Data access method, apparatus and vehicle
By allocating sub-data storage areas to each user account in the smart cockpit and implementing access control, the issue of user data privacy and security in the smart cockpit is resolved, achieving data isolation and improved user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- YINWANG INTELLIGENT TECHNOLOGIES CO LTD
- Filing Date
- 2024-08-30
- Publication Date
- 2026-07-10
AI Technical Summary
In a smart cockpit, how can we ensure data privacy and security when different users use the same display screen, and prevent user data leakage?
By allocating a sub-data storage area for each user account and implementing access control during data storage and retrieval, user account-level data isolation is achieved, ensuring that only authorized users can access their data.
It effectively protects the privacy and security of user data, prevents other users from reading personal data, and improves the user experience without affecting the flexibility of data reading and writing.
Smart Images

Figure CN120524510B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and more specifically, to a data access method, apparatus, and vehicle. Background Technology
[0002] With the increasing intelligence and connectivity of vehicles, vehicle cockpits are gradually evolving into intelligent cockpits centered on human-machine interaction and featuring multi-screen linkage. Currently, the displays in intelligent cockpits may be used by different users at different times. For an application deployed on a display, a user may store some data while using the application, and after that user logs out, they may not want other users to access that stored data. Therefore, how to ensure the privacy and security of user data is the problem that this application's technical solution aims to solve. Summary of the Invention
[0003] This application provides a data access method, apparatus, and vehicle that helps protect the data privacy and security of each user account when multiple user accounts used to log in to the vehicle's infotainment system are associated with the same user space.
[0004] Firstly, a data access method is provided that can be executed by a vehicle, for example, by the vehicle's computing platform, or by a chip or circuitry used in the vehicle.
[0005] The method includes: obtaining information about a first user account, wherein the first user account is one of multiple user accounts, each user account is associated with a sub-data storage area, and the multiple sub-data storage areas associated with the multiple user accounts belong to the same user space; obtaining a first access request of a first application under the first user account, wherein the first access request is used to request the storage of first data; and storing the first data through the first sub-data storage area corresponding to the first user account according to the first access request, wherein the multiple sub-data storage areas include the first sub-data storage area.
[0006] In some implementations, the first sub-data storage area stores the association between each piece of data and the first user account. The association between each piece of data and the first user account can be a field that includes a data identifier and a first user account identifier. Alternatively, the aforementioned association can also be a field that includes a data identifier, an identifier of the application storing the data, and a first user account identifier.
[0007] In the above technical solution, when multiple user accounts used to log in to the vehicle system are associated with the same user space, for applications with data privacy requirements, storing the data requested by the application in the data storage area through the sub-data storage area can prevent applications under other user accounts from reading the data, thus helping to protect the data privacy and security of each user account.
[0008] In conjunction with the first aspect, in some implementations of the first aspect, the multiple user accounts also include a second user account, which is associated with a second sub-data storage area in the multiple sub-data storage areas. The method further includes: obtaining a second access request from a second application of the second user account; and rejecting the second access request when the second access request is used to request to read the first data.
[0009] In some implementations, the first data refers to a first type of data. The method further includes: when a second access request is made to request the reading of the first type of data, reading a first set of data from the data storage area according to the second access request, wherein each item in the first set of data is first type of data, and the first set of data does not include the first data itself. The first type of data can be multimedia data, such as images or videos, or it can be data of categories such as files.
[0010] In the above technical solution, the application under the second user account cannot read the data stored by the first user account through the first sub-data storage area, which helps to achieve data isolation at the user account level, thereby improving the privacy and security of user data.
[0011] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: obtaining a third access request from a third application under the first user account, wherein the third application is an application that does not need to go through the first sub-data storage area when storing data; and rejecting the third access request when the third access request is used to request to read the first data.
[0012] In some implementations, the first data is first type of data. The method further includes: when a third access request is made to request the reading of the first type of data, a second set of data is read from the data storage area according to the second access request, wherein each item in the second set of data is first type of data, and the second set of data does not include the first data.
[0013] It should be noted that the second set of data can be the same as the first set of data, or they can be different.
[0014] In some implementations, the first application is a type of application that requires data isolation. The third application is a type of application that does not require data isolation.
[0015] In the above technical solution, the data stored by the first user account through the first sub-data storage area, that is, the data stored by the first type of application under the first user account, cannot be accessed by the second type of application under the first user account. This can avoid the risk of data leakage by the second type of application under the user account through the first sub-data storage area, and help to further improve the privacy and security of user data.
[0016] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: obtaining a fourth access request from the first application, the fourth access request being used to request the reading of second data, the second data being data stored by the third application; and reading the second data according to the fourth access request.
[0017] In the above technical solution, the first type of application under the first user account can read the data stored in the public storage area for the second type of application under the first user account. This helps to improve the flexibility of the first type of application in reading and writing data while ensuring data privacy and security, thereby improving the user's application experience.
[0018] In conjunction with the first aspect, in some implementations of the first aspect, the second data is stored in a public storage area, and the second data is read according to a fourth access request, including: when the first user account is authorized to access the public storage area, the second data is read according to the fourth access request.
[0019] In the above technical solution, the permission of the first user account can determine whether to respond to the request of the first type of application to read data stored in the public storage area, which helps to further improve data privacy and security. The permissions of the first user account can be determined in response to the user's settings, allowing the user to flexibly modify relevant permissions, which helps to improve the convenience of using the vehicle system and thus improve the user's driving experience.
[0020] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: obtaining a fifth access request from a fourth application under a first user account, the fifth access request being used to request the reading of first data; and when the fourth application is an application that needs to access the first sub-data storage area to store data, reading the first data according to the fifth access request.
[0021] In some implementations, the fourth application is the first type of application.
[0022] In the above technical solution, the fourth application, which is also a first type of application, can read the first data stored by the first application. This helps to improve the flexibility of the first type of application in reading and writing data while ensuring data privacy and security, thereby improving the user experience of using the application.
[0023] Secondly, a data access device is provided, comprising an acquisition unit and a processing unit, wherein the acquisition unit is configured to: acquire information of a first user account, wherein the first user account is one of multiple user accounts, each of the multiple user accounts is associated with a sub-data storage area, and the multiple sub-data storage areas associated with the multiple user accounts belong to the same user space; the acquisition unit is further configured to: acquire a first access request of a first application under the first user account, wherein the first access request is used to request the storage of first data; the processing unit is configured to: store the first data through the first sub-data storage area corresponding to the first user account according to the first access request, wherein the multiple sub-data storage areas include the first sub-data storage area.
[0024] In conjunction with the second aspect, in some implementations of the second aspect, the multiple user accounts also include a second user account, which is associated with a second sub-data storage area in the multiple sub-data storage areas. The acquisition unit is further configured to: acquire a second access request from a second application of the second user account; the processing unit is further configured to: reject the second access request when the second access request is used to request to read the first data.
[0025] In conjunction with the second aspect, in some implementations of the second aspect, the acquisition unit is further configured to: acquire a third access request from a third application under the first user account, wherein the third application is an application that does not need to pass through the first sub-data storage area when storing data; the processing unit is further configured to: reject the third access request when the third access request is for requesting to read the first data.
[0026] In conjunction with the second aspect, in some implementations of the second aspect, the acquisition unit is further configured to: acquire a fourth access request from the first application, the fourth access request being used to request the reading of second data, the second data being data stored by the third application; the processing unit is further configured to: read the second data according to the fourth access request.
[0027] In conjunction with the second aspect, in some implementations of the second aspect, the second data is stored in a public storage area, and the processing unit is used to: read the second data according to the fourth access request when the first user account is authorized to access the public storage area.
[0028] In conjunction with the second aspect, in some implementations of the second aspect, the third application is a second type of application, which is an application that does not require data isolation.
[0029] In conjunction with the second aspect, in some implementations of the second aspect, the acquisition unit is further configured to: acquire a fifth access request from a fourth application under a first user account, the fifth access request being used to request the reading of first data; the processing unit is further configured to: when the fourth application is an application that needs to access the first sub-data storage area to store data, read the first data according to the fifth access request.
[0030] In conjunction with the second aspect, in some implementations of the second aspect, the first application is the first type of application, which is an application that requires data isolation.
[0031] Thirdly, a data access device is provided, the device comprising: a processor for executing a computer program stored in the memory, such that the device performs the method in any possible implementation of the first aspect described above.
[0032] In conjunction with the third aspect, in some implementations of the third aspect, the data access device also includes a memory.
[0033] Fourthly, a computer program product is provided, comprising: computer program code, which, when executed on a computer or processor, causes the computer or processor to perform the method in any possible implementation of the first aspect.
[0034] It should be noted that the above computer program code can be stored in whole or in part on a storage medium, which can be packaged together with the processor or packaged separately from the processor.
[0035] Fifthly, a computer-readable storage medium is provided, the computer-readable medium storing instructions that, when executed by a processor, cause the processor to implement the method in any possible implementation of the first aspect.
[0036] In a sixth aspect, a chip is provided, the chip including circuitry for performing the method in any of the possible implementations of the first aspect described above.
[0037] In a seventh aspect, a vehicle is provided that includes means as in any possible implementation of the second to third aspects, or the vehicle includes computer-readable storage as in any possible implementation of the fifth aspect, or the vehicle includes a chip as in any possible implementation of the sixth aspect, or the vehicle is loaded with computer program code as in any possible implementation of the fourth aspect.
[0038] In conjunction with the seventh aspect, in some implementations of the seventh aspect, the vehicle is a vehicle in a broad sense, such as a means of transportation (e.g., commercial vehicles, passenger cars, motorcycles, flying cars, trains, etc.), industrial vehicles (e.g., forklifts, trailers, tractors, etc.), engineering vehicles (e.g., excavators, bulldozers, cranes, etc.), agricultural equipment (e.g., lawnmowers, harvesters, etc.), amusement equipment, toy vehicles, etc. In practical implementation, the vehicle can also be a road vehicle, a water vehicle, an air vehicle, industrial equipment, agricultural equipment, or other intelligent driving equipment such as entertainment equipment.
[0039] For the beneficial effects not described in detail in aspects two through seven, please refer to the description in aspect one, which will not be repeated here. Attached Figure Description
[0040] Figure 1 This is a functional block diagram of the vehicle provided in the embodiments of this application;
[0041] Figure 2 This is a schematic diagram of a vehicle cabin scenario provided in an embodiment of this application;
[0042] Figure 3 This is a schematic block diagram of the system architecture provided in the embodiments of this application;
[0043] Figure 4 This is another schematic block diagram of the system architecture provided in the embodiments of this application;
[0044] Figure 5 This is another schematic block diagram of the system architecture provided in the embodiments of this application;
[0045] Figure 6 This is a schematic diagram of the data storage architecture provided in an embodiment of this application;
[0046] Figure 7 This is a schematic flowchart of the control method provided in the embodiments of this application;
[0047] Figure 8 This is a schematic diagram of the graphical user interface (GUI) provided in the embodiments of this application;
[0048] Figure 9 This is yet another schematic diagram of the GUI provided in the embodiments of this application;
[0049] Figure 10 This is another schematic diagram of the GUI provided in the embodiments of this application;
[0050] Figure 11 This is another schematic diagram of the GUI provided in the embodiments of this application;
[0051] Figure 12 This is another schematic diagram of the GUI provided in the embodiments of this application;
[0052] Figure 13 This is a schematic flowchart of the data access method provided in the embodiments of this application;
[0053] Figure 14 This is a schematic block diagram of the device provided in the embodiments of this application;
[0054] Figure 15 This is another schematic block diagram of the device provided in the embodiments of this application. Detailed Implementation
[0055] The technical solutions in this application will now be described with reference to the accompanying drawings.
[0056] Figure 1 This is a functional block diagram of a vehicle provided in an embodiment of this application. For example... Figure 1 As shown, the vehicle 100 may include a display device 130 and a computing platform 150. The display device 130 in the cabin is mainly divided into two categories: the first is an in-vehicle display screen; the second is a projection display screen, such as a head-up display (HUD). An in-vehicle display screen is a physical display screen and an important component of the in-vehicle infotainment system. Multiple displays can be installed in the cabin, such as a digital instrument cluster display, a central control screen, a display screen in front of the front passenger (also known as the front-seat passenger), a display screen in front of the left rear passenger, and a display screen in front of the right rear passenger; even the vehicle windows can be used as displays. A head-up display, also known as a head-up display system, is mainly used to display driving information such as speed and navigation on a display device in front of the driver (such as the windshield). This reduces the driver's eye-shifting time, avoids pupil changes caused by eye-shifting, and improves driving safety and comfort. HUDs include, for example, combiner-HUD (C-HUD) systems, windshield-HUD (W-HUD) systems, and augmented reality HUD (AR-HUD) systems.
[0057] Some or all of the functions of vehicle 100 can be controlled by computing platform 150. Computing platform 150 may include processors 151 to 15n. A processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a central processing unit (CPU), microprocessor, graphics processing unit (GPU) (which can be understood as a type of microprocessor), or digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. These logical relationships are fixed or reconfigurable. For example, the processor may be a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as a field-programmable gate array (FPGA). In reconfigurable hardware circuits, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement related functions. Furthermore, the processor can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), tensor processing unit (TPU), deep learning processing unit (DPU), etc. In addition, the computing platform 150 may also include a memory for storing instructions. Some or all of the processors 151 to 15n can call the instructions in the memory to implement the corresponding functions.
[0058] Optionally, the structure of the vehicle 100 described above is merely illustrative. In actual applications, various components of the vehicle 100 may be added or removed as needed.
[0059] Figure 2This is a schematic diagram of a vehicle cockpit scenario provided in an embodiment of this application. The smart cockpit includes one or more in-vehicle displays (or in-vehicle screens), including but not limited to display screen 201 (or central control screen), display screen 202 (or passenger entertainment screen), display screen 203 (or driver's headrest rear screen), display screen 204 (or passenger headrest rear screen), display screen 205 (or second-row entertainment screen) mounted on the cockpit ceiling, and an instrument panel. Further, displays 201 to 205 can display a graphical user interface (GUI), which may include icons for one or more applications, and / or one or more cards. For example, Figure 1 The display device 130 shown can be one or more of the displays 201 to 205. In some possible implementations, the display 201 can also be a long screen extending into the passenger area. In addition, the display 205 can also be a projection screen associated with a projector, which can be associated with a desktop launcher to manage applications projected onto the projection screen.
[0060] Figure 2 The cockpit can also be equipped with one or more cameras to capture images inside or outside the cockpit, such as cameras from a driver monitor system (DMS), a cabin monitor system (CMS), and a dashcam. These cameras can be the same or different cameras. In addition, one or more pressure sensors and acoustic sensors are installed in the cockpit to monitor the presence and location of users.
[0061] In this application, based on the function of the display screen relative to the driver, cockpit displays can be divided into safety-critical screens and non-safety-critical screens. Safety-critical screens refer to screens or display devices that are likely to affect the driver and cause driver distraction, such as instrument panel screens and central control screens. Non-safety-critical screens indicate screens that are less likely to cause driver distraction, screens that are not easily observed by the driver, or screens located far from the driver, such as screens near rear passengers and rear entertainment screens.
[0062] It should be understood that the following embodiments are based on Figure 2The embodiments shown are illustrated using a 5-seat vehicle as an example, but the present application is not limited to this. For example, for a 7-seat sport / suburban utility vehicle (SUV), the cabin may include a central control screen, a passenger entertainment screen, a screen behind the driver's headrest, a screen behind the passenger's headrest, entertainment screens in the left-hand area of the third row, and entertainment screens in the right-hand area of the third row. As another example, for a bus, the cabin may include front and rear entertainment screens; or, the cabin may include a display screen in the driver's area and an entertainment screen in the passenger area. Furthermore, the following embodiments use a left-hand drive vehicle (i.e., the driver is on the left side of the vehicle) as an example; in actual implementation, the vehicle may also be a right-hand drive vehicle (i.e., the driver is on the right side of the vehicle).
[0063] As mentioned above, displays in current smart cockpits may be used by different users at different times. For an application deployed on a display, a user may store data while using the application, and after that user logs out, they may not want other users to access that stored data. Therefore, ensuring the privacy and security of user data has become a pressing issue.
[0064] Therefore, embodiments of this application provide a data access scheme that helps ensure the privacy and security of user data.
[0065] To facilitate understanding of the technical solution of this application, the following is combined with... Figures 3 to 15 This application provides a detailed description of the data access scheme provided in its embodiments.
[0066] Figure 3 A schematic block diagram of a control system provided in an embodiment of this application is shown. Figure 3As shown, this control system includes multiple display devices, such as display device 1, display device 2, and display device n (n is a positive integer). These multiple display devices are associated with a single user space. This means that the multiple display devices share a single set of system services. Regardless of which display device the system account logs into the vehicle system through, the functions the user wants to achieve through this system account are supported by the same system services. For example, the system services may include basic services such as a desktop launcher, voice services, and data management. The desktop launcher has functions such as launching applications, managing applications (e.g., installing and / or uninstalling applications), and displaying desktop widgets; the voice service provides voice recognition capabilities; and the data management provides functions for managing multimedia data such as photos, videos, and music (e.g., reading and writing multimedia data in the storage area). It is understandable that the storage load required by the system services for each user space, as well as the computational load (e.g., CPU load) required to start and stop the user space, are relatively high. If a user space is set up for each display device, the memory load and computational load required by the vehicle system will increase exponentially with the number of display devices. Furthermore, when switching system accounts on each display device, it is necessary to stop a system service (the user space corresponding to the logged-out system account) and start a new system service (the user space corresponding to the newly logged-in system account). Such large-scale starting and stopping of system services can cause system freezes, resulting in choppy displays or long waiting times for newly logged-in system accounts before they can use applications. Therefore, setting up a single user space for multiple display devices helps save on storage and computing costs. When the system account logged into the vehicle system changes, there is no need to stop and start system services, which helps reduce system lag, improves system smoothness, and ultimately enhances the user experience.
[0067] It should be noted that the user space involved in this application can be understood as the application's runtime environment. The applications deployed on any two of display devices 1 to n can be the same or different. Furthermore, Figure 3 Display device 1, display device 2, and display device n can be included in Figure 1 The positions of display device 1, display device 2, and display device n in the cockpit of the display device 130 shown can be referenced. Figure 2 The placement of displays 201 to 205 shown will not be described again here.
[0068] It should also be noted that the applications or application programs mentioned below in this application refer to software running in the vehicle infotainment system. The icon corresponding to an application or application (or application icon, or application icon) refers to the entry point for using or accessing the application. Application login or logout refers to logging in or out of the application account within the application. Application exit refers to closing the application or ending the application-related process. Deploying an application on a specific screen refers to deploying the application's access point on a specific screen; for example, this could be deploying the application or application icon on a specific screen, or deploying the main application or a clone application of the application on a specific screen.
[0069] Figure 4 Another schematic block diagram of the control system provided in an embodiment of this application is shown. For example... Figure 4 As shown, the system includes a user management unit 410, an application management unit 420, a user center service unit 430, and a public data service unit 440. Figure 4 The functional characteristics of each unit shown can be derived from... Figure 1 One or more processors in the computing platform 150 shown are used for implementation. More specifically, the functions of each unit in the system are as described in items (i) to (iv) below:
[0070] (I) The user management unit 410 provides users with interfaces for logging into the vehicle infotainment system and setting system account permissions. More specifically, the user management unit 410 includes a login management unit 411 and a permission management unit 412. The login management unit 411 is used to obtain the system account requesting to log into or log out of the vehicle infotainment system. In some implementations, the system account may include at least three types: vehicle owner system account, authorized system account, and guest system account. The vehicle owner system account is the account of the legal owner of the vehicle; the authorized system account is the account authorized by the legal owner of the vehicle; and the guest system account is the account not authorized by the legal owner of the vehicle. The permission management unit 412 is used to obtain the permissions of the system account. The permissions of the system account may be user-set or default to the vehicle infotainment system. In some implementations, the permissions of the system account may include at least one of the following: whether it has permission to install applications, whether it has permission to uninstall applications, which applications are allowed to be uninstalled and / or installed, which applications are prohibited from being uninstalled and / or installed, whether it can access the data storage area, and which applications can access the data storage area. For example, system account 1 has the permission to install applications, including all applications in the app store, and all applications can access the data storage area; system account 2 cannot uninstall privacy-critical applications, and all applications cannot access the data storage area. For instance, the legitimate owner of the vehicle can set permissions for authorized system accounts and guest system accounts. For example, when the owner's system account logs into the vehicle's infotainment system, the user can set permissions for authorized system accounts and guest system accounts through the vehicle's human-machine interface (HMI). The permission management unit 412 can obtain the permissions of the system account entered by the user through the HMI.
[0071] (II) The application management unit 420 provides users with interfaces for logging into applications and accessing data storage areas. More specifically, the application management unit 420 includes an application login management unit 421, a user center management unit 422, and an access management unit 423. The application login management unit 421 manages and controls application logins. It can obtain the application account used to log into a specific application and control that account's login to that application. The user center management unit 422 obtains the currently logged-in system account of the vehicle system and sends this information to the application login management unit 421. The application login management unit 421 can then use the application account associated with the currently logged-in system account to log into one or more applications. The user center management unit 422 can also obtain the system account used to log out of the vehicle system and send this information to the application login management unit 421. The application login management unit 421 can then control the application account associated with the logged-out system account to log out of one or more applications. The access management unit 423 manages the permissions for applications to read data from the data storage area and store data in the data storage area. Access management unit 423 can determine whether to send a data read request or data storage request from the application to public data service unit 440 based on the application's permissions. In one example, if an application has permission to access the data storage area, access management unit 423 sends a data read / storage request to public data service unit 440 to request to read the data required by the application or write the data requested by the application to the data storage area. In another example, if an application does not have permission to access the data storage area, access management unit 423 ignores the application's data read / storage request, that is, it does not send a data read / storage request to public data service unit 440.
[0072] (III) The user center service unit 430 is used for system account management and data access management. More specifically, the user center service unit 430 includes an account management unit 431 and a data management unit 432. The account management unit 431 controls a system account to log in to the vehicle infotainment system based on a request obtained from the user management unit 410; alternatively, it controls a system account to log out of the vehicle infotainment system based on a request obtained from the user management unit 410. Furthermore, after controlling a system account to log in or out of the vehicle infotainment system, the user center service unit 430 can send a login or logout notification to the application management unit 420. The data management unit 432 can obtain the system account's permission information from the user management unit 410, determine the applications that can access the data storage area under that system account based on the permission information, and then send the information about the applications that can access the data storage area under that system account to the public data service unit 440.
[0073] (iv) The public data service unit 440 is used to provide data storage and retrieval services for applications. More specifically, the public data service unit 440 includes a permission management module 441, a media library 442, and a file library 443. The permission management module 441 is used to create access path units for system accounts. Subsequently, one or more applications used under this system account need to read and write data in the data storage area through this access path unit. Specifically, the vehicle system can be associated with one or more system accounts. Access path units are set for system accounts that have permission to access the data storage area. At least one application running under the system account with the set access path unit needs to store data in or read data from the data storage area through the access path unit associated with that system account. A system account cannot read or write data in the data storage area through the access path unit of another system account. For example, if application 1 under system account 1 stores image 1 in the data storage area through access path unit 1 associated with system account 1, while application 1 under system account 2 does not store image 1 in the data storage area through access path unit 2 associated with system account 2, then system account 2 cannot read image 1 from the data storage area. Furthermore, for certain applications (such as those with low privacy or security requirements), data reading and writing can be performed without going through an access path unit. In this case, if such an application stores data A under one system account, data A can also be read under another system account.
[0074] Media library 442 and file library 443 are used to store data. When media library 442 or file library 443 receives a data read / write request (i.e., a data read or write request) from access management unit 423, request permission management module 441 authenticates the data read / write request to determine whether the request has permission to access the requested data. The data read / write request can be an application's access request to a data storage area. If the data read / write request authentication is successful, public data service unit 440 sends the requested data to application management unit 420; or, if the data read / write request authentication is successful, public data service unit 440 stores the requested data in the corresponding area of media library 442 or file library 443; or, if the data read / write request authentication fails, public data service unit 440 sends a data access failure notification to application management unit 420.
[0075] It should be understood that Figure 4 The architecture shown is for illustrative purposes only; in actual implementation, Figure 4 The system shown may include more or fewer units. For example, Figure 4 The system shown may include multiple login management units 411, each login management unit 411 corresponding to one of a plurality of display devices in the vehicle; for example, Figure 4 The system shown may also include multiple application management units 420, each application management unit 420 being a login interface and / or data access interface corresponding to an application. Multiple applications corresponding to the multiple application management units 420 can be deployed on one or more display devices in the vehicle. More specifically, when a user logs into the vehicle system using system account 1 through a display device (such as display device a), the login management unit 411 corresponding to display device a can send a login request to the user center service unit 430. This login request instructs system account 1 to request login to the vehicle system through display device a. Further, the user center service unit 430, based on the login request, controls system account 1 to log into the vehicle system through display device a. Furthermore, the user center service unit 430 sends a system account 1 login notification to at least one application management unit. This system account 1 login notification indicates that system account 1 has logged into the vehicle system through display device a. At least one application management unit controls the application account associated with system account 1 to log into one or more applications associated with system account 1 deployed on display device a. The aforementioned at least one application management unit may include application management units 420 corresponding to all applications installed in the vehicle system, or at least one application management unit may include application management units 420 corresponding to only the applications deployed in display device a.
[0076] Understandable Figure 4The diagram illustrates a system architecture within a user space. In actual implementation, multiple display devices within the vehicle can be associated with multiple user spaces. Specifically, as shown... Figure 5 As shown, display device 1, display device 2, and display device n (n is a positive integer) can be associated with user spaces 1 to n', where n' is an integer greater than or equal to 2. In actual implementation, within the same time period, the runtime environment required by applications deployed on display devices 1 to n is provided by a single user space. Within different time periods, the runtime environment required by applications deployed on display devices 1 to n can be provided by different user spaces. For example, within time period 1, the runtime environment required by applications deployed on display devices 1 to n is provided by user space 1, and within time period 2, the runtime environment required by applications deployed on display devices 1 to n is provided by user space n'. The end time of time period 1 is earlier than the start time of time period 2, or the end time of time period 1 coincides with the start time of time period 2; or the end time of time period 2 is earlier than the start time of time period 1, or the end time of time period 2 coincides with the start time of time period 1. In some implementations, the runtime environment required by applications deployed on display devices 1 to n within the same time period can be provided by at least two user spaces. For example, the runtime environment required by applications deployed on display device 1 is provided by user space 1, and the runtime environment required by applications deployed on display devices 2 to n is provided by user space n'.
[0077] In practical implementation, to ensure the privacy and security of different users within the same user space, this application embodiment designs a data read / write architecture, which is described below in conjunction with... Figure 6 A detailed introduction will be provided.
[0078] Figure 6 A schematic diagram of the data storage architecture provided in an embodiment of this application is shown. For example... Figure 6As shown, the database includes an access path management unit and a data sandbox. The database may include the aforementioned media library, file library, etc. The data sandbox is used to store data. The access path management unit may include multiple access path units, each associated with a system account. For example, if system accounts a through N are all associated with the same user space (e.g., system accounts a through N are all registered in this user space, or have all logged into the vehicle system under this user space), the access path management unit may include access path units associated with system accounts a through N, such as system account a access path unit, system account N access path unit, etc. More specifically, system account a can log into multiple applications, including applications 1 through m. Applications 1 through m need to read and write data through the access path management unit. For example, at least one of applications 1 through m stores image 11, image 21, image 31, and video 111 in the data sandbox through the system account a access path unit. More specifically, when at least one of applications 1 to m stores data, a reference associated with that data is created (e.g., reference to image 11, image 21, image 31, or video 111), and this reference is stored in the access path unit of system account a. This reference includes fields associated with system account a. When an application reads the aforementioned data, it needs to read it through the reference associated with that data. For example, when application m requests to read video 111 from the data sandbox, it needs to read video 111 through the video 111 reference stored in the access path unit of system account a.
[0079] In some implementations, applications 1 to m are privacy-critical applications. Among the multiple applications logged in under system account a, in addition to applications 1 to m, there may also be at least one rights-sharing application. When at least one rights-sharing application reads or writes data, it can do so without going through the access path management unit.
[0080] For details on how applications 1' to m' under system account N read data from the data sandbox and store data in the data sandbox, please refer to the relevant descriptions of applications 1 to m reading and writing data. These details will not be repeated here.
[0081] It should be noted that applications under system account a, other than applications 1 to m, cannot read data stored through the access path management unit (such as images 11, 21, 31, and video 111). Furthermore, applications running under one system account cannot read data stored through the access path management unit by applications running under another system account. For example, an application running under system account a cannot read images 12, 22, 32, etc., stored through the access path management unit by an application running under system account N.
[0082] In actual implementation, the data reference stored in the aforementioned access path unit can be in the form of a field, which may include the system account name. For example, when application m' running under system account N stores data a in the data storage area, the "System Account N" field is added to the data storage path (or data reference). A more specific data storage path could be: "System Account N - Application m' - Data a". When application 1' running under system account N reads data a from the data storage area, the "System Account N" field is added to the data read path. A more specific data read path could be: "System Account N - Application 1' - Data a". It should be noted that the field representing the access path unit corresponding to a system account can be managed by the public data service unit 440. This field is not perceived by the application. When the public data service unit 440 receives a data access request from an application, it determines whether to respond to the application's data access request based on which system account the application is running under and whether the application needs to read or write data in the data storage area via the access path unit. Therefore, applications running under system account N that can read and write data to the data storage area without accessing the path unit, as well as applications running under other system accounts, cannot read the data stored by applications 1' to m' running under system account N.
[0083] In some implementations, for applications that can read and write data to the data storage area without going through an access path unit (such as rights-sharing applications), a public storage area can be set up. This public storage area is used for the aforementioned applications to read and write data. It should be noted that when a system account is authorized to access the public storage area, the data in that public storage area can be read by any application running under that system account. It should be understood that the aforementioned data storage area includes this public storage area.
[0084] It should also be noted that the privacy-critical applications and benefit-sharing applications involved in this application are categorized based on the application's data privacy requirements. Privacy-critical applications can also be referred to as clone applications, and benefit-sharing applications can also be referred to as instance applications. More specifically, privacy-critical applications refer to applications with data isolation requirements; for example, users do not want data associated with such applications to be accessed or obtained by other users. Privacy-critical applications can include social applications (such as instant messaging applications, social media platforms, etc.), or e-commerce applications, map navigation applications, etc. Benefit-sharing applications involved in this application refer to applications that do not require data isolation; for example, data associated with such applications can be accessed or obtained by other users, such as weather applications; or benefit-sharing applications can also be applications that require data sharing; for example, for one application, multiple system accounts can share the benefits of the same application account, such as audio and video applications. For example, the data associated with the aforementioned applications can include at least one of the following: data stored by the application, data read by the application, or the application's search history, browsing history, purchase history, etc. Furthermore, for privacy-critical applications, when the same application is deployed on multiple displays, the applications on different displays need to log in with different application accounts within the same time period. For benefit-sharing applications, when the same application is deployed on multiple displays, the applications deployed on multiple displays can log in with the same application account within the same time period. In other words, the benefits of an application account can be shared by applications on multiple displays within the same time period.
[0085] In practice, whether an application is classified as a privacy-critical application or a rights-sharing application can be set by the system default. For example, social applications can be set as privacy-critical applications by default, while audio and video applications can be set as rights-sharing applications by default. Alternatively, for a single application, users can be provided with both privacy-critical application installation packages and rights-sharing application installation packages, allowing users to choose which type of application to deploy in the vehicle's infotainment system.
[0086] The above combination Figures 1 to 6 The schematic diagram of the system architecture provided in the embodiments of this application is described in detail. The control method provided in the embodiments of this application is described in detail below.
[0087] Figure 7 A schematic flowchart of a control method provided in an embodiment of this application is shown. This method can be... Figure 4 The system shown is executed, wherein the user management unit, application management unit group, user center service unit, and public data service unit can be respectively a user management unit 410, at least one application management unit 420, a user center service unit 430, and a public data service unit 440 within a user space. The method may include the following steps:
[0088] S711, User Management Unit obtains user permission information 1.
[0089] In one example, when the main user is logged in, the user management unit retrieves user permission information 1 in response to the user's settings.
[0090] In another example, the user management unit obtains user permission information 1 from a vehicle owner application deployed on an electronic device associated with the vehicle. This vehicle owner application may be an application that provides vehicle control to the vehicle owner, and / or an application that provides services such as providing the vehicle owner with information about the vehicle's status. The association between the electronic device and the vehicle may include: the account used to log in to the electronic device and the vehicle being the same; or, although the accounts used to log in to the electronic device and the vehicle are different, both being accounts belonging to an authorized user of the vehicle; or, the electronic device being authorized by an authorized user of the vehicle, thereby establishing an association between the vehicle and the electronic device.
[0091] For example, the main user can be the aforementioned vehicle owner system account; user permission information 1 may include the permissions of each of the multiple system accounts. These multiple system accounts may include one or more authorized system accounts, and may also include one or more guest system accounts. The specific content of the permissions for each system account can be found in the descriptions in the preceding embodiments, and will not be repeated here.
[0092] In some implementations, applications running under a guest system account do not have permission to access the data storage area under that user space.
[0093] S712, the user management unit sends user permission information 1 to the user center service unit.
[0094] S713, the User Center Service Unit performs user permission processing.
[0095] For example, the user center service unit determines the applications that can access the data storage area under each system account based on user permission information 1, and then obtains user permission information 2. User permission information 2 includes information about at least one application and the association between each application and the system account. The at least one application may include one or more applications that can access the data storage area under one or more system accounts.
[0096] S714, The User Center Service Unit sends user permission information 2 to the Public Data Service Unit.
[0097] Furthermore, the public data service unit manages the data access permissions of applications running under each system account based on user permission information 2. For example, the public data service unit determines, based on user permission information 2, which applications can access the data storage area, and under which system accounts these applications can access the data storage area.
[0098] In some implementations, the public data service unit records the applications that can access the data storage area under each system account. When an application not recorded by the public data service unit requests access to the data storage area, the public data service unit rejects its request.
[0099] In some implementations, where at least one application includes a privacy-critical application, the public data service unit establishes an access path unit for the system account associated with the privacy-critical application. The privacy-critical application running under this system account can then read and write data in the data storage area through this access path unit. For a more specific implementation of privacy-critical applications reading and writing data in the data storage area, please refer to the aforementioned... Figure 6 The descriptions of the corresponding parts will not be repeated here.
[0100] S721, the user management unit obtains login instruction 1, which is associated with system account A.
[0101] For example, system account A can be the vehicle owner's system account, or it can be an account authorized by the legal owner of the vehicle. System account A can be any of the aforementioned system accounts a to N, or it can be the aforementioned system account 1 or system account 2.
[0102] Login command 1 is associated with system account A, which can be understood as: Login command 1 requests to log in to the vehicle system using system account A, or Login command 1 requests to log in to the vehicle system using system account A through display device A. For example, display device A can be any one of the aforementioned display devices 1 to n.
[0103] S722, the user management unit sends a login request for system account A to the user center service unit.
[0104] S723, the user center service unit performs login processing for system account A.
[0105] For example, the user center service unit logs into the vehicle system using system account A on display device A.
[0106] S724, Application Management Snap-in Login Application 1.
[0107] For example, the application management unit group responds to the user's operation and controls application account 1 to log in to application 1.
[0108] S725, the Application Management Unit group sends a login notification for Application 1 to the User Center Service Unit.
[0109] For example, the login notification of application 1 instructs application account 1 to log in to application 1 under system account A.
[0110] S726, the User Center Service Unit performs the association processing between Application 1 and System Account A.
[0111] For example, the association process can be understood as binding application 1, system account A and application account 1 together, so that when system account A logs into the vehicle system next time, application account 1 can log into application 1 together.
[0112] In some implementations, if application 1 is a privacy-critical application, the user center service unit will perform the association processing between application 1 and system account A when it receives the login notification from application 1.
[0113] In some other implementations, when the user center service unit receives the login notification of application 1, the control prompt device prompts information 1, which prompts the user to determine whether application 1 needs to be associated with system account A. When it is determined that the user chooses to associate application 1 with system account A, S726 is executed.
[0114] It should be noted that S724 to S726 can be operations performed when logging into application 1 for the first time under system account A; or, S724 to S726 can also be operations performed when logging into application 1 for the first time under system account A using application account 1. For example, before executing S724, application 1 is already associated with system account A, but application 1 is associated with system account A when logging in with application account 2. After executing S724 to S726, the association between application 1 and system account A is updated to: when logging in with system account A, application 1 is logged in using application account 1.
[0115] In some implementations, S727 and S728 are executed after S723. For example, if the association between system account A and the application has already been processed, S727 and S728 are executed after S723.
[0116] S727, the User Center Service Unit sends a login notification for System Account A to the Application Management Unit Group.
[0117] For example, the login notification for system account A instructs system account A to log in to the vehicle system through display device A.
[0118] S728, Application management unit group login system account A associated with application group a.
[0119] In some implementations, application group a may include at least one application deployed on display device A and associated with system account A. For each application, the application is logged in using the application account associated with system account A; the application account used to log in to different applications may be different. It is understood that the association between the application, the application account, and the system account can be determined through steps S724 to S726.
[0120] For example, at least one application includes application 3, and application 3 is a rights-sharing application. That is, when application 3 is deployed on display device A, other display devices in the vehicle can deploy applications 3', 3" and so on. When logging into any one of application 3, application 3', or application 3" using an application account, the remaining two applications are also logged in. In other words, application group a can also include applications such as application 3' and application 3" that are associated with application 3 and deployed on other display devices.
[0121] It should be noted that the applications deployed on different display devices may be different. Therefore, when system account A logs into the vehicle system through different display devices, the applications that log in with system account A may be different.
[0122] In some implementations, S724 to S726 can also be executed after S727 and S728. For example, if application group a in S728 includes application 1, when S728 is executed, application account 2 is controlled to log in to application 1. Further, in response to a user action controlling application account 1 to log out of application 1, S724 to S726 are executed. Thus, the next time system account A is logged in, application account 1 is used to log in to application 1 associated with system account A.
[0123] S731, the user management unit obtains logout instruction 1, and logout instruction 1 requests system account A to log out.
[0124] S732, the user management unit sends a logout request for system account A to the user center service unit.
[0125] S733, the User Center Service Unit performs a logout process for system account A.
[0126] For example, the user center service unit logs out system account A on display device A.
[0127] S734, the User Center Service Unit sends a logout notification for System Account A to the Application Management Unit Group.
[0128] S735, the application management unit logs out at least one application in application group a.
[0129] In some implementations, all applications in application group a are logged out.
[0130] In some implementations, application group a includes at least one safety-critical application. Safety-critical applications refer to applications that affect driving safety, such as navigation applications or intelligent driving applications. Intelligent driving applications are those used to control intelligent driving functions, which may include, but are not limited to, the following functions affecting driving safety: automatic parking assist (APA), automatic valet parking (AVP), adaptive cruise control (ACC), lane cruise control (LCC), navigation cruise assist (NCA), forward collision warning, lane departure warning, lane keeping assist, and rear collision warning. Specifically, NCA refers to the function of controlling the vehicle to travel to its destination according to the navigation route and being able to control the vehicle to perform operations such as passing intersections, changing lanes, and shifting gears based on road information such as traffic lights.
[0131] In one example, when the vehicle is in drive or reverse, if the application management unit receives a logout notification for system account A, the application management unit will control the logout of all applications in application group a except for intelligent driving applications. Furthermore, when the vehicle is in park, the intelligent driving applications will be logged out.
[0132] In another example, when a smart driving application is running, if the application management unit receives a logout notification from system account A, the application management unit will control the logout of all applications in application group a except for the running smart driving application. Furthermore, when the smart driving application exits its running state, the application management unit will also be controlled to log out.
[0133] In some implementations, if application group a includes at least one benefit-sharing application, then when the application management unit receives a logout notification for system account A, it controls the logout of all applications in application group a except for the at least one benefit-sharing application. For example, if the at least one benefit-sharing application includes the aforementioned application 3, application 3', and application 3'", then the application management unit controls the logout of all applications in application group a except for application 3, application 3', and application 3'".
[0134] In some implementations, after controlling at least one application in application group a to log out, it is also possible to control at least one application in application group a to exit.
[0135] In practice, when the same system account logs into the vehicle system through different display devices, the system account can be logged out of the vehicle system before logging in again when the system account logs into the vehicle system through the next display device; or the system account can be kept logged into the vehicle system continuously during the aforementioned process.
[0136] S741, the application management unit group sends a data access request to the public data service unit for application 2 associated with system account B.
[0137] In this context, application 2 associated with system account B can be understood as an application running under system account B. For example, if system account 2 logs into the vehicle system through display device B, then application 2 can be an application deployed on display device B. Exemplarily, display device B can be any one of the aforementioned display devices 1 to n.
[0138] For example, a data access request may include a request to read data in a data storage area and / or a request to store data in a data storage area.
[0139] S742, the public data service unit performs authentication processing.
[0140] For example, the public data service unit determines whether application 2 associated with system account B has permission to access the data storage area. When it is determined that application 2 associated with system account B has permission to access the data storage area, the public data service unit also determines which data in the data storage area application 2 can access.
[0141] In some implementations, multiple system accounts can access application 2 when logging into the vehicle's infotainment system via display device B. However, the permissions of application 2 associated with different system accounts vary. For example, application 2 associated with system accounts B and C both have access to the data storage area, while application 2 associated with system account D does not. Furthermore, application 2 associated with system account B can access the public storage area, while application 2 associated with system account C does not have access to the public storage area.
[0142] S743, upon successful authentication, the public data service unit sends the data read / write results to the application management unit group.
[0143] In one example, if system account B is associated with application 2, which needs to access the data storage area through the access path unit, then the public data service unit stores the data requested by application 2 and / or reads the data requested by application 2 through the access path unit.
[0144] In another example, if application 2 associated with system account B can access the data storage area without going through the access path unit, then the public data service unit stores the data requested by application 2 in the public storage area and / or reads the data requested by application 2 from the public storage area.
[0145] S744, when authentication fails, the Public Data Service Unit sends a data access failure notification to the Application Management Unit Group.
[0146] For example, a data access failure notification is used to notify of a failure to store data in a data storage area, or to notify of a failure to read data from a data storage area.
[0147] It should be noted that when system account A and system account B are different and they log into the vehicle system through different display devices, S741 to S744 can be executed synchronously with any one of the following groups: S721 to S723, S724 to S726, S727 to S728, or S731 to S735, or they can be executed before any one of these groups. Furthermore, S741 to S744 can also be executed synchronously with S711 to S714, or S741 to S744 can be executed before S711 to S714.
[0148] It should also be noted that, in this application, "application login or logout" refers to logging into or logging out of an application using an application account; while "vehicle system login or logout" refers to logging into or logging out of a vehicle system using a system account. Furthermore, application logout and application exit are not the same. Application logout refers to the application account logging out of the application, while application exit refers to the termination or exit of all processes related to the application, such as stopping the application's background operation. In other words, after logging out of an application, the application may or may not exit. If the application does not exit, the display screen may show the application's running interface, or the display screen may not show the application's running interface; in this case, the application can run in the background.
[0149] To facilitate understanding of the data access method provided in the embodiments of this application, the following is combined with... Figures 8 to 12 This application provides a detailed description of its application scenarios and GUI. Figures 8 to 12 The processing actions (such as control, response, etc.) or steps involved can be handled by... Figure 1 The computing platform 150 shown can execute the operation, or it can be executed by the system shown above. For example, data reading and writing related processing actions can be executed by the public data service unit 440.
[0150] Figure 8 An example of a GUI provided in an embodiment of this application is shown. Figure 8As shown, User A is located in the driver's seat area of the vehicle cabin. At this time, the content displayed on the display screen 201 (i.e., the central control screen) can be as follows: Figure 8 As shown in (a), the system includes a content display area 1010 and a function bar 1010'. Exemplarily, the content display area 1010 includes: icons for various applications, each icon used to activate an application; a login control 1011 (in a non-login state) for logging into the vehicle's infotainment system; and Bluetooth, Wi-Fi, and cellular signal icons, respectively indicating the vehicle's Bluetooth on and / or connection status, Wi-Fi on status, and cellular signal strength. The function bar 1010' includes a homepage icon, seat controls, air conditioning controls, and volume controls, respectively used to control the content display area 1010 to display the homepage, control the on / off switch of seat ventilation and / or adjust the airflow of seat ventilation, control the on / off switch of air conditioning and / or adjust the air conditioning temperature and heating / cooling status, adjust the in-vehicle air circulation status, and adjust the volume of the sound device.
[0151] For example, when a user clicks on the login control 1011, the following can be displayed: Figure 8 The prompt box 1012 shown in (b) is shown in the diagram. The prompt box 1012 includes the message "Please select a login method," as well as a face recognition login control, a QR code login control, an account login control, and a cancel control. When the user clicks the account login control, in response to the system account and login password (or verification code) entered by the user, the system account (hereinafter referred to as User A's system account) is controlled to log in to the vehicle system. It is understood that in actual implementation, the user can also choose other methods to log in to the vehicle system. After User A's system account logs in to the vehicle system, the login control can display as shown in the diagram. Figure 8 The system account of user A, shown in (c), has an avatar 1013 associated with it.
[0152] It should be noted that, Figure 8 The icons shown are for illustrative purposes only. In actual implementation, the content display area 1010 and the function bar 1010' may display more or fewer icons. For example, when sliding the interface switching component 1011' in the content display area 1010, the content display area 1010 may switch to other interfaces to display icons for other applications. As another example, the content display area 1010 may display some or all of the Bluetooth, Wi-Fi, and cellular network signal icons, or may not display them, depending on the user's settings. Furthermore, the function bar 1010' may display other styles of icons based on the user's settings for seat ventilation and air conditioning status.
[0153] In some implementations, an application running under user A's system account stores data via the aforementioned access path unit, and applications running under other system accounts cannot read this data. For this scenario, Figure 9 and Figure 10 Each set of GUIs is shown.
[0154] For example, taking an application under user A's system account that needs to store data via an access path unit, including an instant messaging application, the display screen 201 can respond to the user's operation and display... Figure 9 The instant messaging application interface 1030 is shown in (a) above. The left column of interface 1030 is a control bar, which includes an avatar 1031, the avatar of the application account logged into the instant messaging application. The control bar also includes chat controls, contact controls, and file controls, used to control the display of the chat module, contact module, and file module, respectively. The middle column of interface 1030 currently shows thumbnails of multiple contacts, and the right column of interface 1030 shows the chat interface with a specific contact. For example, as shown in interface 1030, the instant messaging application receives an image 1032 from contact a. Further, when image 1032 is detected to be long-pressed, the control display screen 201 displays... Figure 9 The interface shown in (b) includes a control bar 1033 containing edit, forward, and save controls for editing an image, forwarding an image to other contacts, and saving an image, respectively. When the save control is clicked, image 1032 is saved. More specifically, when the save control is clicked, the instant messaging application sends a data storage request to the public data service unit. After the public data service unit authenticates the instant messaging application, it stores image 1032 in the data storage area through the access path unit corresponding to user A's system account. For example, the save path for image 1032 is "User A's system account - Instant messaging application - Image 1032".
[0155] Optionally, when image 1032 is successfully saved, the display screen 201 can be controlled to display, as shown in the image. Figure 9 The prompt bar 1034 shown in (c) includes the message "Image saved".
[0156] Furthermore, when an application running under user B's system account requests access to the image library, the application is unable to obtain the aforementioned image 1032. For example, as... Figure 10As shown in (a), when User B's system account logs into the vehicle's infotainment system via display screen 204 (i.e., the screen behind the passenger headrest), the login control on display screen 204 displays the avatar 1018 associated with User B's system account, and the instant messaging application interface displays the avatar 1035 of the application account logged into the instant messaging application by User B's system account. If the user wants to send a picture to contact C through the instant messaging application running under User B's system account, they can click on the picture control 1036 to open it. Figure 10 The "Pictures and Videos" section 1037, shown in (b) of the diagram, allows users to select pictures from this section and send them to contact C. More specifically, upon detecting a click on the picture control 1036, the instant messaging application sends a data read request to the public data service unit. This request is used to read pictures that the instant messaging application can read. In one example, if the instant messaging application running under user B's system account also needs to store data via the access path unit, the data read request can be used to request pictures stored via the access path unit. In another example, if user B's system account is authorized to access the public storage area, the data read request can also be used to request to read pictures in the public storage area.
[0157] In some implementations, if the images stored in the public storage area include images 6 and 7, and the application under user B's system account needs to store data through the access path unit stores images 1, 2, 3, 4, 5, and 8, then if user B's system account is authorized to access the public storage area, the public data service unit responds to the data read request from the instant messaging application running under user B's system account by reading images 1 to 8 from the data storage area and controls the "Images and Videos" column 1037 to display these images for user selection. That is, when the instant messaging application running under user B's system account requests to read images from the data storage area, it can only read images from the public storage area and images stored by the application under user B's system account that needs to store data through the access path unit; it cannot read images 1032 stored by the instant messaging application running under user A's system account. Furthermore, Figure 10 This example illustrates how an instant messaging application can request to read data. In actual implementation, when other applications running under user B's system account request to read data, these applications are also unable to read image 1032.
[0158] When an application under user A's system account that needs to store data via the access path unit requests access to the image library, that application can obtain the aforementioned image 1032. For example, taking an instant messaging application running under user A's system account that needs to store data via the access path unit as an example, if other applications under user A's system account that need to store data via the access path unit have stored images a to d, and user A's system account is authorized to access the public storage area, then as follows... Figure 11 As shown in (a), when the image control 1038 is clicked, the instant messaging application sends a data read request to the public data service unit. This request is used to read images that the instant messaging application can read. Further, when the public data service unit successfully authenticates the data read request from the instant messaging application running under user A's system account, the public data service unit reads image 1032, images a through d, and images 6 and 7 from the data storage area, and controls... Figure 11 The “Pictures and Videos” section 1039 shown in (b) displays these pictures for the user to select.
[0159] When an application under User A's system account that does not need to store data through an access path unit requests access to the image library, the application cannot obtain the aforementioned image 1032. Taking, for example, applications under User A's system account that do not need to store data through an access path unit, such as video applications... Figure 12 As shown in (a), the interface of the currently displayed video application includes a navigation bar 1021, a video playback bar 1022, and a playback history bar 1023, which are used to display various controls, the video playback interface, and playback history information, respectively. The navigation bar 1021 includes a login control 1024, which allows users to control whether an application account logs in or out of the video application, or to change the image associated with the application account used to log in. For example, a user long-pressing the login control 1024 can trigger the display screen 201 to display... Figure 12 The interface in (b) includes multiple image selection controls, a close window control, and an OK control, which are used to select an image, close the window, and confirm, respectively. Figure 12 The interface in (b) shows the selection of the image associated with the application account. More specifically, upon detecting that the login control 1024 is clicked, the video application sends a data read request to the public data service unit, which is used to read images that the video application can read. Further, when the public data service unit authenticates the data read request of the video application running under user A's system account, the public data service unit reads images 6 and 7 from the data storage area and controls the process as follows: Figure 12 The interface shown in (b) displays these images for the user to select.
[0160] In some implementations, Figure 10 and Figure 11 The scenarios shown can all be in Figure 9 The scene shown occurred after the event, and Figure 10 and Figure 11 The scenes shown can occur within the same time period, i.e. Figure 10 and Figure 11 In the scenario shown, the data stored in the data storage area is identical. However, because some applications under different system accounts store data via access path units, this data cannot be read by applications under other system accounts. Therefore, even though the data stored in the data storage area is the same, the instant messaging application running under user B's system account and the instant messaging application running under user A's system account will not be able to read the same data. This helps protect the privacy and security of user data. Furthermore, Figure 12 The scene shown can also be in Figure 9 What happened after the scene shown is that at this point, the data storage area includes image 1032, as well as images a through d. However, due to... Figure 12 The application's permission settings prevent it from reading image 1032 and images a through d.
[0161] It should be noted that the aforementioned Figures 8 to 12 Using images as an example of data, in actual implementation, the aforementioned stored or retrieved data can also be other data such as videos or files.
[0162] It should also be noted that the aforementioned applications that need to store data through the access path unit can be privacy-critical applications, while the aforementioned applications that do not need to store data through the access path unit can be rights-sharing applications.
[0163] Figure 13 A schematic flowchart of a data access method provided in an embodiment of this application is shown. This method 20 can be applied to... Figure 1 In the vehicle shown, or the method can be derived from Figures 3 to 5 The method is executed on any of the systems shown. More specifically, the method includes:
[0164] S21, obtain the information of the first user account. The first user account is one of multiple user accounts. Each user account is associated with a sub-data storage area. The multiple sub-data storage areas associated with multiple user accounts belong to the same user space.
[0165] For example, multiple user accounts may include the aforementioned vehicle owner system account, authorized system account, etc. The sub-data storage area may be the access path unit in the aforementioned embodiments.
[0166] S22, obtain the first access request of the first application under the first user account. The first access request is used to request the storage of the first data.
[0167] For example, the first data may include data such as images, files, and videos.
[0168] In some implementations, the first application is a first-type application, which is an application that requires data isolation. For example, the first-type application is the privacy-critical application in the aforementioned embodiments.
[0169] S23, based on the first access request, the first data is stored in the first sub-data storage area corresponding to the first user account, and the multiple sub-data storage areas include the first sub-data storage area.
[0170] In some implementations, the first access request carries the identifier of the first user account, and further, based on the identifier of the first user account, the first data is stored in the first sub-data storage area corresponding to the first user account.
[0171] For example, taking the first user account as the system account of user A in the aforementioned embodiment and the first application as the instant messaging application running under user A's system account, the first access request can be a data storage request issued by the instant messaging application running under user A's system account, for example, in response to... Figure 9 The control bar 1033 shown in (b) stores the data storage request generated when a control is clicked. In this scenario, the first data can be... Figure 9 Image 1032 is shown in (a) above. Further, storing the first data through the first sub-data storage area corresponding to the first user account can be achieved by storing the first data through the access path unit corresponding to user A's system account. For example, when storing the first data, a reference to the first data (such as a field including user A's system account) is created and stored in the access path unit, so that when reading the first data later, it needs to be read through the reference to the first data stored in the access path unit. For a more specific implementation of storing the first data, please refer to the aforementioned... Figure 6 Description of the corresponding part and Figure 9 The descriptions of the corresponding parts will not be repeated here.
[0172] In some implementations, the multiple user accounts also include a second user account, which is associated with a second sub-data storage area in the multiple sub-data storage areas. The method further includes: obtaining a second access request from a second application of the second user account; and rejecting the second access request when the second access request is used to request to read the first data.
[0173] In this context, denying the second access request can be understood as refusing to read the first data from the data storage area.
[0174] For example, if the first data is a first type of data, then when the second access request is used to request the reading of the first type of data, the first group of data is read from the data storage area according to the second access request. Each item in the first group of data is first type of data, and the first group of data does not include the first data. When the second access request is used to request the reading of first type of data including the first data, rejecting the second access request can be understood as rejecting the part of the second access request related to reading the first data, but it is still possible to respond to the second access request to read other first type of data besides the first data.
[0175] Taking multimedia data as an example, if the second user account is the system account of user B in the aforementioned embodiment, and the second application is an instant messaging application running under user B's system account, then the second access request can be a data read request issued by the instant messaging application running under user B's system account. For example, in response to... Figure 10 The data read request generated when the image control 1036 shown in (a) is clicked. (Through...) Figure 10 As can be seen in (b), in response to a data read request issued by an instant messaging application, the final read data does not include the first data (such as image 1032), but includes other first-type data besides the first data (such as images 1 to 8). In the aforementioned scenario, images 1 to 8 can be regarded as an example of the first group of data.
[0176] It should be noted that the second application can be a privacy-critical application or a rights-sharing application.
[0177] In some implementations, the method further includes: obtaining a third access request from a third application under the first user account, wherein the third application is an application that does not need to go through the first sub-data storage area when storing data; and rejecting the third access request when the third access request is used to request to read the first data.
[0178] In this context, denying a third access request can be understood as refusing to read the first data from the data storage area.
[0179] In some implementations, the third application is a type of second-class application, which is an application that does not require data isolation. For example, the second-class application can be a rights-sharing application as described in the foregoing embodiments.
[0180] For example, if the first data is a first type of data, then when a third access request is made to request the reading of the first type of data, a second set of data is read from the data storage area according to the third access request. Each item in the second set of data is first type of data, and the second set of data does not include the first data. When a third access request is made to request the reading of first type of data including the first data, rejecting the third access request can be understood as rejecting the part of the third access request concerning the reading of the first data, but still being able to respond to the third access request to read other first type of data besides the first data.
[0181] Taking multimedia data as an example, if the first user account is the system account of user A in the aforementioned embodiment, and the third application is a video application running under user A's system account, then the third access request can be a data read request issued by the video application running under user A's system account. For example, in response to... Figure 12 The data read request generated when the login control 1024 shown in (a) is clicked. Figure 12 As shown in (b), in response to the data read request issued by the video application, the final read data does not include the first data (such as image 1032), but includes other first-type data besides the first data (such as images 6 and 7). In the aforementioned scenario, images 6 and 7 can be considered as an example of the second set of data. It should be noted that the third application can also be other rights-sharing applications.
[0182] In some implementations, the method further includes: obtaining a fourth access request from a first application, the fourth access request being used to request the reading of second data, the second data being data stored by a third application; and reading the second data according to the fourth access request.
[0183] In some implementations, the second data is stored in a public storage area, and the second data is read according to a fourth access request, including: when the first user account is authorized to access the public storage area, the second data is read according to the fourth access request.
[0184] For example, the public storage area can be the public storage area in the aforementioned embodiments, used to store data associated with rights-sharing applications. That is, the second data can be data associated with a second type of application; for example, the second data can be data stored by a second type of application. Taking the first user account as the system account of user A in the aforementioned embodiments, and the first application as an instant messaging application running under user A's system account, as an example, the second data may include... Figure 11 See images 6 and / or 7. In the above scenario, the fourth access request could be a data read request issued by an instant messaging application running under user A's system account, for example, in response to... Figure 11The data read request generated when the image control 1038 shown in (a) is clicked. (Through...) Figure 11 As can be seen in (b), in response to a data read request issued by an instant messaging application, the final read data result includes second data (such as image 6 and / or image 7).
[0185] For example, permissions for a first user account to access the public storage area can be set through S711 to S713 in the foregoing embodiments.
[0186] Understandably, when the first user account is not authorized to access the public storage area, the fourth access request from the first application is rejected, meaning the first application cannot read the data in the public storage area.
[0187] In some implementations, the method further includes: obtaining a fifth access request from a fourth application under a first user account, the fifth access request being used to request the reading of first data; and when the fourth application is an application that needs to access the first sub-data storage area to store data, reading the first data according to the fifth access request.
[0188] It is understandable that the fourth application and the first application are of the same type, that is, the fourth application is also a type of first application.
[0189] For example, taking the first user account as the system account of user A in the aforementioned embodiment, and the fourth application as an instant messaging application running under user A's system account, the first application can be any privacy-critical application other than an instant messaging application, and the first application stores... Figure 11 If at least one of the images a to d is shown, then at least one of the images a to d can be considered as an example of the first data. In the aforementioned scenario, the fifth access request can be a data read request issued by an instant messaging application running under user A's system account, for example, in response to... Figure 11 The data read request generated when the image control 1038 shown in (a) is clicked. (Through...) Figure 11 As can be seen in (b) above, in response to a data read request issued by an instant messaging application, the final read data result includes first data (such as at least one of the images a to d).
[0190] It should be noted that the type of application involved in this application (such as a privacy-critical application or a rights-sharing application) can be the system default; or it can be set by the user. For example, when deploying the application for the first time, the user can choose the type of application, or the user can change the type of application after the application has been deployed.
[0191] The data access method provided in this application embodiment, when multiple user accounts used to log in to the vehicle system are associated with the same user space, allows applications with data privacy requirements to store the data requested by the application in the data storage area through a sub-data storage area. This can prevent applications under other user accounts from reading the data, thus helping to protect the data privacy and security of each user account.
[0192] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions between the various embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0193] The above text combines Figures 1 to 13 The methods provided in the embodiments of this application are described in detail below. Figure 14 and Figure 15 The apparatus provided in the embodiments of this application is described in detail. It should be understood that the description of the apparatus embodiments corresponds to the description of the method embodiments. Therefore, for content not described in detail, please refer to the method embodiments above. For the sake of brevity, it will not be repeated here.
[0194] Figure 14 A schematic block diagram of an apparatus 2000 provided in an embodiment of this application is shown. The apparatus 2000 may include units for executing the methods described in the foregoing embodiments. Furthermore, each unit in the apparatus 2000 implements a corresponding process of the above method embodiments. The apparatus 2000 includes an acquisition unit 2010, which can be used to implement corresponding data acquisition or transmission / reception functions. The apparatus 2000 also includes a processing unit 2020, which can be used to implement corresponding processing functions.
[0195] Optionally, the device 2000 further includes a storage unit, which can be used to store instructions and / or data. The processing unit 2020 can read the instructions and / or data in the storage unit so that the device can perform the relevant actions in the aforementioned method embodiments.
[0196] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0197] It should also be understood that the device 2000 described herein is embodied in the form of a functional unit. The terms “module” or “unit” may refer to application-specific ASICs, electronic circuits, processors (e.g., shared processors, proprietary processors, or group processors) and memory for executing one or more software or firmware programs, integrated logic circuits, and / or other suitable components that support the described functions.
[0198] The apparatuses described above are capable of implementing the corresponding steps performed by the computing platform 150 in the methods described above. These functions can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the functions described above; for example, the acquisition unit 2010 can be replaced by a transceiver, and other units, such as processing units, can be replaced by a processor, used to execute the relevant processing operations in each method embodiment.
[0199] For example, the acquisition unit 2010 and the processing unit 2020 can be set in Figure 1 In the vehicle 100 shown, or it can also be set in Figures 3 to 5 In any of the systems shown, more specifically, the acquisition unit 2010 and processing unit 2020 can be located in the public data service unit 440. Exemplarily, the operations performed by the acquisition unit 2010 and processing unit 2020 can be executed by a single processor, or by different processors. In specific implementations, the one or more processors can be located in the public data service unit 440. Figure 1 The processor in the vehicle 100 shown; or, the device 2000 described above may be a chip disposed in the vehicle 100.
[0200] In the specific implementation process, the units in the above device can be fully or partially integrated together, or they can be implemented independently. In one implementation, these units are integrated together and implemented in the form of a system-on-a-chip (SoC).
[0201] Figure 15 This is another schematic block diagram of the device provided in the embodiments of this application. Figure 15 The illustrated device 2100 may include a processor 2110, a transceiver 2120, and a memory 2130. The processor 2110, transceiver 2120, and memory 2130 are connected via internal interconnects. The memory 2130 stores instructions, and the processor 2110 executes the instructions stored in the memory 2130 to implement the methods described in the above embodiments. Optionally, the memory 2130 may be coupled to the processor 2110 via an interface or integrated with the processor 2110.
[0202] It should be noted that the transceiver 2120 mentioned above may include, but is not limited to, transceiver devices such as input / output interfaces, to realize communication between device 2100 and other devices or communication networks.
[0203] Memory 2130 can be volatile memory and / or non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM includes various forms such as: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0204] Transceiver 2120 uses transceiver devices, such as but not limited to transceivers, to enable communication between device 2100 and other devices or communication networks to receive / send data / information for implementing the methods in the above embodiments.
[0205] This application also provides an intelligent driving device, which includes the device 2000 or device 2100 in the above embodiments.
[0206] This application also provides a computer program product, which includes computer program code. When the computer program code is run on a computer, it causes the computer to implement the methods described in the above embodiments of this application.
[0207] This application also provides a computer-readable storage medium storing computer instructions that, when executed on a computer, cause the computer to implement the methods described in the above embodiments of this application.
[0208] This application also provides a chip, including circuitry, for performing the methods described in the above embodiments of this application.
[0209] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0210] In the description of the embodiments of this application, unless otherwise stated, " / " means "or", for example, A / B can mean A or B; "and / or" in this document describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. In this application, "at least one" means one or more, and "more" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or multiple items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.
[0211] The use of prefixes such as "first" and "second" in this application embodiment is solely for distinguishing different descriptive objects and does not limit the position, order, priority, quantity, or content of the described objects. The use of ordinal numbers and other prefixes to distinguish descriptive objects in this application embodiment does not constitute a limitation on the described objects. The description of the described objects is found in the claims or the context of the embodiments, and the use of such prefixes should not constitute unnecessary restrictions.
[0212] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0213] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions between the various embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0214] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0215] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0216] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A data access method, characterized in that, include: Obtain information about a first user account, which is one of multiple user accounts. Each user account is associated with a sub-data storage area. The multiple sub-data storage areas associated with the multiple user accounts belong to the same user space. The multiple sub-data storage areas belonging to the same user space means that the multiple sub-data storage areas share a set of system services. Obtain the first access request of the first type of application under the first user account, wherein the first access request is used to request the storage of the first data; According to the first access request, the first data is stored in the first sub-data storage area corresponding to the first user account, and the plurality of sub-data storage areas include the first sub-data storage area; Wherein, the first sub-data storage area is a storage area that is prohibited from being accessed by user accounts other than the first user account, and the first sub-data storage area is a storage area that is prohibited from being accessed by the second type of application of the first user account and the second type of application of the other user accounts. The first type of application is an application that needs to be isolated by data, and the second type of application is an application that does not need to be isolated by data. The method further includes: Obtain the fifth access request of the fourth application under the first user account, the fifth access request being used to request to read the first data; When the fourth application is the first type of application, the first data is read according to the fifth access request.
2. The method according to claim 1, characterized in that, The plurality of user accounts also includes a second user account, which is associated with a second sub-data storage area within the plurality of sub-data storage areas. The method further includes: Obtain the second access request of the second application of the second user account; When the second access request is used to request the reading of the first data, the second access request is rejected.
3. The method according to claim 1 or 2, characterized in that, The method further includes: Obtain a third access request from a third application under the first user account, wherein the third application is an application that does not need to go through the first sub-data storage area when storing data; When the third access request is made to request to read the first data, the third access request is rejected.
4. The method according to claim 3, characterized in that, The method further includes: Obtain the fourth access request of the first type of application, the fourth access request being used to request to read the second data, the second data being the data stored by the third application; The second data is read according to the fourth access request.
5. The method according to claim 4, characterized in that, The second data is stored in a public storage area. Reading the second data according to the fourth access request includes: When the first user account is authorized to access the public storage area, the second data is read according to the fourth access request.
6. The method according to claim 3, characterized in that, The third application is the second type of application.
7. A data access device, characterized in that, include: The acquisition unit is used to acquire information about a first user account, which is one of multiple user accounts. Each user account is associated with a sub-data storage area. The multiple sub-data storage areas associated with the multiple user accounts belong to the same user space. The multiple sub-data storage areas belonging to the same user space means that the multiple sub-data storage areas share a set of system services. The acquisition unit is further configured to: acquire a first access request for a first type of application under a first user account, wherein the first access request is used to request storage of first data; The processing unit is configured to store the first data in a first sub-data storage area corresponding to the first user account according to the first access request, wherein the plurality of sub-data storage areas include the first sub-data storage area; Wherein, the first sub-data storage area is a storage area that is prohibited from being accessed by user accounts other than the first user account, and the first sub-data storage area is a storage area that is prohibited from being accessed by the second type of application of the first user account and the second type of application of the other user accounts. The first type of application is an application that needs to be isolated by data, and the second type of application is an application that does not need to be isolated by data. The acquisition unit is also used for: Obtain the fifth access request of the fourth application under the first user account, the fifth access request being used to request to read the first data; The processing unit is also used for: When the fourth application is the first type of application, the first data is read according to the fifth access request.
8. The apparatus according to claim 7, characterized in that, The plurality of user accounts also includes a second user account, which is associated with a second sub-data storage area in the plurality of sub-data storage areas. The acquisition unit is further configured to: Obtain the second access request of the second application of the second user account; The processing unit is also used for: When the second access request is used to request the reading of the first data, the second access request is rejected.
9. The apparatus according to claim 7 or 8, characterized in that, The acquisition unit is also used for: Obtain a third access request from a third application under the first user account, wherein the third application is an application that does not need to go through the first sub-data storage area when storing data; The processing unit is also used for: When the third access request is made to request to read the first data, the third access request is rejected.
10. The apparatus according to claim 9, characterized in that, The acquisition unit is also used for: Obtain the fourth access request of the first type of application, the fourth access request being used to request to read the second data, the second data being the data stored by the third application; The processing unit is also used for: The second data is read according to the fourth access request.
11. The apparatus according to claim 10, characterized in that, The second data is stored in a common storage area, and the processing unit is used for: When the first user account is authorized to access the public storage area, the second data is read according to the fourth access request.
12. The apparatus according to claim 9, characterized in that, The third application is the second type of application.
13. A data access device, characterized in that, include: A processor for executing a computer program stored in memory to cause the apparatus to perform the method as described in any one of claims 1 to 6.
14. The apparatus according to claim 13, characterized in that, The device also includes the memory.
15. A computer-readable storage medium, characterized in that, It stores instructions that, when executed by a processor, implement the method as described in any one of claims 1 to 6.
16. A chip, characterized in that, The chip includes circuitry for performing the method as described in any one of claims 1 to 6.
17. A computer program product, characterized in that, The computer program product includes: computer program code, which, when executed by a processor, implements the method as described in any one of claims 1 to 6.
18. A vehicle, characterized in that, Includes the apparatus as described in any one of claims 7 to 14, or the computer-readable storage medium as described in claim 15, or the chip as described in claim 16, or the vehicle is equipped with the computer program product as described in claim 17.
Citation Information
Patent Citations
Isolation method and isolation device for application program
CN106778291A
A data management method for an in-vehicle driving recorder and its in-vehicle unit
CN114936360A
Application account management method and related device
CN117951664A