Method for anonymization of motion data
By combining vehicle private key signing and TLS certificate verification with data transmission proxy and noise reduction strategies, the problem of data evaluation quality degradation during anonymization is solved, achieving high-quality anonymization and data protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- MERCEDES BENZ GRP
- Filing Date
- 2022-02-10
- Publication Date
- 2026-06-19
AI Technical Summary
Existing technologies struggle to maintain high-quality data evaluation while anonymizing traffic participant motion data, especially since existing anonymization methods affect the accuracy of traffic condition reconstruction.
By using vehicle private key signing and TLS certificate verification for data transmission, and utilizing other vehicles as data transmission proxies, while introducing location and time-related noise before transmission, combined with data exchange and noise reduction strategies between vehicles, the anonymity of data on the backend server is ensured.
This approach achieves data anonymization on the backend server while maintaining high-quality data evaluation, improving data protection while reducing data transmission volume and enhancing data privacy.
Smart Images

Figure CN120032516B_ABST
Abstract
Description
[0001] This application is a divisional application of patent application No. 202280005466.3, entitled "Method for Anonymizing Motion Data", filed with the Chinese Patent Office on February 10, 2022. Technical Field
[0002] The present invention relates to a method for anonymizing motion data of traffic participants equipped with positioning devices, of the type detailed in the preamble of claim 1. Background Technology
[0003] Publication DE 10 2015 217 793 A1 describes an apparatus, method, and computer program for providing congestion information via a vehicle-to-vehicle interface. In this application, vehicles detect congestion indicators, including at least vehicle speed and / or congestion warnings transmitted by nearby vehicles. Therefore, vehicles are able to exchange and forward relevant data to each other.
[0004] It is also known from existing technologies that vehicles in a fleet periodically exchange data with backend servers, such as those implemented via the internet as a cloud solution. There, current traffic conditions can be reconstructed directly or in downstream systems from motion data of vehicles that periodically transmit their data groups. This is then used to control traffic volume and can include congestion information and / or congestion warnings.
[0005] Generally, when a data set is transmitted to the backend server, the vehicle verifies itself accordingly, for example, using a TLS client certificate. The accuracy of traffic condition reconstruction depends on the spatial and temporal resolution of the data sets transmitted by the vehicle.
[0006] However, traffic participant movement data, especially vehicle movement data, should be treated as personally relevant data and should be pseudonymous or anonymized on the backend server side, for example. However, common anonymization practices, such as introducing artificial spatial and / or temporal obfuscation or random noise, can adversely affect the usability of the pre-defined dataset on the backend, particularly regarding the quality of traffic condition reconstruction. Therefore, abandoning anonymization to maintain high reconstruction quality is also a serious drawback. Summary of the Invention
[0007] Therefore, the objective of this invention is to provide a method for anonymizing motion data according to the preamble of claim 1, wherein not only is anonymization guaranteed, but high quality is also achieved in data evaluation.
[0008] According to the invention, this task is accomplished by a method having the features of claim 1, and particularly the characteristic portion of claim 1 herein. Advantageous designs and modifications of the method of the invention are derived from its dependent claims.
[0009] The solution according to the method of the present invention mainly includes two approaches, which can be used individually or in combination to ensure the anonymization of motion data. According to the invention, the motion data here consists of at least individual time-related and location-related data sets, and thus, for example, locations with timestamps. To ensure transmission from the corresponding authorized vehicles in the fleet to the backend server, this data is typically signed with the vehicle's private key, and its association with the vehicle is proven by a certificate, such as a TLS client certificate, sent along with the private key. However, this now ensures that the corresponding data sets can be easily assigned to the corresponding vehicles in the backend server. To particularly prevent this, data transmission between different vehicles, known in principle from the prior art described in the preface, can now be utilized. Motion data collected in data sets and transmitted to the backend server is transmitted in such a way that, according to the invention, the transmission of at least several data sets is carried out indirectly through at least one other vehicle. Thus, the other vehicle acts as a "proxy" to conceal the actual source of the data relative to the backend, because the information does not reach the backend server but only reaches the other vehicle locally, which then forwards the data, thus hiding the actual source of the data. Anonymization is thus achieved.
[0010] Another problem with anonymization is that if a backend server has a largely complete set of data for a vehicle, it can reconstruct the vehicle's complete and ordered movement history from that set, even if the road segments might be unclassified or mixed with those traveled by another vehicle. This is because if these individual road segments match in terms of their location and timestamps and are therefore clearly and unambiguously assigned to a vehicle, then those road segments can be reconstructed accordingly from a seamlessly contiguous set of data in time and space.
[0011] To counteract this problem, a supplementary or alternative solution to the above can be stipulated by noisening the location and / or time associations in at least several data sets before transmission. This introduces inaccuracy to prevent data classification in the aforementioned sense, while still allowing conclusions about the correspondence between the entire motion curve and a particular vehicle. The noise intensity should be as low as possible, yet the corresponding timestamps should be noisy enough that they are no longer precisely consistent. The same applies to location data, which can be noisy, for example, so that while a vehicle can be identified as being on a certain road, the lane in a multi-lane road scenario cannot be identified. Therefore, it is no longer possible to definitively ascertain how the data corresponds to each other, thus enabling anonymization. Nevertheless, data quality is maintained with high precision to ensure that the data is always evaluated with high quality by the backend server in the desired manner. That is, in many cases, it is not important which vehicle is at which exact time and place for traffic condition reconstruction, but rather to know the approximate spatiotemporal average speed of the vehicle on that road, while the lane used is meaningless.
[0012] What is particularly advantageous now is that anonymization is achieved through a combination of two solutions. Thus, it becomes difficult to trace data back to a specific vehicle based on the data transmitted to the backend server. Therefore, this ultimately improves the quality of anonymization without adversely affecting the data quality associated with data evaluation.
[0013] A highly advantageous improvement to the method according to the present invention stipulates that all vehicles in a fleet connected to a backend server share a common, shared vehicle certificate and an associated private key, wherein a signature created using that private key is transmitted to the backend server directly or via at least one other vehicle along with the data set. By exchanging the signature, created using the shared private key of all vehicles, along with the motion data, it is ensured on the backend server side that the received data is actually recorded by one vehicle in the fleet and transmitted directly or indirectly to the backend server. Therefore, security requirements on the backend server side are met, while the signature and the certificate used for its verification cannot directly assign each data set to a specific vehicle in the fleet.
[0014] A highly advantageous design of the method according to the invention also specifies that the noise reduction of the data sets is carried out with varying intensities according to their distance from the route start point and / or when initiating destination guidance, such as a navigation system, towards the planned route endpoint. The intensity or magnitude of the noise reduction, i.e., the degree of artificially introduced ambiguity regarding location and / or time within each data set, can therefore be adjusted particularly according to the route start point and potential endpoint. Since the start point and endpoint require more data protection than midway points in the vehicle's journey, they are suitable for high levels of protection. Accordingly, it can be specified that noise reduction is more intense in the area of the start point and endpoint, for example, within a corresponding radius of several kilometers or within a corresponding period of several cycles, than in other areas, so that although quality may degrade in these areas, overall improved data protection can be achieved due to the stronger noise reduction in these particularly "private" location areas.
[0015] A highly advantageous improvement to this variation of the method according to the invention even specifies that data sets related to locations such as the starting point and the destination (when destination guidance is enabled by the navigation system) are not transmitted to the backend server, and data sets collected, especially in cases of spatial proximity to the starting point and / or the destination, are not transmitted. This further improves the protection of the starting and ending points of a route, which may allow for inferences, particularly for a specific vehicle and especially for the person using the vehicle.
[0016] In the case of both variant combinations—namely, in the case of noise generation and the transmission of at least several data sets via at least one other vehicle—a highly advantageous improvement to this concept can also specify that the type and intensity of the noise are coordinated among the participating vehicles. This coordination of noise type is particularly meaningful when vehicles meet and the meeting is used to exchange data sets subsequently forwarded to a backend server by another vehicle. In particular, better anonymization can then be achieved at these points through temporarily slightly stronger noise.
[0017] According to a highly advantageous improvement, a corresponding variation of the method of the invention may specify that the data set related to the location of the vehicle encounter and the data set being transferred from one vehicle to another has correspondingly greater noise than other datasets. That is, the data set shortly before and after the exchange therefore has greater noise, thereby allowing for better spoofing of the location and time of the exchange.
[0018] For cases where several data sets are transmitted via at least one other vehicle (in which case the vehicles exchange data sets), it can be stipulated that the vehicles exchange data sets and simultaneously delete the data sets they sent to the other vehicle, and update their own routes based on the exchanged data sets. Therefore, from the backend server's perspective, a vehicle that originally traveled from point A to point D and encountered another vehicle at point C is disguised as having traveled from point B (actually the other vehicle's starting point) to C, and then from C to point D. Its original route from B to C and then to E is altered, thus creating a false journey from point A (the first vehicle's starting point) through C to E for the backend server. This also improves data anonymization and reduces the amount of data to be transmitted, because each vehicle no longer has to transmit multiple data sets of its own and the other vehicle's; instead, it only needs to transmit the untransmitted data sets of the other vehicle before encountering another vehicle, and then transmits its own data sets from that point onwards, perhaps until encountering a third vehicle, and so on.
[0019] Therefore, this particularly advantageous design of the method according to the invention allows for the exchange or transmission of data between vehicles when they are close to each other in time and / or space. This can be ensured by vehicle-to-vehicle communication transmission technology and by corresponding location data. If, for example, the vehicles are traveling adjacent to each other on a multi-lane road, the exchange can be made so that simple communication can be achieved on the one hand, and a correspondingly high data quality is maintained at the back-end server despite the data exchange and the resulting anonymization.
[0020] A highly advantageous design of the method of the present invention now also allows for the transmission of data sets based on a predetermined parameterizable time and / or the number of data sets. For example, a periodic time can be set so that data is transmitted accordingly every 60 seconds, or transmission can be performed, for example, after every 10 to 20 data sets are collected.
[0021] According to a particularly advantageous embodiment of the method according to the invention, the anonymized motion data can also be appropriately labeled. The backend server can then use the corresponding label to identify that it performs its evaluation and reconstruction based on the anonymized data. This may or necessarily lead to different interpretations of the data, as knowing that individual road segments rather than the entire route were traversed by the same vehicle may be crucial, for example, when specific data, speed curves, etc., should be considered for each vehicle type.
[0022] Other advantageous designs of the method of the invention can also be obtained by referring to the embodiments detailed below with reference to the figures. Attached Figure Description
[0023] The only appendix Figure 1 This shows route maps for two simple routes, each traversed by two different vehicles and consisting of three route points. Detailed Implementation
[0024] For example, what is feasible now is, such as Figure 1 One of the two cars 1 and 2 shown transmits its motion data as a sequence of location data sets consisting of location and timestamps. For example, such a sequence could be defined as ((location 1, timestamp 1), (location 2, timestamp 2), (location 3, timestamp 3)...). These data sets are then transmitted accordingly to a backend server 3, which is exemplarily shown as a cloud. The backend server 3 then obtains information of value to it, such as the spatiotemporal average speeds of vehicles 1 and 2 in the road segments described by the two subsequent location data sets. It should be noted here that isolated data sets of the above form are essentially worthless for traffic analysis, as they only indicate that a vehicle 1 or 2 was located at the stated location at the timestamps. What is most valuable to the backend server 3 is a sequence of data sets that is as complete as possible, ideally pre-classified compared to an unclassified set of road segments, and thus can be processed quickly and less laboriously by the backend server 3. In principle, the information content is the same regardless of the classification, as the same information can be reconstructed, but the computational cost for unclassified data sets is correspondingly higher.
[0025] Therefore, the preferred transmission format for backend 3 is a (continuous) sequence of location data sets, all belonging to the same vehicle 1 and 2. However, this is also the least anonymous form of the collected vehicle motion data, because the total motion history of vehicles 1 and 2 can be directly derived from this sequence.
[0026] Anonymity is typically violated in two ways when transmitting location data sets.
[0027] 1. On one hand, location data sets are transmitted from vehicles 1 and 2 to backend 3. To ensure that only data from reliable sources is transmitted to backend 3, vehicles 1 and 2 should authenticate themselves with backend 3 before transmission, for example, using proprietary certificates and TLS. In this way, backend 3 always knows which vehicles 1 and 2 it is communicating with and thus knows from which vehicle it obtained its respective location data sets.
[0028] 2. If backend 3 has a (basically) complete (potentially unclassified) set of road segments traversed by vehicles 1 and 2, then backend 3 can reconstruct the (substantially) entire ordered motion history of the vehicles from the set, even if these road segments are unclassified and may be confused or mixed with road segments traversed by other vehicles. This is because the road segments of the complete motion history of vehicles 1 and 2 are contiguous or "matched" with each other in that the end point or end time stamp of the earlier road segment is equal to the start point or start time stamp of the later road segment. Since the location (e.g., GPS coordinates) and the (at least second-accurate) timestamp precisely identify space-time, the probability that another road segment belonging to another vehicle has a "matching"—that is, an identical start or end point in terms of location and timestamp—is extremely low, almost zero. Therefore, it is always possible to identify "merged" road segments, that is, those belonging to vehicles 1 and 2 or their motion history, even those from a potentially large "unclassified" set of multiple vehicles 1 and 2, and to arrange them in the correct order, thus compiling a (complete) motion history.
[0029] The remedy for the first weakness is to use a "proxy" to transmit location data sets in the following manner: vehicles 1 and 2 do not transmit their own location data sets, but instead use an "intermediate station" trusted by backend 3 for transmission. This "intermediate station" receives data from vehicles 1 and 2 but does not forward their identities to backend 3. Specifically, another vehicle 1 or 2 nearby can perform this task and send the "other's" location data set along with its own location data set to backend 3, though its origin is not specified here. Alternatively, road segments can be exchanged between vehicles 1 and 2 in the following manner: each vehicle 1 or 2 partially transmits its own road segments and partially transmits the other's, or partially transmits its movement history.
[0030] If road segments are transmitted only from vehicles 1 and 2 to backend 3, then each road segment provided to backend 3 should ultimately be transmittable by any vehicle 1 or 2. The goal should be to transmit road segments from other vehicles 1 and 2 to backend 3 in a way that maximizes anonymization with the "non-corresponding attributes" of vehicles 1 and 2 that traversed those road segments. For example, it might be meaningful to transmit a certain number of first or last road segments of the route that are not transmitted themselves—that is, road segments immediately following the origin or shortly before the destination. This is because, on the one hand, information concerning the origin or destination of the route may be particularly sensitive; on the other hand, such partial motion history cannot be associated with vehicles 1 and 2 that traversed that partial motion history because it is only unilaterally associated with the entire motion history. In this way, a particularly high level of technical and semantic anonymization can be achieved by having other vehicles 1 and 2 transmit a certain number of first or last road segments of the route.
[0031] In the example shown in the attached diagram, vehicle 1 starts at point A and travels along route ACD. Vehicle 2 starts at point B and travels along route BCE. Vehicles 1 and 2 thus meet at intersection point C, where they are very close in time and space, for example, driving side-by-side on a multi-lane road. At this moment when the two vehicles 1 and 2 are very close in both time and space, they now exchange their data. Data sets that have not yet been transmitted between points A and C of vehicle 1 and between points B and C of vehicle 2 are exchanged accordingly, with each vehicle 1 or 2 erasing the transmitted data after it is transmitted to the other vehicle 2 or 1, and then continuing its previously planned route. At the end of the route, vehicle 1 now provides motion data related to route BCD in the area of backend server 3, and vehicle 2 correspondingly provides motion data for route ACE. The motion data history therefore no longer corresponds to reality and is correspondingly anonymized relative to backend server 3.
[0032] The measure to address the second weakness mentioned above would be to noise-enlarge the data contained in the road segment. This would be done by slightly but sufficiently altering the location and / or timestamp before transmission to make reconstructing the motion history and / or assigning these road segments to vehicles 1 and 2 significantly difficult, or even impossible. The problem here is that the more accurate the data, the better the subsequent traffic analysis based on vehicle motion data. This means that excessive noise will adversely affect the results of subsequent traffic analysis. However, while insufficient purely symbolic noise-enlargement makes pure syntactic comparison of the endpoints impossible and has almost no impact on their semantics, i.e., their values, it is not enough to prevent the reconstruction of the motion history and / or the assignment of a road segment to a vehicle 1 or 2. This is because, in this case, there is no need to check for strict equality; simply using the spatiotemporal distance values of the location data set is sufficient to identify the corresponding insufficiently noise-enlarged road segment endpoints even when the formulas are not equal, thus enabling the appropriate assignment of the road segment endpoints.
[0033] Therefore, the goal should be to use "noise" cautiously and only noise the end point of the road segment before transmission, so that the noise will make a significant contribution to anonymization, and to transmit the other end points of the road segment unchanged to the back end 3.
[0034] As proposed above, when two vehicles 1 and 2 are sufficiently close in time and space, i.e., when the two vehicles 1 and 2 are spatially adjacent at a certain moment, the location data set of one vehicle 1 that has appeared previously but has not yet been transmitted to the backend 3 is transmitted to the other vehicle 2 (the neighboring vehicle), and then transmitted from the other vehicle 2 to the backend 3 at a subsequent or later moment, for example in the form of an (unclassified) set of road segment data or in the form of a (classified) location data sequence, i.e., a partial motion history.
[0035] In particular, it is proposed that, in the case of more than two spatially and temporally adjacent vehicles 1 and 2, one vehicle collects a set of location data from more than one other adjacent vehicle and then transmits them together to the backend 3.
[0036] In particular, it is proposed that, in the case of two or more vehicles 1 and 2 that are spatially and temporally adjacent, the adjacent vehicles 1 and 2 may exchange their data that has appeared so far, and then transmit the other party's data together with their own location data set to the backend 3 at the next or later time, for example in the form of an (unclassified) set of road segment data or in the form of a (classified) sequence of location data.
[0037] Furthermore, it is proposed that when deciding which vehicle 1, 2 will transmit the data of which other vehicle 1, 2 to the backend 3, the strength of the anonymization effect that can be obtained by each should be taken into account. For example, the approach could be to transmit the road segments or parts of the motion history traveled immediately after the starting point and immediately before the destination according to the possibility of the other vehicle 1, 2.
[0038] It is also proposed that since the spatiotemporally adjacent vehicles 1 and 2 so jointly and in a coordinated manner noise up the location-timestamp data that is very similar at that location and at that time, the backend 3 can no longer directly identify which future partial motion history matches which past partial motion history (transferred from one vehicle to another vehicle 1 or 2 at that spatiotemporal point or exchanged between vehicles at that spatiotemporal point).
[0039] It is also proposed that all vehicles 1 and 2 adjacent to each other at this location and time participate in the noise reduction of the location data group by importing a mutually coordinated location data group (synchronization data group). This mutually coordinated location data group is limited to the end point of the road segment each has traveled before the synchronization point and the start point of the road segment each has to travel after the synchronization point. In this way, it is obviously difficult for the backend 3 to identify the corresponding motion history of each other, that is, the motion history of the same vehicle 1 and 2 in terms of time and space, that is, the partial motion history that is located before the synchronization point and the partial motion history that is located after the synchronization point.
[0040] It is also proposed to use the same synchronization data set for all adjacent vehicles 1 and 2, specifically one of the synchronization points, namely one of the following spatiotemporal points where all related vehicles 1 and 2 are adjacent to each other. In this case, although the backend 3 can quickly identify it as a synchronization point (because there will be no more vehicles 1 and 2 at the same spatiotemporal point), it can no longer simply and directly assign the motion history before the synchronization point to the motion history after the synchronization point.
[0041] Alternatively, it could be proposed that among adjacent vehicles 1 and 2, a slightly noisy (close to each other) but not identical synchronization data set at a synchronization point be selected. The endpoint of the final segment of the motion history potentially originating from another vehicle 1 or 2 before this synchronization data set is adapted to this artificially generated synchronization data set, thus disguising to the backend 3 a continuous and consistent motion history originating from vehicles 1 and 2. In this way, it becomes difficult for the backend 3 to identify the potential synchronization point. It is also proposed that vehicles 1 and 2 belonging to a group of adjacent vehicles 1 and 2 first exchange their traversed motion history not far before the synchronization point according to the aforementioned maximum anonymization principle or according to a random principle, and then match the other's partial motion history to their own synchronization data set. If one vehicle 1 or 2 transmits partial motion histories of multiple vehicles 1 and 2 before the synchronization point, then one or more of these partial motion histories can be coordinated with this synchronization data set.
[0042] It was also proposed that decisions regarding "which vehicle 1 or 2 transmits which location data group or which part of the motion history to the rear end 3" and "which parts of the motion history are combined to form a reasonable total motion history for camouflage purposes" be independent of each other.
[0043] It is also proposed that, for example, if for any two vehicles 1 and 2 in the relevant set of vehicles 1 and 2, the predefined positive distance value of the distance time is >0 and the distance space is >0, there exists a time t from the time interval [timestamp - distance time, timestamp + distance time] at which the spatial distance between the two vehicles is less than or equal to the distance space, then multiple vehicles 1 and 2 are considered to be spatiotemporally adjacent (position, timestamp) at the synchronization point.
Claims
1. A method for anonymizing motion data of traffic participants (1,2) equipped with positioning devices, the traffic participants having communication means for transmitting and receiving data with a backend server (3) and for other traffic participants (2,1), wherein Motion data is collected and transmitted to the backend server (3) in the form of separate time-related and location-related data sets, wherein at least a portion of the data sets are transmitted indirectly via at least one other vehicle (1,2). Its characteristic is that the vehicles (1,2) exchange data groups, delete the data groups sent for this purpose, and update their own routes based on the exchanged data groups, thereby spoofing the vehicle's movement history to the backend server.
2. The method of claim 1, wherein, All vehicles (1,2) of the fleet connected to the backend server (3) share a common vehicle certificate, wherein the signature created therefrom is transmitted directly or indirectly to the backend server (3) along with the data set, either directly or indirectly through at least one other vehicle (1,2).
3. The method according to claim 1 or 2, characterized in that, At least a portion of the location and / or time associations in the data set are noised before transmission.
4. The method according to claim 3, characterized in that, The noise in the data sets is adjusted according to the proximity to the route start point and / or when destination guidance for the route planning endpoint is enabled.
5. The method according to claim 4, characterized in that, The starting point and / or the ending point, as well as the data sets collected in the vicinity of the starting point and / or the ending point, were not transmitted to the backend server (3).
6. The method according to claim 3, characterized in that, In the case where at least a portion of the data set is noise-enhanced and transmitted indirectly through at least another vehicle (1,2), the type and intensity of the noise are implemented in a manner coordinated among the participating vehicles (1,2).
7. The method of claim 6, characterized in that, Data sets associated with the location "vehicles (1,2) meet and data sets are transferred from one vehicle to another (2,1)" have more noise than data sets at other locations.
8. The method according to claim 1 or 2, characterized in that, Data group transmissions take place between vehicles (1,2) that are close to each other in time and space.
9. The method according to claim 1 or 2, characterized in that, Data group transmission to the backend server (3) is performed based on a predetermined time period and / or number of data groups with configurable parameters.
10. The method according to claim 1 or 2, characterized in that, Anonymized motion data is labeled accordingly.