the size of the data group acquired during (second predetermined time)-(first predetermined time) and (third predetermined time)-(second predetermined time).

[0071] For example, when the scanning speed of the sensor is 30 fps and the first predetermined time is 10 seconds, the data may be divided and encrypted every 30 frames. As another example, the data may be encrypted frame by frame. In this way, the size of the data may be combined in an arbitrarily set unit within an appropriate range, and encryption processing may be performed.

[0072] As described above, according to the present embodiment, by storing the acquired data in an unencrypted state, a state encrypted with a first encryption key, and a state encrypted with a second encryption key, based on the elapsed time, it is possible to appropriately protect the privacy of the user while recording data that can be freely restored as needed by public agencies, etc. in the event of an incident such as an accident to verify the accident.

[0073] (Second Implementation Method) In the above embodiment, as an example, a mode has been described in which after the second-level data encrypted with the first encryption key reaches the third level, decryption corresponding to the first encryption key is performed, and then the data is encrypted with the second encryption key and stored.

[0074] Figure 4 1 is a block diagram schematically showing an example of an electronic device 1 according to an embodiment. The information processing device 20 of the electronic device 1 includes Figure 1 In addition to the similar configuration in , the third encryption unit 212 and the key issuing unit 214 are included. Note that the third encryption unit 212 is not an essential configuration, and for example, the first encryption unit 202 may perform the following processing of the third encryption unit 212.

[0075] The third encryption unit 212 encrypts the unencrypted data stored in the data storage unit 200 using the third encryption key issued by the key issuing unit 214. The encryption timing may be when data is input from the data generating unit 102 to the data storage unit 200, or may be when data is set to the second level after a first predetermined time has passed.

[0076] The key issuing unit 214 issues the third encryption key. For example, the key issuing unit 214 issues the third encryption key at each predetermined timing and updates the third encryption key. For example, the predetermined timing may be the timing when encryption of the data used as the encryption unit is completed in the above-mentioned embodiment, or may be every predetermined time.

[0077] After the second-level data is encrypted by the third encryption unit 212, the first encryption unit 202 encrypts the third encryption key using the first encryption key. The second encryption unit 204 encrypts the third encryption key for the third-level data using the second encryption key. Each of the first encryption unit 202 and the second encryption unit 204 stores the encrypted data and the encrypted third encryption key in the data storage unit 200 in association with each other.

[0078] In the case of extracting data, the data and the encrypted third encryption key used to encrypt the data may be acquired from the data storage unit 200, the third encryption key may be decrypted using a key corresponding to the privacy level, and the data may be decrypted using the decrypted third encryption key.

[0079] The data is encrypted using the third encryption key, and the first encryption unit 202 and the second encryption unit 204 encrypt the same third encryption key used for the encryption using the first encryption key and the second encryption key when the data is converted to the second level and the third level respectively.

[0080] The third encryption key may be stored in the key storage unit 206 until the encryption of the third encryption key using the second encryption key is completed. As another example, the third encryption key encrypted using the first encryption key may be decrypted when the third encryption key is encrypted using the second encryption key, and the second encryption unit 204 may encrypt the decrypted third encryption key using the second encryption key.

[0081] In the former case, a storage area for storing the third encryption key is required, and in the case where the information processing device 20 fails due to an event or the like, there is a possibility that the third encryption key remains in the storage area. However, the time and calculation cost at the time of performing encryption using the second encryption key can be reduced. Therefore, it is desirable to have: a configuration in which the third encryption key is automatically deleted from the memory in the case of a failure of the information processing device 20, for example, by using a volatile memory; or a configuration in which the third encryption key is deleted from the memory when a failure or the like occurs.

[0082] In the latter case, although the cost of decrypting the third encryption key encrypted with the first encryption key is incurred at the timing of encryption with the second encryption key, the storage cost can be reduced and an event that may become a security weakness can be avoided.

[0083] As described above, the data stored in the data storage section 200 is encrypted using the third encryption key. Therefore, when the same third encryption key is used for a long time, there is a possibility that the data of the third level is decrypted using a decryption key that can only be seen at the second level.

[0084] Therefore, as described above, the key issuing unit 214 updates the third encryption key at a predetermined timing. For example, in the case where the first predetermined time is 10 seconds, the key issuing unit 214 may update the third encryption key in a span such as every 1 second, or may update the third encryption key every time one unit of data encryption is completed. The numerical values ​​are given as examples and are not limited to these numerical values.

[0085] In addition, for example, the key issuing unit 214 may issue a random key as the third encryption key. By issuing such a third encryption key, a third encryption key capable of appropriately protecting privacy can be generated.

[0086] Figure 5is a flowchart showing the processing of the information processing apparatus 20 according to the embodiment. Figure 2 The same figure numbers in the figure basically represent the same processing, and thus their detailed description will be omitted.

[0087] The third encryption unit 202 encrypts the data of the second level using the third encryption key, and stores the encrypted data in the data storage unit 200 (S120). Note that the third encryption unit 202 may encrypt the data of the first level using the third encryption key in advance, and store the encrypted data in the data storage unit 200. In this case, by associating the data with the appropriate key, the data of the second level can be appropriately decrypted.

[0088] For the data of the second level, the first encryption unit 202 encrypts the third encryption key that has encrypted the data using the first encryption key, and stores the encrypted key in the data storage unit 200 in association with the data ( S122 ).

[0089] For the data of the third level, the second encryption unit 204 encrypts the third encryption key that encrypted the data with the second encryption key, and stores the encrypted key in association with the data in the data storage unit 200 (S124). Note that in the case where the third encryption key used for encryption is not stored in the memory until this timing, a process of acquiring the third encryption key encrypted with the first encryption key from the data storage unit 200, decrypting the third encryption key, and then encrypting the third encryption key again with the second encryption key may be performed.

[0090] Figure 6 is a diagram showing an example of storage data according to an embodiment. Figure 6 As shown, in this embodiment, the data is encrypted using the third encryption key. Depending on the privacy level, the third encryption key used to encrypt the data is encrypted using different keys. Then, the encrypted third encryption key is stored in association with each piece of data.

[0091] Note that in this embodiment, a construction has been described in which the third encryption key is encrypted using the first encryption key or the second encryption key, but the present invention is not limited to this, and the third decryption key used to decrypt data encrypted using the third encryption key can be encrypted using the first encryption key or the second encryption key.

[0092] As described above, according to the present embodiment, similar to the first embodiment described above, data on the accident cause investigation can be extracted as needed while protecting privacy, and in addition, the time cost and calculation cost for encryption can be reduced. As a result, the probability of data corruption during encryption can be reduced, and more appropriate data encryption and recording can be performed.

[0093] (Third Implementation Option) In the above-described respective embodiments, the encryption level is changed as time passes, but the mode of the present disclosure is not limited thereto.

[0094] Figure 7 is a flowchart showing the processing of the information processing apparatus 20 according to the embodiment. S100 and S200 are similar to those in the above-described embodiment.

[0095] The data storage section 200 records the data output from the data generation section 102 without encrypting the data ( S140 ).

[0096] The data control section 208 discards the data stored in the data storage section 200 and for which the third predetermined time has elapsed from the data control section 208 and / or uploads the data to an external server or the like ( S142 ).

[0097] As described above, in the present embodiment, data until the third predetermined time has passed is stored without encryption in the data storage section 200. Note that at this timing, the data control section 208 may add a privacy level to the data in the data storage section 200, for example.

[0098] In the case where no event occurs ( S144 : No), the processes of S140 to S142 are repeatedly performed, and data for which the third predetermined time has not elapsed is continuously stored in the data storage section 200 .

[0099] When an event occurs ( S144 : Yes), the data storage unit 200 continues to record the data generated by the data generation unit 102 ( S146 ). At this time, the data control unit 208 may stop uploading the data to the server or the like, and erase the data from the data storage unit 200 .

[0100] The first encryption unit 202 encrypts the second-level data for which the first predetermined time has elapsed since the data was generated at the timing of the event occurrence, using the first encryption key ( S148 ).

[0101] Similarly, the second encryption unit 204 encrypts the third level data for which the second predetermined time has passed since the data was generated at the time of the event occurrence using the second encryption key (S150). Note that in the case where the data for which the third predetermined time has passed is stored in the data storage unit 200, the second encryption unit 204 may also encrypt the data for which the third predetermined time has passed using the second encryption key.

[0102] As described above, according to this embodiment, encryption according to the level can be performed at the timing of an event. By performing such processing, the cost of data recording can be reduced, and more resources of the information processing device 20 can be allocated to other processing.

[0103] Note that in the above description, encryption similar to that in the first embodiment is used, but encryption similar to that in the second embodiment may also be used. In this case, data after the first predetermined time has passed may be sequentially encrypted using the third encryption key, and the data may be stored in association with the third encryption key, and the decryption key of the third encryption key associated with the data encrypted when the event occurs may be sequentially encrypted using the first encryption key or the second encryption key according to the level, and the decryption key may be stored in association with each data.

[0104] In this way, access is free as long as no incident has occurred, but privacy protection can be applied when an incident occurs.

[0105] (Fourth Implementation Scheme) In the above-described various embodiments, the privacy level is given according to the time elapsed from the generation of data, but the present disclosure is not limited thereto.

[0106] Figure 8 is a diagram showing an example of data storage according to an embodiment. Figure 8 As shown, the information processing device 20 may set the encryption level according to the type of data rather than the time elapsed from the data generation. As a non-limiting example, the first type of data may be image data, and the second type of data may be audio data.

[0107] The configuration of the information processing device 20 and the processing of the information processing device 20 may be similar to those in the above-described embodiment.

[0108] The information processing device 20 sets the data until the first predetermined time has passed to the first level, and records the data without encryption in the data storage section 200. In this state, the information processing device 20 sets the level of the first type of data after the first predetermined time has passed to the second level, and sets the level of the second type of data after the first predetermined time has passed to the third level.

[0109] After the first predetermined time has passed, the first encryption unit 202 encrypts the data set to the second level using the first encryption key. Similarly, after the first predetermined time has passed, the second encryption unit 204 encrypts the data set to the third level using the second encryption key. Of course, even in the mode where the first encryption unit 202 and the second encryption unit 204 encrypt the third encryption key, similar processing can be performed.

[0110] The data after the third predetermined time has passed is appropriately processed by the data control section 208 .

[0111] As described above, the privacy level can also be set according to the data type. According to this embodiment, the privacy level of data including a large amount of information on privacy can be set high, and privacy protection can be further strengthened and data required for accident investigation can be appropriately acquired.

[0112] Note that in each of the above embodiments, encryption mainly sets whether data content can be browsed, but is not limited to this. For example, encryption can be encryption to prevent data tampering. In addition, encryption can be encryption to restrict data browsing and prevent data tampering.

[0113] Examples of encryption used to prevent tampering include, but are not limited to, Advanced Encryption Standard (AES), Cipher-based Message Authentication Code (CMAC), Galois Message Authentication Code (GMAC), and techniques where only someone who knows the key can create an identifier. Encryption to prevent data tampering can be applied to data at all privacy levels. By performing such processing, data tampering can be prevented and evidence capabilities can be improved.

[0114] In addition, in each of the above-mentioned embodiments, an example of the data to be recorded is shown as data about the vehicle acquired by the vehicle-mounted sensor 10, but the mode of the present disclosure is not limited thereto. For example, it can be used for a fixed-point camera such as a surveillance camera, or it can be used for a mobile terminal such as a smartphone or a tablet. Even in this case, when an event occurs, the immediately preceding data can be easily accessed, and encryption and anti-tampering processing that sets a privacy level according to the elapsed time or the type of data can be performed.

[0115] The technology according to the present disclosure can be applied to various products. For example, the technology according to the present disclosure can also be implemented as a device installed on any type of mobile body such as an automobile, an electric car, a hybrid electric car, a motorcycle, a bicycle, a personal mobile device, an airplane, a drone, a ship, a robot, a construction machine, an agricultural machine (tractor), etc.

[0116] Fig. 9 7000 is a block diagram showing a schematic configuration example of a vehicle control system 7000 as an example of a mobile body control system to which the technology according to the present disclosure can be applied. The vehicle control system 7000 includes a plurality of electronic control units connected to each other via a communication network 7010. Fig. 9In the example shown, the vehicle control system 7000 includes a drive system control unit 7100, a body system control unit 7200, a battery control unit 7300, an external information detection unit 7400, an internal information detection unit 7500, and an integrated control unit 7600. For example, the communication network 7010 connecting the plurality of control units to each other may be an in-vehicle communication network conforming to any standard such as a controller area network (CAN), a local interconnect network (LIN), a local area network (LAN), FlexRay (registered trademark), or the like.

[0117] Each control unit includes: a microcomputer that executes algorithm processing according to various programs; a storage unit that stores programs executed by the microcomputer, parameters for various operations, etc.; and a drive circuit that drives various control object devices. Each control unit also includes: a network interface (I / F) for communicating with other control units via the communication network 7010; and a communication I / F for communicating with devices, sensors, etc. inside and outside the vehicle through wired or wireless communications. Fig. 9 7, a microcomputer 7610, a general communication I / F 7620, a dedicated communication I / F 7630, a positioning unit 7640, a beacon receiving unit 7650, an in-vehicle device I / F 7660, a sound / image output unit 7670, an in-vehicle network I / F 7680, and a storage unit 7690 are shown as the functional configuration of the integrated control unit 7600. Other control units also include a microcomputer, a communication I / F, a storage unit, and the like.

[0118] The drive system control unit 7100 controls the operation of devices related to the drive system of the vehicle according to various programs. For example, the drive system control unit 7100 is used as a control device for the following devices: a drive force generating device such as an internal combustion engine, a drive motor, etc. for generating the drive force of the vehicle, a drive force transmitting mechanism for transmitting the drive force to the wheels, a steering mechanism for adjusting the steering angle of the vehicle, a braking device for generating the braking force of the vehicle, etc. The drive system control unit 7100 may have a function as a control device for an anti-lock braking system (ABS), an electronic stability control (ESC), etc.

[0119] The drive system control unit 7100 is connected to the vehicle state detection unit 7110. For example, the vehicle state detection unit 7110 includes at least one of a gyro sensor for detecting the angular velocity of the axial rotational motion of the vehicle body, an acceleration sensor for detecting the acceleration of the vehicle, and a sensor for detecting the amount of operation of the accelerator pedal, the amount of operation of the brake pedal, the steering angle of the steering wheel, the engine speed, or the wheel speed. The drive system control unit 7100 performs algorithm processing using the signal input from the vehicle state detection unit 7110, and controls the internal combustion engine, the drive motor, the electric power steering device, the brake device, and the like.

[0120] The body system control unit 7200 controls the operation of various devices provided on the vehicle body according to various programs. For example, the body system control unit 7200 is used as a control device for a keyless entry system, a smart key system, a power window device, or various lights such as a headlight, a reverse light, a brake light, a turn signal light, a fog light, etc. In this case, a radio wave or a signal of various switches transmitted from a mobile device as a substitute for a key may be input to the body system control unit 7200. The body system control unit 7200 receives these input radio waves or signals and controls the door lock device, the power window device, the lights, etc. of the vehicle.

[0121] The battery control unit 7300 controls the secondary battery 7310 as the power supply source for the drive motor according to various programs. For example, information about the battery temperature, the battery output voltage, the remaining amount of power in the battery, etc. is provided to the battery control unit 7300 from the battery device including the secondary battery 7310. The battery control unit 7300 performs algorithm processing using these signals, and performs control for adjusting the temperature of the secondary battery 7310 or control of a cooling device provided on the battery device, etc.

[0122] The vehicle exterior information detection unit 7400 detects information about the exterior of the vehicle including the vehicle control system 7000. For example, the vehicle exterior information detection unit 7400 is connected to at least one of the camera unit 7410 and the vehicle exterior information detection unit 7420. The camera unit 7410 includes at least one of a time-of-flight (ToF) camera, a stereo camera, a monocular camera, an infrared camera, and other cameras. For example, the vehicle exterior information detection unit 7420 includes at least one of an environmental sensor for detecting current atmospheric conditions or weather conditions and a peripheral information detection sensor for detecting other vehicles, obstacles, pedestrians, and the like around the vehicle including the vehicle control system 7000.

[0123] For example, the environmental sensor may be at least one of a raindrop sensor for detecting rain, a fog sensor for detecting fog, a sunshine sensor for detecting the degree of sunshine, and a snow sensor for detecting snowfall. The peripheral information detection sensor may be at least one of an ultrasonic sensor, a radar device, and a LIDAR (LIDAR: light detection and ranging, or laser imaging detection and ranging) device. Each of the imaging unit 7410 and the vehicle exterior information detection unit 7420 may be provided as an independent sensor or device, or may be provided as a device in which a plurality of sensors or devices are integrated.

[0124] here, Fig.10An example of the installation position of the camera unit 7410 and the vehicle exterior information detection unit 7420 is shown. For example, the camera units 7910, 7912, 7914, 7916 and 7918 are arranged at least one of the positions on the front nose, side mirrors, rear bumper and rear door of the vehicle 7900 and the position on the upper part of the windshield inside the vehicle. The camera unit 7910 arranged on the front nose and the camera unit 7918 arranged on the upper part of the windshield inside the vehicle mainly obtain the image in front of the vehicle 7900. The camera units 7912 and 7914 arranged on the side mirrors mainly obtain the image of the side of the vehicle 7900. The camera unit 7916 arranged on the rear bumper or the rear door mainly obtains the image of the rear of the vehicle 7900. The camera unit 7918 arranged on the upper part of the windshield inside the vehicle is mainly used to detect the front vehicle, pedestrians, obstacles, signal lights, traffic signs, lanes, etc.

[0125] Notice, Fig.10 Examples of the imaging ranges of the respective imaging units 7910, 7912, 7914, and 7916 are shown. Imaging range a represents the imaging range of the imaging unit 7910 provided on the front nose. Imaging ranges b and c represent the imaging ranges of the imaging units 7912 and 7914 provided on the side mirrors, respectively. Imaging range d represents the imaging range of the imaging unit 7916 provided on the rear bumper or the rear door. For example, by superimposing image data captured by the imaging units 7910, 7912, 7914, and 7916, a bird's-eye view image of the vehicle 7900 viewed from above can be obtained.

[0126] For example, the vehicle exterior information detection units 7920, 7922, 7924, 7926, 7928, and 7930 disposed at the front, rear, side, and corner of the vehicle 7900 and the upper portion of the windshield inside the vehicle may be ultrasonic sensors or radar devices. For example, the vehicle exterior information detection units 7920, 7926, and 7930 disposed at the front nose of the vehicle 7900, the rear bumper of the vehicle 7900, the rear door, and the upper portion of the windshield inside the vehicle may be LIDAR devices. These vehicle exterior information detection units 7920-7930 are mainly used to detect vehicles ahead, pedestrians, obstacles, and the like.

[0127] return Fig. 9, the description continues. The vehicle exterior information detection unit 7400 enables the camera unit 7410 to capture images of the outside of the vehicle and receives the captured image data. In addition, the vehicle exterior information detection unit 7400 receives detection information from the vehicle exterior information detection unit 7420 connected to the vehicle exterior information detection unit 7400. In the case where the vehicle exterior information detection unit 7420 is an ultrasonic sensor, a radar device, or a LIDAR device, the vehicle exterior information detection unit 7400 transmits ultrasonic waves, electromagnetic waves, etc., and receives information of the received reflected waves. The vehicle exterior information detection unit 7400 can perform detection processing of objects such as people, vehicles, obstacles, signs, characters on the road surface, etc. based on the received information, or perform detection processing of the distance therebetween. The vehicle exterior information detection unit 7400 can perform environmental recognition processing of identifying rainfall, fog, road conditions, etc. based on the received information. The vehicle exterior information detection unit 7400 can calculate the distance to the object outside the vehicle based on the received information.

[0128] In addition, the vehicle exterior information detection unit 7400 can perform image recognition processing to identify people, vehicles, obstacles, signs, characters on the road surface, etc. based on the received image data, or perform distance detection processing therebetween. The vehicle exterior information detection unit 7400 can perform processing such as distortion correction and alignment on the received image data, and can synthesize image data captured by multiple different camera units 7410 to generate a bird's-eye view image or a panoramic image. The vehicle exterior information detection unit 7400 can use the image data captured by different camera units 7410 to perform viewpoint conversion processing.

[0129] The in-vehicle information detection unit 7500 detects information about the interior of the vehicle. For example, the in-vehicle information detection unit 7500 is connected to a driver state detection unit 7510 that detects the driver's state. The driver state detection unit 7510 may include a camera that takes a video of the driver, a biosensor that detects the driver's biometric information, a microphone that collects in-vehicle sounds, and the like. For example, the biosensor is arranged in a seat surface, a steering wheel, and the like, and detects the biometric information of an occupant sitting in a seat or a driver holding a steering wheel. The in-vehicle information detection unit 7500 can calculate the driver's fatigue level or the driver's concentration level based on the detection information input from the driver state detection unit 7510, or can determine whether the driver is taking a nap. The in-vehicle information detection unit 7500 can perform processing such as noise elimination processing on the audio signal obtained by sound collection.

[0130] The integrated control unit 7600 controls the overall operation within the vehicle control system 7000 according to various programs. The integrated control unit 7600 is connected to the input unit 7800. For example, the input unit 7800 is implemented by a device such as a touch panel, a button, a microphone, a switch, a joystick, etc., which can be input by the occupant. Data obtained by voice recognition of a voice input via a microphone can be supplied to the integrated control unit 7600. For example, the input unit 7800 can be a remote control device using infrared or other radio waves, or an external connection device such as a mobile phone, a personal digital assistant (PDA), etc. that supports the operation of the vehicle control system 7000. For example, the input unit 7800 can be a camera. In this case, the occupant can input information through gestures. Alternatively, data obtained by detecting the movement of a wearable device worn by the occupant can be input. In addition, for example, the input unit 7800 may include an input control circuit that generates an input signal based on information input by the occupant, etc. using the above-mentioned input unit 7800 and outputs the generated input signal to the integrated control unit 7600. The occupant or the like inputs various data or gives instructions for processing operations to the vehicle control system 7000 through the operation input unit 7800 .

[0131] The storage unit 7690 may include a read-only memory (ROM) storing various programs executed by the microcomputer and a random access memory (RAM) storing various parameters, operation results, sensor values, etc. In addition, the storage unit 7690 may be implemented by a magnetic storage device such as a hard disk drive (HDD), a semiconductor storage device, an optical storage device, a magneto-optical storage device, or the like.

[0132] The general communication I / F 7620 is a widely used communication I / F that mediates communication with various devices existing in the external environment 7750. The general communication I / F 7620 can implement cellular communication protocols such as Global System for Mobile Communications (GSM (registered trademark)), Worldwide Interoperability for Microwave Access (WiMAX (registered trademark)), Long Term Evolution (LTE (registered trademark)), Advanced LTE (LTE-A), or other wireless communication protocols such as wireless LAN (also known as Wireless Fidelity (Wi-Fi (registered trademark)), Bluetooth (registered trademark), etc.). For example, the general communication I / F 7620 can be connected to a device (e.g., an application server or a control server) existing on an external network (e.g., the Internet, a cloud network, or a company private network) via a base station or an access point. In addition, for example, the general communication I / F 7620 can be connected to a terminal existing near the vehicle (e.g., the terminal is a terminal of a driver, a pedestrian, or a store, or a machine type communication (MTC) terminal) using a peer-to-peer (P2P) technology.

[0133] The dedicated communication I / F 7630 is a communication I / F that supports a communication protocol developed for use in a vehicle. For example, the dedicated communication I / F 7630 may implement a standard protocol such as Wireless Access in a Vehicular Environment (WAVE), which is a combination of Institute of Electrical and Electronics Engineers (IEEE) 802.11p as a lower layer and IEEE 1609 as an upper layer, dedicated short range communication (DSRC), or a cellular communication protocol. The dedicated communication I / F 7630 generally performs V2X communication as a concept, which includes one or more of communication between vehicles (vehicle-to-vehicle), communication between roads and vehicles (vehicle-to-infrastructure), communication between vehicles and homes (vehicle-to-home), and communication between pedestrians and vehicles (vehicle-to-pedestrian).

[0134] For example, the positioning unit 7640 performs positioning by receiving a GNSS signal (e.g., a GPS signal from a GPS satellite) from a GNSS satellite, and generates position information including the latitude, longitude, and altitude of the vehicle. Incidentally, the positioning unit 7640 may identify the current position by exchanging signals with a wireless access point, or may obtain position information from a terminal having a positioning function such as a mobile phone, a personal handyphone system (PHS), or a smart phone.

[0135] For example, the beacon receiving unit 7650 receives radio waves or electromagnetic waves transmitted from a radio station installed on the road, etc., thereby obtaining information on the current position, congestion, closed roads, required time, etc. Incidentally, the function of the beacon receiving unit 7650 may be included in the above-mentioned dedicated communication I / F 7630.

[0136] The in-vehicle device I / F 7660 is a communication interface that mediates the connection between the microcomputer 7610 and various in-vehicle devices 7760 present in the vehicle. The in-vehicle device I / F 7660 can establish a wireless connection using a wireless communication protocol such as wireless LAN, Bluetooth (registered trademark), near field communication (NFC), or wireless universal serial bus (WUSB). In addition, the in-vehicle device I / F 7660 can establish a wired connection through a universal serial bus (USB), a high-definition multimedia interface (HDMI (registered trademark)), a mobile high-definition link (MHL), etc. via a connection terminal not shown in the figure (if necessary, it can also be via a cable). For example, the in-vehicle device 7760 may include at least one of a mobile device and a wearable device owned by an occupant and an information device carried or attached to the vehicle. The in-vehicle device 7760 may also include a navigation device that searches for a route to an arbitrary destination. The in-vehicle device I / F 7660 exchanges control signals or data signals with these in-vehicle devices 7760.

[0137] The in-vehicle network I / F 7680 is an interface which mediates communication between the microcomputer 7610 and the communication network 7010. The in-vehicle network I / F 7680 transmits and receives signals and the like according to a predetermined protocol supported by the communication network 7010.

[0138] The microcomputer 7610 of the integrated control unit 7600 controls the vehicle control system 7000 according to various programs based on information obtained via at least one of the general communication I / F 7620, the dedicated communication I / F 7630, the positioning unit 7640, the beacon receiving unit 7650, the in-vehicle device I / F 7660, and the in-vehicle network I / F 7680. For example, the microcomputer 7610 may calculate a control target value of a driving force generating device, a steering mechanism, or a braking device based on the obtained information about the inside and outside of the vehicle, and output a control command to the drive system control unit 7100. For example, the microcomputer 7610 may perform cooperative control aimed at realizing an advanced driver assistance system (ADAS) function including vehicle collision avoidance or collision mitigation, following driving based on vehicle-to-vehicle distance, vehicle speed keeping driving, vehicle collision warning, vehicle lane departure warning, and the like. In addition, microcomputer 7610 can perform cooperative control intended for autonomous driving, etc., which controls the driving force generating device, steering mechanism, braking device, etc. based on the information obtained about the vehicle's surroundings, allowing the vehicle to travel automatically without relying on the driver's operation.

[0139] The microcomputer 7610 can generate three-dimensional distance information between the vehicle and objects such as surrounding structures and people based on information obtained via at least one of the general communication I / F 7620, the dedicated communication I / F 7630, the positioning unit 7640, the beacon receiving unit 7650, the in-vehicle device I / F 7660, and the vehicle network I / F 7680, and generate local map information including surrounding information about the current position of the vehicle. In addition, the microcomputer 7610 can predict dangers such as vehicle collision, approach of pedestrians, etc., entering a closed road, etc. based on the obtained information, and generate a warning signal. For example, the warning signal can be a signal for generating a warning sound or lighting a warning light.

[0140] The sound / image output unit 7670 sends an output signal of at least one of sound and image to an output device, which can visually or auditorily notify the vehicle occupants or the outside of the vehicle of information. Fig. 9In the example of , an audio speaker 7710, a display unit 7720, and an instrument panel 7730 are shown as output devices. For example, the display unit 7720 may include at least one of an in-vehicle display and a head-up display. The display unit 7720 may have an augmented reality (AR) display function. The output device may be a device other than these devices, and may be other devices such as headphones, wearable devices such as glasses-type displays worn by passengers, projectors, lights, etc. In the case where the output device is a display device, the display device visually displays the results obtained by various processes performed by the microcomputer 7610 or information received from other control units in various forms such as text, images, tables, charts, etc. In addition, in the case where the output device is an audio output device, the audio output device converts an audio signal composed of reproduced audio data or sound data, etc. into an analog signal and outputs the analog signal audibly.

[0141] Note that Fig. 9 In the example shown, at least two control units connected via the communication network 7010 can be integrated into one control unit. Alternatively, each individual control unit may include multiple control units. In addition, the vehicle control system 7000 may include other control units not shown in the figure. In addition, part or all of the functions performed by one of the control units in the above description can be assigned to other control units. In other words, as long as information can be sent and received via the communication network 7010, any control unit can perform predetermined algorithm processing. Similarly, a sensor or device connected to one control unit can be connected to other control units, and multiple control units can send and receive detection information to each other via the communication network 7010.

[0142] Note that for reference Figures 1 to 8 The computer program for each function of the information processing device 20 according to the present embodiment described above can be installed on any control unit, etc. In addition, a computer-readable recording medium storing such a computer program can be provided. The recording medium is, for example, a magnetic disk, an optical disk, a magneto-optical disk, a flash memory, etc. In addition, without using a recording medium, the above-mentioned computer program can be distributed via, for example, a network.

[0143] In the vehicle control system 7000, referring to Figures 1 to 8 The electronic device 1 or information processing device 20 according to the present embodiment described above can be applied to Fig. 9The vehicle exterior information detection unit 7400 or the vehicle interior information detection unit 7500 of the application example shown. For example, the camera unit 7410, the vehicle exterior information detection unit 7420 and / or the driver state detection unit 7510 may be implemented as a part of the vehicle-mounted sensor 10. For example, at least one configuration of the vehicle exterior information detection unit 7400 and / or the vehicle interior information detection unit 7500 may be at least one configuration of the information processing device 20.

[0144] The above-described embodiments may have the following forms. (1) An information processing device includes a processing circuit that sets a level for data generated by a sensor mounted on a vehicle based on the time elapsed since the data was generated or the type of the data, and performs encryption processing of the data based on the set level. (2) The information processing device according to (1), further comprising a storage unit, The processing circuit stores the encrypted data in the storage unit. (3) The information processing device according to (2), wherein The processing circuit sets the data until a first predetermined time elapses after the data is acquired to a first level, and The processing circuit stores the data of the first level in the storage section without encryption. (4) The information processing device according to (3), wherein The processing circuit sets the data after the first predetermined time has passed since the data was acquired until a second predetermined time has passed to the second level, and The processing circuit encrypts the data of the second level using a first encryption key and stores the data in the storage section. (5) The information processing device according to (4), wherein The processing circuit sets the data after the second predetermined time has passed since the data was acquired until a third predetermined time has passed, to a third level, and The processing circuit encrypts the data of the third level using a second encryption key and stores the data in the storage section. (6) The information processing device according to (5), wherein When the data set to the second level and encrypted is set to the third level after the second predetermined time has elapsed, the processing circuit performs decryption corresponding to the first encryption key and then encrypts the data using the second encryption key. (7) The information processing device according to (5), wherein After the first predetermined time has elapsed, the processing circuit encrypts the data using a third encryption key, encrypts a key for decrypting the data encrypted using the third encryption key using the first encryption key, and stores the encrypted key in association with the data encrypted using the third encryption key, and After the second predetermined time has elapsed, the processing circuit encrypts a key for decrypting the data encrypted using the third encryption key using the second encryption key, and stores the encrypted key in association with the data encrypted using the third encryption key. (8) The information processing device according to (7), wherein The processing circuit generates the third encryption key as a random key, and The processing circuit updates the third encryption key at every predetermined opportunity. (9) The information processing device according to any one of (5) to (8), wherein After the third predetermined time has passed since the data was acquired, the processing circuit discards the data or uploads the data to an external server or storage. (10) The information processing device according to any one of (1) to (9), wherein The data includes one or more frames of data. (11) The information processing device according to (10), wherein The data includes data having images and audio. (12) The information processing device according to (3), wherein After the first predetermined time has elapsed since the data was acquired, the processing circuit sets the first type of data in the data to a second level and sets the second type of data in the data to a third level, The processing circuit encrypts the data set to the second level using a first encryption key, The processing circuit encrypts the data set to the third level using a second encryption key, and The processing circuit stores each encrypted data in the storage unit. (13) An electronic device, comprising: On-board sensors; and The information processing device according to any one of (1) to (11), The processing circuit of the information processing device encrypts and stores the data sensed and generated by the vehicle-mounted sensor. (14) The electronic device according to (13), wherein The vehicle-mounted sensor includes a camera unit. (15) The electronic device according to (13) or (14), wherein The vehicle-mounted sensor includes a sound collecting unit. (16) An information processing method, comprising: Through the processing circuit, setting a level for data generated by a sensor mounted on the vehicle based on a time elapsed since the data was generated; and The encryption process of the data is performed based on the set level. (17) A program for causing a processing circuit to execute an information processing method, the information processing method comprising: setting a level for data generated by a sensor mounted on the vehicle based on a time elapsed since the data was generated; and The encryption process of the data is performed based on the set level. (18) An information processing device includes a processing circuit that sets a level for data generated by a sensor based on a time elapsed since the data was generated or a type of the data, and performs encryption processing of the data based on the set level. (19) An information processing device, comprising: a first encryption unit that encrypts data from a first predetermined time after acquisition of the data until a second predetermined time has passed based on a first encryption key; a second encryption unit that encrypts the data after the second predetermined time has elapsed since the data was acquired based on a second encryption key; and A data storage unit stores the data encrypted by the first encryption unit and the second encryption unit. (20) The information processing device according to any one of (1) to (12), the electronic device according to any one of (13) to (15), the information processing method according to (16), the program according to (17), or the information processing device according to (18) or (19), wherein The above encryption includes encryption that implements at least one of the following: encryption that controls data access, and encryption that prevents data tampering.

[0165] The aspects of the present disclosure are not limited to the above-described embodiments, and include various conceivable variations. The effects of the present disclosure are not limited to the above-described contents. The components in the various embodiments may be appropriately combined and applied. That is, various additions, variations, and partial deletions may be made without departing from the conceptual ideas and purport of the present disclosure derived from the contents defined in the claims and their equivalents, etc.

[0166] 1 Electronic equipment 10 Vehicle Sensors 100 Sensor unit 102 Data Generation Department 20 Information processing device 200 Data Storage Department 202 First Encryption Department 204 Second Encryption Department 206 Key storage unit 208 Data Control Department 210 Output I / F 212 The Third Encryption Department 214 Key light emitting unit

Claims

1. An information processing device comprising a processing circuit that sets a level for data generated by a sensor mounted on a vehicle based on a time elapsed since the data was generated or a type of the data, and that performs encryption processing of the data based on the set level.

2. The information processing device according to claim 1, further comprising a storage unit, The processing circuit stores the encrypted data in the storage unit.

3. The information processing device according to claim 2, wherein The processing circuit sets the data until a first predetermined time elapses after the data is acquired to a first level, and The processing circuit stores the data of the first level in the storage section without encryption.

4. The information processing device according to claim 3, wherein The processing circuit sets the data after the first predetermined time has passed since the data was acquired until a second predetermined time has passed to the second level, and The processing circuit encrypts the data of the second level using a first encryption key and stores the data in the storage section.

5. The information processing device according to claim 4, wherein The processing circuit sets the data after the second predetermined time has passed since the data was acquired until a third predetermined time has passed, to a third level, and The processing circuit encrypts the data of the third level using a second encryption key and stores the data in the storage section.

6. The information processing device according to claim 5, wherein When the data set to the second level and encrypted is set to the third level after the second predetermined time has elapsed, the processing circuit performs decryption corresponding to the first encryption key and then encrypts the data using the second encryption key.

7. The information processing device according to claim 5, wherein After the first predetermined time has elapsed, the processing circuit encrypts the data using a third encryption key, encrypts a key for decrypting the data encrypted using the third encryption key using the first encryption key, and stores the encrypted key in association with the data encrypted using the third encryption key, and After the second predetermined time has elapsed, the processing circuit encrypts a key for decrypting the data encrypted using the third encryption key using the second encryption key, and stores the encrypted key in association with the data encrypted using the third encryption key.

8. The information processing device according to claim 7, wherein The processing circuit generates the third encryption key as a random key, and The processing circuit updates the third encryption key at every predetermined opportunity.

9. The information processing device according to claim 5, wherein After the third predetermined time has passed since the data was acquired, the processing circuit discards the data or uploads the data to an external server or storage.

10. The information processing device according to claim 1, wherein The data includes one or more frames of data.

11. The information processing device according to claim 10, wherein The data includes data having images and audio.

12. The information processing device according to claim 3, wherein After the first predetermined time has elapsed since the data was acquired, the processing circuit sets the first type of data in the data to a second level and sets the second type of data in the data to a third level, The processing circuit encrypts the data set to the second level using a first encryption key, The processing circuit encrypts the data set to the third level using a second encryption key, and The processing circuit stores each encrypted data in the storage unit.

13. An electronic device, comprising: On-board sensors; and The information processing device according to claim 1, The processing circuit of the information processing device encrypts and stores the data sensed and generated by the vehicle-mounted sensor.

14. The electronic device according to claim 13, wherein The vehicle-mounted sensor includes a camera unit.

15. The electronic device according to claim 13, wherein The vehicle-mounted sensor includes a sound collecting unit.

16. An information processing method, comprising: Through the processing circuit, setting a level for data generated by a sensor mounted on the vehicle based on a time elapsed since the data was generated; and The encryption process of the data is performed based on the set level.

17. A program for causing a processing circuit to execute an information processing method, the information processing method comprising: setting a level for data generated by a sensor mounted on the vehicle based on a time elapsed since the data was generated; and The encryption process of the data is performed based on the set level.

Citation Information

Patent Citations

  • Information recording device, information recording method, information recording program, and recording medium

    JP2022028858A