Intelligent cabin data safety management method and device, electronic equipment and vehicle
By intercepting data in cockpit data management and combining it with policy library and scenario information for desensitization and noise reduction, the problem of privacy data leakage and weak user control under static permission management is solved, and the secure use and transparent management of data are realized.
Patent Information
- Application Number
- CN202511734781.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-24
- Publication Date
- 2026-01-13
AI Technical Summary
Existing cockpit data management solutions based on static permissions lack effective management of the data lifecycle, resulting in a high risk of privacy data leakage, inability to provide personalized services, weak user control, and opaque data collection and usage.
By intercepting privacy data access requests from cockpit applications through a security agent, combining vehicle operation scenario information and the built-in operation policy library to determine the target operation policy, perform de-identification processing and erase the original data, and achieve local processing and noise reduction of privacy data.
While protecting user privacy, we aim to achieve secure data use and effective management, reduce the risk of privacy data leakage, and enhance users' sense of control and transparency in data utilization.
Smart Images

Figure CN121333779A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data management technology, and in particular to methods, devices, electronic devices and vehicles for data security management in smart cockpits. Background Technology
[0002] Existing cockpit data management solutions based on static permissions propose that each application requests access to sensor data interfaces from the operating system. After a user grants authorization once, each application gains continuous access, resulting in decentralized data flow without centralized monitoring. However, this solution has at least the following drawbacks: First, it lacks effective management of the data lifecycle, allowing raw privacy data to be stored locally by applications for extended periods or arbitrarily uploaded to the cloud, increasing the risk of privacy data leakage. Second, it either completely prohibits providing user privacy data to applications, making personalized services impossible, or allows direct provision of user privacy data to applications, posing a significant risk of privacy leakage. Summary of the Invention
[0003] The main objective of this application is to provide a method, device, electronic device, and vehicle for data security management in smart cockpits, which can reduce the risk of leakage of user privacy data in smart cockpit scenarios.
[0004] To achieve the above objectives, one aspect of this application proposes a smart cockpit data security management method, the method comprising: When the cockpit application sends a privacy data access request to the vehicle operating system, the privacy data access request is intercepted; Obtain vehicle operation scenario information, and then determine the target operation strategy based on the privacy data access request, the vehicle operation scenario information, and the built-in operation strategy library; When the target operation policy indicates that only local processing results regarding the original privacy data are allowed, the privacy data requested for access in real time is de-identified to obtain de-identified data, which is then sent to the cockpit application, and the requested privacy data is erased.
[0005] In some embodiments, the privacy data access request includes the name of the cockpit application and the type of privacy data requested for access; determining the target operation strategy based on the privacy data access request, the vehicle operation scenario information, and the built-in operation strategy library includes: Based on the privacy data type, the name of the cockpit application, and the vehicle operation scenario information, a query and match are performed in the operation strategy library to obtain the matching result; If the matching result is not empty, then the operation strategy indicated by the matching result shall be used as the target operation strategy; If the matching result is empty, the operation strategy corresponding to the cockpit application is generated through the interface interaction, and then the generated operation strategy is used as the target operation strategy and stored in the operation strategy library.
[0006] In some embodiments, generating the operation strategy corresponding to the cockpit application through interface interaction includes: The user privacy control panel displays the configuration interface corresponding to the cockpit application, which includes a privacy data type configuration area, a vehicle operation scenario configuration area, and a privacy data access method configuration area. In response to user operations in the privacy data type configuration area, the vehicle operation scenario configuration area, and the privacy data access method configuration area, an operation policy corresponding to the cockpit application is generated.
[0007] In some embodiments, after de-identifying the privacy data requested for access in real time to obtain de-identified data, the method further includes: The de-identified data is temporarily cached in the local storage area; When the cloud sends a data collection request to the vehicle operating system, the data collection request is intercepted; Multiple de-identified data temporarily cached in the local storage area are subjected to noise addition processing to obtain multiple noisy data. The multiple noisy data are then sent to the cloud so that the cloud can perform aggregation calculations on the multiple noisy data.
[0008] In some embodiments, sending the plurality of noisy data to the cloud includes: sending the plurality of noisy data to the cloud through an anonymous channel.
[0009] In some embodiments, the method further includes: When the target operation policy indicates that access to raw privacy data is permitted, the requested privacy data is sent to the cockpit application.
[0010] In some embodiments, the method further includes: When the target operation policy indicates that access to raw privacy data is prohibited, the privacy data access request shall not be responded to.
[0011] To achieve the above objectives, another aspect of this application provides a smart cockpit data security management device, the device comprising: The request interception module is used to intercept the privacy data access request when the cockpit application sends a privacy data access request to the vehicle operating system; The strategy determination module is used to acquire vehicle operation scenario information, and then determine the target operation strategy based on the privacy data access request, the vehicle operation scenario information and the built-in operation strategy library. The data processing module is used to perform desensitization processing on the privacy data requested for access in real time when the target operation policy indicates that only access to the local processing results of the original privacy data is allowed, to obtain desensitized data, and then send the desensitized data to the cockpit application, and erase the privacy data requested for access.
[0012] To achieve the above objectives, another aspect of this application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-described intelligent cockpit data security management method.
[0013] To achieve the above objectives, another aspect of this application provides a vehicle that includes the aforementioned intelligent cockpit data security management device or the aforementioned electronic device.
[0014] The embodiments of this application include at least the following beneficial effects: by intercepting the privacy data access requests sent by the cockpit application to the vehicle operating system in the form of a security agent, and then analyzing the built-in operation policy library and the acquired vehicle operation scenario information to determine the target operation policy, and then when the target operation policy indicates that only access to the local processing results of the original privacy data is allowed, the privacy data requested for access in real time is de-identified, and then the de-identified data is sent to the cockpit application and the requested privacy data is erased. This can ensure that the data can still be securely used to improve services while protecting user privacy, and at the same time achieve effective management of the privacy data lifecycle.
[0015] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description
[0016] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the description of the embodiments taken in conjunction with the following drawings, in which: Figure 1 This is a flowchart illustrating a smart cockpit data security management method provided in an embodiment of this application; Figure 2 This is a schematic diagram illustrating the composition of an intelligent cockpit data security management device provided in an embodiment of this application; Figure 3 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the reference to "embodiment" herein means that a specific feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments. The implementation methods described in the following exemplary embodiments do not represent all implementation methods consistent with the embodiments of this application; they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this application as detailed in the appended claims.
[0018] It is understood that the terms "first," "second," etc., used in this application may be used to describe various concepts herein, but unless specifically stated otherwise, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the words "if" or "when" as used herein may be interpreted as "when," "in response to a determination," or "at least one," "multiple," "each," "any," etc., as used in this application, at least one includes one, two, or more than two, multiple includes two or more, each refers to each of the corresponding multiple, and any refers to any one of the multiple.
[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.
[0020] With the rapid development of intelligent connected vehicles, the role of smart cockpits is becoming increasingly significant. Smart cockpits integrate numerous sensors (such as cameras and microphones) and applications, capable of collecting and processing massive amounts of sensitive user data, including biometric information (such as facial and voiceprint data), behavioral data, geolocation, and personal account information. Currently, the commonly used technical solutions for data security in the industry include the following: (1) Adopt the application sandbox mode to isolate different applications in an independent running environment to prevent different applications from accessing data at will; (2) A static permission management mode is adopted. When the application is installed, a set of fixed data access permissions (such as "access camera", "access location", etc.) are requested from the user. The user can only choose "allow" or "deny". (3) Adopt a data encryption transmission mode to encrypt the data uploaded to the cloud (such as TLS / SSL).
[0021] Existing cockpit data management solutions based on static permissions propose that each application requests access to sensor data interfaces from the operating system. After a one-time user authorization, each application gains continuous access, resulting in decentralized data flow without centralized monitoring. However, this solution has the following drawbacks, making it unable to meet privacy compliance requirements in smart cockpit scenarios: (1) Lack of data lifecycle management: The system lacks effective management of "when to store, how long to store, and when to delete" data, which may cause original sensitive data (such as facial images, recordings, etc.) to be stored locally by the application for a long time or uploaded to the cloud at will, increasing the risk of privacy data leakage; (2) It is difficult to balance privacy protection and data utilization: either completely prohibit the provision of user privacy data to applications, resulting in the inability to realize personalized services (such as insurance discount recommendations based on driving habits), or allow the direct provision of user privacy data to applications, which brings great risks of privacy leakage; (3) Data collection and usage are not transparent: Once an application obtains permission, it can continuously collect data in the background, even if the user is not using the application at that time; for example, a music app may listen to conversations in the car after obtaining microphone permission, in order to achieve non-music related purposes (such as targeted advertising push, etc.), which clearly violates the principle of minimum necessary data.
[0022] (4) Weak and coarse-grained user control: The control capabilities provided by static permission management cannot meet the needs of dynamic scenarios. The only authorization options provided to users are "one-time" and "all or nothing". For example, users cannot achieve fine intentions such as "only allow the video conferencing APP to use the camera during the call, but prohibit the navigation APP from using it" or "allow the navigation APP to obtain the location when it is in use, but prohibit it from obtaining it in the background", resulting in weak user control and poor permission setting experience.
[0023] In view of this, this application proposes a smart cockpit data security management method, device, electronic device, and vehicle. This solution intercepts privacy data access requests sent by the cockpit application to the vehicle operating system in the form of a security agent. Then, it analyzes the built-in operation policy library and the acquired vehicle operation scenario information to determine the target operation policy. Subsequently, when the target operation policy indicates that access to the local processing results of the original privacy data is only allowed, the privacy data requested for access in real time is de-identified. The de-identified data is then sent to the cockpit application, and the requested privacy data is erased. This allows the data to be securely used to improve services while protecting user privacy, and also achieves effective management of the privacy data lifecycle.
[0024] This application provides a smart cockpit data security management method, which can be applied to the electronic devices provided in this application. The electronic devices can be terminals or servers. Terminals can be tablets, laptops, desktop computers, etc., but are not limited to these. Servers can be independent physical servers, server clusters or distributed systems composed of multiple physical servers, or cloud servers providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks, and big data and artificial intelligence platforms.
[0025] Please refer to Figure 1 , Figure 1 This is a flowchart illustrating a smart cockpit data security management method provided in an embodiment of this application. It should be noted that the steps shown in the flowchart can be executed in a computer system, such as a computer system containing a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0026] The intelligent cockpit data security management method provided in this application embodiment may include, but is not limited to, the three steps S101 to S103, as follows: S101. When the cockpit application sends a privacy data access request to the vehicle operating system, the privacy data access request is intercepted. S102. Obtain vehicle operation scenario information, and then determine the target operation strategy based on the privacy data access request, vehicle operation scenario information and built-in operation strategy library. S103. When the target operation policy indicates that only local processing results about the original privacy data are allowed, the privacy data requested for access in real time is de-identified to obtain de-identified data, and then the de-identified data is sent to the cockpit application, and the privacy data requested for access is erased.
[0027] The three steps S101 to S103 illustrated in the embodiments of this application can send the privacy data requested to be accessed to the cockpit application after desensitization processing, enabling the data to be still safely used to improve services while protecting user privacy; subsequently, by erasing the privacy data requested to be accessed, effective management of the privacy data life cycle can be achieved, reducing the risk of privacy data leakage.
[0028] In S102 of some embodiments, the privacy data access request includes the name of the cockpit application and the type of privacy data requested to be accessed; regarding the determination of the target operation policy based on the privacy data access request, vehicle operation scenario information, and the built-in operation policy library, the corresponding implementation manners may include but are not limited to the following: Query and match in the built-in operation policy library according to the type of privacy data requested to be accessed, the name of the cockpit application, and the vehicle operation scenario information to obtain a matching result; if the matching result is not empty, use the operation policy indicated by the matching result as the target operation policy, where the operation policy indicated by the matching result refers to an operation policy obtained by matching in the built-in operation policy library; if the matching result is empty, that is, no compliant operation policy is obtained by matching in the built-in operation policy library, generate the operation policy corresponding to the cockpit application through an interface interaction method, and then use the generated operation policy as the target operation policy and store it in the built-in operation policy library for direct application in the next query and match. It should be noted that the built-in operation policy library can be understood as being dynamically configured and generated by the user through the user privacy control panel.
[0029] Among them, the built-in operation policy library contains several different operation policies, and the policy rules set for each operation policy are <application identifier, data category, scenario, operation>. The application identifier refers to the name of the cockpit application, the data category refers to the type of privacy data requested to be accessed, the scenario refers to the vehicle operation scenario information, which includes the driving state scenario and / or interaction state scenario of the vehicle, and the operation refers to the access method for the privacy data requested to be accessed.
[0030] Exemplarily, the policy rules set for the operation policy corresponding to the video conferencing APP are <APP: Video Conferencing, DATA: Image Data, Sound Data, SCENE: The video conferencing APP is running in the foreground and the state is in a call, ACTION: Allow access to raw data>, and the policy rules set for the operation policy corresponding to the navigation APP are <APP: Navigation, DATA: Location Data, SCENE: Any situation, ACTION: Allow access to raw data>, where any situation means not restricting any scenario.
[0031] In some embodiments, the user privacy control panel is primarily used for interface interaction. This control panel can be integrated into the vehicle's infotainment screen and can also be remotely viewed and configured via a mobile app, facilitating management after the user leaves the vehicle. Regarding the generation of the corresponding operation strategy for the cockpit application through interface interaction, the implementation may include, but is not limited to, the following two steps: S201 to S202.
[0032] S201. Control the user privacy control panel to display the configuration interface corresponding to the cockpit application. The configuration interface includes a privacy data type configuration area, a vehicle operation scenario configuration area, and a privacy data access method configuration area. Specifically, when the matching result is empty, the user privacy control panel is first controlled to display the main interface. At this time, the main interface displays a prompt message about the privacy data access request and the advanced configuration control corresponding to the cockpit application. The prompt message is used to prompt the user to set privacy data access permissions for the cockpit application. Then, in response to the user's operation on the advanced configuration control, which can be a direct touch operation or a voice control selection operation, the configuration interface corresponding to the cockpit application is displayed.
[0033] The privacy data type configuration area has multiple different first selection controls, each indicating a type of privacy data, such as: a first selection control indicating image data, a first selection control indicating location data, a first selection control indicating sound data, a first selection control indicating vehicle VIN, etc.
[0034] The vehicle operation scenario configuration area has multiple different second selection controls. Each second selection control indicates a type of vehicle operation scenario. For example, a second selection control indicates that the cockpit application is running in the foreground, a second selection control indicates that the cockpit application is running in the foreground and is in a certain interactive state (such as a video conferencing APP being in a call state), a second selection control indicates that the vehicle is in a certain driving state (such as the vehicle's driving speed being greater than a certain speed threshold), and a second selection control indicates any situation.
[0035] The privacy data access method configuration area has multiple different third-party selection controls. Each third-party selection control indicates a certain access method for privacy data, such as: a third-party selection control that indicates that raw data access is allowed, a third-party selection control that indicates that raw data access is prohibited, and a third-party selection control that indicates that local processing is allowed but raw data output is prohibited.
[0036] In addition, the main interface also features an application permission overview area, which displays the current access permissions of all cockpit applications for various types of privacy data in a list format.
[0037] In addition, the main interface also features a real-time access status indicator area. This area displays whether a particular cockpit application is accessing a certain type of private data, and also displays a close control. When the user closes the control, the cockpit application can directly terminate its access to that private data.
[0038] S202. In response to the user's operations in the privacy data type configuration area, vehicle operation scenario configuration area, and privacy data access method configuration area, generate the corresponding operation policy for the cockpit application.
[0039] In this application, a user privacy control panel is set up to make complex permission settings intuitive and easy to operate. Users can independently and meticulously manage the data behavior of each cockpit application in specific scenarios, thereby enhancing user experience and sense of security.
[0040] In some embodiments, S103, the desensitization processing of privacy data requested for access in real time can be performed by extracting features from the privacy data requested for access in real time, such as image feature extraction, acoustic feature extraction, etc. Alternatively, other privacy enhancement techniques such as image blurring, speech-to-text conversion, and data generalization can be used to process the privacy data requested for access in real time. This can achieve the security effect of keeping the original privacy data out of the vehicle, that is, even if the cockpit application is granted access, it cannot access the original privacy data, thus preventing privacy leakage from the source.
[0041] In some embodiments, after de-identifying the privacy data requested for access in real time to obtain de-identified data in S103, other operations can be performed, specifically including the three steps S301 to S303, as follows: S301. Temporarily cache the processed de-identified data to the local storage area; S302. When the cloud sends a data collection request to the vehicle operating system, intercept the data collection request; S303. Add noise to multiple de-identified data temporarily cached in the local storage area to obtain multiple noisy data, and then send the multiple noisy data to the cloud so that the cloud can perform aggregation calculation on the multiple noisy data.
[0042] Regarding the content on adding noise to multiple de-identified data temporarily cached in the local storage area, the implementation method can be to inject random noise or precisely calculated statistical noise into each de-identified data in the local storage area temporary cache.
[0043] Regarding the sending of multiple noisy data to the cloud, one possible implementation is to send multiple noisy data to the cloud through an anonymous channel, where each noisy data does not contain any information that can directly or indirectly identify an individual.
[0044] It should be noted that, due to the linear additivity of differential privacy, the mean of noise will tend to zero. When the amount of noisy data received by the cloud is large enough, the noise carried in all the noisy data will cancel each other out, enabling the cloud to obtain valuable aggregated data for further application in tasks such as model training and service optimization. At the same time, it ensures that the cloud cannot identify specific personal information, thus achieving the goal of making privacy data usable but invisible.
[0045] In some embodiments, after performing S102 to determine the target operation policy, the method includes: when the target operation policy indicates that access to raw privacy data is permitted, sending the requested privacy data acquired in real time to the cockpit application; or, when the target operation policy indicates that access to raw privacy data is prohibited, prohibiting the response to privacy data access requests, which can be understood as not sending the requested privacy data to the cockpit application even if it is acquired in real time.
[0046] In some embodiments, the aforementioned intelligent cockpit data security management method can be implemented by a security proxy component positioned between the vehicle operating system kernel and upper-layer applications. The user privacy control panel serves as the interface for user interaction with the security proxy component. The security proxy component intercepts and arbitrates all privacy data access requests sent by the cockpit application to the vehicle operating system. This allows for seamless embedding of the data link without significant modifications to existing cockpit applications and the vehicle operating system, achieving intelligent cockpit data security and privacy compliance. Optionally, the aforementioned intelligent cockpit data security management method can be implemented by a functional module of the vehicle operating system kernel, a separate hardware security chip, or a secure virtual machine.
[0047] The following is a specific application example of how a vehicle manufacturer wants to collect driving data to optimize the accuracy of the Driver State Detection (DMS) algorithm while strictly protecting the biometric privacy of the driver. Based on this specific application example, the solution provided in the embodiments of this application will be further explained as follows.
[0048] Step 1: After the vehicle is started, the DMS application needs to continuously access the image data collected by the in-vehicle camera to monitor the driver's status. The DMS application sends a target privacy data access request to the vehicle operating system. This can be understood as the DMS application initiating a request to the vehicle operating system to access the camera. At this time, the target privacy data access request is intercepted.
[0049] Step 2: Since no suitable target operation policy can be matched in the built-in operation policy library, it indicates that the DMS application is making a first request. Control the user privacy control panel to display the main interface and pop up a prompt message "The driver status monitoring application requests access to the camera for fatigue driving warning" on it. The user clicks on the target advanced configuration control corresponding to the DMS application on this main interface to enter the corresponding target configuration interface. This target configuration interface has a target privacy data type configuration area, a target vehicle operation scenario configuration area, and a target privacy data access method configuration area. The user selects the first selection control indicating image data in the target privacy data type configuration area, the second selection control indicating any situation in the target vehicle operation scenario configuration area, and the third selection control indicating only allowing local processing but prohibiting the output of raw data in the target privacy data access method configuration area to generate the operation policy corresponding to the DMS application and store it in the built-in operation policy library. At this time, the policy rule set for the operation policy corresponding to the DMS application is <APP: DMS, DATA: camera video data, SCENE: any situation, ACTION: only allowing local processing but prohibiting the output of raw data>. It should be noted that in the target privacy data access method configuration area, actually only two options are displayed, and clear explanatory notes are given behind each option. Specifically, it is presented in the form of "Option A (allow raw data access): Allow the DMS application to directly process the face image data collected by the camera. Option B (recommended, only allow local processing): Agree that the DMS application conducts fatigue monitoring, but the raw face image data is locally processed by the system security module and immediately discarded after analysis, and only the analysis results (such as attention scores, etc.) are reported to improve the service." for interface prompt, and the font describing Option A is set to gray to prompt the user of the high risk of choosing Option A and not recommend Option A.
[0050] Step 3: When the in-vehicle camera continuously collects the driver's facial video stream during vehicle driving, perform real-time feature extraction and analysis on each frame of the obtained facial video through the embedded lightweight AI model to obtain biometric information such as the driver's facial key points, eyelid closure degree, and line of sight direction, and further determine the driving attention score. Immediately and securely erase the original facial video frame data from the memory after analysis, and send the analyzed non-personally identifiable driving attention score as the target desensitized data to the DMS application, so that the DMS application can decide whether to issue an alarm to the driver based on the received target desensitized data, such as reminding the driver to take a rest, and temporarily cache the target desensitized data in the local storage area.
[0051] Step four: Since the OEM needs to collect anonymized driving performance data to optimize the model, it sends a target data collection request to the vehicle operating system via the cloud. This can be understood as the cloud server initiating a request to the vehicle operating system to obtain the statistical distribution of the driving attention score. At this point, the target data collection request is intercepted, and random noise is injected into all the target anonymized data generated in the past period and temporarily cached in the local storage area to obtain the corresponding target noisy data. Then, all the target noisy data is uploaded to the cloud server through an anonymized communication channel so that the cloud server can directly perform an aggregation calculation by averaging all the received target noisy data. The average driving attention score calculated at this time will be very close to the real situation. For example, if the calculated average driving attention score is 82, the real average driving attention score may fall within the range of [81.5, 82.5]. Subsequently, OEMs can use the calculated average driving attention score for analysis to optimize the warning function of the DMS application. Furthermore, OEMs can collect multiple average driving attention scores of drivers of a certain model on highways at night, and when most of the multiple average driving attention scores are significantly low, they can optimize the DMS warning algorithm in the scenario of driving on highways at night.
[0052] Please refer to Figure 2 , Figure 2 This is a schematic diagram illustrating the composition of a smart cockpit data security management device provided in an embodiment of this application. This device can implement the aforementioned smart cockpit data security management method, and may include, but is not limited to, the following components: The request interception module 401 is used to intercept privacy data access requests when the cockpit application sends privacy data access requests to the vehicle operating system; The strategy determination module 402 is used to obtain vehicle operation scenario information, and then determine the target operation strategy based on the privacy data access request, vehicle operation scenario information and built-in operation strategy library. The data processing module 403 is used to de-identify the privacy data requested for access in real time when the target operation policy indicates that only access to the local processing results of the original privacy data is allowed, to obtain de-identified data, and then send the de-identified data to the cockpit application, and erase the privacy data requested for access.
[0053] It is understood that the content of the above method embodiments is applicable to the present device embodiments. The functions specifically implemented by the present device embodiments are the same as those specifically implemented by the above method embodiments, and the beneficial effects achieved by the present device embodiments are also the same as those achieved by the above method embodiments.
[0054] This application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the aforementioned smart cockpit data security management method. This electronic device can include any smart terminal such as a tablet computer or in-vehicle computer.
[0055] It is understood that the content of the above method embodiments is applicable to the present device embodiments. The specific functions implemented by the present device embodiments are the same as those implemented by the above method embodiments, and the beneficial effects achieved by the present device embodiments are also the same as those achieved by the above method embodiments.
[0056] Please see Figure 3 , Figure 3 This is a schematic diagram illustrating the hardware structure of an electronic device according to another embodiment. The electronic device includes: The processor 501 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application. The memory 502 can be implemented in the form of read-only memory (ROM), static storage device, dynamic storage device or random access memory (RAM). The memory 502 can store the operating system and other applications. When the technical solution provided in the embodiments of this application is implemented by software or firmware, the relevant program code is stored in the memory 502 and is called and executed by the processor 501. The input / output interface 503 is used to implement information input and output; The communication interface 504 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). Bus 505 transmits information between various components of the device (e.g., processor 501, memory 502, input / output interface 503, and communication interface 504); The processor 501, memory 502, input / output interface 503 and communication interface 504 are connected to each other within the device via bus 505.
[0057] This application also provides a vehicle that includes the aforementioned intelligent cockpit data security management device or the aforementioned electronic device. Specifically, the vehicle can be a private car, such as a sedan or SUV; the vehicle can also be a new energy vehicle, such as a hybrid vehicle or a pure electric vehicle.
[0058] It is understood that the content of the above method embodiments is applicable to this vehicle embodiment, the specific functions implemented by this vehicle embodiment are the same as those implemented by the above method embodiments, and the beneficial effects achieved by this vehicle embodiment are the same as those achieved by the above method embodiments.
[0059] This application also provides a computer program product, which includes a computer program that, when executed by one or more processors, implements the above-described intelligent cockpit data security management method.
[0060] It is understood that the content of the above method embodiments is applicable to this computer program product. The specific functions implemented by the embodiments of this computer program product are the same as those implemented by the above method embodiments, and the beneficial effects achieved by the embodiments of this computer program product are also the same as those achieved by the above method embodiments.
[0061] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.
[0062] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.
[0063] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0064] Those skilled in the art will understand that all or some of the steps, apparatuses, or functional modules / units in the methods disclosed above can be implemented as software, firmware, hardware, or suitable combinations thereof.
[0065] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, apparatus, product, or device that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.
[0066] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0067] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed between the devices or units may be through some interfaces, and the indirect coupling or communication connection may be electrical, mechanical, or other forms.
[0068] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0069] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0070] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0071] The preferred embodiments of this application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of this application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of this application shall be within the scope of the claims of this application.
Claims
1. A method for data security management in an intelligent cockpit, characterized in that, The method includes: When the cockpit application sends a privacy data access request to the vehicle operating system, the privacy data access request is intercepted; Obtain vehicle operation scenario information, and then determine the target operation strategy based on the privacy data access request, the vehicle operation scenario information, and the built-in operation strategy library; When the target operation policy indicates that only local processing results regarding the original privacy data are allowed, the privacy data requested for access in real time is de-identified to obtain de-identified data, which is then sent to the cockpit application, and the requested privacy data is erased.
2. The intelligent cockpit data security management method according to claim 1, characterized in that, The privacy data access request includes the name of the cockpit application and the type of privacy data requested for access; determining the target operation strategy based on the privacy data access request, the vehicle operation scenario information, and the built-in operation strategy library includes: Based on the privacy data type, the name of the cockpit application, and the vehicle operation scenario information, a query and match are performed in the operation strategy library to obtain the matching result; If the matching result is not empty, then the operation strategy indicated by the matching result shall be used as the target operation strategy; If the matching result is empty, the operation strategy corresponding to the cockpit application is generated through the interface interaction, and then the generated operation strategy is used as the target operation strategy and stored in the operation strategy library.
3. The intelligent cockpit data security management method according to claim 2, characterized in that, The operation strategy for generating the cockpit application through interface interaction includes: The user privacy control panel displays the configuration interface corresponding to the cockpit application, which includes a privacy data type configuration area, a vehicle operation scenario configuration area, and a privacy data access method configuration area. In response to user operations in the privacy data type configuration area, the vehicle operation scenario configuration area, and the privacy data access method configuration area, an operation policy corresponding to the cockpit application is generated.
4. The intelligent cockpit data security management method according to claim 1, characterized in that, After anonymizing the privacy data obtained from real-time access requests, the process also includes: The de-identified data is temporarily cached in the local storage area; When the cloud sends a data collection request to the vehicle operating system, the data collection request is intercepted; Multiple de-identified data temporarily cached in the local storage area are subjected to noise addition processing to obtain multiple noisy data. The multiple noisy data are then sent to the cloud so that the cloud can perform aggregation calculations on the multiple noisy data.
5. The intelligent cockpit data security management method according to claim 4, characterized in that, Sending the plurality of noisy data to the cloud includes sending the plurality of noisy data to the cloud through an anonymous channel.
6. The intelligent cockpit data security management method according to claim 1, characterized in that, The method further includes: When the target operation policy indicates that access to raw privacy data is permitted, the requested privacy data is sent to the cockpit application.
7. The intelligent cockpit data security management method according to claim 1, characterized in that, The method further includes: When the target operation policy indicates that access to raw privacy data is prohibited, the privacy data access request shall not be responded to.
8. A smart cockpit data security management device, characterized in that, The device includes: The request interception module is used to intercept the privacy data access request when the cockpit application sends a privacy data access request to the vehicle operating system; The strategy determination module is used to acquire vehicle operation scenario information, and then determine the target operation strategy based on the privacy data access request, the vehicle operation scenario information and the built-in operation strategy library. The data processing module is used to perform desensitization processing on the privacy data requested for access in real time when the target operation policy indicates that only access to the local processing results of the original privacy data is allowed, to obtain desensitized data, and then send the desensitized data to the cockpit application, and erase the privacy data requested for access.
9. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the intelligent cockpit data security management method as described in any one of claims 1 to 7.
10. A vehicle, characterized in that, The vehicle includes the intelligent cockpit data security management device as described in claim 8 or the electronic device as described in claim 9.