Privacy protection method for shared screen and related equipment

By constructing a secure view cone and controlling optical components on the vehicle-sharing screen, the privacy issue of vehicle-sharing screens when used by multiple people is solved, achieving dynamic adaptability and improved information security.

CN121734099APending Publication Date: 2026-03-27VOYAH AUTOMOBILE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-16
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Vehicle-sharing screens lack dynamic privacy protection when used by multiple people, leading to a high risk of information leakage. Existing technologies cannot intelligently adapt to changes in user location.

Method used

By detecting open requests for target type files, collecting the trigger location and the user's eye spatial coordinates, constructing a secure visual cone, and using adjustable optical components to control light propagation, sensitive content is made visible only to the target user.

Benefits of technology

It achieves dynamic privacy protection when the user's location changes, reduces the possibility of non-target users snooping on sensitive information, and improves information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121734099A_ABST
    Figure CN121734099A_ABST
Patent Text Reader

Abstract

The invention discloses a privacy protection method for a shared screen and related equipment, relates to the technical field of automobile intelligent cabins, and mainly aims to solve the problems that the privacy is poor and the dynamic adaptability is lacked when the current vehicle shared screen is operated for a single user. The method comprises the steps that under the condition that an opening request of a target type file is detected, the triggering position of the opening request and eye space coordinates of a target user at the triggering position are collected, and the triggering position is a main driver or a co-driver; based on the eye space coordinates, determining a safe view cone of the target user, the safe view cone being a three-dimensional conical area which takes an area displaying the target type file on the shared screen as a vertex and points to the eye space coordinates of the target user; a target control instruction is generated based on the safe view cone of the target user, so that the target type file is only visually displayed for the target user, and the target control instruction is used for controlling an adjustable optical assembly of the shared screen.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of automotive smart cockpit technology, and in particular to a privacy protection method and related equipment for shared screens. Background Technology

[0002] With the rapid development of in-vehicle infotainment systems, integrated large screens, due to their excellent technological feel and space utilization, are increasingly becoming the mainstream configuration in smart cockpits, allowing the driver and front passenger to share a continuous physical screen. However, while this shared display mode enhances the interactive experience, it also brings significant risks of information privacy leaks. When the front passenger operates the screen to view business documents, private messages, or conduct video conferences, the sensitive content displayed can easily be unintentionally viewed by the driver in the driver's seat, posing a security hazard.

[0003] Currently, common solutions such as physical sunshades or advising users to avoid displaying sensitive information not only offer a poor user experience but also have limited practicality. Therefore, existing technologies generally suffer from insufficient privacy protection and a severe lack of flexibility and dynamic adaptability when dealing with user-specific operations on shared vehicle screens. There is an urgent need for a dynamic privacy protection technology that can intelligently adapt to changes in the user's real-time location. Summary of the Invention

[0004] In view of the above problems, the present invention provides a privacy protection method and related equipment for shared screens, the main purpose of which is to solve the problems of poor privacy and lack of dynamic adaptability when the shared screens in vehicles are operated by a single user.

[0005] To address at least one of the aforementioned technical problems, in a first aspect, the present invention provides a privacy protection method for shared screens, the method comprising: When an open request for a target type file is detected, the trigger location of the open request and the eye spatial coordinates of the target user at the trigger location are collected, wherein the trigger location is the driver's seat or the passenger's seat. The safe viewing cone of the target user is determined based on the eye spatial coordinates, wherein the safe viewing cone is a three-dimensional cone-shaped region with the area displaying the target type file on the shared screen as its vertex and pointing to the eye spatial coordinates of the target user; Based on the target user's security frustum, a target control instruction is generated to make the target type file only visually displayed to the target user, wherein the target control instruction is used to control the adjustable optical components of the shared screen.

[0006] Optionally, when an open request for a target type file is detected, collecting the trigger location of the open request and the eye spatial coordinates of the target user at the trigger location includes: Upon detecting an open request for a target type file, obtain the logical display area of ​​the open request on the shared screen; The trigger position is determined based on the logical display area; The view sensor is invoked to obtain the spatial coordinates of the target user's eye at the trigger location.

[0007] Optionally, determining the target user's safety visual cone based on the eye spatial coordinates includes: In the area where the target type file is displayed on the shared screen, a specific pixel is determined as the vertex of the safe view frustum; The vector pointing from the vertex to the target user's eye spatial coordinates is used as the axis of the safety cone; The angle of the safety cone is determined, wherein the width of the angle is greater than a first preset dynamic value and less than a second preset dynamic value, the first preset dynamic value is the sum of the interpupillary distance of the target user and the head sway threshold, and the second preset dynamic value is the upper limit of the viewing angle to prevent non-target users from viewing the target type file.

[0008] Optionally, the adjustable optical component includes a microlens array, and the method includes: The range of the target microlens array is determined based on the vertex and the preset pixel microlens mapping relationship, wherein the preset pixel microlens mapping relationship is the mapping relationship between screen pixels and the microlens array; The target direction vector for light deflection of the target microlens array is determined based on the centerline. The optical phase profile of the target microlens array is determined based on the target direction vector, wherein the optical phase profile is used to control the light rays emitted from the microlens to be converged and constrained within the conical range of the safety cone.

[0009] Optionally, the step of generating target control instructions based on the target user's security view frustum to cause the target type file to be visually displayed only to the target user includes: Based on the range of the target microlens array, the target direction vector of light deflection, and the optical phase profile, a target control command is generated, wherein the target control command is a driving voltage matrix, and each element of the driving voltage matrix is ​​a specific voltage value that needs to be applied to the corresponding microlens.

[0010] Optionally, the above methods also include: Upon detecting an open request for a target type file, the area of ​​the target type file is encrypted, wherein the encryption process is used to visually encrypt the area of ​​the target type file displayed on the shared screen; Upon receiving the authentication signal from the target user, the region of the target type file is decrypted.

[0011] Optionally, the above methods also include: Obtain the occupant information of the driver and the front passenger; If the occupant information indicates that there is a vacancy in the driver's seat or the front passenger seat, the target type file will be directly displayed on the shared screen.

[0012] Secondly, embodiments of the present invention also provide a privacy protection device for shared screens, comprising: The acquisition unit is used to acquire the triggering location of the opening request and the eye spatial coordinates of the target user at the triggering location when an opening request for a target type file is detected, wherein the triggering location is the driver's seat or the passenger's seat. The determining unit is used to determine the safe viewing cone of the target user based on the eye spatial coordinates, wherein the safe viewing cone is a three-dimensional cone-shaped region with the area displaying the target type file on the shared screen as its vertex and pointing to the eye spatial coordinates of the target user; The display unit is configured to generate target control instructions based on the target user's safety frustum, so that the target type file is visually displayed only to the target user, wherein the target control instructions are used to control the adjustable optical components of the shared screen.

[0013] To achieve the above objectives, according to a third aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium comprising a stored program, wherein, when the program is executed by a processor, the steps of the above-described privacy protection method for screen sharing are implemented.

[0014] To achieve the above objectives, according to a fourth aspect of the present invention, an electronic device is provided, including at least one processor and at least one memory connected to the processor; wherein the processor is configured to invoke program instructions in the memory to execute the steps of the above-described screen sharing privacy protection method.

[0015] By employing the above technical solutions, the privacy protection method and related devices for shared screens provided by this invention address the problems of poor privacy and lack of dynamic adaptability when operating shared screens in vehicles for a single user. This invention, upon detecting an open request for a target type file, acquires the trigger position of the open request and the eye spatial coordinates of the target user at that trigger position, where the trigger position is either the driver's or passenger's seat. Based on the eye spatial coordinates, a safe viewing cone for the target user is determined, where the safe viewing cone is a three-dimensional cone-shaped area with the area displaying the target type file on the shared screen as its vertex, pointing towards the target user's eye spatial coordinates. Based on the target user's safe viewing cone, a target control command is generated to ensure that the target type file is only visually displayed to the target user, wherein the target control command is used to control the adjustable optical components of the shared screen. In this solution, a precise and calculable spatial vector relationship is established between the user's eye position and the screen display area, and this relationship is used to actively control the propagation path of light. When an open request for a target file type is detected, the current operator, i.e., the target user, is first identified by the trigger location, and the spatial coordinates of the user's eyes are collected, transforming the abstract concept of "user" into a concrete, quantifiable three-dimensional spatial location point. Then, using the area displaying sensitive content on the screen as a reference, a three-dimensional cone-shaped region, i.e., the safety cone of vision, is constructed with that area as its vertex and pointing towards the user's eye coordinates. This cone of vision defines a unique visual channel in space, bound to the current user's position. Finally, specific control commands are generated to drive adjustable optical components, confining light emitted from the sensitive area of ​​the screen within the cone-shaped space of the safety cone of vision. Only when the observer's eyes are within this cone-shaped space can they receive sufficient light intensity to form a clear image; for observers outside this cone-shaped space, such as someone in the driver's seat peeking at the passenger's screen, the perceived brightness of the screen content will be significantly reduced because the light cannot effectively reach their eyes, making the visual information blurry or unrecognizable. This optically reduces the risk of information leakage due to direct peeping by non-target users. By tracking the user's position in real time and dynamically adjusting optical parameters, the viewing range can be controlled to adapt to the natural movement of the user's head.

[0016] Accordingly, the privacy protection device, equipment, and computer-readable storage medium for shared screens provided in the embodiments of the present invention also have the above-mentioned technical effects.

[0017] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and in order to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description

[0018] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings: Figure 1 A flowchart illustrating a privacy protection method for screen sharing provided by an embodiment of the present invention is shown; Figure 2 This diagram illustrates the composition of a privacy protection device for sharing a screen according to an embodiment of the present invention. Figure 3 This diagram illustrates the composition of a privacy-protecting electronic device for sharing a screen, as provided in an embodiment of the present invention. Detailed Implementation

[0019] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this invention will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.

[0020] To address the issues of poor privacy and lack of dynamic adaptability when using shared screens in vehicles for individual user operations, this invention provides a privacy protection method for shared screens, such as... Figure 1 As shown, the method includes: S101. When an open request for a target type file is detected, the trigger location of the open request and the eye spatial coordinates of the target user at the trigger location are collected, wherein the trigger location is the driver's seat or the passenger's seat. In one embodiment, upon detecting an open request for a target type file, acquiring the trigger location of the open request and the eye spatial coordinates of the target user at the trigger location includes: Upon detecting an open request for a target type file, obtain the logical display area of ​​the open request on the shared screen; The trigger position is determined based on the logical display area; The view sensor is invoked to obtain the spatial coordinates of the target user's eye at the trigger location.

[0021] For example, the aforementioned target type file refers to special files or application content that are marked as requiring privacy protection measures, such as sensitive information like business documents, private messages, or video conferencing interfaces. The aforementioned trigger location refers to the driver's or passenger's seat position corresponding to the operation of issuing the open request. The target user's eye spatial coordinates refer to the specific coordinate positions of the user's eyes in the three-dimensional space of the vehicle corresponding to the trigger location. These coordinates typically include the three-dimensional coordinate values ​​of the left and right eyes, used to accurately characterize the specific orientation of the eyes in the vehicle space. The logical display area refers to the specific screen area allocated to the driver's or passenger's operation according to preset screen division rules.

[0022] Upon detecting an open request for a target type file, this application first obtains the logical display area corresponding to the open request on the shared screen. This logical display area is associated with a preset screen area for the driver or passenger. Then, based on this logical display area, it determines whether the current operation originates from the driver or passenger, thus identifying the trigger location. Once the trigger location is determined, it invokes perspective sensors located within the vehicle, such as depth cameras, to perform real-time monitoring of the target user at that trigger location, obtaining the precise three-dimensional coordinates of their eyes in space.

[0023] For example, when the front passenger touches a file icon marked "Confidential" on the screen in front of them, the system detects the open request. First, it determines that the touch point is within a pre-allocated logical display area for the front passenger, thus identifying the front passenger as the trigger. Next, it invokes a dedicated perspective sensor monitoring the front passenger's area. This sensor captures an image of the front passenger's face, and through image processing and spatial calculations, outputs the three-dimensional spatial coordinates of the passenger's eyes at the current moment. This series of actions prepares the data for subsequently constructing a dedicated safety cone of vision specifically for that front passenger.

[0024] The above technical solution dynamically and precisely links an abstract file-opening operation to a specific physical space, the user, and their visual focus position. The trigger location is indirectly determined through the logical display area, providing a basis for subsequently differentiating the operation subject and implementing differentiated control. Directly acquiring eye spatial coordinates from the perspective sensor lays the data foundation for building a user-centric, personalized, and secure visual cone. This ensures that the entire privacy protection process begins on the user's actual spatial state, creating conditions for adaptive display control.

[0025] S102. Determine the safe viewing cone of the target user based on the eye spatial coordinates, wherein the safe viewing cone is a three-dimensional cone-shaped region with the area displaying the target type file on the shared screen as its vertex and pointing to the eye spatial coordinates of the target user; In one embodiment, determining the target user's safe visual cone based on the eye spatial coordinates includes: In the area where the target type file is displayed on the shared screen, a specific pixel is determined as the vertex of the safe view frustum; The vector pointing from the vertex to the target user's eye spatial coordinates is used as the axis of the safety cone; The angle of the safety cone is determined, wherein the width of the angle is greater than a first preset dynamic value and less than a second preset dynamic value, the first preset dynamic value is the sum of the interpupillary distance of the target user and the head sway threshold, and the second preset dynamic value is the upper limit of the viewing angle to prevent non-target users from viewing the target type file.

[0026] For example, the aforementioned safe viewing cone is a three-dimensional cone-shaped region whose vertex is located in the area on the shared screen where the target type file is displayed. The axis is a vector pointing from the vertex to the spatial coordinates of the target user's eyes, and the angle is the opening angle of the cone-shaped region. The first preset dynamic value is the lower limit of the angle set to ensure normal viewing for the target user, and the second preset dynamic value is the upper limit of the angle set to prevent viewing by non-target users.

[0027] Based on the obtained spatial coordinates of the target user's eyes, this application first determines a specific pixel point as the vertex of the safe viewing cone in the area where the target type file is displayed on the shared screen. Then, the vector pointing from this vertex to the center point of the target user's eyes is used as the axis of the safe viewing cone. Next, the angular width of the safe viewing cone is determined. The lower limit of this angular width is set as the sum of the target user's interocular distance and head movement threshold, while the upper limit is set as the upper limit of the viewing angle that effectively prevents non-target users from seeing the content. In this way, a cone-shaped area is dynamically determined that ensures comfortable viewing for the target user while preventing information leakage.

[0028] It is important to note that in determining the angle of the safety cone, the second preset dynamic value is dynamically calculated based on the continuously acquired eye spatial coordinates of the non-target user. The second preset dynamic value is determined by calculating the line connecting the vertex of the safety cone to the eye spatial coordinates of the non-target user and evaluating the angle between this line and the axis. By updating this angle in real time, the upper limit of the angle of the safety cone is always constrained within a light dispersion range that effectively prevents the non-target user from receiving a clear image, thereby achieving dynamic optimization of privacy protection. The "second preset dynamic value" is defined as the "upper limit of the viewing angle preventing the non-target user from viewing the target type file." This "upper limit" is not a fixed value. For example, when the non-target user in the driver's seat is turned to the side of the passenger seat, the risk of being spied on increases, and the upper limit of the angle of the safety cone, i.e., the second preset dynamic value, needs to be narrowed. When the driver is looking at the road ahead, the risk of being spied on decreases, and the upper limit of the angle can be appropriately widened to improve the viewing experience of the target user.

[0029] For example, a passenger in the front seat opens confidential business documents: 1. Determine the vertex: On the shared screen, locate the rectangular area where the confidential PDF file will be displayed. Within this rectangular area, determine a specific pixel as the vertex. To simplify calculations and ensure coverage, this vertex can typically be chosen as the geometric center of the display area. Assuming the screen plane is Z=0, define it as P_pixel(Xp,Yp,0).

[0030] 2. Determine the axis of rotation: Calculate the three-dimensional coordinates of the center point P_eye_center of the front passenger's eyes. These coordinates can be obtained by averaging the coordinates of the left and right eyes. X_center=(Xl+Xr) / 2 Y_center=(Yl+Yr) / 2 Z_center=(Zl+Zr) / 2 Therefore, the axis of the safe view cone is a three-dimensional vector that points from the vertex P_pixel on the screen to the center point P_eye_center of both eyes.

[0031] 3. Determine the dynamic subtraction angle (θ): This is the key to achieving dynamic adaptability. This application will calculate a subtraction angle θ and ensure that: the first preset dynamic value < θ < the second preset dynamic value.

[0032] 3.1 Calculate the first preset dynamic value (lower limit): Calculate interocular distance (IPD): First, calculate the actual interocular distance of the front passenger based on the obtained left and right eye coordinates: IPD = distance_between(Pl, Pr).

[0033] In addition, a head sway threshold is added: a preset tolerance angle or distance is established to allow for natural head sway (e.g., ±5 cm offset). The first preset dynamic value is IPD + head sway threshold. This value ensures that the opening of the visual cone is large enough to allow users to see complete and clear content in a normal sitting posture and within a range of slight swaying.

[0034] 3.2 Setting the second preset dynamic value (upper limit): This value is set based on the requirement to prevent the driver in the driver's seat from seeing the screen content. It is an empirical or calculated value that ensures that the maximum diffusion angle of light emitted from the top of the screen does not reach the typical eye position range of the driver's passenger.

[0035] 3.3 Final determination of θ: A value of θ will be set that is greater than the first preset dynamic value (to ensure the passenger's visibility) and less than the second preset dynamic value (to prevent the driver's view).

[0036] At this point, a dynamic safety cone "tailor-made" for the current front passenger is complete. Its apex is at the center of the document display area on the screen, its axis points towards the center of the passenger's eyes, and its subtended angle θ ensures both viewing comfort and privacy.

[0037] By employing the aforementioned technical solution, a precise geometric constraint framework is provided for subsequent light control by establishing a three-dimensional cone-shaped spatial model with the screen display area as the vertex and pointing towards the user's eyes. Setting the lower limit of the viewing angle to cover the interpupillary distance and head movement range can adapt to changes in the target user's head position in a natural state, avoiding viewing interruptions due to minor movements. Simultaneously, controlling the upper limit of the viewing angle within the privacy protection range ensures that light emitted from the screen is confined to a specific spatial channel, thereby reducing the possibility of non-target users accessing the screen content through direct eye contact. This method of dynamically determining the safe viewing cone lays the spatial geometric foundation for achieving personalized and adaptive privacy protection.

[0038] S103. Generate target control instructions based on the target user's safety frustum, so that the target type file is only visually displayed to the target user, wherein the target control instructions are used to control the adjustable optical components of the shared screen.

[0039] In one embodiment, the adjustable optical component includes a microlens array, and the method includes: The range of the target microlens array is determined based on the vertex and the preset pixel microlens mapping relationship, wherein the preset pixel microlens mapping relationship is the mapping relationship between screen pixels and the microlens array; The target direction vector for light deflection of the target microlens array is determined based on the centerline. The optical phase profile of the target microlens array is determined based on the target direction vector, wherein the optical phase profile is used to control the light rays emitted from the microlens to be converged and constrained within the conical range of the safety cone.

[0040] For example, the target control command is a control signal used to drive the adjustable optical components, the range of the target microlens array refers to the set of microlenses that need to participate in light modulation, the target direction vector is the spatial direction in which the light needs to be deflected, and the optical phase profile is a physical quantity that describes how the microlens unit changes the wavefront of the light to control its propagation characteristics.

[0041] Considering that the apex of the security cone corresponds to an area on the screen displaying sensitive content, the first step is to determine which pixels on the screen require optical control. Using a pre-calibrated pixel microlens mapping—a table recording which microlens unit corresponds to each screen pixel—all microlens units covering the display area can be precisely identified. The set of these identified microlens units constitutes the range of the target microlens array. This step solves the problem of where to control, mapping the privacy-protected screen area to specific, individually addressable physical lens units. The axis of the security cone defines an ideal principal direction of light emission. This direction information needs to be translated into instructions that the microlens array can understand. Through mathematical calculations, this axis is transformed into a target direction vector in three-dimensional space. This vector precisely indicates where each microlens unit needs to deflect the light rays from the pixels below it. This step solves the problem of which direction to control, setting a clear control target for each microlens unit. For electrically controlled microlens arrays, such as those based on liquid crystal arrays, this is achieved by designing a specific "optical phase profile" for each lens unit. In simple terms, light rays are deflected when passing through a lens with different thicknesses or refractive index distributions. An optical phase profile is like a detailed "blueprint" that specifies how much phase delay each point on the lens needs to create for the light rays to converge along the "target direction vector." For electrically controlled microlenses, this "blueprint" is translated into a set of specific voltage values ​​applied to each lens element. These voltages alter the alignment of the liquid crystal molecules, effectively forming the desired phase profile. This step solves the "how to control" problem, converting the direction vector into a physically executable driving signal.

[0042] This application generates target control commands based on a defined safety cone. First, based on the vertex position of the safety cone and the pre-calibrated mapping relationship between screen pixels and the microlens array, it determines which microlens units need to be controlled, thus defining the range of the target microlens array. Next, based on the axis of the safety cone, the target direction vector that the light rays need to be deflected is calculated, pointing towards the target user's eye region. Subsequently, based on this target direction vector, a specific optical phase profile is calculated for each microlens unit in the target microlens array. This optical phase profile determines the phase delay distribution generated when light passes through the microlens, enabling the outgoing light rays to undergo the required deflection and convergence. Finally, these optical parameters are converted into specific electrical control commands that drive the microlens array, such as a drive voltage matrix containing the required voltage values ​​for each microlens unit.

[0043] By employing the aforementioned technical solution, the abstract geometric model of the security view frustum is transformed into executable optical control commands, enabling adjustable optical components to precisely guide the light emitted from the screen. By controlling the optical phase profile of the microlens array, light emitted from specific areas of the screen can be redirected and primarily converged within the three-dimensional spatial channel defined by the security view frustum. This ensures that the target user receives clear light from their normal viewing position, while non-target users, located outside this light-converging channel, receive significantly reduced effective light intensity, thereby decreasing the likelihood of sensitive information being directly viewed. This process achieves dynamic and active control over the propagation path of the displayed light.

[0044] In one embodiment, generating target control instructions based on the target user's security view frustum to cause the target type file to be visually displayed only to the target user includes: Based on the range of the target microlens array, the target direction vector of light deflection, and the optical phase profile, a target control command is generated, wherein the target control command is a driving voltage matrix, and each element of the driving voltage matrix is ​​a specific voltage value that needs to be applied to the corresponding microlens.

[0045] For example, the driving voltage matrix described above is a two-dimensional control signal, where each element represents a specific voltage value that needs to be applied to the corresponding individual microlens unit in the microlens array.

[0046] This application, based on the calculated range of the target microlens array, the target direction vector of light deflection, and the optical phase profile, converts the physical quantity of the optical phase profile into an electrical driving signal. Specifically, according to the optical phase profile designed for each microlens unit, a specific voltage value required to achieve the phase modulation effect is calculated. These voltage values ​​are arranged according to the row and column positions of the microlenses in the array, ultimately forming a complete driving voltage matrix. This driving voltage matrix is ​​the final generated target control command.

[0047] Taking the construction of a safe visual cone pointing towards its eyes as an example: 1. Based on the file window's position on the screen (the area where the vertex is located), immediately locate all microlenses responsible for displaying this file window using a mapping table (e.g., 100x100 microlens units in the center of the screen). These lenses are marked as the "target range".

[0048] 2. Calculate the "target direction vector" pointing from the center of the file window to the center of the front passenger's eyes (for example, a vector pointing to the lower right at a 30-degree angle to the screen normal).

[0049] 3. Based on this target direction vector, calculate the "optical phase profile" required to achieve the deflection effect for each of the 100x100 target microlens units, and convert it into the corresponding voltage signal by generating target control commands.

[0050] 4. The driving circuit applies this special voltage value to the corresponding microlens unit. These lens units immediately adjust, precisely deflecting the light emitted from the lower pixels and focusing it onto the front passenger's eyes. At this point, from the driver's perspective, the file window area will appear dark or distorted, thus achieving visual isolation.

[0051] The aforementioned technical solution transforms the calculated optical control parameters into electrical instructions that can directly drive hardware execution. By applying precisely calculated voltages to each unit in the microlens array, changes in physical properties such as the orientation of liquid crystal molecules can be controlled, thereby actually constructing the desired optical phase profile. This enables the theoretical control of the light propagation direction to be realized at the physical level, ensuring that the light emitted from the screen can be deflected and converged according to the model of a safe viewing cone, thus supporting the achievement of the goal of effectively propagating visual information only towards the target user.

[0052] In one embodiment, the above method further includes: Upon detecting an open request for a target type file, the area of ​​the target type file is encrypted, wherein the encryption process is used to visually encrypt the area of ​​the target type file displayed on the shared screen; Upon receiving the authentication signal from the target user, the region of the target type file is decrypted.

[0053] For example, the above encryption process refers to converting the content of the target type file displayed on the shared screen into a form that is not visually directly recognizable, the decryption process is to restore the encrypted content to its original clear display state, and the authentication signal is the receipt and confirmation of an authorization instruction representing the legitimacy of the target user's identity.

[0054] Upon detecting an open request for a target type file, this application simultaneously initiates encryption processing on the corresponding display area of ​​the file on the screen. This processing is completed at the graphics rendering level, replacing the normally displayed clear content in real time with visual elements that cannot be directly recognized, such as static noise or dynamic snowflake patterns, for rendering and output. When a correct authentication signal from the target user is subsequently received, such as successful verification via a biometric scanner on the passenger side, a decryption processing command is triggered, stopping the rendering of the obfuscated image and outputting the original clear file content to the screen for normal display.

[0055] By employing the aforementioned technical solution, an additional layer of data-level protection is added beyond optical control methods. Even in extreme cases where optical control fails to completely block light, allowing non-target users to see the corresponding area of ​​the screen, what they observe is only encrypted and invalid visual information, unable to access the actual document content. The target user, after authentication, can obtain a clear display. This process, working in conjunction with optical control, reduces the likelihood of sensitive information being leaked in a shared screen environment through direct viewing or indirect reflection, thus enhancing the reliability of privacy protection.

[0056] In one embodiment, the above method further includes: Obtain the occupant information of the driver and the front passenger; If the occupant information indicates that there is a vacancy in the driver's seat or the front passenger seat, the target type file will be directly displayed on the shared screen.

[0057] For example, occupant information refers to status data used to determine whether there is an occupant in the driver's seat or the front passenger seat. An occupant vacancy indicates that, after detection, it is confirmed that there is no occupant seated in the corresponding position.

[0058] Before or during the privacy protection process, this application acquires occupant information for the driver and front passenger via in-vehicle sensors. If analysis of the occupant information confirms a vacancy in either the driver's or front passenger's seat (e.g., the driver has exited the vehicle and only the front passenger remains), it will be determined that there is no need to activate optical viewing angle restriction measures for that vacant position. In this case, for requests to open files of the target type, the shared screen will directly display the file content in normal mode without triggering the safety cone calculation and the driving process of the adjustable optical components.

[0059] The aforementioned technical solution intelligently adjusts its operating mode based on the actual occupant distribution. When an empty occupant is detected, unnecessary privacy protection procedures are automatically waived, and normal display proceeds directly. This avoids the additional load and energy consumption associated with complex light control in single-user scenarios, while also ensuring an unrestricted and optimal viewing experience for users in an environment free from potential spying risks. This mechanism enhances the practicality and intelligence of the solution, making its operation more aligned with the needs of real-world usage scenarios.

[0060] By employing the aforementioned technical solution, privacy protection is transformed from a preset, fixed physical constraint into a flexible optical constraint that moves with the user. When an open request for a target type of file is detected, the current operator, i.e., the target user, is first identified by the trigger location, and sensors are immediately invoked to acquire the precise three-dimensional coordinates of the user's eyes within the carriage space. This establishes a dynamic association with the specific user, providing input for subsequent personalized control. Subsequently, a three-dimensional spatial model called a safety cone is constructed for the user, using the area on the screen where sensitive content will be displayed as a reference. The axis of this cone points from the screen display area to the user's eyes, and its angle is specifically designed to accommodate the distance between the user's eyes and minor head movements to ensure basic visibility, while also limiting the angle of light diffusion. Finally, this geometrically defined safety cone model is converted into specific control commands that drive adjustable optical components in front of the screen. By applying these commands, the adjustable optical components can dynamically adjust the optical characteristics of each micro-unit, thereby precisely guiding the light emitted from the screen pixels, confining its main propagation path within the cone-shaped space defined by the safety cone. This means that only observers located within or near this cone-shaped area can receive sufficient light intensity to see the screen content. However, from other directions, such as when the driver is peering at the passenger's screen, the effective information that can be observed is greatly reduced due to the significantly reduced light intensity or the deflected direction. This reduces the possibility of information leakage caused by direct peeping by non-target users at the physical optics level and can accommodate reasonable head movements of the target user.

[0061] Furthermore, as a response to the above Figure 1In addition to the implementation of the method shown, this embodiment of the invention also provides a privacy protection device for shared screens, used to protect the privacy of the aforementioned screens. Figure 1 The method shown is implemented accordingly. This device embodiment corresponds to the foregoing method embodiment. For ease of reading, this device embodiment will not repeat the details of the foregoing method embodiment, but it should be clear that the device in this embodiment can implement all the contents of the foregoing method embodiment. Figure 2 As shown, the device includes: a data acquisition unit 21, a determination unit 22, and a display unit 23, wherein... The acquisition unit 21 is used to acquire the triggering location of the opening request and the eye spatial coordinates of the target user at the triggering location when an opening request for a target type file is detected, wherein the triggering location is the driver's seat or the passenger's seat. The determining unit 22 is used to determine the safe viewing cone of the target user based on the eye spatial coordinates, wherein the safe viewing cone is a three-dimensional cone-shaped region with the area displaying the target type file on the shared screen as the vertex and pointing to the eye spatial coordinates of the target user; Display unit 23 is used to generate target control instructions based on the target user's safety frustum, so that the target type file is only visually displayed to the target user, wherein the target control instructions are used to control the adjustable optical components of the shared screen.

[0062] The processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured, and adjusting kernel parameters can implement a privacy protection method for shared screens. This addresses the current issues of poor privacy and lack of dynamic adaptability when shared screens in vehicles are used for individual user operations.

[0063] This invention provides a computer-readable storage medium including a stored program that, when executed by a processor, implements the privacy protection method for screen sharing.

[0064] This invention provides a processor for running a program, wherein the program executes the privacy protection method for shared screens during runtime.

[0065] This invention provides an electronic device, which includes at least one processor and at least one memory connected to the processor; wherein the processor is configured to invoke program instructions in the memory to execute the privacy protection method for screen sharing as described above. This invention provides an electronic device 30, such as... Figure 3As shown, the electronic device includes at least one processor 301, and at least one memory 302 and bus 303 connected to the processor; wherein, the processor 301 and the memory 302 communicate with each other through the bus 303; the processor 301 is used to call program instructions in the memory to execute the above-mentioned privacy protection method for sharing the screen.

[0066] The smart electronic devices mentioned in this article can be PCs, tablets, mobile phones, etc.

[0067] This application also provides a computer program product that, when executed on a process management electronic device, is adapted to perform a program that initializes the privacy protection method steps described above for sharing a screen.

[0068] It should be noted that the descriptions of each embodiment in the above embodiments have different focuses. For parts that are not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0069] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0070] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0071] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0072] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0073] This application also provides a computer program product, which includes computer software instructions that, when executed on a processing device, cause the processing device to perform actions such as... Figure 1 The control flow of the memory in the corresponding embodiment.

[0074] A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).

[0075] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0076] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, or indirect coupling or communication connection between apparatuses or units, and may be electrical, mechanical, or other forms.

[0077] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0078] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0079] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0080] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A method for protecting the privacy of a shared screen, wherein the shared screen is used by the driver and the passenger, characterized in that, include: When an open request for a target type file is detected, the trigger location of the open request and the eye spatial coordinates of the target user at the trigger location are collected, wherein the trigger location is the driver's seat or the passenger's seat. The safe viewing cone of the target user is determined based on the eye spatial coordinates, wherein the safe viewing cone is a three-dimensional cone-shaped region with the area displaying the target type file on the shared screen as its vertex and pointing to the eye spatial coordinates of the target user; Based on the target user's security frustum, a target control instruction is generated to make the target type file only visually displayed to the target user, wherein the target control instruction is used to control the adjustable optical components of the shared screen.

2. The method according to claim 1, characterized in that, The step of collecting the trigger location of the open request and the eye spatial coordinates of the target user at the trigger location when an open request for a target type file is detected includes: Upon detecting an open request for a target type file, obtain the logical display area of ​​the open request on the shared screen; The trigger position is determined based on the logical display area; The view sensor is invoked to obtain the spatial coordinates of the target user's eye at the trigger location.

3. The method according to claim 1, characterized in that, Determining the target user's safe visual cone based on the eye spatial coordinates includes: In the area where the target type file is displayed on the shared screen, a specific pixel is determined as the vertex of the safe view frustum; The vector pointing from the vertex to the target user's eye spatial coordinates is used as the axis of the safety cone; The angle of the safety cone is determined, wherein the width of the angle is greater than a first preset dynamic value and less than a second preset dynamic value, the first preset dynamic value is the sum of the interpupillary distance of the target user and the head sway threshold, and the second preset dynamic value is the upper limit of the viewing angle to prevent non-target users from viewing the target type file.

4. The method according to claim 2, characterized in that, The adjustable optical component includes a microlens array, and the method includes: The range of the target microlens array is determined based on the vertex and the preset pixel microlens mapping relationship, wherein the preset pixel microlens mapping relationship is the mapping relationship between screen pixels and the microlens array; The target direction vector for light deflection of the target microlens array is determined based on the centerline. The optical phase profile of the target microlens array is determined based on the target direction vector, wherein the optical phase profile is used to control the light rays emitted from the microlens to be converged and constrained within the conical range of the safety cone.

5. The method according to claim 4, characterized in that, The step of generating target control instructions based on the target user's security view frustum to ensure that the target type file is only visually displayed to the target user includes: Based on the range of the target microlens array, the target direction vector of light deflection, and the optical phase profile, a target control command is generated, wherein the target control command is a driving voltage matrix, and each element of the driving voltage matrix is ​​a specific voltage value that needs to be applied to the corresponding microlens.

6. The method according to claim 1, characterized in that, Also includes: Upon detecting an open request for a target type file, the area of ​​the target type file is encrypted, wherein the encryption process is used to visually encrypt the area of ​​the target type file displayed on the shared screen; Upon receiving the authentication signal from the target user, the region of the target type file is decrypted.

7. The method according to claim 1, characterized in that, Also includes: Obtain the occupant information of the driver and the front passenger; If the occupant information indicates that there is a vacancy in the driver's seat or the front passenger seat, the target type file will be directly displayed on the shared screen.

8. A privacy protection device for shared screens, characterized in that, Also includes: The acquisition unit is used to acquire the triggering location of the opening request and the eye spatial coordinates of the target user at the triggering location when an opening request for a target type file is detected, wherein the triggering location is the driver's seat or the passenger's seat. The determining unit is used to determine the safe viewing cone of the target user based on the eye spatial coordinates, wherein the safe viewing cone is a three-dimensional cone-shaped region with the area displaying the target type file on the shared screen as its vertex and pointing to the eye spatial coordinates of the target user; The display unit is configured to generate target control instructions based on the target user's safety frustum, so that the target type file is visually displayed only to the target user, wherein the target control instructions are used to control the adjustable optical components of the shared screen.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein, when the program is executed by a processor, it implements the steps of the privacy protection method for sharing a screen as described in any one of claims 1 to 7.

10. An electronic device, characterized in that, The electronic device includes at least one processor and at least one memory connected to the processor; wherein the processor is configured to invoke program instructions in the memory to execute the steps of the privacy protection method for sharing a screen as described in any one of claims 1 to 7.