Privacy security protection method, device, equipment and vehicle

By using voiceprint authentication and access control, the privacy and security threats to in-vehicle terminal users are resolved. Non-vehicle owners can access non-sensitive information interfaces, ensuring normal use and privacy protection for vehicle owners, and improving the security and response efficiency of the in-vehicle system.

CN122113072APending Publication Date: 2026-05-29ZHEJIANG GEELY HLDG GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZHEJIANG GEELY HLDG GRP CO LTD
Filing Date
2026-02-12
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

When in-vehicle terminal users call interfaces via voice, there are privacy and security threats, especially when non-vehicle owners initiate commands involving sensitive information, making it difficult to effectively prevent the leakage of privacy data.

Method used

Authentication is performed using voiceprint information to generate identity tags, restrict large models from calling sensitive information interfaces, and generate permission prompts to distinguish between vehicle owners and non-vehicle owners. Hardware isolation and role-based access control strategies are adopted to ensure that non-vehicle owners can only call non-sensitive information interfaces.

Benefits of technology

Effectively prevent privacy data leakage, improve data security and interactive transparency, ensure that car owners can use the large model function normally, reduce false interception rate, and optimize response efficiency and system stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122113072A_ABST
    Figure CN122113072A_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of vehicles, and discloses a privacy security protection method, device, equipment and vehicle, the privacy security protection method comprises the following steps: acquiring voiceprint information of a user who initiates a voice interaction instruction; identity verification is carried out on the user based on the voiceprint information, and a corresponding identity label is generated; if the identity label represents that the user is not the vehicle owner, and the voice interaction instruction involves sensitive information, then the sensitive information interface of the vehicle terminal called by the large model is limited, and corresponding permission prompt information is generated, the present application can improve the privacy security when the user of the vehicle terminal uses the large model by calling the interface of the vehicle terminal in the voice mode.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle technology, and more specifically to privacy and security protection methods, devices, equipment, and vehicles. Background Technology

[0002] Currently, in-vehicle terminal users mainly use large models by calling the interface of the in-vehicle terminal via voice. However, with the increase in AI scenarios, the number of interfaces that large models can call also increases, thereby threatening users' privacy and security. Summary of the Invention

[0003] This invention provides a privacy and security protection method, device, equipment, and vehicle to address the problem of user privacy and security threats when vehicle terminal users access large models via voice commands through the vehicle terminal's interface.

[0004] In a first aspect, the present invention provides a privacy and security protection method, comprising: obtaining the voiceprint information of the user who initiates the voice interaction command; verifying the user's identity based on the voiceprint information and generating a corresponding identity tag; if the identity tag indicates that the user is not the vehicle owner and the voice interaction command involves sensitive information, then restricting the large model from calling the sensitive information interface of the vehicle terminal and generating a corresponding permission prompt message.

[0005] The privacy and security protection method provided by this invention uses voiceprint information for identity verification, which can effectively distinguish between vehicle owners and non-vehicle owners. This proactively restricts the large model's access to sensitive interfaces when a non-vehicle owner initiates a voice command involving sensitive information, thus avoiding the risk of privacy data leakage. Simultaneously, by ensuring the normal use of the large model's functions by vehicle owners while providing corresponding privacy protection permissions to temporary passengers or other unauthorized users, data security in in-vehicle scenarios is significantly improved. Furthermore, the generation of permission prompts further enhances the transparency of the interaction, helping users clearly understand the reasons for the current operational restrictions, thus maintaining user experience and strengthening the proactive defense capability for privacy protection.

[0006] In an optional implementation, the method further includes: if the identity tag indicates that the user is not the vehicle owner and the voice interaction command does not involve sensitive information, then authorize the large model to call the non-sensitive information interface of the vehicle terminal to generate first response information in response to the voice interaction command based on the first inference data obtained.

[0007] The privacy and security protection method provided by this invention not only ensures that non-vehicle owners can still use the basic functions of the in-vehicle large model normally in scenarios that do not involve sensitive information, but also effectively avoids the risk of unauthorized access to privacy data through the control of interface permissions. Through differentiated authorization strategies, it can ensure both security and ease of use, allowing unauthorized users such as temporary passengers to obtain regular services such as navigation and entertainment without triggering privacy protection permissions. In addition, by defining the boundaries between sensitive and non-sensitive interface calls, it significantly reduces the false interception rate of legitimate commands, thereby maintaining the overall service smoothness in the complex and ever-changing in-vehicle interaction environment.

[0008] In one optional implementation, obtaining the first data to be inferred includes: parsing the voice interaction command to obtain the voice text content; extracting the command intent and required data items based on the voice text content; and calling the non-sensitive information interface of the vehicle terminal according to the command intent and required data items to obtain the first data to be inferred.

[0009] The privacy and security protection method provided by this invention can precisely restrict the scope of data access through hierarchical parsing of voice commands, calling only non-sensitive interfaces directly related to the command intent, effectively avoiding the risk of exposing irrelevant data fields. At the same time, by adopting an intent-driven interface calling strategy, it can ensure that temporary passengers can obtain routine service data such as navigation routes and music playlists, while blocking interface access permissions involving sensitive fields such as vehicle location history, contacts, and trip statistics. In addition, by filtering unnecessary data requests in advance, it ensures response generation efficiency while maintaining the real-time interactive performance of the in-vehicle system.

[0010] In one optional implementation, generating first response information in response to a voice interaction command based on the acquired first data to be inferred includes: inputting the voice interaction command, identity tag, and desensitized first data to be inferred into a large model, so that the large model can use the permission restrictions corresponding to the identity tag to parse the voice interaction command, obtain a first parsing result, perform semantic analysis on the desensitized data content to obtain semantic content, and perform reasoning based on the first parsing result and semantic content to obtain a first reasoning result; and generating first response information in response to the voice interaction command based on the first reasoning result.

[0011] The privacy and security protection method provided by this invention inputs voice interaction commands, identity tags, and de-identified data into a large model. This allows for the application of permission restrictions using identity tags, ensuring that the large model performs command parsing and semantic analysis only within the authorized scope during processing. This completely isolates the risk of accessing sensitive information during the response generation stage. Furthermore, by combining the first parsing result with semantic content for reasoning, the accuracy and contextual relevance of response information are improved. Pre-emptive permission filtering also reduces model computational redundancy, significantly optimizing data processing efficiency. In addition, this implementation enhances the real-time interactive capabilities of the in-vehicle system, providing users with a smooth navigation, entertainment, and other service experience while ensuring privacy and security, and simultaneously reducing the resource consumption and maintenance costs of the large model.

[0012] In one optional implementation, generating first response information in response to a voice interaction command based on a first inference result includes: if the first inference result involves sensitive information, generating first response information in response to a voice interaction command based on the desensitized first inference result; if the first inference result does not involve sensitive information, generating first response information in response to a voice interaction command based on the first inference result; and if the first inference result involves erroneous or invalid data, generating error message information as the first response information.

[0013] The privacy and security protection method provided by this invention, when the first inference result involves sensitive information, forces the generation of a response based on the de-identified data, effectively preventing the risk of leakage of the original sensitive information and strengthening the security protection of user privacy data. When the first inference result does not involve sensitive information, it directly generates a response based on the inference result, avoiding unnecessary de-identification processing overhead, optimizing the utilization of computing resources, and ensuring that the response speed meets the needs of real-time interaction. When the first inference result involves erroneous or invalid data, it promptly generates error prompts to help users quickly identify problems and re-enter commands, reducing the number of invalid interactions and enhancing the fault tolerance and user experience of the in-vehicle system. In addition, through the synergistic effect of the first inference result and the aforementioned permission restrictions, the probability of model misoperation is further reduced, improving the service continuity of the in-vehicle system in scenarios such as navigation and entertainment. At the same time, by simplifying the data processing flow, the maintenance cost and energy consumption of large models are reduced.

[0014] In an optional implementation, the method further includes: if the identity tag indicates that the user is a vehicle owner, then authorizing the large model to call the full information interface of the vehicle terminal to generate second response information in response to the voice interaction command based on the acquired second inference data.

[0015] The privacy and security protection method provided by this invention significantly improves the personalized service level of the in-vehicle system by dynamically authorizing the invocation of the full information interface based on identity tags. This ensures that vehicle owners can obtain more comprehensive and accurate response information, enhancing user satisfaction and interactive experience. Simultaneously, by enabling the full information interface only when the user is verified as the vehicle owner, unauthorized users are prevented from accessing sensitive data, further strengthening privacy and security protection and reducing the risk of data leakage. Furthermore, by only invoking the full interface when necessary, system resource allocation is optimized, unnecessary computational overhead is reduced, response efficiency is improved, and real-time interactive performance is ensured. Finally, by combining the aforementioned permission restrictions, the probability of model malfunctions can be effectively reduced, improving the stability and reliability of the in-vehicle system in complex scenarios.

[0016] In one optional implementation, generating second response information in response to a voice interaction command based on the acquired second data to be inferred includes: inputting the voice interaction command, identity tag, and second data to be inferred into a large model, so that the large model parses the voice interaction command based on the full permissions corresponding to the identity tag to obtain a second parsing result; matching the second parsing result with the second data to be inferred to obtain a matching result; performing inference based on the matching result to obtain a second inference result; and generating second response information in response to the voice interaction command based on the second inference result.

[0017] The privacy and security protection method provided by this invention, by inputting voice interaction commands, identity tags, and second data to be inferred into a large model, and performing parsing, matching, and inference based on the full permissions corresponding to the identity tags, can ensure the accuracy and completeness of response information, significantly improving the personalized service experience for car owners. Simultaneously, by strictly limiting the access permissions to the full information interface, triggering it only when the user is verified as a car owner, unauthorized access to sensitive data is effectively avoided, strengthening privacy and security protection. Furthermore, by optimizing the demand matching and inference process, redundant system calculations are reduced, response efficiency is improved, and real-time interaction performance is ensured. Finally, the inference mechanism based on matching results reduces the risk of model misoperation in complex scenarios, improving the stability and reliability of the in-vehicle system.

[0018] Secondly, the present invention provides a privacy and security protection device, comprising: an information acquisition module for acquiring the voiceprint information of the user who initiates the voice interaction command; a tag generation module for authenticating the user based on the voiceprint information and generating a corresponding identity tag; and a privacy protection module for restricting the large model from calling the sensitive information interface of the vehicle terminal and generating a corresponding permission prompt message if the identity tag indicates that the user is not the vehicle owner and the voice interaction command involves sensitive information.

[0019] Thirdly, the present invention provides an electronic device, comprising: a memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to perform the privacy and security protection method of the first aspect or any corresponding embodiment described above.

[0020] Fourthly, embodiments of the present invention provide a vehicle equipped with a privacy and security protection system, which is used to execute the vehicle status prompting method of the first aspect or any corresponding embodiment described above.

[0021] Fifthly, the present invention provides a computer-readable storage medium storing computer instructions for causing a computer to execute the privacy and security protection method of the first aspect or any corresponding embodiment described above.

[0022] In a sixth aspect, the present invention provides a computer program product, including computer instructions for causing a computer to execute the privacy and security protection method described in the first aspect or any corresponding embodiment thereof. Attached Figure Description

[0023] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0024] Figure 1 This is a schematic diagram of the first type of privacy and security protection method according to an embodiment of the present invention;

[0025] Figure 2 This is a schematic diagram of a second process for a privacy and security protection method according to an embodiment of the present invention; Figure 3 This is a schematic diagram of the third process of the privacy and security protection method according to an embodiment of the present invention; Figure 4 This is a structural block diagram of a privacy and security protection device according to an embodiment of the present invention; Figure 5 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0026] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0027] It is understood that before using the technical solutions disclosed in the various embodiments of the present invention, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in the present invention and their authorization should be obtained in accordance with relevant laws and regulations through appropriate means.

[0028] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.

[0029] According to an embodiment of the present invention, a privacy and security protection method embodiment is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0030] This embodiment provides a privacy and security protection method. Figure 1 This is a flowchart of a privacy and security protection method according to an embodiment of the present invention, such as... Figure 1 As shown, the process includes the following steps: Step S101: Obtain the voiceprint information of the user who initiated the voice interaction command.

[0031] Voice interaction commands refer to commands or requests initiated by users through voice input, used to trigger interactive functions of devices or systems, such as waking up the device, performing specific tasks, or accessing restricted services. Voiceprint information refers to a user's voice biometric data, including but not limited to unique attributes such as the frequency, pitch, rhythm, spectral characteristics, and pronunciation patterns of speech. These features are collected by acoustic sensors to form digital templates, used to uniquely identify the user and achieve identity verification and privacy protection during voice interaction.

[0032] When acquiring the voiceprint information of the user initiating the voice interaction command, it can be collected in real time through acoustic sensor arrays or microphones deployed on the vehicle. These acoustic devices can be integrated into the vehicle interior, such as the steering wheel, center console, or seat headrest area, to optimize the reception quality of the voice signal. During the acquisition process, noise reduction algorithms can be used to filter ambient noise, ensuring that the extracted voiceprint features (such as frequency, pitch, and spectral characteristics) are more accurate and reliable. Furthermore, the voiceprint acquisition strategy can be dynamically adjusted according to the vehicle's status (such as driving speed or location), for example, enabling directional microphone focusing when driving at high speeds, further improving the accuracy and efficiency of voiceprint acquisition.

[0033] As an example, when the vehicle is traveling at low speed in congested urban areas, it can switch to a multi-microphone array mode to enhance the capture of voice signals in the passenger area through spatial filtering technology while ignoring background traffic noise. When the vehicle is cruising at high speeds (such as speeds exceeding 100 km / h), beamforming algorithms are enabled to focus the acoustic sensors toward the driver's seat and track changes in head position in real time to compensate for the effects of wind noise and engine vibration. This ensures the stability of voiceprint feature extraction (including fundamental frequency and harmonic structure) and provides a high-fidelity input source for subsequent privacy protection (such as dynamically encrypted voiceprint templates).

[0034] Step S102: Verify user identity based on voiceprint information and generate corresponding identity tags.

[0035] The identity tag is a unique identifier generated based on voiceprint features, used to achieve seamless identity authentication in subsequent voice interactions and associated with the user's personalized profile. The tag is securely stored and transmitted using encryption algorithms (such as AES or RSA) to prevent unauthorized access, and is dynamically activated only in authorized sessions to enhance privacy protection.

[0036] When authenticating users based on voiceprint information and generating corresponding identity tags, a small voiceprint model or voiceprint feature matching model (such as MFCC or GMM) can be used for real-time comparison and verification, and a unique identity tag can be generated based on the matching result. At the same time, the verification strategy can be dynamically optimized by combining contextual information (such as vehicle speed or location). For example, adaptive noise reduction can be enabled in noisy environments to enhance feature extraction accuracy, and cryptographic hash functions (such as SHA-256) can be used to ensure the security and immutability of the tag generation process, so as to seamlessly associate user personalized configurations and maintain session authorization status.

[0037] As an example, when the vehicle is cruising at high speed (over 100 km / h), the GMM model is used first for real-time comparison of voiceprint features. Combined with GPS positioning data, the beamforming algorithm is dynamically activated to focus on the direction of the driver's seat and track the slight head movements in real time to compensate for wind noise interference. At the same time, the accuracy of MFCC feature extraction is enhanced in noisy environments (such as urban main roads), and a unique identity tag is generated by the SHA-256 encrypted hash function. This identity tag is immediately bound to the dynamic voiceprint template after generation, ensuring seamless association with the user's personalized profile even in low signal areas (such as tunnels) and maintaining the session authorization status until the engine is turned off.

[0038] In step S103, if the identity tag indicates that the user is not the vehicle owner and the voice interaction command involves sensitive information, then the large model is restricted from calling the sensitive information interface of the vehicle terminal, and corresponding permission prompt information is generated.

[0039] Sensitive information includes vehicle location data, user personal identification information, payment account details, trip history, contact lists, and any data related to access permissions to in-vehicle terminal interfaces involving privacy or security. The "large model" refers to the large language model in the in-vehicle system used to process and analyze user voice commands to achieve intelligent interaction functions. Sensitive information interfaces refer to functional modules in the in-vehicle system used to access or manipulate sensitive data, including but not limited to location service APIs, payment gateway SDKs, contact list read / write interfaces, trip log storage areas, and vehicle control bus protocol channels. When restricting large models from calling sensitive information interfaces of the in-vehicle terminal, hardware isolation mechanisms can be used to block data access channels. Simultaneously, role-based access control policies ensure that only authorized processes can temporarily activate the interface. Permission prompts include dynamic voice broadcasts and visual warnings on the central control screen, including restrictions on interface types and re-authentication guidance, such as "Non-owner operation detected; vehicle location interface access is prohibited."

[0040] When the identity tag indicates that the user is not the vehicle owner, and the voice interaction command involves sensitive information, the large model is restricted from calling the sensitive information interface of the vehicle terminal and generating corresponding permission prompts. Hardware isolation mechanisms can be used to block the data access channel of the interface. At the same time, based on the preset role access control policy, it is ensured that only authorized processes can temporarily activate the sensitive information interface. The generated permission prompts specifically include dynamic voice broadcasts and visual warnings on the central control screen. The content includes the restricted interface type and re-authentication guidance. For example, a voice prompt will say "Non-owner operation detected, vehicle location interface access is prohibited", and detailed operation steps and the vehicle owner authentication entry will be displayed on the central control screen to improve the transparency and security level of user interaction.

[0041] As an example, when the vehicle detects that a passenger is attempting to query real-time location data via voice command, it physically disconnects the location service API. Simultaneously, based on a preset role-based access control policy, only the authenticated vehicle owner process is allowed to temporarily enable the interface in emergency situations. At this time, a dynamic voice broadcast will issue a warning: "Non-owner operation detected; vehicle location interface access is prohibited." An interactive interface will be displayed on the central control screen, detailing the restricted interface types (such as location services and payment gateways), re-authentication steps (including biometric verification or scanning with the vehicle owner's APP), and a prominent "Vehicle Owner Authentication Entry" virtual control to guide the user to complete identity verification, thereby ensuring both enhanced transparency of user operations and improved system security.

[0042] The privacy and security protection method provided in this embodiment uses voiceprint information for identity verification, which can effectively distinguish between vehicle owners and non-vehicle owners. This proactively restricts the large model's access to sensitive interfaces when a non-vehicle owner initiates a voice command involving sensitive information, thus avoiding the risk of privacy data leakage. Simultaneously, by ensuring the normal use of the large model's functions by vehicle owners while providing corresponding privacy protection permissions to temporary passengers or other unauthorized users, data security in in-vehicle scenarios is significantly improved. Furthermore, the generation of permission prompts further enhances the transparency of the interaction, helping users clearly understand the reasons for the current operational restrictions, thus maintaining user experience and strengthening the proactive defense capability for privacy protection.

[0043] This embodiment provides a privacy and security protection method. Figure 2 This is a flowchart of a privacy and security protection method according to an embodiment of the present invention, such as... Figure 2 As shown, the process includes the following steps: Step S201: Obtain the voiceprint information of the user who initiated the voice interaction command. For details, please refer to [link to relevant documentation]. Figure 1 Step S101 of the illustrated embodiment will not be described again here.

[0044] Step S202: Verify user identity based on voiceprint information and generate a corresponding identity tag. For details, please refer to [link to relevant documentation]. Figure 1 Step S101 of the illustrated embodiment will not be described again here.

[0045] Step S203: If the identity tag indicates that the user is not the vehicle owner and the voice interaction command does not involve sensitive information, then the big model is authorized to call the non-sensitive information interface of the vehicle terminal to generate the first response information in response to the voice interaction command based on the first inference data obtained.

[0046] The non-sensitive information interface is a component in the in-vehicle terminal specifically designed to access and provide non-sensitive data, including real-time vehicle location, ambient temperature, traffic conditions, or entertainment content—information that does not involve personal privacy. This non-sensitive information interface has corresponding access control mechanisms to ensure that only authorized large-scale models are invoked after successful authentication, thereby preventing the leakage of sensitive information when responding to voice interaction commands, while maintaining the availability of in-vehicle functions and the smoothness of the user experience. Furthermore, the non-sensitive information interface is physically isolated from the sensitive information interface and uses encrypted protocols to transmit data to prevent unauthorized access or data tampering. In addition, both the non-sensitive and sensitive information interfaces adhere to the principle of least privilege, exposing only necessary data fields to strengthen the defense layer of privacy protection.

[0047] When the identity tag indicates that the user is not the vehicle owner and the voice interaction command does not involve sensitive information, the authorized large model can call the non-sensitive information interface of the vehicle terminal to generate the first response information in response to the voice interaction command based on the first inference data obtained. The principle of least privilege can be applied to expose only the necessary data fields and transmit the data through an encryption protocol to prevent unauthorized access or data tampering. At the same time, physical isolation is combined to ensure that the interaction with the non-sensitive information interface is completely independent of the sensitive information interface. In this way, the privacy and security defense layer is continuously maintained during the generation of response information. Based on non-sensitive information such as the vehicle's real-time location, ambient temperature, traffic conditions or entertainment media content, the response content is dynamically optimized to improve the smoothness of the user experience and the efficiency of the vehicle functions.

[0048] As an example, when a non-vehicle owner user issues a voice command to "check the current location and ambient temperature," the large model obtains the vehicle's real-time location and ambient temperature data based on a non-sensitive information interface, exposing only necessary data fields such as geographic coordinates and Celsius values. This data is transmitted encrypted using the TLS protocol to prevent man-in-the-middle attacks or data tampering. Simultaneously, a physical isolation mechanism ensures that this call is completely independent of sensitive information interfaces, avoiding any privacy leakage risks. During the generation of the initial response information, traffic condition predictions can be combined to provide clothing suggestions or air conditioning adjustment prompts, thereby improving the responsiveness of in-vehicle functions and the smoothness of the user interaction experience.

[0049] As another example, when a non-car owner user issues a voice interaction command to "play recommended music", the large model calls a non-sensitive information interface to access the entertainment media content library, exposing only the song title and artist information, without involving personal playback history; after transmitting data through an encrypted channel, a response is dynamically generated based on the user preference model, such as recommending popular playlists, while maintaining the efficiency of the interface to support real-time media streaming playback, ensuring a seamless user experience.

[0050] The privacy and security protection method provided by this invention not only ensures that non-vehicle owners can still use the basic functions of the in-vehicle large model normally in scenarios that do not involve sensitive information, but also effectively avoids the risk of unauthorized access to privacy data through the control of interface permissions. Through differentiated authorization strategies, it can ensure both security and ease of use, allowing unauthorized users such as temporary passengers to obtain regular services such as navigation and entertainment without triggering privacy protection permissions. In addition, by defining the boundaries between sensitive and non-sensitive interface calls, it significantly reduces the false interception rate of legitimate commands, thereby maintaining the overall service smoothness in the complex and ever-changing in-vehicle interaction environment.

[0051] In some optional implementations, when acquiring the first data to be inferred, the voice interaction command can be parsed first to obtain the voice text content; then, based on the voice text content, the command intent and required data items can be extracted; finally, the non-sensitive information interface of the vehicle terminal can be called according to the command intent and required data items to obtain the first data to be inferred.

[0052] Specifically, the voice interaction commands can be converted into standard text format using the voice recognition module built into the vehicle terminal. Then, a natural language processing model is applied to analyze the voice text content, identify the user's command intent such as "play recommended music," "check the weather," or "external conditions," and extract the required data items such as "music type," "location information," or "external environment." Next, based on the command intent, a preset non-sensitive interface call rule is matched. For example, when calling the media content library interface for entertainment requests, only non-sensitive fields such as song titles and artists are returned, ensuring that the user's personal history or identity is not involved in the data acquisition process. At the same time, an intent classification algorithm is used to optimize the accuracy of data extraction and reduce the probability of accidentally triggering sensitive interfaces, thereby achieving efficient acquisition of the first data to be inferred.

[0053] As an example, when a non-vehicle owner user issues the voice command "Check today's Beijing weather," the in-vehicle terminal converts it into the standard text format "Check today's Beijing weather" using a voice recognition module. Next, a natural language processing model analyzes the text, identifying the command intent as "weather query," and extracts the required data items "location: Beijing" and "time: today." Based on preset non-sensitive interface call rules, it matches a call to an external weather service interface, obtaining only public meteorological data such as temperature, humidity, and weather conditions, while masking user location history or identity information. Simultaneously, the intent classification algorithm optimizes the data extraction process through model training, for example, using convolutional neural networks to reduce intent ambiguity, ensuring only non-sensitive fields are returned, and avoiding triggering vehicle location or personal preference interfaces. Furthermore, after data acquisition, the interface return content is further verified to comply with privacy rules, such as filtering out any fields associated with user IDs, and interface call events are logged for subsequent auditing and accuracy improvement, thus efficiently and securely completing the acquisition of the first set of data to be inferred.

[0054] As another example, when a non-vehicle owner user issues a voice command to "navigate to the nearest gas station," the in-vehicle terminal converts it into the standard text format "navigate to the nearest gas station" using a voice recognition module. A natural language processing model analyzes this text, identifying the command intent as a "navigation request," and extracts the required data items: "target location type: gas station" and "location: near the current location." Based on preset non-sensitive interface call rules, a map service interface is matched, and only a list of nearby gas station coordinates and basic information (such as name and distance) based on the current vehicle location (anonymized and not associated with user ID) is obtained, while sensitive data such as the user's home address, frequently used routes, or personal travel habits are masked. Simultaneously, the intent classification algorithm accurately identifies the ambiguous requirement of "nearest," converting it into a radius search based on real-time location, avoiding accidental triggering of interfaces containing historical trajectory analysis. After obtaining the list of gas stations, the data returned by the interface is further filtered to remove any fields that may contain user identifiers or preference tags (such as the "frequently visited locations" label). The details of the interface call for this navigation request, the timestamp, and the types of data items obtained are recorded in encrypted logs for subsequent privacy compliance audits and model optimization. This ensures that the process of obtaining the first data to be inferred (i.e., the anonymized list of gas station locations) meets user needs while strictly protecting personal privacy.

[0055] The privacy and security protection method provided by this invention can precisely restrict the scope of data access through hierarchical parsing of voice commands, calling only non-sensitive interfaces directly related to the command intent, effectively avoiding the risk of exposing irrelevant data fields. At the same time, by adopting an intent-driven interface calling strategy, it can ensure that temporary passengers can obtain routine service data such as navigation routes and music playlists, while blocking interface access permissions involving sensitive fields such as vehicle location history, contacts, and trip statistics. In addition, by filtering unnecessary data requests in advance, it ensures response generation efficiency while maintaining the real-time interactive performance of the in-vehicle system.

[0056] In some optional implementations, when generating the first response information in response to the voice interaction command based on the acquired first data to be inferred, the voice interaction command, identity tag, and the anonymized first data to be inferred can be input into a large model. The large model can then use the permission restrictions corresponding to the identity tag to parse the voice interaction command, obtain a first parsing result, and perform semantic analysis on the anonymized data content to obtain semantic content. Based on the first parsing result and the semantic content, a first inference result is obtained; and based on the first inference result, the first response information in response to the voice interaction command is generated.

[0057] As an example, after a non-car owner initiates a voice interaction command to "play music suitable for me," the system uses a voiceprint mini-model to identify the non-car owner and generate a non-car owner identity tag. Simultaneously, it extracts the user's voiceprint age (e.g., "25"). The voice interaction command, along with the non-owner's identity tag and the anonymized current weather data (e.g., "sunny," with sensitive information such as specific area and humidity removed), is used as the first inference data. This voice interaction command, the non-owner's identity tag, and the anonymized data are then input into the larger model. The larger model first uses the permission restrictions corresponding to the non-owner's identity tag (only non-sensitive entertainment interfaces can be accessed, and privacy data such as driving trajectory cannot be accessed) to parse the voice interaction command, obtaining the first parsing result: "Music should be recommended based on user characteristics and weather." Then, semantic analysis is performed on the anonymized data such as "25 years old, female, sunny," yielding the semantic content: "Suitable for recommending upbeat, pop music." Finally, based on the first parsing result and the semantic content, inference is performed to determine the specific music recommendation list, obtaining the first inference result. Based on this inference result, the first response information, "Upbeat pop music suitable for sunny weather is recommended for you; it has been played," is generated.

[0058] The privacy and security protection method provided by this invention inputs voice interaction commands, identity tags, and de-identified data into a large model. This allows for the application of permission restrictions using identity tags, ensuring that the large model performs command parsing and semantic analysis only within the authorized scope during processing. This completely isolates the risk of accessing sensitive information during the response generation stage. Furthermore, by combining the first parsing result with semantic content for reasoning, the accuracy and contextual relevance of response information are improved. Pre-emptive permission filtering also reduces model computational redundancy, significantly optimizing data processing efficiency. In addition, this implementation enhances the real-time interactive capabilities of the in-vehicle system, providing users with a smooth navigation, entertainment, and other service experience while ensuring privacy and security, and simultaneously reducing the resource consumption and maintenance costs of the large model.

[0059] In some optional implementations, when generating first response information in response to a voice interaction command based on the first inference result, if the first inference result involves sensitive information, then the first response information in response to the voice interaction command is generated based on the desensitized first inference result; if the first inference result does not involve sensitive information, then the first response information in response to the voice interaction command is generated based on the first inference result; if the first inference result involves erroneous or invalid data, then an error message is generated as the first response information.

[0060] As an example, when a user issues a voice interaction command to "recommend music suitable for me," the system infers a first inference result based on the user's identity tags and anonymized data. If the result involves sensitive information such as the user's age or location, the response information is generated using only the anonymized music style (e.g., "upbeat pop"). If the inference result only contains non-sensitive music genres (e.g., "pop" or "rock"), the response is generated directly based on that result. If the inference result cannot generate a recommendation list due to data errors (e.g., invalid or missing weather data), an error message "Data error, please re-enter the command" is generated.

[0061] The privacy and security protection method provided by this invention, when the first inference result involves sensitive information, forces the generation of a response based on the de-identified data, effectively preventing the risk of leakage of the original sensitive information and strengthening the security protection of user privacy data. When the first inference result does not involve sensitive information, it directly generates a response based on the inference result, avoiding unnecessary de-identification processing overhead, optimizing the utilization of computing resources, and ensuring that the response speed meets the needs of real-time interaction. When the first inference result involves erroneous or invalid data, it promptly generates error prompts to help users quickly identify problems and re-enter commands, reducing the number of invalid interactions and enhancing the fault tolerance and user experience of the in-vehicle system. In addition, through the synergistic effect of the first inference result and the aforementioned permission restrictions, the probability of model misoperation is further reduced, improving the service continuity of the in-vehicle system in scenarios such as navigation and entertainment. At the same time, by simplifying the data processing flow, the maintenance cost and energy consumption of large models are reduced.

[0062] This embodiment provides a privacy and security protection method. Figure 3 This is a flowchart of a privacy and security protection method according to an embodiment of the present invention, such as... Figure 3 As shown, the process includes the following steps: Step S301: Obtain the voiceprint information of the user who initiated the voice interaction command. For details, please refer to [link to relevant documentation]. Figure 1 Step S101 of the illustrated embodiment will not be described again here.

[0063] Step S302: Verify user identity based on voiceprint information and generate a corresponding identity tag. For details, please refer to [link to relevant documentation]. Figure 1 Step S101 of the illustrated embodiment will not be described again here.

[0064] Step S303: If the identity tag indicates that the user is the car owner, then the big model is authorized to call the full information interface of the vehicle terminal to generate second response information in response to the voice interaction command based on the acquired second inference data.

[0065] The full-data interface is used to access the core data resources of the in-vehicle terminal, including the vehicle's real-time location, driving status parameters, user personalized preference settings, and historical interaction records. Once authorized, this full-data interface can seamlessly integrate multi-dimensional information required for navigation route planning, entertainment content recommendation, and driver assistance functions. This ensures high accuracy and contextual consistency when the large model generates response information, while appropriate access control mechanisms prevent unauthorized access and protect the privacy and security of sensitive data.

[0066] When the identity tag identifies the user as the car owner, the authorized big model calls the full information interface of the vehicle terminal to generate the second response information in response to the voice interaction command based on the second inference data obtained. Based on the data obtained from the full information interface, the inference logic of the big model can be dynamically adjusted to generate highly personalized service responses. For example, it can provide accurate navigation suggestions based on the real-time location of the vehicle, recommend entertainment content based on the user's personalized preferences, or trigger driving assistance alarms in combination with driving status parameters. At the same time, abnormal access can be revoked in a timely manner by monitoring the use of permissions in real time to ensure the real-time performance and security of data processing.

[0067] As an example, when a user issues the voice command "Navigate home," the system dynamically optimizes route planning based on the vehicle's real-time location to avoid congested areas. Alternatively, if user fatigue is detected (e.g., abnormal steering wheel vibration frequency), a safety warning is triggered based on driving status parameters, and rest suggestions are provided. Simultaneously, the system continuously tracks the call logs of all information interfaces; if unauthorized access attempts are identified (e.g., high-frequency data requests), the session is immediately terminated and the risk is isolated to ensure sensitive data is not leaked. Furthermore, by analyzing historical interaction records, user needs can be predicted (e.g., automatically starting navigation during commuting hours), further enhancing the humanization and intelligence of the service response. All operations are executed in an encrypted environment to maintain privacy integrity.

[0068] The privacy and security protection method provided by this invention significantly improves the personalized service level of the in-vehicle system by dynamically authorizing the invocation of the full information interface based on identity tags. This ensures that vehicle owners can obtain more comprehensive and accurate response information, enhancing user satisfaction and interactive experience. Simultaneously, by enabling the full information interface only when the user is verified as the vehicle owner, unauthorized users are prevented from accessing sensitive data, further strengthening privacy and security protection and reducing the risk of data leakage. Furthermore, by only invoking the full interface when necessary, system resource allocation is optimized, unnecessary computational overhead is reduced, response efficiency is improved, and real-time interactive performance is ensured. Finally, by combining the aforementioned permission restrictions, the probability of model malfunctions can be effectively reduced, improving the stability and reliability of the in-vehicle system in complex scenarios.

[0069] In some optional implementations, when generating second response information in response to voice interaction commands based on the acquired second data to be inferred, the voice interaction commands, identity tags, and second data to be inferred can be input into a large model. The large model can then parse the voice interaction commands based on the full permissions corresponding to the identity tags to obtain a second parsing result. The second parsing result is then matched with the second data to be inferred to obtain a matching result. Inference is then performed based on the matching result to obtain a second inference result. Finally, the second response information in response to the voice interaction commands is generated based on the second inference result.

[0070] As an example, when a car owner initiates a voice interaction command to "query my vehicle's historical driving trajectory for the past three days," the voiceprint mini-model identifies and verifies the car owner's identity, generating a car owner identity tag. Simultaneously, the main model, based on the full permissions corresponding to the car owner identity tag, calls external tools to obtain complete historical driving trajectory data for the past three days, including daily departure time, route, stops, and mileage, as the second inference data. Subsequently, the voice interaction command, the car owner identity tag, and the complete driving trajectory data are input into the main model. The main model first parses the voice interaction command based on the car owner's full permissions, obtaining a second parsing result: "The complete driving trajectory information for the past three days needs to be extracted and integrated and fed back to the user." Then, the main model matches this second parsing result with the obtained complete driving trajectory data to obtain a matching result: "The data covers all driving information for the past three days, satisfying the query requirement." Finally, based on this matching result, inference is performed to summarize the driving trajectory in a clear and organized manner, resulting in the second inference result.

[0071] The privacy and security protection method provided by this invention, by inputting voice interaction commands, identity tags, and second data to be inferred into a large model, and performing parsing, matching, and inference based on the full permissions corresponding to the identity tags, can ensure the accuracy and completeness of response information, significantly improving the personalized service experience for car owners. Simultaneously, by strictly limiting the access permissions to the full information interface, triggering it only when the user is verified as a car owner, unauthorized access to sensitive data is effectively avoided, strengthening privacy and security protection. Furthermore, by optimizing the demand matching and inference process, redundant system calculations are reduced, response efficiency is improved, and real-time interaction performance is ensured. Finally, the inference mechanism based on matching results reduces the risk of model misoperation in complex scenarios, improving the stability and reliability of the in-vehicle system.

[0072] This embodiment also provides a privacy and security protection device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0073] This embodiment provides a privacy and security protection device, such as Figure 4 As shown, it includes: The information acquisition module 401 is used to acquire the voiceprint information of the user who initiates the voice interaction command; The tag generation module 402 is used to authenticate users based on voiceprint information and generate corresponding identity tags; The privacy protection module 403 is used to restrict the large model from calling the sensitive information interface of the vehicle terminal and generate corresponding permission prompt information if the identity tag indicates that the user is not the vehicle owner and the voice interaction command involves sensitive information.

[0074] In some optional implementations, the privacy protection module 403 is further configured to authorize the large model to call the non-sensitive information interface of the vehicle terminal if the identity tag indicates that the user is not the vehicle owner and the voice interaction command does not involve sensitive information, so as to generate first response information in response to the voice interaction command based on the first inference data obtained.

[0075] In some alternative implementations, the privacy protection module 403 includes: The voice command parsing unit is used to parse voice interaction commands and obtain voice text content; The text content extraction unit is used to extract the instruction intent and required data items based on the voice text content; The first data acquisition unit is used to call the non-sensitive information interface of the vehicle terminal according to the instruction intent and the required data items to obtain the first data to be inferred.

[0076] In some alternative implementations, the privacy protection module 403 further includes: The first reasoning unit is used to input the voice interaction command, identity tag and the first data to be reasoned after desensitization into the large model, so that the large model can use the permission restrictions corresponding to the identity tag to parse the voice interaction command, obtain the first parsing result, and perform semantic analysis on the desensitized data content to obtain semantic content. Based on the first parsing result and the semantic content, reasoning is performed to obtain the first reasoning result. The first response unit is used to generate first response information in response to the voice interaction command based on the first reasoning result.

[0077] In some alternative implementations, the first response unit includes: The first response subunit is used to generate first response information in response to voice interaction commands based on the desensitized first inference result if the first inference result involves sensitive information. The second response subunit is used to generate first response information in response to the voice interaction command based on the first inference result if the first inference result does not involve sensitive information. The third response subunit is used to generate an error message as the first response message if the first inference result involves erroneous or invalid data.

[0078] In some optional implementations, the privacy protection module 403 is further configured to authorize the large model to call the full information interface of the vehicle terminal if the identity tag indicates that the user is the vehicle owner, so as to generate second response information in response to the voice interaction command based on the acquired second inference data.

[0079] In some alternative implementations, the privacy protection module 403 includes: The second reasoning unit is used to input voice interaction commands, identity tags, and second data to be reasoned into the large model, so that the large model can parse the voice interaction commands based on the full permissions corresponding to the identity tags, obtain the second parsing result, match the second parsing result with the second data to be reasoned, obtain the matching result, and perform reasoning based on the matching result to obtain the second reasoning result. The second response unit is used to generate second response information in response to the voice interaction command based on the second inference result.

[0080] The privacy and security protection device provided in this embodiment of the invention can execute the privacy and security protection method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects for executing the method. Further functional descriptions of the various modules and units described above are the same as in the corresponding embodiments described above, and will not be repeated here.

[0081] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention.

[0082] The following is a detailed reference. Figure 5 The diagram illustrates a structural schematic suitable for implementing an electronic device according to embodiments of the present invention. The electronic device may include a processor (e.g., a central processing unit, graphics processor, etc.) 501, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 502 or a program loaded from memory 508 into random access memory (RAM) 503. The RAM 503 also stores various programs and data required for the operation of the electronic device. The processor 501, ROM 502, and RAM 503 are interconnected via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0083] Typically, the following devices can be connected to I / O interface 505: input devices 506 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 507 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; memory devices 508 including, for example, magnetic tapes, hard disks, etc.; and communication devices 509. Communication device 509 allows electronic devices to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 5Electronic devices with various devices are shown, but it should be understood that it is not required to implement or have all of the devices shown, and more or fewer devices may be implemented or have instead.

[0084] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 509, or installed from a memory 508, or installed from a ROM 502. When the computer program is executed by the processor 501, it performs the functions defined in the privacy and security protection method of the embodiments of the present invention.

[0085] Figure 5 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of use of the embodiments of the present invention.

[0086] This invention also provides a vehicle equipped with a privacy protection system, which is used to perform the aforementioned privacy protection method.

[0087] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code. When the software or computer code is accessed and executed by the computer, processor, or hardware, the privacy and security protection methods shown in the above embodiments are implemented.

[0088] A portion of this invention can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to the invention through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions, or the computer compiling the instructions and then executing the corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.

[0089] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.

Claims

1. A privacy and security protection method, characterized in that, The method includes: Obtain the voiceprint information of the user who initiates the voice interaction command; The user is authenticated based on the voiceprint information, and a corresponding identity tag is generated; If the identity tag indicates that the user is not the vehicle owner, and the voice interaction command involves sensitive information, then the large model is restricted from calling the sensitive information interface of the vehicle terminal, and corresponding permission prompt information is generated.

2. The method according to claim 1, characterized in that, The method further includes: If the identity tag indicates that the user is not the vehicle owner, and the voice interaction command does not involve the sensitive information, then the large model is authorized to call the non-sensitive information interface of the vehicle terminal to generate first response information in response to the voice interaction command based on the first inference data obtained.

3. The method according to claim 2, characterized in that, The acquisition of the first data to be inferred includes: The voice interaction command is parsed to obtain the voice text content; Based on the voice text content, extract the instruction intent and required data items; According to the instruction intent and the required data items, the non-sensitive information interface of the vehicle terminal is invoked to obtain the first data to be inferred.

4. The method according to claim 2 or 3, characterized in that, The generation of first response information in response to the voice interaction command based on the acquired first data to be inferred includes: The voice interaction command, the identity tag, and the anonymized first data to be inferred are input into the large model, so that the large model can use the permission restrictions corresponding to the identity tag to parse the voice interaction command, obtain the first parsing result, and perform semantic analysis on the anonymized data content to obtain semantic content. Based on the first parsing result and the semantic content, the model can perform inference to obtain the first inference result. First response information is generated based on the first reasoning result in response to the voice interaction command.

5. The method according to claim 4, characterized in that, The generation of first response information in response to the voice interaction command based on the first inference result includes: If the first inference result involves sensitive information, then a first response information in response to the voice interaction command is generated based on the desensitized first inference result. If the first reasoning result does not involve sensitive information, then a first response information in response to the voice interaction command is generated based on the first reasoning result; If the first reasoning result involves erroneous or invalid data, an error message is generated as the first response message.

6. The method according to claim 1, characterized in that, The method further includes: If the identity tag indicates that the user is the car owner, then the large model is authorized to call the full information interface of the vehicle terminal to generate second response information in response to the voice interaction command based on the acquired second inference data.

7. The method according to claim 6, characterized in that, The generation of second response information in response to the voice interaction command based on the acquired second data to be inferred includes: The voice interaction command, the identity tag, and the second data to be inferred are input into the large model, so that the large model parses the voice interaction command based on the full permissions corresponding to the identity tag to obtain a second parsing result. The second parsing result is matched with the second data to be inferred to obtain a matching result. Based on the matching result, inference is performed to obtain a second inference result. Based on the second reasoning result, a second response information is generated in response to the voice interaction command.

8. A privacy and security protection device, characterized in that, The device includes: The information acquisition module is used to acquire the voiceprint information of the user who initiates the voice interaction command; The tag generation module is used to authenticate the user based on the voiceprint information and generate a corresponding identity tag; The privacy protection module is used to restrict the large model from calling the sensitive information interface of the vehicle terminal and generate corresponding permission prompt information if the identity tag indicates that the user is not the vehicle owner and the voice interaction command involves sensitive information.

9. An electronic device, characterized in that, include: A memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, the processor executing the computer instructions to perform the method of any one of claims 1 to 7.

10. A vehicle, characterized in that, The vehicle is equipped with a privacy and security protection system, which is used to perform the method according to any one of claims 1 to 7.