Geographic information security supervision method and related device and system

By performing compliance verification of vehicle geographic information-related data on the server, the problem of difficult to ensure compliance with vehicle data processing is solved, the risk of geographic information security is reduced, and compliance control of data processing is achieved.

CN120186573APending Publication Date: 2025-06-20YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202311716498.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-12
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

In the prior art, whether the geographical information collection or transmission of related data of vehicles is not clear, resulting in a greater risk of geographical information security.

Method used

By conducting compliance verification of the geographic information related data collected by the vehicle on the server, the vehicle's processing authority for these data is determined based on the verification results to supervise and control the vehicle's data processing.

Benefits of technology

It reduces the risk of geographic information security, ensures compliance with data processing, and reduces data security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120186573A_ABST
    Figure CN120186573A_ABST
Patent Text Reader

Abstract

The invention provides a geographic information security supervision method, a related device and a related system, which can reduce the security risk of geographic information. The method comprises the following steps: a server receives geographic information related data from a vehicle; performing compliance verification on the geographic information related data; based on the result of the compliance verification, a first control message is sent to the vehicle, and the first control message is used for indicating the processing authority of the vehicle to the geographic information related data. The server performs compliance verification on the geographic information related data acquired by the vehicle, and determines the processing authority of the vehicle to the geographic information related data according to the compliance verification result, so as to supervise and control the processing of the geographic information related data of the vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security, and in particular to a method for supervising and managing geographic information security and related devices and systems. Background Art

[0002] With the development of intelligent vehicles, vehicles can collect geographic information during driving, and transmit relevant data (referred to as geographic information-related data in this article), and transmit the geographic information-related data to the server for map updating, algorithm iteration, test simulation, etc. These collections of geographic information and transmissions of relevant data are usually carried out through the crowdsourcing collection method of mass-produced vehicles.

[0003] To ensure data security, currently, vehicles will perform encrypted storage and encrypted transmission of geographic information-related data. However, in some cases, it is not clear whether the collection of geographic information by vehicles or the transmission of relevant data is compliant. Therefore, there are still relatively large geographic information security risks. Summary of the Invention

[0004] This application provides a method for supervising and managing geographic information security and related devices and systems, in order to reduce geographic information security risks.

[0005] In a first aspect, this application provides a method for supervising and managing geographic information security. This method is applied to a server. The steps of this method can be executed by the server, or this method can also be executed by components (such as chips, chip systems, etc.) configured in the server, or it can also be implemented by a logic module or software that can implement all or part of the server functions. This application does not make any limitations in this regard.

[0006] Exemplarily, this method includes: receiving geographic information-related data from a vehicle; performing compliance verification on the geographic information-related data; and based on the result of the compliance verification, sending a first control message to the vehicle, where the first control message is used to indicate the processing authority of the vehicle for the geographic information-related data.

[0007] Among them, geographic information-related data can be understood as data obtained during the collection process of geographic information, and can include, but are not limited to, image data, point cloud data, composition data, positioning data, vehicle behavior data, or vehicle-related data.

[0008] Based on the above technical solution, the server performs compliance verification on the geographic information-related data collected by the vehicle, and then decides the processing authority of the vehicle for these geographic information-related data according to the result of the compliance verification, so as to supervise and control the processing of the vehicle's geographic information-related data, thereby reducing geographic information security risks.

[0009] In combination with the first aspect, in some possible implementation manners, before performing compliance verification on the geographic information-related data, the method further includes: determining that the vehicle is a randomly inspected object, where the randomly inspected object includes vehicles with a specific brand, a specific model, or a specific software system version number.

[0010] That is, randomly inspect vehicles with a specific brand, a specific model, or a specific software system version number, perform compliance verification on the geographic information-related data, and determine the processing authority of these vehicles with a specific brand, a specific model, or a specific software system version number for the geographic information-related data according to the result of the compliance verification. Thus, compliance verification can be performed on vehicles of newly launched brands and models, or newly upgraded software systems, reducing security risks.

[0011] In combination with the first aspect, in some possible implementation manners, before performing compliance verification on the geographic information-related data, the method further includes: determining that the vehicle enters a fenced area.

[0012] Perform compliance verification on the geographic information-related data of the vehicle entering the fenced area, and determine the processing authority of the vehicle entering the fenced area for the geographic information-related data according to the result of the compliance verification, reducing security risks.

[0013] It can be understood that the server can send one or more first control messages to the vehicle to indicate its processing authority for the geographic information-related data. The vehicle can control its various behaviors for the geographic information-related data according to the most recently received first control message. Thus, the effect of dynamic adjustment is achieved.

[0014] In combination with the first aspect, in some possible implementation manners, performing compliance verification on the geographic information-related data includes: performing statistics according to the geographic information-related data to obtain a statistical result; calculating a compliance compliance confidence level according to the statistical result, where the compliance compliance confidence level is used to indicate the credibility of the vehicle's compliance with a preset rule; extracting the geographic information-related data according to the compliance compliance confidence level; and performing compliance verification on the extracted geographic information-related data.

[0015] In combination with the first aspect, in some possible implementation manners, statistics are performed based on the geospatial information related data, including: based on the geospatial information related data, statistics are performed on at least one of the following: the frequency of performing a desensitization operation on image data according to a preset rule, the frequency of not performing a desensitization operation on image data according to the preset rule, the frequency of performing a desensitization operation on point cloud data according to a preset rule, the frequency of not performing a desensitization operation on point cloud data according to the preset rule, the frequency of performing frame thinning on point cloud data according to a preset rule, the frequency of not performing frame thinning operation on point cloud data according to the preset rule, the frequency of performing encryption processing on location coordinate data according to a preset rule, the frequency of not performing encryption processing on location coordinate data according to the preset rule, the frequency of performing data thinning on location coordinate data according to a preset rule, the frequency of not performing data thinning on location coordinate data according to the preset rule, the frequency of the geospatial information related data exceeding the road surface range, the area of the geospatial information related data exceeding the road surface range, or the frequency of performing compliance processing on the geospatial information related data exceeding the road surface range according to a preset rule.

[0016] In combination with the first aspect, in some possible implementation manners, when it is determined that the vehicle enters the fence area, statistics are performed based on the geospatial information related data, including: based on the geospatial information related data, statistics are performed on at least one of the following: the frequency of the vehicle entering each fence area, whether the fence areas entered by the vehicle multiple times are the same fence areas, the total frequency of the vehicle entering the fence area, the way the vehicle enters the fence area, the behavior state of the vehicle in the fence area, and the behavior state includes: turning off the engine, starting, parking, decelerating, the residence time exceeding a first preset threshold, or the data traffic transmitted exceeding a second preset threshold.

[0017] In combination with the first aspect, in some possible implementation manners, the method further includes: in the case where the compliance verification is passed, using the geospatial information related data.

[0018] In combination with the first aspect, in some possible implementation manners, the method further includes: in the case where the compliance verification fails, the server discards the geospatial information related data.

[0019] That is to say, the server will not use the geospatial information related data that fails the compliance verification, which can also reduce the geospatial information security risk to a certain extent.

[0020] In combination with the first aspect, in some possible implementation manners, the method further includes: in the case where the compliance verification fails, the server performs compliance processing on the geospatial information related data and uses the geospatial information related data after the compliance processing.

[0021] Exemplarily, the compliance processing may include, but is not limited to, one or more of the following: cropping the data outside the road surface range in the geographical information related data to obtain the data within the compliant road surface range; or, performing desensitization processing on the un-desensitized data or the data with incomplete desensitization to obtain compliant desensitized data; or, performing encryption processing on the data that needs to be encrypted but has not been encrypted to obtain compliant encrypted data; or, performing frame thinning processing on the data that needs to be frame-thinned but has not been frame-thinned or has non-compliant frame thinning to obtain the data with compliant frame thinning; or, performing data thinning processing on the data that needs to be data-thinned but has not been data-thinned or has non-compliant data thinning to obtain the data with compliant data thinning; and so on.

[0022] In combination with the first aspect, in some possible implementation manners, when the compliance verification of a part of the geographical information related data fails and the compliance verification of another part of the geographical information related data passes, the server may directly use this part of the geographical information related data that passes the compliance verification. For the geographical information related data whose compliance verification fails, the server may directly discard it or use it after performing compliance processing on it. This application does not make any limitation in this regard.

[0023] It can be understood that in a possible scenario, the failure of the compliance verification may be caused by insufficient processing capabilities at the vehicle end, such as low computing power at the vehicle end, incomplete compliance processing models, etc. And the server has the ability to perform compliance processing on the geographical information related data whose compliance verification fails at the vehicle end. Using the data after performing compliance processing on these geographical information related data whose compliance verification fails can also reduce the geographical information security risk.

[0024] In combination with the first aspect, in some possible implementation manners, the method further includes: based on the result of the compliance verification, sending a second control message, where the second control message is used to indicate whether the path planning can pass through the fence area.

[0025] When the compliance verification passes, it can be considered that the vehicle's processing of the geographical information related data complies with the legal rules and / or industry rules, and the vehicle's path planning can be allowed to pass through the fence area without generating a large geographical information security risk; while when the compliance verification fails, it can be considered that the vehicle's processing of the geographical information related data does not comply with the legal rules and / or industry rules, and the vehicle's path planning is not allowed to pass through the fence area, thereby avoiding generating a large geographical information security risk.

[0026] In combination with the first aspect, in some possible implementation manners, the method further includes: based on the result of the compliance verification, sending a third control message, where the third control message is used to indicate whether to reduce the crowdsourcing collection task.

[0027] When the compliance verification is passed, it can be considered that the vehicle can process the geographic information related data in a manner that complies with legal rules and / or industry rules, and without reducing the crowdsourcing collection tasks, no significant geographic information security risks will be generated; when the compliance verification fails, it can be considered that the vehicle cannot process the geographic information related data in a manner that complies with legal rules and / or industry rules, and by controlling the vehicle to reduce the crowdsourcing collection tasks, significant geographic information security risks can be avoided.

[0028] In combination with the first aspect, in some possible implementation manners, before receiving the geographic information related data from the vehicle, the method further includes: sending a service configuration message to the vehicle, where the service configuration message is used to configure one or more of the following: the type of the geographic information related data that needs to be collected by the vehicle, the parameters for collection, or the trigger condition for collection.

[0029] In combination with the first aspect, in some possible implementation manners, before receiving the geographic information related data from the vehicle, the method further includes: sending a fourth control message to the vehicle, where the fourth control message is used to indicate the timing of transmitting the geographic information related data and / or the mode of transmitting the geographic information related data, and the timing of transmitting the geographic information related data includes one or more of the following: immediate transmission, periodic transmission, event-triggered transmission, and the mode of transmitting the geographic information related data includes: full transmission or extraction transmission.

[0030] In a second aspect, the present application provides a geographic information security supervision method, which is applied to a vehicle. The steps of the method can be executed by the vehicle, or, the method can also be executed by components (such as chips, chip systems, etc.) configured in the vehicle, or, can also be implemented by a logic module or software capable of implementing all or part of the vehicle functions. The present application does not make any limitation in this regard.

[0031] Exemplarily, the method includes: sending geographic information related data to a server for compliance verification; receiving a first control message from the server, where the first control message is sent based on the result of the compliance verification, and the first control message is used to indicate the processing authority of the vehicle for the geographic information related data.

[0032] Among them, the geographic information related data can be understood as the data obtained during the collection process of geographic information, and can include, but is not limited to, image data, point cloud data, composition data, positioning data, vehicle behavior data, or vehicle related data.

[0033] Based on the above technical solution, the vehicle can cooperate with the server to implement compliance verification of geographical information-related data according to the control instructions sent by the server, and can process the geographical information-related data according to the processing authority of the geographical information-related data indicated by the server for this vehicle, thereby reducing the geographical information security risk.

[0034] Combined with the second aspect, in some possible implementation manners, the method further includes: receiving a second control message, where the second control message is used to indicate whether path planning can pass through a fenced area.

[0035] In the case where the compliance verification is passed, it can be considered that the vehicle's processing of geographical information-related data complies with legal rules and / or industry rules, and the path planning of the vehicle can be allowed to pass through the fenced area without generating a large geographical information security risk; while in the case where the compliance verification fails, it can be considered that the vehicle's processing of geographical information-related data does not comply with legal rules and / or industry rules, and the path planning of the vehicle is not allowed to pass through the fenced area, thereby avoiding generating a large geographical information security risk.

[0036] Combined with the second aspect, in some possible implementation manners, the method further includes: receiving a third control message, where the third control message is used to indicate whether to reduce the crowdsourcing collection task.

[0037] In the case where the compliance verification is passed, it can be considered that the vehicle can process geographical information-related data in a manner that complies with legal rules and / or industry rules, and without reducing the crowdsourcing collection task, it will not generate a large geographical information security risk; in the case where the compliance verification fails, it can be considered that the vehicle cannot process geographical information-related data in a manner that complies with legal rules and / or industry rules, and by controlling the vehicle to reduce the crowdsourcing collection task, a large geographical information security risk can be avoided.

[0038] Combined with the second aspect, in some possible implementation manners, before sending geographical information-related data to the server, the method further includes: receiving a service configuration message from the server, where the service configuration message is used to configure one or more of the following: the type of the geographical information-related data that needs to be collected by the vehicle, the parameters for collection, or the trigger condition for collection.

[0039] Combined with the second aspect, in some possible implementation manners, before sending geographical information-related data to the server, the method further includes: receiving a fourth control message from the server, where the fourth control message is used to indicate the timing of transmitting the geographical information-related data and / or the mode of transmitting the geographical information-related data, and the timing of transmitting the geographical information-related data includes one or more of the following: immediate transmission, periodic transmission, event-triggered transmission, and the mode of transmitting the geographical information-related data includes: full transmission or extraction transmission.

[0040] Combining the first aspect and the second aspect, in some possible implementations, the processing permission is as follows: all geographical information-related data can be stored or transmitted; or, part of the geographical information-related data can be stored or transmitted; or, any of the geographical information-related data cannot be stored or transmitted.

[0041] Combining the first aspect and the second aspect, in some possible implementations, part of the geographical information-related data includes: part of the types of geographical information-related data, or geographical information-related data of part of the geographical regions.

[0042] In a third aspect, the present application provides a geographical information security supervision system, which includes a server and a vehicle. The server is used to execute the functions of the server in any possible implementation manner of the above first aspect, and the vehicle is used to execute the functions of the vehicle in any possible implementation manner of the above second aspect.

[0043] In a fourth aspect, the present application provides a geographical information security supervision device, which can implement the execution steps of the server in any possible implementation manner of the above first aspect, or can implement the execution steps of the vehicle in any possible implementation manner of the above second aspect. The device includes corresponding modules for executing the above methods. The modules included in the device can be implemented in software and / or hardware manners.

[0044] In a fifth aspect, the present application provides a geographical information security supervision device, which includes a processor. The processor is coupled with a memory and can be used to execute programs in the memory to implement the execution steps of the server in any possible implementation manner of the above first aspect, or to implement the execution steps of the vehicle in any possible implementation manner of the above second aspect.

[0045] Optionally, the geographical information security supervision device further includes a memory.

[0046] Optionally, the geographical information security supervision device further includes a communication interface, and the processor is coupled with the communication interface.

[0047] In a sixth aspect, the present application provides a chip system, which includes at least one processor for supporting the implementation of the functions involved in any possible implementation manner of the above first aspect, second aspect, first aspect, and second aspect, for example, receiving or processing the data and / or indication information involved in the above methods.

[0048] In a possible design, the chip system further includes a memory for storing program instructions and data, and the memory is located inside or outside the processor.

[0049] The chip system may be composed of chips or may include chips and other discrete devices.

[0050] In a seventh aspect, the present application provides a readable storage medium storing a program (which may also be referred to as code or instruction), and when the program is run by a processor, the methods in any possible implementation manner of the first aspect, the second aspect, the first aspect, and the second aspect are executed.

[0051] In an eighth aspect, the present application provides a computer program product, which includes: a program (which may also be referred to as code or instruction), and when the program is run, the methods in any possible implementation manner of the first aspect, the second aspect, the first aspect, and the second aspect are executed.

[0052] It should be understood that the third aspect to the eighth aspect of the present application correspond to the technical solutions of the first aspect and the second aspect of the present application, and the beneficial effects obtained by each aspect and the corresponding feasible implementation manners are similar and will not be elaborated herein. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 is a structural block diagram of a geographic information security supervision system provided by an embodiment of the present application;

[0054] Figure 2 is a schematic flowchart of a geographic information security supervision method provided by an embodiment of the present application;

[0055] Figure 3 is a schematic block diagram of a geographic information security supervision device provided by the present application;

[0056] Figure 4 is another schematic block diagram of a geographic information security supervision device provided by the present application;

[0057] Figure 5 is still another schematic block diagram of a geographic information security supervision device provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0058] Next, the technical solutions in the present application will be described with reference to the accompanying drawings.

[0059] First, in this application, the terms "include" and "have" and any of their variations are intended to cover non-exclusive inclusion. For example, a device, system, product, or equipment that includes a series of modules, units, or components does not necessarily have to be limited to those clearly listed modules, units, or components, but may include other modules, units, or components that are not clearly listed or are inherent to these devices, systems, products, or equipment.

[0060] Second, in this application, words such as "exemplarily" and "for example" are used to give examples, illustrations, or explanations. Any embodiment or design described as "exemplarily" or "for example" in the embodiments of this application should not be construed as being more preferred or having more advantages than other embodiments or designs. Rather, the use of words such as "exemplarily" or "for example" is intended to present relevant concepts in a specific manner.

[0061] Third, in this application, "when", "in the case of", "if", and "when" all refer to the situation where the device will perform corresponding processing under certain objective circumstances, not limited to a specific time, and do not require the device to have a judgment action when implemented, nor does it mean there are other limitations.

[0062] Fourth, in this application, terms such as "first", "second", "third", and "fourth" are used to distinguish identical or similar items with basically the same functions and roles. For example, the first control message, the second control message, the third control message, and the fourth control message are used to distinguish different control messages, and the first preset threshold and the second preset threshold are used to distinguish different preset thresholds, without limiting their order. Those skilled in the art can understand that the terms "first", "second", "third", and "fourth" do not limit the quantity and execution order, and the terms "first", "second", "third", and "fourth" do not necessarily mean they are different.

[0063] Fifth, in this application, "preset" can be understood as predefined, defined, pre-defined, stored, pre-stored, pre-negotiated, prefabricated, pre-set, or pre-configured, etc.

[0064] Sixth, in this application, "at least one (item)" means one (item) or more (items). "And / or" describes the association relationship of associated objects and indicates that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, or B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship, but does not exclude the case where the associated objects before and after are in an "and" relationship. The specific meaning can be understood in combination with the context.

[0065] Seventh, the terms "send" and "receive" in this application indicate the direction of signal transmission. For example, "a vehicle sends geospatial information-related data to a server" can be understood as the destination of the geospatial information-related data being the server, which may include direct sending via the air interface, connection line, or bus, and also include indirect sending by other units or modules via the air interface, connection line, or bus. "The server receives geospatial information-related data from the vehicle" can be understood as the source of the geospatial information-related data being the vehicle, which may include directly receiving from the vehicle via the air interface, connection line, or bus, and may also include indirectly receiving from the vehicle via the air interface, connection line, or bus from other units or modules. "Send" can also be understood as "output" of the chip interface, and "receive" can also be understood as "input" of the chip interface.

[0066] In other words, sending and receiving can be carried out between devices, for example, between a server and a vehicle; or can be carried out within a device, for example, sending or receiving between components, modules, chips, software modules, or hardware modules within a device via a bus, trace, or interface.

[0067] First, a brief explanation of the terms involved in this application is given.

[0068] 1. Geospatial information-related data: Data obtained during the acquisition of geospatial information, which may include one or more of the following types of data: image data, point cloud data, map composition data, positioning data, vehicle behavior data, or vehicle-related data. Among them, image data and point cloud data are obtained by different sensors respectively, and can also be collectively referred to as sensor data.

[0069] 2. Map composition data: It can refer to data of map elements used by a vehicle to construct a local map within a road surface inferred from the vehicle's own perception data. Map elements may include, but are not limited to, elements such as roads and intersections (also known as road intersections, road crossings, intersections, road junctions, etc.). Therefore, map composition data includes map data applicable to a high-precision map.

[0070] 3. Fenced area: In this application, the fenced area can be understood as the area enclosed by a geofence. A geofence is a virtual boundary of a real-world geographical area. A geofence can be dynamically generated (such as a radius around a point location) or match a set of predefined boundaries (such as a school area or a community boundary).

[0071] Since a vehicle can collect geographical information during driving, transmit relevant data (referred to as geographical information-related data in this article), and transmit the geographical information-related data to a server for requirements such as map updating, algorithm iteration, and test simulation. The collection of such geographical information and the transmission of relevant data are usually carried out through the crowdsourcing collection method of mass-produced vehicles. It is not clear whether the collection of the vehicle's geographical information or the transmission of relevant data is compliant. For example, the vehicle may enter certain fenced areas without knowing it and collect geographical information and upload relevant data. It is not difficult to see that there are still significant geographical information security risks in the collection of geographical information. Even if the data is encrypted for storage and transmission, there are still security hazards, such as the encrypted data being intercepted and cracked. Therefore, it is desired to provide a method that can supervise and control the collection and data transmission of geographical information and reduce the security risks related to geographical information.

[0072] In view of the above problems, the present application provides a method. By performing compliance verification on the geographical information-related data collected by the vehicle, and according to the result of the compliance verification, the processing authority of the vehicle for these geographical information-related data is determined, so as to supervise and control the processing of the geographical information-related data by the vehicle, thereby reducing the geographical information security risk.

[0073] Before elaborating on the geographical information security supervision method provided by the embodiments of the present application in detail, first in combination with Figure 1 an exemplary description is given of the system for the geographical information security supervision method applicable to the embodiments of the present application.

[0074] Figure 1 is a structural block diagram of a geographical information security supervision system provided by the embodiments of the present application.

[0075] As Figure 1 shown, the geographical information security supervision system may include a security supervision platform configured on the server side and a security supervision platform configured on the vehicle side. Among them, the server may be a cloud server, a physical server, or a server cluster, etc. The present application does not make any limitations on the specific form and quantity of the server.

[0076] Among them, the security supervision platform on the server side may include a security supervision control module 101 and a data verification and filing module 102. The security supervision control module 101 can be used to receive geographical information-related data from the vehicle and can also be used to transfer the geographical information-related data to the data verification and filing module 102. The data verification and filing module 102 can be used to perform compliance verification on the geographical information-related data to obtain the result of the compliance verification, and can also be used to transfer (transmit or feedback) the result of the compliance verification to the security supervision control module 101. The security supervision control module 101 can generate a control message based on the result of the compliance verification and send the control message to the vehicle. The control message can be used to control the vehicle's processing authority for geographical information-related data, such as the authority for collection, storage, use, or transmission, etc.

[0077] Optionally, the security supervision platform on the server side further includes a data collection configuration module 103. The data collection configuration module 103 can be used to generate a collection configuration policy and transfer the collection configuration policy to the security supervision control module 101 on the server side.

[0078] The security supervision control module 101 can also be used to generate a service configuration message based on the collection configuration policy and send the service configuration message to the vehicle. The service configuration message can be used to indicate the collection configuration policy to the vehicle. Exemplarily, the collection configuration policy may include, but is not limited to, the type of geographical information-related data that needs to be collected by the vehicle, the parameters for collection, or the triggering conditions for collection, etc. This application does not make any limitations in this regard.

[0079] In a possible implementation scenario, the collection configuration policy generated by the data collection configuration module 103 can be an operation by relevant staff to set, modify, or add a collection configuration policy for the collection of geographical information-related data on the server according to geographical information security supervision regulations, supervision requirements, or compliance requirements, etc. The data collection configuration module 103 can generate a corresponding collection configuration policy in response to the operation of the relevant staff. This application does not make any limitations in this regard.

[0080] In another possible implementation scenario, the data collection configuration module 103 generates a collection configuration policy, which can be a collection configuration policy automatically generated according to geographical information security supervision regulations, supervision requirements, or compliance requirements, etc. pre-stored or obtained by the server. For example, an algorithm or model for automatically generating a collection configuration policy is deployed in the data collection configuration module 103. The input data of the algorithm or model can include geographical information security supervision regulations, supervision requirements, or compliance requirements, etc., and the output of the algorithm or model is the collection configuration policy. This application does not make any limitations in this regard.

[0081] Optionally, the security supervision platform on the server side may further include a data application module 104. The data application module 104 may be used to use the geographical information related data transmitted by the security supervision control module 101 or the data verification and filing module 102. By way of example and not limitation, the data application module 104 may be used to use the geographical information related data, which may include model training, simulation, map updating, etc. based on the geographical information related data. This application does not make any limitation thereto.

[0082] Exemplarily, when the data verification and filing module 102 passes the compliance verification on the geographical information related data, the data verification and filing module 102 may feedback the result of passing the compliance verification to the security supervision control module 101, and the data verification and filing module 102 may directly transmit the geographical information related data that has passed the compliance verification to the data application module 104, so that the data application module 104 can use these geographical information related data that has passed the compliance verification. Or, when the data verification and filing module 102 passes the compliance verification on the geographical information related data, the data verification and filing module 102 may feedback the result of passing the compliance verification to the security supervision control module 101, and then, the security supervision control module 101 may transmit the geographical information related data that has passed the compliance verification to the data application module 104, so that the data application module 104 can use these geographical information related data that has passed the compliance verification. This application does not make any limitation thereto.

[0083] It should be noted that for a more detailed description of messages such as geographical information related data, control messages, and service configuration messages, reference may be made to the relevant descriptions in the geographical information security supervision method below, and details are not elaborated here for the time being.

[0084] The security supervision platform on the vehicle side may include a security supervision control module 111, a transmission control module 112, and a storage control module 113. The security supervision platform on the vehicle side may be implemented by one or more processors in the vehicle, for example, to implement its related functions.

[0085] Among them, the security supervision control module 111 may be used to obtain geographical information related data. For example, it may obtain data from various sensors of the vehicle, and may also obtain data from other systems or modules of the vehicle, etc. This application does not make any limitation thereto. The security supervision control module 111 may perform corresponding actions based on the control messages or service configuration messages sent by the server.

[0086] The transmission control module 112 may control the transmission of geographical information related data; the storage control module 113 may control the storage of geographical information related data.

[0087] As mentioned above, the geographical information-related data may include one or more of the following types of data: image data, point cloud data, composition data, positioning data, vehicle behavior data, or vehicle-related data. In a possible implementation, different types of geographical information-related data may be respectively integrated into different data packets and then transmitted to the server separately; or, different types of geographical information-related data may also be integrated into one data packet and then transmitted to the server together. This application does not make any limitation in this regard.

[0088] It can be understood that Figure 1 the division of each module in Figure 1 is only exemplary. In actual applications, different functional modules may be divided according to different functional requirements. This application does not make any limitation on the division form and quantity of functional modules in actual applications, and

[0089] Figure 2 is a schematic flowchart of a geographical information security supervision method provided by an embodiment of this application.

[0090] As Figure 2 shown, the method 200 may be applied to the system as Figure 1 shown. For example, the sending action in step 210 and the receiving action in step 230 of the method 200 may be executed by the vehicle, or may also be executed by components (such as chips, chip systems, etc.) configured in the vehicle, or may further be implemented by a logic module or software capable of implementing all or part of the vehicle functions. This application does not make any limitation in this regard; the receiving action in step 210, step 220, and the sending action in step 230 of the method 200 may be executed by the server, or may also be executed by components (such as chips, chip systems, etc.) configured in the server, or may further be implemented by a logic module or software capable of implementing all or part of the server functions. This application does not make any limitation in this regard. The following will make a detailed description of Figure 2 each step in

[0091] In step 210, the vehicle sends data related to geographical information to the server. Correspondingly, the server receives the data related to geographical information from the vehicle.

[0092] Exemplarily, in Figure 1 the system shown, the safety supervision and control module 111 on the vehicle side can obtain data related to geographical information. For example, various sensors of the vehicle can obtain data, and data can also be obtained from other systems or modules of the vehicle, etc. This application does not limit this. The safety supervision and control module 111 sends the data related to geographical information to the safety supervision and control module 101 on the server side. Correspondingly, the safety supervision and control module 101 on the server side receives the data related to geographical information from the safety supervision and control module 111 on the vehicle side.

[0093] As mentioned above, the data related to geographical information includes one or more of the following types of data: image data, point cloud data, composition data, positioning data, vehicle behavior data, or vehicle-related data.

[0094] Image data, point cloud data, or composition data, etc. can be obtained from sensors such as visual sensors and radar sensors of the vehicle; positioning data can be vehicle position coordinate data obtained from the vehicle's Beidou Navigation Satellite System (BDS); vehicle behavior data and vehicle-related data can be obtained from other systems or modules of the vehicle. Vehicle behavior data can include, for example, but is not limited to: starting, shutting down, starting and stopping, motion data (such as speed, heading, etc.), abnormal deceleration, abnormal stay time, autonomous driving start and takeover status, working status of sensors, or abnormal vehicle data transmission traffic, etc., data for describing the vehicle behavior state; vehicle-related data can include, for example, but is not limited to: the identifier (ID) of the vehicle, the brand of the vehicle, the model of the vehicle, the software system version number of the vehicle, and so on.

[0095] In a possible implementation manner, different types of data related to geographical information can be respectively integrated into different data packets and then transmitted to the server separately; or, different types of data related to geographical information can also be integrated into one data packet and then transmitted to the server together. This application does not limit this.

[0096] It can be understood that in some possible application scenarios, the vehicle may periodically send data related to geographical information to the server. Alternatively, it may also send data related to geographical information to the server when the trigger condition indicated in the control message received from the server is met. Or, it may also send data related to geographical information to the server when receiving a control message sent by the server for indicating the transmission of data related to geographical information. This application does not make any limitation in this regard. Among them, the trigger condition may include, for example, but is not limited to, the occurrence of an emergency event (such as an emergency brake, a collision, etc.), entering or approaching certain designated areas (such as a certain intersection, a certain fenced area, etc.), and so on. This application includes but is not limited to this.

[0097] Optionally, before step 210, the method 200 further includes: the server sends a service configuration message to the vehicle, and the service configuration message is used to configure one or more of the following: the type of the data related to geographical information that the vehicle needs to collect, the parameters for collection, or the trigger condition for collection. Correspondingly, the vehicle receives the service configuration message from the server.

[0098] Exemplarily, in Figure 1 In the system shown, the security supervision and control module 101 on the server side sends a service configuration message to the security supervision and control module 111 on the vehicle side to instruct the vehicle to collect data related to geographical information according to the collection configuration policy in the service configuration message. The collection configuration policy may include one or more of the following: the type of the data related to geographical information that the vehicle needs to collect, the parameters for collection, or the trigger condition for collection. Correspondingly, the security supervision and control module 111 on the vehicle side receives the service configuration parameter and collects data related to geographical information according to the collection configuration policy indicated by the service configuration message.

[0099] Among them, the parameters for collection may include, for example, but are not limited to: data frame rate (i.e., the frequency of collecting data), collection duration, data density, cropping road surface range, element (or element) set, etc. Among them, the data density may be, for example, the data density for point cloud data; the cropping road surface range may be, for example, the range for cropping and discarding the point cloud data outside the road surface range in the point cloud data, or, the cropping road surface range may also be, for example, the range for cropping and retaining the point cloud data within the road range in the point cloud data; the element set may be the element set for composition data, and may include, for example, elements such as roads and road intersections. The vehicle may collect data related to geographical information according to the parameters for collection indicated by the server.

[0100] The type of the data related to geographical information has been described above. Refer to the relevant description of the data related to geographical information above and will not be elaborated here.

[0101] The triggering condition can be some pre-set conditions that require the vehicle to actively collect and report data related to geographical information, such as, but not limited to, the emergency events, entering or approaching certain designated areas, etc. shown above.

[0102] Optionally, before step 210, the method 200 further includes: the server sends a fourth control message to the vehicle, and the fourth control message is used to indicate the timing of transmitting the data related to geographical information and / or the mode of transmitting the data related to geographical information. The timing of transmitting the data related to geographical information includes one or more of the following: immediate transmission, periodic transmission, event-triggered transmission. The mode of transmitting the data related to geographical information includes: full transmission or extraction transmission.

[0103] Exemplarily, in Figure 1 the system shown, the security supervision and control module 101 on the server side generates a fourth control message to indicate to the vehicle at what timing to transmit the data related to geographical information to the server, and / or to indicate to the vehicle in what mode to transmit the data related to geographical information to the server. Correspondingly, the vehicle can transmit the data related to geographical information to the server according to the timing and / or mode indicated by the fourth control message.

[0104] Among them, immediate transmission means transmitting the data related to geographical information to the server immediately after it is collected. Periodic transmission means transmitting the collected data related to geographical information to the server at a preset time interval. Event-triggered transmission means transmitting the collected data related to geographical information to the server when the triggering condition is met. The triggering condition can be the same as the triggering condition collected previously. For the relevant description of the triggering condition, please refer to the above, and it will not be elaborated here.

[0105] Full transmission means transmitting all the data related to geographical information collected by the vehicle to the server. Extraction transmission means extracting the data related to geographical information collected by the vehicle according to the collection frequency or collection time, and transmitting a part of the extracted data to the server. Extraction transmission can also be understood as downsampling the data related to geographical information.

[0106] It can be seen that the service configuration message is mainly used to control the collection, and the fourth control message is mainly used to control the transmission. The server can also carry the contents indicated by these two messages in the same signaling for sending. This application does not make any limitations on this.

[0107] In step 220, the server performs compliance verification on the data related to geographical information.

[0108] Exemplarily, in Figure 1In the system shown, after the security supervision and control module 101 on the server side receives the geographical information related data from the vehicle, the security supervision and control module 101 can transfer the geographical information related data to the data verification and filing module 102, and then the data verification and filing module 102 performs compliance verification on the geographical information related data.

[0109] Optionally, the server performs compliance verification on the geographical information related data, including:

[0110] The server performs statistics based on the geographical information related data to obtain a statistical result;

[0111] The server calculates a compliance compliance confidence level based on the statistical result, and the compliance compliance confidence level is used to indicate the degree of trust that the vehicle complies with the preset rules;

[0112] The server extracts geographical information related data based on the compliance compliance confidence level;

[0113] Perform compliance verification on the extracted geographical information related data.

[0114] The following will detail each step of this compliance verification.

[0115] In a possible implementation, the server performs statistics based on the geographical information related data, including: The server performs statistics on at least one of the following based on the geographical information related data: the frequency of performing desensitization operations on image data according to preset rules, the frequency of not performing desensitization operations on image data according to preset rules, the frequency of performing desensitization operations on point cloud data according to preset rules, the frequency of not performing desensitization operations on point cloud data according to preset rules, the frequency of performing frame thinning on point cloud data according to preset rules, the frequency of not performing frame thinning operations on point cloud data according to preset rules, the frequency of performing encryption processing on location coordinate data according to preset rules, the frequency of not performing encryption processing on location coordinate data according to preset rules, the frequency of performing data thinning on location coordinate data according to preset rules, the frequency of not performing data thinning on location coordinate data according to preset rules, the frequency of the geographical information related data exceeding the road surface range, the area of the geographical information related data exceeding the road surface range, or the frequency of performing compliance processing on the geographical information related data exceeding the road surface range according to preset rules.

[0116] Among them, the geographical information related data exceeding the road surface range can be understood as that the geographical information related data contains some data outside the road range, such as data of buildings around the road, etc.

[0117] In this implementation, the server can, based on the data related to geographical information, count the frequency of vehicles processing certain data in the data related to geographical information according to a preset rule, and / or count the frequency of vehicles not processing certain data in the data related to geographical information according to the preset rule, so as to obtain the required statistical result.

[0118] It should be noted that the preset rule mentioned here does not specifically refer to a certain preset rule. The preset rule can be determined according to legal rules and / or industry rules, or can be legal rules and / or industry rules. The specific content of the preset rule in this application is not limited either.

[0119] After the server obtains the statistical result, the server can calculate the compliance confidence based on the statistical result.

[0120] The compliance confidence is used to indicate the degree of trust that a vehicle complies with legal rules and / or industry rules. Legal rules and / or industry rules can include, for example, geographical information security supervision regulations, supervision requirements, or compliance requirements, etc. This application does not limit this. A high compliance confidence of a vehicle indicates that the collection and data transmission of geographical information by the vehicle largely meet the preset rules and the security risk is low; on the contrary, a low compliance confidence of a vehicle indicates that the collection and data transmission of geographical information by the vehicle largely do not meet the preset rules and the security risk is high.

[0121] In a possible design, the compliance confidence can be represented by a numerical value. For example, a numerical value between 0 and 1, or a numerical value between 0 and 10, or a numerical value between 0 and 100, etc. Taking the compliance confidence as a numerical value between 0 and 100 as an example, compliance confidence ∈ [0, 60] can indicate low compliance confidence; compliance confidence ∈ (60, 90] can indicate medium compliance confidence; compliance confidence ∈ (90, 100] can indicate high compliance confidence.

[0122] Exemplarily, after the server statistically processes the above-mentioned multiple frequencies based on the geospatial information-related data to obtain a statistical result, it determines the corresponding compliance confidence for each statistical result, and then calculates the final compliance confidence through weighted calculation based on the preset weight values corresponding to the above-mentioned multiple compliance confidences. Taking the compliance confidence as a value between 0 and 100 as an example, for instance, the compliance confidence corresponding to the frequency of performing desensitization operations on image data according to the preset rules is 50, and the corresponding weight is 0.15; the compliance confidence corresponding to the frequency of performing desensitization operations on point cloud data according to the preset rules is 60, and the corresponding weight is 0.15; the compliance confidence corresponding to the frequency of performing frame thinning on point cloud data according to the preset rules is 70, and the corresponding weight is 0.15; the compliance confidence corresponding to the frequency of encrypting location coordinate data according to the preset rules is 80, and the corresponding weight is 0.15; the compliance confidence corresponding to the frequency of performing data thinning on location coordinate data according to the preset rules is 90, and the corresponding weight is 0.15; the compliance confidence corresponding to the frequency of not performing desensitization operations on image data according to the preset rules is 55, and the corresponding weight is 0.05; the compliance confidence corresponding to the frequency of not performing desensitization operations on point cloud data according to the preset rules is 65, and the corresponding weight is 0.05; the compliance confidence corresponding to the frequency of not performing frame thinning on point cloud data according to the preset rules is 75, and the corresponding weight is 0.05; the compliance confidence corresponding to the frequency of not encrypting location coordinate data according to the preset rules is 85, and the corresponding weight is 0.05; the compliance confidence corresponding to the frequency of not performing data thinning on location coordinate data according to the preset rules is 95, and the corresponding weight is 0.05. Then the finally calculated compliance confidence is 71.25 (obtained from 50×0.15 + 60×0.15 + 70×0.15 + 80×0.15 + 90×0.15 + 55×0.05 + 65×0.05 + 75×0.05 + 85×0.05 + 95×0.05), and 71.25 ∈ (60, 90], so it can be considered that the compliance confidence is medium.

[0123] In another possible design, the compliance confidence can also be represented by a gear or level. For example, 3 gears or levels can be divided. Gear 1 (or level 1) represents a low compliance confidence, gear 2 (or level 2) represents a medium compliance confidence, and gear 3 (or level 3) represents a high compliance confidence. This application does not make any limitation on the specific form of the compliance confidence.

[0124] Exemplarily, the server statistically analyzes the above multiple frequencies based on the geographical information-related data. After obtaining the statistical results, it determines the compliance confidence level based on the magnitude relationship between the sum of the frequencies of processing data according to the preset rules and the preset first frequency threshold, and the magnitude relationship between the sum of the frequencies of not processing data according to the preset rules and the preset second frequency threshold. For example, the sum of the frequency of performing desensitization operations on image data according to the preset rules, the frequency of performing desensitization operations on point cloud data according to the preset rules, the frequency of performing frame thinning on point cloud data according to the preset rules, the frequency of performing encryption processing on location coordinate data according to the preset rules, and the frequency of performing data thinning on location coordinate data according to the preset rules is less than or equal to the first frequency threshold, and moreover, the sum of the frequency of not performing desensitization operations on image data according to the preset rules, the frequency of not performing desensitization operations on point cloud data according to the preset rules, the frequency of not performing frame thinning on point cloud data according to the preset rules, the frequency of not performing encryption processing on location coordinate data according to the preset rules, and the frequency of not performing data thinning on location coordinate data according to the preset rules is greater than or equal to the second frequency threshold. In this case, it can be considered that the compliance confidence level is relatively low. Another example is that the sum of the frequency of performing desensitization operations on image data according to the preset rules, the frequency of performing desensitization operations on point cloud data according to the preset rules, the frequency of performing frame thinning on point cloud data according to the preset rules, the frequency of performing encryption processing on location coordinate data according to the preset rules, and the frequency of performing data thinning on location coordinate data according to the preset rules is greater than the first frequency threshold, and moreover, the sum of the frequency of not performing desensitization operations on image data according to the preset rules, the frequency of not performing desensitization operations on point cloud data according to the preset rules, the frequency of not performing frame thinning on point cloud data according to the preset rules, the frequency of not performing encryption processing on location coordinate data according to the preset rules, and the frequency of not performing data thinning on location coordinate data according to the preset rules is less than the second frequency threshold. In this case, it can be considered that the compliance confidence level is relatively high. Yet another example is that the sum of the frequency of performing desensitization operations on image data according to the preset rules, the frequency of performing desensitization operations on point cloud data according to the preset rules, the frequency of performing frame thinning on point cloud data according to the preset rules, the frequency of performing encryption processing on location coordinate data according to the preset rules, and the frequency of performing data thinning on location coordinate data according to the preset rules is less than or equal to the first frequency threshold, or the sum of the frequency of not performing desensitization operations on image data according to the preset rules, the frequency of not performing desensitization operations on point cloud data according to the preset rules, the frequency of not performing frame thinning on point cloud data according to the preset rules, the frequency of not performing encryption processing on location coordinate data according to the preset rules, and the frequency of not performing data thinning on location coordinate data according to the preset rules is greater than or equal to the second frequency threshold. In this case, it can be considered that the compliance confidence level is relatively medium.

[0125] After obtaining the compliance confidence, the server can extract geospatial information related data based on the compliance confidence.

[0126] That is to say, the server can, based on the compliance confidence, extract some geospatial information related data for further compliance verification. Different compliance confidences may result in different types, amounts, or frequencies of the extracted geospatial information related data.

[0127] Exemplarily, when the compliance confidence of the vehicle is high, the server can extract a small amount of data from the geospatial information related data, or extract individual types of geospatial information related data for further compliance verification; when the compliance confidence is medium or low, the server can extract a large amount of data from the geospatial information related data, or extract partial geospatial information related data of multiple or each type for further compliance verification. That is to say, the result of the compliance confidence will affect the server's further compliance verification of the geospatial information related data, that is, the result of the previous compliance confidence will affect the server's calculation of the compliance confidence next time.

[0128] In a possible implementation, when the compliance confidence of the vehicle is low, the server can, through a control message, instruct the vehicle to remind the driver that the compliance confidence is low via the screen or display, or via voice, etc.

[0129] Furthermore, the server can further count the vehicles that sent the control message, compare the statistical result after the reminder with the statistical result before the reminder, and the change in the statistical result can affect the vehicle's compliance confidence. For example, if the compliance risk corresponding to the statistical result decreases after the reminder, the compliance confidence can be increased; if the compliance risk corresponding to the statistical result remains unchanged or becomes higher after the reminder, the compliance confidence will be further decreased.

[0130] A possible situation is that before the server conducts compliance verification on the geospatial information related data, method 200 further includes: the server determines that the vehicle is a randomly inspected object, and the randomly inspected object includes vehicles with a specific brand, specific model, or specific software system version number.

[0131] Exemplarily, before the server conducts compliance verification on the geospatial information related data, the server can use the security supervision control module 101 on the server side as shown in Figure 1 to determine which vehicles are randomly inspected objects based on the vehicle's brand, vehicle model, or software system version number, etc.

[0132] It can be seen that the server can actively conduct random inspections on vehicles with specific brands, specific models, or specific software system version numbers for compliance. In other words, the server actively initiates random inspections on the vehicle's geographical information-related data for compliance. This random inspection can also be called an active random inspection or a mandatory random inspection.

[0133] As an example but not a limitation, this implementation method can be applied to scenarios before the launch of new products of certain brands or certain models, or after the upgrade of certain software system versions deployed on vehicles. The server can conduct random inspections on these vehicles with specific brands, specific models, or specific software system version numbers to determine whether these vehicles are compliant.

[0134] In addition, this implementation method can also be applied to the daily compliance judgment scenario of vehicles. That is to say, the server can regularly or irregularly conduct random inspections on certain vehicles with specific brands, specific models, or specific software system version numbers for compliance to determine whether these vehicles are compliant. Among them, determining whether a vehicle is compliant can be understood as determining whether the vehicle complies with geographical information security supervision regulations, supervision requirements, or compliance requirements, etc. In other words, determining whether a vehicle is compliant is to determine whether the vehicle meets (or complies with) legal rules and / or industry rules.

[0135] Optionally, the method further includes: the server sends the first control message to vehicles with the same brand, the same model, or the same software system version number as the random inspection object.

[0136] That is to say, the server can select a part of the vehicles with specific brands, specific models, or specific software system version numbers for compliance verification, and can, according to the results of the compliance verification, supervise and control the vehicles with the same brand, the same model, or the same software system version number.

[0137] Another possible situation is that before the server conducts compliance verification on the geographical information-related data, the method 200 further includes: the server determines that the vehicle enters the fenced area.

[0138] It should be noted that the fenced area mentioned in this application does not specifically refer to a certain fenced area. The location and quantity of the fenced area vary according to different geographical regions. The fenced areas in each geographical region can be pre-configured by staff according to geographical information security supervision regulations, supervision requirements, or compliance requirements, etc., or can also be determined by the server itself according to geographical information security supervision regulations, supervision requirements, or compliance requirements, etc. This application does not make any limitations in this regard.

[0139] Exemplarily, the server, for example, specifically can be such as Figure 1The security supervision and control module 101 on the server side as shown can, based on the position coordinate data of the vehicle, determine that the vehicle has entered a certain fenced area, and then perform compliance verification on the data related to the geographical information of the vehicle, so as to determine whether the vehicle is compliant.

[0140] It can be seen that when the vehicle travels into a certain fenced area and triggers the server to perform compliance verification on the data related to the geographical information obtained for the vehicle, this can be understood as the server performing a passive random inspection of the compliance of the vehicle. This random inspection can be called a passive random inspection or a non-mandatory random inspection.

[0141] Furthermore, when it is determined that the vehicle has entered the fenced area, the server makes statistics based on the data related to the geographical information, including: the server makes statistics on at least one of the following based on the data related to the geographical information: the frequency of performing desensitization operations on image data according to a preset rule, the frequency of not performing desensitization operations on image data according to a preset rule, the frequency of performing desensitization operations on point cloud data according to a preset rule, the frequency of not performing desensitization operations on point cloud data according to a preset rule, the frequency of performing frame thinning on point cloud data according to a preset rule, the frequency of not performing frame thinning operations on point cloud data according to a preset rule, the frequency of performing encryption processing on position coordinate data according to a preset rule, the frequency of not performing encryption processing on position coordinate data according to a preset rule, the frequency of performing data thinning on position coordinate data according to a preset rule, the frequency of not performing data thinning on position coordinate data according to a preset rule, the frequency of the data related to the geographical information exceeding the road surface range, the area of the data related to the geographical information exceeding the road surface range, the frequency of performing compliance processing on the data related to the geographical information exceeding the road surface range according to a preset rule, the frequency of the vehicle entering each fenced area, whether the fenced areas entered multiple times by the vehicle are the same fenced area, the total frequency of the vehicle entering the fenced area, the way the vehicle enters the fenced area, the behavior state of the vehicle in the fenced area, and the behavior state includes: turning off the engine, starting, parking, decelerating, the residence time exceeding a first preset threshold, or the transmitted data traffic exceeding a second preset threshold.

[0142] It can be seen that when the vehicle enters the fenced area, the data randomly inspected by the server not only includes the above-mentioned statistical data on compliance operations, but also includes the statistics on the behavior data of the vehicle in the fenced area, etc. By statistically analyzing the data listed above, the server can obtain more comprehensive data about the vehicle, which is conducive to obtaining a more accurate compliance confidence level of the vehicle.

[0143] In step 230, the server sends a first control message to the vehicle based on the result of the compliance verification.

[0144] Exemplarily, in Figure 1In the system shown, the security supervision and control module 101 on the server side can send the geographical information-related data to the data verification and filing module 102 for compliance verification; after the data verification and filing module 102 conducts the compliance verification, it sends the result of the compliance verification to the security supervision and control module 101, so that the security supervision and control module 101 can use this as a reference to determine the processing authority of the vehicle for the geographical information-related data, and then issue a first control message.

[0145] Among them, the first control message is used to indicate the processing authority of the vehicle for the geographical information-related data.

[0146] In an actual application scenario, the result of the compliance verification can be a qualitative result or a quantitative result. This application does not make any restrictions on this.

[0147] As an example rather than a limitation, when the result of the compliance verification is a qualitative result, the result of the compliance verification can include passing the compliance verification or failing the compliance verification; alternatively, the result of the compliance verification can include compliance or non-compliance.

[0148] As an example rather than a limitation, when the result of the compliance verification is a quantitative result, the result of the compliance verification can be a numerical result. For example, a numerical value between 0 and 1, or a numerical value between 0 and 10, or a numerical value between 0 and 100, etc. Different numerical intervals of the result of the compliance verification can correspond to different degrees of compliance. Taking the result of the compliance verification as a numerical value between 0 and 10 as an example, if the result of the compliance verification ∈ [0, 5], it can indicate a low degree of compliance; if the result of the compliance verification ∈ (5, 8], it can indicate a medium degree of compliance; if the result of the compliance verification ∈ (8, 10], it can indicate a high degree of compliance.

[0149] Exemplarily, in Figure 1 In the system shown, after the data verification and filing module 102 on the server side conducts the compliance verification on the geographical information-related data, it can obtain the result of the compliance verification. The data verification and filing module can transfer the result of the compliance verification to the security supervision and control module 101. Subsequently, the security supervision and control module 101 generates the first control message according to the result of the compliance verification and sends the first control message to the vehicle.

[0150] The processing authority for geographical information-related data includes: permissions in multiple aspects such as storage and transmission. Exemplarily, the processing authority for geographical information-related data is: can store or transmit all geographical information-related data, can store or transmit part of the geographical information-related data, or cannot store or transmit any geographical information-related data.

[0151] Furthermore, storage and transmission can also be decoupled. For example, the processing permissions for geographical information-related data include storage permissions and transmission permissions. The storage permissions can be: can store all geographical information-related data, can store some geographical information-related data, or cannot store any geographical information-related data. The transmission permissions can be: can transmit all geographical information-related data, can transmit some geographical information-related data, or cannot transmit any geographical information-related data.

[0152] On this basis, the processing permissions for geographical information-related data also include collection permissions and usage permissions. For example, the collection permissions are: can collect all geographical information-related data, can collect some geographical information-related data, or cannot collect any geographical information-related data. The transmission permissions can be: can use all geographical information-related data, can use some geographical information-related data, or cannot use any geographical information-related data.

[0153] It can be seen that the processing permissions for geographical information-related data can include multiple aspects such as collection, usage, storage, and transmission. By superimposing the permissions in different aspects, the processing permissions of the vehicle for geographical information-related data can be obtained. As an example, the processing permissions of the vehicle for geographical information-related data are: can collect and use all geographical information-related data, and can store and transmit some geographical information-related data. Another example, the processing permissions of the vehicle for geographical information-related data are: can collect and use all geographical information-related data, and cannot store and transmit any geographical information-related data.

[0154] Among them, all geographical information-related data can include: all types of geographical information-related data, or geographical information-related data in all geographical regions. Some geographical information-related data includes: some types of geographical information-related data, or geographical information-related data in some geographical regions. Among them, all types of geographical information-related data can be determined according to the vehicle's own configuration. For example, the more types of sensors configured in the vehicle, the more data can be collected. Some types of geographical information-related data can be specified by the server. For example, through the first control message, the vehicle can store or transmit some of the following multiple types of data: image data, point cloud data, composition data, positioning data, vehicle behavior data, or vehicle-related data.

[0155] As an example, the processing permissions are: can collect, use, store, and transmit all geographical information-related data.

[0156] For example, when the result of compliance verification indicates a high level of compliance, the server can, through a first control message, instruct the vehicle that it can collect, use, store, and transmit all the data related to geographical information. It can be understood that when the result of compliance verification indicates a high level of compliance, it can be considered that the collection or transmission of geographical information by the vehicle is compliant. Therefore, the vehicle can be permitted to store or transmit all the data related to geographical information.

[0157] Another example, the processing permission is: it can collect and transmit all the data related to geographical information, and can store and transmit some of the data related to geographical information.

[0158] For example, when the result of compliance verification indicates a medium level of compliance, the server can, through a first control message, instruct the vehicle that it can collect and transmit all the data related to geographical information, and can store and transmit some of the data related to geographical information.

[0159] It can be understood that when the result of compliance verification indicates a medium level of compliance, it can be considered that the collection or transmission of geographical information by the vehicle is basically compliant, but there are also some non-compliant issues. Therefore, the vehicle can be permitted to collect and transmit all the data related to geographical information, but store or transmit some of the data related to geographical information. That is, the vehicle is not permitted to store or transmit the other part of the data related to geographical information, thereby reducing the geographical information security risk.

[0160] It can be understood that when the data related to geographical information of different types or different geographical regions are respectively integrated into different data packets, when the vehicle stores or transmits some of the data related to geographical information, the data related to geographical information of different types or different geographical regions can be integrated into different data packets for storage or transmission. When the data related to geographical information of different types or different geographical regions are all integrated into one data packet, when the vehicle stores or transmits some of the data related to geographical information, it is necessary to specifically avoid some types or some geographical regions of the data related to geographical information and not integrate this data into the data packet to be stored or transmitted.

[0161] Another example, the processing permission is: it can collect and transmit all the data related to geographical information, and is not allowed to store or transmit any of the data related to this geographical information.

[0162] Exemplarily, when the result of compliance verification indicates a low level of compliance, the server can, through a first control message, instruct the vehicle that it can collect and transmit all the data related to geographical information, but is not allowed to store or transmit any of the data related to this geographical information.

[0163] It can be understood that when the result of compliance verification indicates a low level of compliance, it can be considered that the collection or transmission of geographical information by the vehicle is non-compliant, with many non-compliance issues. Therefore, the vehicle is not permitted to store or transmit any geographical information-related data, thereby reducing the geographical information security risk. In this case, the vehicle can only collect and use geographical information-related data, that is, use it and discard it immediately.

[0164] In addition to determining the vehicle's processing authority for geographical information-related data, the server can also determine whether the geographical information-related data can be used based on the result of compliance verification.

[0165] It should be noted that the vehicle sending geographical information-related data to the server in step 210 above, and the server's compliance verification of the geographical information-related data in step 220, may be periodic or triggered by an event. That is to say, steps 210 and 220 may be executed more than once. The server can, in step 230, determine the vehicle's processing authority for geographical information-related data based on the result of the most recent compliance verification, and then send the most recently determined processing authority to the vehicle through the first control message, that is, step 230 may also be executed more than once. Depending on the different results of compliance verification, the processing authorities indicated by different first control messages may be the same or different. In other words, the vehicle's processing authority for geographical information-related data may not be fixed. The vehicle can determine its own processing authority based on the most recent first control message received and make corresponding controls based on this processing authority.

[0166] The result of compliance verification not only affects the vehicle's processing authority for geographical information-related data, but can also be used as reference information for the server to make other decisions. For example, the server can also determine whether the geographical information-related data can be used based on the result of compliance verification; for another example, the server can also impose constraints on the vehicle's path planning based on the result of this compliance verification; for yet another example, the server can also determine whether to adjust the crowdsourcing collection task based on the result of this compliance verification.

[0167] The following will elaborate on these aspects.

[0168] Optionally, the method 200 further includes: when the compliance verification passes, the server uses the geographical information-related data; when the compliance verification fails, the server discards the geographical information-related data.

[0169] Exemplarily, in Figure 1In the system shown, the security supervision and control module 101 on the server side can send the geographical information-related data to the data verification and filing module 102 for compliance verification; when the compliance verification is passed, the data verification and filing module 102 can send the geographical information-related data to the data application module 104, and the data application module 104 can use the geographical information-related data. Or, when the compliance verification fails, the data verification and filing module 102 can discard the geographical information-related data without sending it to the data application module 104 for use. By way of example and not limitation, the data application module 104 can be used to use geographical information-related data, and can include model training, simulation, map updating, etc. based on the geographical information-related data. This application does not make any limitations in this regard.

[0170] In addition, when the compliance verification is passed, and when the server side receives the geographical information-related data of the vehicle next time, the security supervision and control module 101 can directly send the geographical information-related data to the data application module 104 for use without forwarding it through the data verification and filing module 102.

[0171] It can be understood that when the result of the compliance verification is a qualitative result, it is easy to judge whether the compliance verification is passed or fails. For example, the result of the compliance verification is either passed or failed, or compliant or non-compliant.

[0172] As an example, when the result of the compliance verification is a quantitative result. For example, taking the result of the compliance verification as a value between 0 and 10 as an example, when the result of the compliance verification is 3, 3 ∈ [0, 5], it can be considered that the compliance verification fails; when the result of the compliance verification is 8, 8 ∈ (5, 8], it can be considered that the compliance verification is passed; when the result of the compliance verification is 9, 9 ∈ (8, 10], it can be considered that the compliance verification is passed.

[0173] Another example, still taking the result of the compliance verification as a value between 0 and 10 as an example, when the result of the compliance verification is less than the preset threshold, it can be considered that the compliance verification fails; when the result of the compliance verification is greater than or equal to the preset threshold, it can be considered that the compliance verification is passed. For example, the preset threshold is 5. When the result of the compliance verification is 3, 3 is less than 5, it can be considered that the compliance verification fails; when the result of the compliance verification is 8, 3 is greater than 5, it can be considered that the compliance verification is passed.

[0174] Or, in another implementation, when the compliance verification fails, instead of the server discarding the geographical information-related data, it can also be replaced with: performing compliance processing on the geographical information-related data and using the geographical information-related data after compliance processing.

[0175] Exemplarily, inFigure 1 In the system shown, when the data verification and filing module 102 fails to pass the compliance verification of the geographic information-related data, it can first perform compliance processing on the geographic information-related data that fails to pass the compliance verification, and transfer the geographic information-related data after the compliance processing to the data application module 104. Subsequently, the data application module 104 can use the geographic information-related data after the compliance processing.

[0176] It can be understood that the compliance processing may include, but is not limited to, one or more of the following: cropping the data outside the road surface range in the geographic information-related data to obtain the data within the compliant road surface range; or, performing desensitization processing on the un-desensitized data or the data with incomplete desensitization to obtain compliant desensitized data; or, performing encryption processing on the data that needs to be encrypted but is not encrypted to obtain compliant encrypted data; or, performing frame rate thinning processing on the data that needs to be frame rate thinned but has not been frame rate thinned or has non-compliant frame rate thinning to obtain the data after compliant frame rate thinning; or, performing data thinning processing on the data that needs to be data thinned but has not been data thinned or has non-compliant data thinning to obtain the data after compliant data thinning; and so on.

[0177] A possible situation is caused by insufficient processing power at the vehicle end. For example, the computing power at the vehicle end is not high, the compliance processing model is incomplete, etc. Therefore, there may be a situation where the compliance verification of some of the geographic information-related data fails, while the compliance verification of some other geographic information-related data passes. The server can directly use this part of the geographic information-related data that passes the compliance verification. For those geographic information-related data that fail to pass the compliance verification, the server can directly discard them, or use them after performing compliance processing on them. This application does not make any limitations on this.

[0178] Since the server has higher computing power, it can perform compliance processing on these geographic information-related data that fail to pass the compliance verification and then use them, thereby reducing the geographic information security risk. Optionally, the method 200 further includes: the server sends a second control message based on the result of the compliance verification, and the second control message is used to indicate whether the path planning can pass through the fence area. Correspondingly, the vehicle receives the second control message.

[0179] Exemplarily, when the result of the compliance verification is that the compliance verification passes, or is compliant, or has a high degree of compliance, the server may, through a second control message, indicate that the vehicle path planning may pass through the fenced area; when the result of the compliance verification is that the compliance verification fails, or is non-compliant, or has a low degree of compliance, the server may, through a second control message, indicate that the vehicle path planning may not pass through the fenced area. When the result of the compliance verification is of medium degree of compliance, the server may, through a second control message, indicate that the vehicle path planning may pass through the fenced area, or indicate that the vehicle path planning may not pass through the fenced area. Or, when the result of the compliance verification is of medium degree of compliance, the server may consider other factors to decide whether to allow the vehicle path planning to pass through the fenced area, and this application does not make any limitations in this regard.

[0180] Optionally, the method 200 further includes: the server, based on the result of the compliance verification, sends a third control message, and the third control message is used to indicate whether to reduce the crowdsourcing collection task. Correspondingly, the vehicle receives the third control message.

[0181] Reducing the crowdsourcing collection task can be understood as reducing the collection frequency of the vehicle for the geographic information related data, or reducing the amount of the collected geographic information related data of the vehicle for a certain type or certain geographic regions, etc.

[0182] Exemplarily, when the result of the compliance verification is that the compliance verification passes, or is compliant, or has a high degree of compliance, the server may, through a third control message, indicate that the vehicle does not need to reduce the crowdsourcing collection task; when the result of the compliance verification is that the compliance verification fails, or is non-compliant, or has a low degree of compliance, the server may, through a third control message, indicate that the vehicle reduces the crowdsourcing collection task. When the result of the compliance verification is of medium degree of compliance, the server may, through a third control message, indicate that the vehicle does not need to reduce the crowdsourcing collection task, or indicate that the vehicle reduces the crowdsourcing collection task. Or, when the result of the compliance verification is of medium degree of compliance, the server may consider other factors to decide whether the vehicle needs to reduce the crowdsourcing collection task, and this application does not make any limitations in this regard.

[0183] Based on the above solution, the server performs compliance verification on the geographic information related data collected by the vehicle, and then decides the processing authority of the vehicle for these geographic information related data according to the result of the compliance verification, so as to supervise and control the processing of the vehicle geographic information related data, thereby reducing the geographic information security risk.

[0184] In addition, the server does not use the geographic information related data that fails to pass the compliance, but discards or further performs compliance processing on the geographic information related data that fails to pass the compliance verification, which also helps to reduce the geographic information security risk.

[0185] In addition, when the compliance verification is passed, it can be considered that the vehicle's processing of geoinformation-related data complies with legal rules and / or industry rules, and the vehicle's path planning can be allowed to pass through the fenced area without generating significant geoinformation security risks; while when the compliance verification fails, it can be considered that the vehicle's processing of geoinformation-related data does not comply with legal rules and / or industry rules, and the vehicle's path planning is not allowed to pass through the fenced area, thus avoiding the generation of significant geoinformation security risks.

[0186] Furthermore, when the compliance verification is passed, it can be considered that the vehicle can process geoinformation-related data in a manner that complies with legal rules and / or industry rules, and without reducing the crowdsourcing collection tasks, it will not generate significant geoinformation security risks; when the compliance verification fails, it can be considered that the vehicle cannot process geoinformation-related data in a manner that complies with legal rules and / or industry rules, and by controlling the vehicle to reduce the crowdsourcing collection tasks, the generation of significant geoinformation security risks can be avoided.

[0187] Figure 3 It is a schematic block diagram of the geoinformation security supervision device provided by the present application.

[0188] As Figure 3 shown, the geoinformation security supervision device 300 may include: a transceiver module 310 and a processing module 320. The geoinformation security supervision device 300 can be used to execute the execution steps of the server in the geoinformation security supervision method proposed in the embodiments of the present application.

[0189] Exemplarily, when the geoinformation security supervision device 300 is used to execute the execution steps of the server in method 200, wherein the transceiver module 310 can be used to receive geoinformation-related data from the vehicle; the processing module 320 can be used to perform compliance verification on the geoinformation-related data; the transceiver module 310 can also be used to send a first control message to the vehicle based on the result of the compliance verification.

[0190] Optionally, the processing permission is: it can store or transmit all geoinformation-related data; or, it can store or transmit part of the geoinformation-related data; or, it cannot store or transmit any geoinformation-related data.

[0191] Optionally, part of the geoinformation-related data includes: part of the types of geoinformation-related data, or geoinformation-related data of part of the geographical area.

[0192] Optionally, the processing module 320 may also be configured to: determine that the vehicle is a randomly inspected object, where the randomly inspected object includes vehicles with a specific brand, specific model, or specific software system version number; or, determine that the vehicle enters a fenced area.

[0193] Optionally, the processing module 320 may specifically be configured to: perform statistics based on the geospatial information-related data to obtain a statistical result; calculate a compliance confidence level based on the statistical result, where the compliance confidence level is used to indicate the credibility of the vehicle's compliance with a preset rule; extract geospatial information-related data based on the compliance confidence level; and perform compliance verification on the extracted geospatial information-related data.

[0194] Optionally, the processing module 320 may specifically be configured to: perform statistics on at least one of the following based on the geospatial information-related data: the frequency of performing a desensitization operation on image data according to a preset rule, the frequency of not performing a desensitization operation on image data according to a preset rule, the frequency of performing a desensitization operation on point cloud data according to a preset rule, the frequency of not performing a desensitization operation on point cloud data according to a preset rule, the frequency of performing a frame thinning operation on point cloud data according to a preset rule, the frequency of not performing a frame thinning operation on point cloud data according to a preset rule, the frequency of performing an encryption process on location coordinate data according to a preset rule, the frequency of not performing an encryption process on location coordinate data according to a preset rule, the frequency of performing a data thinning operation on location coordinate data according to a preset rule, the frequency of not performing a data thinning operation on location coordinate data according to a preset rule, the frequency of the geospatial information-related data exceeding the road surface range, the area of the geospatial information-related data exceeding the road surface range, or the frequency of performing a compliance process on the geospatial information-related data exceeding the road surface range according to a preset rule.

[0195] Optionally, when it is determined that the vehicle enters a fenced area, the processing module 320 may specifically be configured to: perform statistics on at least one of the following based on the geospatial information-related data: the frequency of the vehicle entering each fenced area, whether the fenced areas entered by the vehicle multiple times are the same fenced area, the total frequency of the vehicle entering the fenced area, the manner in which the vehicle enters the fenced area, the behavior state of the vehicle in the fenced area, where the behavior state includes: turning off the engine, starting, parking, decelerating, the residence time exceeding a first preset threshold, or the data traffic transmitted exceeding a second preset threshold.

[0196] Optionally, the processing module 320 may also be configured to: use the geospatial information-related data when the compliance verification is passed.

[0197] Optionally, the transceiver module 310 may also be configured to: send a second control message based on the result of the compliance verification, where the second control message is used to indicate whether path planning can pass through the fenced area.

[0198] Optionally, the transceiver module 310 may further be configured to: based on the result of the compliance verification, send a third control message for indicating whether to reduce the crowdsourcing collection task.

[0199] Figure 4 It is another schematic block diagram of the geographic information security supervision device provided by the present application.

[0200] As Figure 4 shown, the geographic information security supervision device 400 may include: a sending module 410 and a receiving module 420. The geographic information security supervision device 400 may be configured to execute the vehicle execution steps in the geographic information security supervision method provided in the embodiments of the present application.

[0201] Exemplarily, when the geographic information security supervision device 400 is configured to execute the vehicle execution steps in method 200, wherein the sending module 410 may be configured to send geographic information related data to the server for compliance verification; the receiving module 420 may be configured to receive a first control message from the server, the first control message is sent based on the result of the compliance verification, and the first control message is used to indicate the processing authority of the vehicle for the geographic information related data.

[0202] Optionally, the processing authority is: all geographic information related data can be stored or transmitted; or, partial geographic information related data can be stored or transmitted; or, any geographic information related data cannot be stored or transmitted.

[0203] Optionally, the partial geographic information related data includes: partial types of geographic information related data, or geographic information related data of partial geographic regions.

[0204] Optionally, the receiving module 420 may further be configured to: receive a second control message for indicating whether path planning can pass through a fenced area.

[0205] Optionally, the receiving module 420 may further be configured to: receive a third control message for indicating whether to reduce the crowdsourcing collection task.

[0206] Figure 5 It is another schematic block diagram of the geographic information security supervision device provided by the present application.

[0207] The geographic information security supervision device 500 may be configured to implement the functions of the server or the vehicle in the above method. The geographic information security supervision device 500 may be a chip system. In the embodiments of the present application, the chip system may be composed of chips, or may include chips and other discrete devices.

[0208] As Figure 5As shown, the geographic information security supervision device 500 may include at least one processor 510, which is used to implement the functions of the server or the vehicle in the method provided by the embodiments of the present application.

[0209] For example, when the geographic information security supervision device 500 is used to implement the function of the server in the method 200 provided by the embodiments of the present application, the processor 510 may be used to receive geographic information related data from the vehicle; perform compliance verification on the geographic information related data; and based on the result of the compliance verification, send a first control message to the vehicle, where the first control message is used to indicate the processing permission of the vehicle for the geographic information related data. For specific details, refer to the detailed description in the method example, which will not be elaborated here.

[0210] For example, when the geographic information security supervision device 500 is used to implement the function of the vehicle in the method 200 provided by the embodiments of the present application, the processor 510 may be used to send geographic information related data to the server, where the geographic information related data is used for compliance verification; and receive a first control message from the server, where the first control message is sent based on the result of the compliance verification, and the first control message is used to indicate the processing permission of the vehicle for the geographic information related data. For specific details, refer to the detailed description in the method example, which will not be elaborated here.

[0211] The geographic information security supervision device 500 may further include at least one memory 520, which is used to store program instructions and / or data. The memory 520 is coupled to the processor 510. The coupling in the embodiments of the present application is an indirect coupling or communication connection between devices, units or modules, which may be electrical, mechanical or other forms, and is used for information interaction between devices, units or modules. The processor 510 may cooperate with the memory 520. The processor 510 may execute the program instructions stored in the memory 520. At least one of the at least one memory may be included in the processor.

[0212] The geographic information security supervision device 500 may further include a communication interface 530, which is used to communicate with other devices through a transmission medium, so that the geographic information security supervision device 500 can communicate with other devices. Exemplarily, when the geographic information security supervision device 500 is used to implement the function of the server in the method provided by the embodiments of the present application, the other device may be a vehicle; when the geographic information security supervision device 500 is used to implement the function of the vehicle in the method provided by the embodiments of the present application, the other device may be a server. The communication interface 530 may be, for example, a transceiver, an interface, a bus, a circuit or a device capable of implementing a transceiver function. The processor 510 may use the communication interface 530 to send and receive data and / or information, and is used to implement Figure 2 the methods performed by the server or the vehicle described in the corresponding embodiments in

[0213] In the embodiments of the present application, the specific connection medium between the above-mentioned processor 510, memory 520, and communication interface 530 is not limited. In the embodiments of the present application, Figure 5 it is connected by a bus 540 between the processor 510, memory 520, and communication interface 530. The bus 540 is represented by a thick line in Figure 5 it. The connection manners between other components are only for illustrative purposes and are not limited thereto. The bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, Figure 5 it is only represented by a thick line in it, but it does not mean that there is only one bus or one type of bus.

[0214] The present application also provides a geographic information security supervision system, which includes a server and a vehicle. The server is used to execute the functions of the server in the method embodiments as Figure 2 shown, and the vehicle is used to execute the functions of the vehicle in the method embodiments as Figure 2 shown.

[0215] The present application also provides a chip system, which includes at least one processor for implementing the functions involved in the methods executed by the server or the vehicle in the above Figure 2 shown embodiments. For example, receiving or processing the data and / or information involved in the above methods.

[0216] In a possible design, the chip system further includes a memory for storing program instructions and data. The memory is located inside or outside the processor.

[0217] The chip system can be composed of chips or can include chips and other discrete devices.

[0218] The embodiments of the present application also provide a readable storage medium, on which a program is stored. When the program is run, Figure 2 the methods executed by the server in the above shown embodiments are executed, or the methods executed by the vehicle are executed.

[0219] The embodiments of the present application also provide a program product, including a program. When the program is run, Figure 2 the methods executed by the server in the above shown embodiments are executed, or the methods executed by the vehicle are executed.

[0220] It should be understood that the processor in the embodiments of the present application may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method embodiments may be completed by the integrated logic circuit in the hardware of the processor or instructions in the form of software. The above-mentioned processor may be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application may be directly embodied as being executed and completed by a hardware decoding processor, or executed and completed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.

[0221] It should also be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0222] As used in this specification, terms such as "unit", "module", etc. can be used to represent an entity, hardware, firmware, a combination of hardware and software, software, or software in execution related to a device or apparatus.

[0223] Those of ordinary skill in the art can realize that the various illustrative logical blocks and steps described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application. In several embodiments provided in this application, it should be understood that the disclosed devices, equipment, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or modules can be in electrical, mechanical, or other forms.

[0224] The modules described as separate components may or may not be physically separated. The components shown as modules may or may not be physical modules, that is, they can be located in one place, or they can be distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0225] In addition, in each embodiment of this application, the functional modules can be integrated into one processing module, or each module can exist physically separately, or two or more units can be integrated into one module.

[0226] In the above embodiments, the functions of each functional module can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a program product. The program product includes one or more instructions (programs). When the program instructions (programs) are loaded and executed on a device or apparatus, the processes or functions described in the embodiments of the present application are generated in whole or in part. The instructions can be stored in a readable storage medium, or transmitted from one readable storage medium to another readable storage medium. For example, the instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The readable storage medium can be any available medium that can be accessed by the device or apparatus, or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a digital videodisc (DVD)), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0227] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The software product is stored in a storage medium and includes several instructions for causing a device or apparatus (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.

[0228] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for geographical information security supervision, characterized in that, Applied to a server, the method includes: Receiving geographical information related data from a vehicle; Performing compliance verification on the geographical information related data; Based on the result of the compliance verification, sending a first control message to the vehicle, the first control message being used to indicate the processing permission of the vehicle for the geographical information related data.

2. The method according to claim 1, characterized in that, The processing permission is: All geographical information related data can be stored or transmitted; or, Part of the geographical information related data can be stored or transmitted; or Any geographical information related data cannot be stored or transmitted.

3. The method according to claim 2, characterized in that, The part of the geographical information related data includes: part of the types of geographical information related data, or geographical information related data of part of the geographical area.

4. The method according to any one of claims 1 to 3, characterized in that, Before performing the compliance verification on the geographical information related data, the method further includes: Determining that the vehicle is a spot-check object, the spot-check object including vehicles with a specific brand, a specific vehicle model, or a specific software system version number; or, Determining that the vehicle enters a fenced area.

5. The method according to any one of claims 1 to 4, characterized in that, The performing the compliance verification on the geographical information related data includes: Performing statistics according to the geographical information related data to obtain a statistical result; Calculating a compliance compliance confidence level according to the statistical result, the compliance compliance confidence level being used to indicate the credibility of the vehicle's compliance with a preset rule; Performing extraction of the geographical information related data according to the compliance compliance confidence level; Performing the compliance verification on the extracted geographical information related data.

6. The method according to claim 5, characterized in that, The performing statistics according to the geographical information related data includes: Performing statistics on at least one of the following according to the geographical information related data: the frequency of performing desensitization operations on image data according to a preset rule, the frequency of not performing desensitization operations on image data according to the preset rule, the frequency of performing desensitization operations on point cloud data according to the preset rule, the frequency of not performing desensitization operations on point cloud data according to the preset rule, the frequency of performing frame thinning on point cloud data according to the preset rule, the frequency of not performing frame thinning operations on point cloud data according to the preset rule, the frequency of performing encryption processing on position coordinate data according to the preset rule, the frequency of not performing encryption processing on position coordinate data according to the preset rule, the frequency of performing data thinning on position coordinate data according to the preset rule, the frequency of not performing data thinning operations on position coordinate data according to the preset rule, the frequency of the geographical information related data exceeding the road surface range, the area of the geographical information related data exceeding the road surface range, or the frequency of performing compliance processing on the geographical information related data exceeding the road surface range according to the preset rule.

7. The method according to claim 5 or 6, characterized in that, When it is determined that the vehicle enters the fenced area, the performing statistics according to the geographical information related data includes: Statistically analyze at least one of the following based on the geospatial information related data: the frequency of the vehicle entering each fenced area, whether the fenced areas entered multiple times by the vehicle are the same fenced areas, the total frequency of the vehicle entering the fenced areas, the manner in which the vehicle enters the fenced areas, and the behavioral state of the vehicle in the fenced areas, where the behavioral state includes: turning off the engine, starting, parking, decelerating, the residence duration exceeding a first preset threshold, or the data traffic transmitted exceeding a second preset threshold.

8. The method according to any one of claims 1 to 7, characterized in that, The method further includes: Using the geospatial information related data when the compliance verification is passed.

9. The method according to any one of claims 1 to 8, characterized in that, The method further includes: Sending a second control message based on the result of the compliance verification, where the second control message is used to indicate whether path planning can pass through the fenced area.

10. The method according to any one of claims 1 to 9, characterized in that, The method further includes: Sending a third control message based on the result of the compliance verification, where the third control message is used to indicate whether to reduce the crowdsourcing collection task.

11. A method for geographical information security supervision, characterized in that, Applied to a vehicle, the method includes: Sending geospatial information related data to the server, where the geospatial information related data is used for compliance verification; Receiving a first control message from the server, where the first control message is sent based on the result of the compliance verification, and the first control message is used to indicate the processing permission of the vehicle for the geospatial information related data.

12. The method according to claim 11, characterized in that, The processing permission is: All of the geospatial information related data can be stored or transmitted; or, Some of the geospatial information related data can be stored or transmitted; or, None of the geospatial information related data can be stored or transmitted.

13. The method according to claim 12, characterized in that, The some of the geospatial information related data includes: some types of the geospatial information related data, or the geospatial information related data of some geographical regions.

14. The method according to any one of claims 11 to 13, characterized in that, The method further includes: Receiving a second control message, where the second control message is used to indicate whether path planning can pass through the fenced area.

15. The method according to any one of claims 11 to 14, characterized in that, The method further includes: Receiving a third control message, where the third control message is used to indicate whether to reduce the crowdsourcing collection task.

16. A geographical information security supervision device, characterized in that, Comprising a processor and a communication interface, where the processor is configured to execute a program to cause the method according to any one of claims 1 to 10 to be executed, or to cause the method according to any one of claims 11 to 15 to be executed.

17. A readable storage medium, on which a program is stored, characterized in that, When the program is executed by the processor, the method according to any one of claims 1 to 10 is executed, or the method according to any one of claims 11 to 15 is executed.

18. A computer program product, characterized in that, Comprising a program, when the program is run, the method according to any one of claims 1 to 10 is executed, or the method according to any one of claims 11 to 15 is executed.

Citation Information

Cited By

  • Security protection method and device for space coordinates in C-V2X scene

    CN120434623A

  • A method and device for protecting spatial coordinates in a C-V2X scenario

    CN120434623B