Information management device

By equiping the vehicle with a user consent module, a correction module and a deletion module, and determining its operation according to the legal domain, the compliance problem of privacy information under different legal domains is solved, and the automated protection and compliance of privacy information is achieved.

CN120509044APending Publication Date: 2025-08-19TOYOTA JIDOSHA KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510129133.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-02-16
Filing Date
2025-02-05
Publication Date
2025-08-19

AI Technical Summary

Technical Problem

In vehicles, the prior art cannot effectively deal with the differences in privacy regulations between different jurisdictions, resulting in the inability to properly protect privacy information.

Method used

The information management device is equipped with a module for obtaining user consent, a module for correction and a module for deletion, and communicates with the data processing hardware through the user interface, and determines whether these modules are operated based on the legal domain of the vehicle, ensuring compliance and protection of privacy information.

Benefits of technology

It realizes automatic adjustment of the storage, correction and deletion of privacy information according to the privacy regulations of different legal regions, reducing user inquiries and ensuring compliance and protection of privacy information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120509044A_ABST
    Figure CN120509044A_ABST
Patent Text Reader

Abstract

An information management device is mounted in a vehicle and includes data processing hardware, a memory, and a user interface. The switching module judges whether the user agreement obtaining module, the correction module and the deletion module are operated or not according to the normal domain where the vehicle is located. The user agreement obtaining module associates the privacy setting with a normal region in which the vehicle is located and stores the privacy setting and the normal region in the memory. The correction module corrects the stored privacy information item according to the correction requirement. The deletion module deletes one stored privacy information item according to a deletion request.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information management device mounted on a vehicle. Background Art

[0002] Japanese Patent Application Laid-Open No. 2021-170016 discloses an information management device installed in a vehicle. The device asks the vehicle user whether to allow the user's private information to be permanently stored in a storage device. Examples of private information include the user's name, credit card number, location, and vehicle speed.

[0003] If the user permits permanent storage of private information on the storage device, the information management device permanently stores the user's private information on the storage device. If the user denies permanent storage of private information on the storage device, the information management device loads the user's private information into volatile memory for use. In these cases, the user's private information is not permanently stored on the storage device.

[0004] Privacy regulations applicable in one jurisdiction may differ from those applicable in another. A jurisdiction may be, for example, a country, state, or territory. For example, some jurisdictions require user consent for the permanent storage of private information items on a storage device, while others do not.

[0005] Therefore, the functions required to properly protect private information may differ depending on the privacy laws in each jurisdiction. As a result, there is a risk that private information may not be properly protected when moving to a jurisdiction with different privacy laws. Summary of the Invention

[0006] According to one embodiment of the present disclosure, there is provided an information management device, which is mounted on a vehicle and comprises: data processing hardware; a storage device configured to communicate with the data processing hardware; and a user interface configured to communicate with the data processing hardware, wherein the data processing hardware comprises: a user consent acquisition module configured to display on the user interface a privacy setting indicating whether one or more items of private information are permitted to be stored in the storage device, receive the privacy setting from the user interface, associate the privacy setting with the legal jurisdiction in which the vehicle is located, and store the privacy setting in the storage device; and a correction module configured to display on the user interface a correction of one or more items of private information that are already stored in the storage device. a deletion module configured to display on the user interface a request for modifying one privacy information item stored in the storage among the one or more privacy information items, receive the request for modification from the user interface, and modify the one privacy information item that has been stored according to the request; a deletion module configured to display on the user interface a request for deletion of one privacy information item that has been stored in the storage among the one or more privacy information items, receive the request for deletion from the user interface, and delete the one privacy information item that has been stored according to the request; and a switching module configured to determine whether to respectively operate the user consent obtaining module, the modification module, and the deletion module according to the legal jurisdiction in which the vehicle is located at the moment the drive system of the vehicle is turned on. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] Figure 1 This is a diagram showing an information management device according to an embodiment mounted on a vehicle.

[0008] Figure 2 This is a diagram showing an example of screen display in the user interface.

[0009] Figure 3 Yes Figure 1 Flowchart of the processing executed by the information management device shown.

[0010] Figure 4 Yes Figure 3 Flowchart of module operation determination processing shown.

[0011] Figure 5 This is a flowchart illustrating a process for complying with privacy laws in jurisdictions that require users to be repeatedly asked about their privacy settings.

[0012] Figure 6 This is a flowchart showing a process for acquiring privacy settings related to a legal domain adjacent to the legal domain in which the vehicle is currently located. DETAILED DESCRIPTION

[0013] Hereinafter, an information management device according to an embodiment will be described with reference to the drawings.

[0014] <Configuration of Information Management Device 100>

[0015] Reference Figure 1 The configuration of the information management device 10 mounted on the vehicle 100 will be described. The information management device 10 includes data processing hardware 20 , a storage device 30 , and a user interface 40 . The storage device 30 and the user interface 40 are each configured to communicate with the data processing hardware 20 .

[0016] An ignition switch 31 is provided in vehicle 100. Data processing hardware 20 includes a drive system module 28. When a user presses ignition switch 31, drive system module 28 turns on drive system 50 of vehicle 100. This also turns on switching module 24, current jurisdiction determination module 25, storage module 26, and control module 27. Details of these modules included in data processing hardware 20 will be described later.

[0017] A GPS (Global Positioning System) sensor 32 is provided in vehicle 100. Current jurisdiction determination module 25 determines the jurisdiction in which vehicle 100 is located based on the location information of vehicle 100 obtained by GPS sensor 32. Current jurisdiction determination module 25 provides information indicating the jurisdiction in which vehicle 100 is located to switching module 24. A jurisdiction is, for example, a country, state, or territory. Multiple countries can constitute a single jurisdiction.

[0018] The switching module 24 determines whether to operate the privacy protection module group according to the legal domain in which the vehicle 100 is located when the driving system 50 of the vehicle 100 is turned on. Here, the privacy protection module group includes the user consent acquisition module 21, the modification module 22, and the deletion module 23. The privacy protection module group will be described later. The process of determining whether to operate the privacy protection module group is Figure 3 Step S314 and Figure 4 The module operation determination process shown in FIG. Figure 3 As will be described later in step S310, the switching module 24 also performs module operation determination processing immediately after switching from the restricted mode to the normal mode. Figure 3 As will be described later in step S316 of the control, the restriction mode is a mode set when the position of the vehicle 100 cannot be obtained. Figure 3 As will be described later in step S302 of FIG. 1 , the normal mode is a mode set when the position of the vehicle 100 can be obtained. Figure 3As will be described later in step S312 , the switching module 24 also performs the module operation determination process when the legal domain in which the vehicle 100 is currently located is different from the legal domain in which the vehicle 100 was previously determined to be located.

[0019] The DCM (Data Communication Module) 33 is provided in the vehicle 100. The DCM 33 can communicate with a device located outside the vehicle 100. As described above, the switching module 24 performs the module operation determination process according to the jurisdiction in which the vehicle 100 is located when the drive system 50 of the vehicle 100 is turned on. The module operation determination process performed by the switching module 24 can be changed via the DCM 33. For example, for a certain jurisdiction, it is possible to change from a form in which only the user consent module 21 is operated to a form in which all privacy protection module groups are operated. The update tool 34 can be provided in the vehicle 100. By connecting the update tool 34 to the vehicle 100 by wire, the module operation determination process can be changed.

[0020] The user interface 40 is provided in the vehicle 100. The user interface 40 is, for example, a touch display that receives input from the user.

[0021] Next, the privacy protection module group included in the data processing hardware 20 will be described in detail.

[0022] The user consent module 21 displays a message on the user interface 40 for accepting privacy settings from the user. The privacy settings indicate whether to permit storage of one or more items of private information in the storage 30. The user consent module 21 receives the privacy settings from the user interface 40. The user consent module 21 associates the privacy settings with the jurisdiction in which the vehicle 100 is located and stores the privacy settings in the storage 30. The storage module 26 stores the privacy settings in the storage 30.

[0023] Correction module 22 displays a message on user interface 40 for accepting a correction request. The correction request is a request to correct one of one or more private information items already stored in storage 30. Correction module 22 receives the correction request from user interface 40. Correction module 22 corrects the stored private information item in accordance with the correction request. The correction of the stored private information item is performed by storage module 26.

[0024] Deletion module 23 displays a message on user interface 40 for accepting a deletion request. The deletion request is a request to delete one of one or more private information items stored in storage 30. Deletion module 23 receives the deletion request from user interface 40. In response to the deletion request, deletion module 23 deletes the stored private information item. Deletion of the stored private information item is performed by storage module 26.

[0025] As described above, the data processing hardware 20 includes the control module 27. The control module 27 requests the storage module 26 to store the private information items in the memory 30 according to the privacy setting.

[0026] <An Example of Screen Display 200 on User Interface 40>

[0027] Reference Figure 2 An example of the screen display 200 in the user interface 40 will be described. The screen display 200 in the user interface 40 includes four private information items. These four private information items are Figure 2 The four private information items are name, credit card number, location information of vehicle 100, and speed of vehicle 100. The one or more private information items displayed on user interface 40 may differ for each jurisdiction.

[0028] The screen display 200 in the user interface 40 shows whether or not there is consent for each of the four privacy information items. Figure 2 is surrounded by a single dotted line 204. Figure 2 In the example shown, the user agrees to store the name, credit card number, and speed of the vehicle 100 in the storage 30. The user does not agree to store the location information of the vehicle 100 in the storage 30. Figure 2 In the example shown, the presence or absence of consent is indicated for each of the four privacy information items. Alternatively, the presence or absence of consent may be indicated for all the privacy information items at once.

[0029] exist Figure 2 In the example shown, the user consent module 21 is in operation. Depending on the jurisdiction, the user consent module 21 may not be in operation. Specifically, whether to operate the user consent module 21 is determined for each jurisdiction. If the user consent module 21 is in operation, the user is asked for permission to collect one or more items of private information for each jurisdiction.

[0030] exist Figure 2 In the example shown, the deletion module 23 is not running. One or more private information items may not be deleted or may be automatically deleted. For example, when the vehicle 100 moves from the first legal domain to the second legal domain, one or more private information items associated with the first legal domain may be automatically deleted. Figure 2 Different from the example shown, when the deletion module 23 is running, it can be Figure 2One to four delete buttons are displayed in the area surrounded by the dot-dash line 206. That is, whether to operate the delete module 23 is determined for each jurisdiction. When the delete module 23 is operated, it is determined whether the user can delete any one of one or more private information items.

[0031] exist Figure 2 In the example shown, the correction module 22 operates. Figure 2 In the example shown, the name and credit card number can be modified. In contrast, the position information of the vehicle 100 and the speed of the vehicle 100 cannot be modified. Figure 2 In the area surrounded by the single-dot chain line 208, a correction button for correcting the name and a correction button for correcting the credit card number are displayed. Figure 2 In the example shown, only private information items manually entered by the user can be modified; private information items automatically entered cannot be modified. Depending on the jurisdiction, all private information items may be modifiable. That is, depending on the jurisdiction, modification is possible regardless of whether or not user input has occurred. Depending on the jurisdiction, modification module 22 may also be disabled. Thus, whether modification module 22 is enabled is determined for each jurisdiction. When modification module 22 is enabled, whether or not the user can modify any of one or more private information items is determined.

[0032] <Overview of Processing Executed by the Information Management Device 10>

[0033] Reference Figure 3 An overview of the processing executed by the information management device 10 will be described.

[0034] The information management device 10 repeatedly executes the following operations at a predetermined period during the operation of the drive system 50: Figure 3 The processing shown. The information management device 10 attempts to obtain the position of the vehicle 100 in step S300. Next, the information management device 10 proceeds to step S302. The information management device 10 determines whether the position of the vehicle 100 has been obtained in step S302. When a negative determination is made in step S302 (S302: No), the information management device 10 proceeds to step S316. The information management device 10 is set to restricted mode in step S316. That is, the switching module 24 migrates to restricted mode when the position of the vehicle 100 cannot be obtained. Restricted mode is a mode in which the operation of one or more of the user consent module 21, the correction module 22, and the deletion module 23 is stopped regardless of the jurisdiction. For example, in restricted mode, the information management device 10 of this embodiment will stop the operation of all the user consent module 21, the correction module 22, and the deletion module 23 regardless of the jurisdiction.

[0035] If the information management device 10 makes an affirmative determination in step S302 (S302: Yes), the process proceeds to step S304. In step S304, the information management device 10 is set to normal mode. Normal mode is a mode in which no restriction mode is applied. Next, the information management device 10 proceeds to step S306.

[0036] In step S306, the information management device 10 determines the legal jurisdiction in which the vehicle 100 is currently located based on the vehicle 100's location. Next, the information management device 10 proceeds to step S308. In step S308, the information management device 10 determines whether the ignition switch 31 has just been turned on. If the information management device 10 makes an affirmative determination in step S308 (S308: Yes), the information management device 10 proceeds to step S314. If the information management device 10 makes a negative determination in step S308 (S308: No), the information management device 10 proceeds to step S310. In step S310, the information management device 10 determines whether the switching module 24 has just been switched from restricted mode to normal mode. If the information management device 10 makes an affirmative determination in step S310 (S310: Yes), the information management device 10 proceeds to step S314. If the information management device 10 makes a negative determination in step S310 (S310: No), the information management device 10 proceeds to step S312. In step S312, the information management device 10 determines whether the current legal jurisdiction of the vehicle 100 is different from the legal jurisdiction previously determined to be the location of the vehicle 100. If the information management device 10 makes an affirmative determination in step S312 (S312: Yes), the process proceeds to step S314.

[0037] In step S314, the information management device 10 performs a reference Figure 4 The module operation determination process will be described later.

[0038] When the information management device 10 makes a negative determination in step S312 (S312: No), the process ends. Figure 3 The information management device 10 also ends when step S314 or step S316 is completed. Figure 3 The processing shown.

[0039] Module operation determination processing

[0040] Reference Figure 4 ,right Figure 3 The module operation determination process of step S314 is described below. Figure 3As shown in step S306, the information management device 10 knows the legal domain in which the vehicle 100 is currently located. In step S400, the information management device 10 determines whether the module operation information related to the legal domain in which the vehicle 100 is currently located has been stored in the storage 30. The module operation information is information indicating whether the privacy protection module group is operated. When the information management device 10 makes a negative determination in step S400 (S400: No), it proceeds to step S424. In step S424, the information management device 10 attempts to obtain the module operation information related to the legal domain in which the vehicle 100 is currently located. For example, the information management device 10 requests the module operation information from the data center located in the legal domain in which the vehicle 100 is currently located. Next, the information management device 10 proceeds to step S426. In step S426, the information management device 10 determines whether the module operation information related to the legal domain in which the vehicle 100 is currently located has been obtained. If the information management device 10 makes a positive determination in step S426 ( S426: Yes), the process proceeds to step S402 . If the information management device 10 makes a negative determination in step S426 ( S426: No), the process proceeds to step S428 . In step S428, the information management device 10 prohibits the operation of the user consent acquisition module 21 , the modification module 22 , and the deletion module 23 .

[0041] If the information management device 10 makes an affirmative determination in step S400 (S400: Yes), the process proceeds to step S402. The module operation information related to the jurisdiction in which the vehicle 100 is currently located indicates whether the user consent module 21 is being operated in the jurisdiction in which the vehicle 100 is currently located. In step S402, the information management device 10 determines whether the user consent module 21 is being operated. If the information management device 10 makes an affirmative determination in step S402 (S402: Yes), the process proceeds to step S404. In step S404, the information management device 10 operates the user consent module 21. Next, the information management device 10 proceeds to step S406. In step S406, the information management device 10 determines whether the privacy settings related to the jurisdiction in which the vehicle 100 is currently located are stored in the storage 30. If the information management device 10 makes an affirmative determination in step S406 (S406: Yes), the process proceeds to step S412. When a negative determination is made in step S406 ( S406 : No), the information management apparatus 10 proceeds to step S408 . In step S408 , the information management apparatus 10 obtains the privacy setting by inquiring the user.

[0042] If a negative determination is made in step S402 (S402: No), the information management device 10 proceeds to step S410. In step S410, the information management device 10 prohibits the operation of the user consent module 21. The information management device 10 also proceeds to step S412 after completing step S408 or step S410.

[0043] The module operation information related to the legal domain in which the vehicle 100 is currently located indicates whether the correction module 22 is operated in the legal domain in which the vehicle 100 is currently located. In step S412, the information management device 10 determines whether the correction module 22 is operated. If the determination in step S412 is affirmative (S412: Yes), the information management device 10 proceeds to step S414. In step S414, the information management device 10 operates the correction module 22.

[0044] If a negative determination is made in step S412 (S412: No), the information management device 10 proceeds to step S416. In step S416, the information management device 10 prohibits the operation of the correction module 22. If the correction module 22 is operating and the operation is prohibited, the information management device 10 stops the operation of the correction module 22.

[0045] After completing step S414 or step S416 , the information management device 10 proceeds to step S418 .

[0046] The module operation information related to the legal domain currently located by the vehicle 100 indicates whether the deletion module 23 is activated in the legal domain currently located by the vehicle 100. In step S418, the information management device 10 determines whether the deletion module 23 is activated. If the determination in step S418 is affirmative (S418: Yes), the information management device 10 proceeds to step S420. In step S420, the information management device 10 activates the correction module 22.

[0047] If a negative determination is made in step S418 (S418: No), the information management device 10 proceeds to step S422. In step S422, the information management device 10 prohibits the operation of the deletion module 23. If the deletion module 23 is operating and the operation is prohibited, the information management device 10 stops the operation of the deletion module 23.

[0048] The information management device 10 ends when step S420, step S422 or step S428 is completed. Figure 4 process.

[0049] <Handling of Repeated Inquiries about User Privacy Settings>

[0050] Reference Figure 5, explains the process used to comply with privacy regulations in jurisdictions that require users to repeatedly ask for their privacy settings. Figure 4 The process shown is repeated when the normal mode is set. Figure 5 The processing shown.

[0051] In step S500, the information management device 10 determines whether the legal jurisdiction in which the vehicle 100 is currently located requires periodic inquiry of the user regarding privacy settings. Specifically, the information management device 10 determines whether the laws and regulations in the legal jurisdiction in which the vehicle 100 is currently located require periodic confirmation of the user's privacy settings. For example, the module operation information may include information indicating whether periodic inquiry of the user regarding privacy settings is required.

[0052] If the information management device 10 makes an affirmative determination in step S500 (S500: Yes), the process proceeds to step S502. In step S502, the information management device 10 determines whether a predetermined period has elapsed since the last inquiry. If the information management device 10 makes an affirmative determination in step S502 (S502: Yes), the process proceeds to step S504.

[0053] In step S504 , the information management device 10 obtains the privacy setting by inquiring the user.

[0054] The information management device 10 ends the process after completing step S504. Figure 5 The information management device 10 also ends the process when a negative determination is made in step S500 (S500: No). Figure 5 The information management device 10 also ends the process when a negative determination is made in step S502 (S502: No). Figure 5 process.

[0055] <Privacy Settings Regarding Jurisdiction Adjacent to the Jurisdiction Where Vehicle 100 Is Currently Located>

[0056] Reference Figure 6 , the process for obtaining the privacy settings related to the legal domain adjacent to the legal domain where the vehicle 100 is currently located will be described. When the information management device 10 is set to the normal mode, it repeatedly executes Figure 6 processing.

[0057] In step S600, the information management device 10 determines whether the vehicle 100 is within a predetermined distance from the boundary of a legal domain adjacent to the legal domain currently located by the vehicle 100. If the information management device 10 makes a negative determination in step S600 (S600: No), the information management device 10 repeats step S600. If the information management device 10 makes an affirmative determination in step S600 (S600: Yes), the process proceeds to step S602.

[0058] In step S602, the information management device 10 determines whether module operation information for a jurisdiction adjacent to the jurisdiction in which the vehicle 100 is currently located is stored in the memory 30. If the information management device 10 makes an affirmative determination in step S602 (S602: Yes), the information management device 10 proceeds to step S608. If the information management device 10 makes a negative determination in step S602 (S602: No), the information management device 10 proceeds to step S604. In step S604, the information management device 10 attempts to obtain module operation information for a jurisdiction adjacent to the jurisdiction in which the vehicle 100 is currently located. Next, the information management device 10 proceeds to step S606. In step S606, the information management device 10 determines whether module operation information for a jurisdiction adjacent to the jurisdiction in which the vehicle 100 is currently located has been obtained. If the information management device 10 makes an affirmative determination in step S606 (S606: Yes), the information management device 10 proceeds to step S608. If the information management device 10 makes a negative determination in step S606 (S606: No), the process ends. Figure 6 process.

[0059] The module operation information of the legal domain adjacent to the legal domain currently located by the vehicle 100 includes information indicating whether the module 21 for obtaining user consent is operated in the adjacent legal domain. In step S608, the information management device 10 determines whether the module 21 for obtaining user consent is operated in the legal domain adjacent to the legal domain currently located by the vehicle 100. If a negative determination is made in step S608 (S608: No), the information management device 10 ends the process. Figure 6 The information management device 10 proceeds to step S610 when it makes a positive determination in step S608 (S608: Yes). In step S610, the information management device 10 determines whether the privacy settings related to the legal domain adjacent to the legal domain where the vehicle 100 is currently located are stored in the memory 30. The information management device 10 ends the process when it makes a positive determination in step S610 (S610: Yes). Figure 6 When the information management device 10 makes a negative determination in step S610 (S610: No), it proceeds to step S612. In step S612, the information management device 10 obtains the privacy settings of the legal domains adjacent to the legal domain where the vehicle 100 is currently located by asking the user. The information management device 10 ends after completing step S612. Figure 6 process.

[0060] <Function of this embodiment>

[0061] according to Figure 3In step S306, the information management device 10 repeatedly determines the legal domain in which the vehicle 100 is currently located while the drive system 50 is on. The module operation information of the legal domain in which the vehicle 100 is currently located is information indicating whether the privacy protection module group is to be operated. The privacy protection module group includes a user consent acquisition module 21, a correction module 22, and a deletion module 23. When a positive determination is made in step S308, step S310, or step S312, steps S314 and S315 are executed. Figure 4 The module operation determination process shown is performed. In particular, according to steps S308 and S314, this process is performed according to the legal jurisdiction in which the vehicle 100 is located when the drive system 50 of the vehicle 100 is turned on. In the module operation determination process, as shown in steps S402 to S422, it is determined whether the privacy protection module group is to be operated.

[0062] according to Figure 3 The following can be described regarding steps S310 and S314. When the location of vehicle 100 is available, switching module 24 performs the following processing. Specifically, switching module 24 determines whether to operate user consent acquisition module 21, modification module 22, and deletion module 23, respectively, based on the jurisdiction in which vehicle 100 is located.

[0063] according to Figure 3 The following can be described regarding steps S312 and S314. Regarding switching module 24, during operation of vehicle 100's drive system 50, vehicle 100 may move from the first legal domain to the second legal domain. In this case, switching module 24 determines whether to operate user consent obtaining module 21, modification module 22, and deletion module 23, respectively, based on the second legal domain.

[0064] The following can be seen from steps S402 to S406. When the vehicle 100 is located in a jurisdiction where the user consent module 21 is operating, the information management device 10 operates the user consent module 21. If privacy settings associated with the jurisdiction are stored in the memory 30, the user consent module 21 does not request the user to set the privacy settings. In other words, the user consent module 21 does not display a message on the user interface 40 to request the user to set the privacy settings.

[0065] according to Figure 5 The following can be said. The law in the jurisdiction where vehicle 100 is currently located may require regular confirmation from the user regarding the user's consent to store private information items in storage 30. In such cases, even if privacy settings associated with that jurisdiction are stored in storage 30, user consent module 21 will periodically inquire about the user's privacy settings. Specifically, user consent module 21 displays a message on user interface 40 to request the user to confirm the privacy settings.

[0066] <Effects of this embodiment>

[0067] (1) The information management device 10 mounted on the vehicle 100 includes data processing hardware 20. The information management device 10 includes a storage 30 configured to communicate with the data processing hardware 20. The information management device 10 includes a user interface 40 configured to communicate with the data processing hardware 20. The data processing hardware 20 includes a user consent module 21. The user consent module 21 displays on the user interface 40 a message for accepting a privacy setting indicating whether or not the user permits one or more privacy information items to be stored in the storage 30. The user consent module 21 receives the privacy setting from the user interface 40. The user consent module 21 associates the privacy setting with the legal jurisdiction in which the vehicle 100 is located and stores the privacy setting in the storage 30. The data processing hardware 20 includes a correction module 22. The correction module 22 displays on the user interface 40 a message for accepting a correction request for one of the one or more privacy information items already stored in the storage 30. The correction module 22 receives the correction request from the user interface 40. The correction module 22 corrects the stored one privacy information item in accordance with the correction request. The data processing hardware 20 includes a deletion module 23. The deletion module 23 displays a message on the user interface 40 to receive a deletion request for deleting one of one or more private information items stored in the storage 30. The deletion module 23 receives the deletion request from the user interface 40. In response to the deletion request, the deletion module 23 deletes the stored private information item. The data processing hardware 20 includes a switching module 24. The switching module 24 determines whether to operate the user consent obtaining module 21, the modification module 22, and the deletion module 23. This determination is made based on the jurisdiction in which the vehicle 100 is located when the drive system 50 of the vehicle 100 is turned on.

[0068] According to the above configuration, switching module 24 determines whether to operate user consent obtaining module 21, modification module 22, and deletion module 23, respectively, depending on the jurisdiction. Therefore, it is possible to operate the required modules in accordance with privacy laws that vary from jurisdiction to jurisdiction. Therefore, according to the above configuration, it is possible to appropriately protect privacy information in accordance with privacy laws that vary from jurisdiction to jurisdiction.

[0069] (2) Vehicle 100 may be located in the first domain where user consent module 21 is operating. Even in this case, if privacy settings associated with the first domain are stored in memory 30, no inquiry regarding the privacy settings is made. In other words, user consent module 21 does not display a message on user interface 40 to request the user to set the privacy settings.

[0070] According to the above configuration, when the privacy setting associated with the first domain is already stored, the user consent module 21 does not inquire the user about the privacy setting. This can reduce the user's annoyance with privacy setting inquiries.

[0071] (3) There may be cases where the law in the first jurisdiction requires periodic confirmation from the user regarding whether or not the privacy information item is permitted to be stored in the storage 30. In this case, even if the privacy settings associated with the first jurisdiction are stored in the storage 30, the inquiry regarding the privacy settings is performed. In other words, the user consent module 21 periodically displays a display on the user interface 40 for accepting the privacy settings from the user.

[0072] According to the above configuration, it is possible to appropriately protect privacy information by repeatedly asking the user about the privacy laws and regulations of the jurisdiction where the privacy setting is made as needed.

[0073] (4) There is a situation where the location of the vehicle 100 cannot be obtained. In this situation, regardless of the jurisdiction, the switching module 24 transitions to a restricted mode in which the operation of one or more of the user consent acquisition module 21, the correction module 22, and the deletion module 23 is stopped. When the location of the vehicle 100 can be obtained, the switching module 24 transitions to the normal mode. When transitioning to the normal mode, the switching module 24 makes the following determination. Specifically, the switching module 24 determines whether to operate the user consent acquisition module 21, the correction module 22, and the deletion module 23, respectively, based on the jurisdiction in which the vehicle 100 is located.

[0074] If the location of vehicle 100 cannot be acquired, the operation of one or more of the user consent acquisition module 21, the modification module 22, and the deletion module 23 is stopped. Furthermore, if the location of vehicle 100 cannot be acquired, whether to operate each module is determined based on the jurisdiction in which vehicle 100 is located. Therefore, when the location of vehicle 100 can be acquired, the processing of private information can be restored to a state in accordance with the privacy laws of the jurisdiction in which vehicle 100 is located.

[0075] (5) There is a case where the vehicle 100 moves from the first legal domain to the second legal domain while the drive system 50 of the vehicle 100 is in operation. In this case, the switching module 24 determines whether to operate the user consent obtaining module 21, the modification module 22, and the deletion module 23, respectively, based on the second legal domain.

[0076] Vehicle 100 may move from a first jurisdiction to a second jurisdiction having different privacy laws from those of the first jurisdiction while drive system 50 of vehicle 100 is in operation. With the above configuration, privacy information can be appropriately protected in accordance with the privacy laws of the second jurisdiction.

[0077] <Change Example>

[0078] This embodiment can be implemented by modifying as follows: This embodiment and the following modified examples can be implemented in combination with each other within a range that does not technically conflict.

[0079] In the above embodiment, privacy settings are stored in memory 30 via storage module 26. Modification of a stored item of privacy information is performed via storage module 26. Deletion of a stored item of privacy information is performed via storage module 26. However, these storage, modification, and deletion may not be performed via storage module 26.

[0080] Can be omitted Figure 3 At least one of step S310 and step S312.

[0081] In the above embodiment, restricted mode is a mode in which the operation of one or more of the user consent acquisition module 21, the modification module 22, and the deletion module 23 is stopped. However, this is merely an example. Restricted mode may also be a mode in which whether to operate the privacy protection module group is determined based on module operation information in the jurisdiction in which the vehicle 100 is located immediately before entering restricted mode.

[0082] In the above embodiment, the information management device 10 prohibits the operation of all of the user consent acquisition module 21, the modification module 22, and the deletion module 23 in step S428. However, this is merely an example. For example, the information management device 10 may prohibit the operation of one or more of the user consent acquisition module 21, the modification module 22, and the deletion module 23.

[0083] In the above embodiment, the information management device 10 determines in step S400 whether the module operation information related to the legal domain in which the vehicle 100 is currently located has been stored. For example, a configuration may be implemented in which the module operation information related to all legal domains is pre-stored in the memory 30. In this case, steps S400, S424, S426, and S428 may be omitted.

[0084] · Figure 5 The processing can be omitted.

[0085] · Figure 6 The processing can be omitted.

Claims

1. An information management device, mounted on a vehicle, wherein: have: Data processing hardware; a memory configured to communicate with the data processing hardware; and a user interface configured to communicate with the data processing hardware, The data processing hardware includes: a user consent obtaining module configured to display on the user interface a privacy setting request from the user indicating whether to permit storage of one or more items of private information in the storage, receive the privacy setting from the user interface, associate the privacy setting with the legal jurisdiction in which the vehicle is located, and store the privacy setting in the storage; a correction module configured to display on the user interface a request for correcting one of the one or more private information items already stored in the storage, receive the correction request from the user interface, and correct the one stored private information item in accordance with the correction request; a deletion module configured to display on the user interface a request for deleting one of the one or more private information items stored in the storage, receive the deletion request from the user interface, and delete the stored one private information item in accordance with the deletion request; as well as The switching module is configured to determine whether to respectively operate the user consent obtaining module, the correction module, and the deletion module based on a legal jurisdiction in which the vehicle is located when the driving system of the vehicle is turned on.

2. The information management device according to claim 1, wherein Even if the vehicle is in the first legal domain where the user consent module is operating, when the privacy settings associated with the first legal domain are stored in the storage, the user consent module does not perform the display on the user interface for accepting the privacy settings from the user.

3. The information management device according to claim 2, wherein: In a case where the regulations in the first legal domain require periodic confirmation from the user as to whether the privacy information item is permitted to be stored in the storage, even if the privacy setting associated with the first legal domain is stored in the storage, the module for obtaining user consent periodically performs the display on the user interface for accepting the privacy setting from the user.

4. The information management device according to claim 1, wherein: The switching module is configured to migrate to a restricted mode in which the operation of one or more of the user consent module, the correction module, and the deletion module is stopped regardless of the jurisdiction when the position of the vehicle cannot be obtained, and to determine whether to operate the user consent module, the correction module, and the deletion module separately according to the jurisdiction in which the vehicle is located when the position of the vehicle becomes available.

5. The information management device according to claim 1, wherein The switching module is configured to determine whether to respectively operate the user consent obtaining module, the correction module, and the deletion module according to the second legal domain when the vehicle moves from the first legal domain to the second legal domain during the operation of the driving system of the vehicle.

Citation Information

Patent Citations

  • Design for user privacy protection on autonomous driving vehicle

    JP2021170016A