User interface generation method, apparatus, device, and vehicle

By identifying the user and driving context within the vehicle and dynamically adjusting user interface permissions, the problem of insufficient security in the vehicle user interface is solved, ensuring that sensitive data is not accessed by unauthorized users and improving the security of the user interface.

CN122219818APending Publication Date: 2026-06-16XINGCHEN FUTURE (SUZHOU) AUTOMOTIVE TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
XINGCHEN FUTURE (SUZHOU) AUTOMOTIVE TECHNOLOGY CO LTD
Filing Date
2026-03-10
Publication Date
2026-06-16

AI Technical Summary

Technical Problem

The current vehicle user interface design has flaws in access control, which allows users with different identities to access and operate all functional modules indiscriminately, resulting in poor security.

Method used

By identifying the user's identity and driving context in the target vehicle, and determining the permitted access functions and sensitive data access permissions based on the user's identity and driving context, the system performs de-identification processing, generates and renders the target user interface elements, and ensures that sensitive data is not leaked.

Benefits of technology

It enables dynamic adjustment of user interface permissions based on user identity and driving context, preventing sensitive data leakage and improving the security of the vehicle user interface.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122219818A_ABST
    Figure CN122219818A_ABST
Patent Text Reader

Abstract

The application provides a user interface generation method, device and equipment and a vehicle. The user interface generation method comprises the following steps: determining a user identity in a target vehicle and a driving situation of the target vehicle; determining allowed access functions and sensitive data access permissions corresponding to the allowed access functions based on the user identity and the driving situation; obtaining to-be-displayed data of the allowed access functions, and performing desensitization processing on the to-be-displayed data based on the sensitive data access permissions to obtain safe data of the allowed access functions; generating a target user interface element based on the allowed access functions and the safe data of the allowed access functions, rendering the target user interface element, and generating a target user interface. The application can improve the security of the user interface of the vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle technology, and in particular to a user interface generation method, apparatus, device, and vehicle. Background Technology

[0002] With the continuous upgrading of intelligent cockpits, the user interface carried by the in-vehicle screen has gradually evolved into a comprehensive operating platform that integrates navigation planning, multimedia entertainment, vehicle status monitoring and other functions.

[0003] However, current vehicle user interface designs have significant flaws in access control. Users with different identities—whether owners, family members, visitors, or temporary passengers—can access and operate all functional modules on the user interface without distinction. This results in poor security for the vehicle's user interface. Summary of the Invention

[0004] This application provides a user interface generation method, apparatus, device, and vehicle to improve the security of the vehicle's user interface.

[0005] According to a first aspect of the embodiments of this application, a user interface generation method is provided, comprising: Determine the user identity in the target vehicle and the driving context of the target vehicle; Based on the user identity and the driving context, determine the allowed access function and the sensitive data access permissions corresponding to the allowed access function; Obtain the data to be displayed for the allowed access function, and perform desensitization processing on the data to be displayed based on the sensitive data access permission to obtain the secure data for the allowed access function; Based on the access permission function and the security data of the access permission function, a target user interface element is generated and rendered to generate the target user interface.

[0006] Optionally, determining the user identity in the target vehicle and the driving context of the target vehicle includes: Obtain the user identifier and user biometric features in the target vehicle, and determine the user identity in the target vehicle based on the user identifier and user biometric features; The vehicle status and task status of the target vehicle are obtained, and the driving situation of the target vehicle is determined based on the vehicle status and task status.

[0007] Optionally, determining the allowed access function and the corresponding sensitive data access permissions based on the user identity and the driving context includes: Based on the user identity and the driving context, the function access permissions and sensitive data access permissions corresponding to each function are retrieved from the preset permission matrix; wherein, the preset permission matrix stores the mapping relationship between user identity, driving context, function, function access permissions and sensitive data access permissions; Based on the access permissions corresponding to each function, determine the functions that are allowed to be accessed from each function; Find the sensitive data access permissions corresponding to the allowed access function from the sensitive data access permissions corresponding to each function.

[0008] Optionally, generating the target user interface element based on the access permission function and the security data of the access permission function includes: Based on the access permission function, the security data of the access permission function, and the user interface element template library, predictive user interface elements are generated; wherein, the predictive user interface elements include atomic-level user interface elements; The predicted user interface elements are subjected to security constraint checks, and the predicted user interface elements that pass the security constraint checks are determined as the target user interface elements.

[0009] Optionally, generating predicted user interface elements based on the access permission function, the security data of the access permission function, and the user interface element template library includes: The user identity, the driving scenario, the allowed access functions, the security data of the allowed access functions, and the user interface element template library are input into the generative model to generate predicted user interface elements.

[0010] Optionally, the step of performing a security constraint check on the predicted user interface element and determining the predicted user interface element that passes the security constraint check as the target user interface element includes: Determine whether the predicted user interface element meets safe driving requirements, whether the function referenced by the predicted user interface element is included in the allowed access function, and whether the data referenced by the predicted user interface element is included in the security data of the allowed access function; If the predicted user interface element meets the requirements for safe driving, and the function referenced by the predicted user interface element is included in the allowed access function, and the data referenced by the predicted user interface element is included in the security data of the allowed access function, then the safety constraint check of the predicted user interface element is determined to be passed. The predicted user interface elements that pass the safety constraint check are identified as the target user interface elements.

[0011] Optionally, the method further includes: Real-time monitoring of whether the user's identity and the driving situation change; If the user identity and / or the driving situation changes, the target user interface is cleared, and a new target user interface is regenerated based on the latest user identity and the latest driving situation.

[0012] According to a second aspect of the embodiments of this application, a user interface generation apparatus is provided, comprising: A context-aware unit is used to determine the user's identity in the target vehicle and the driving context of the target vehicle; The permission determination unit is used to determine the allowed access function and the sensitive data access permissions corresponding to the allowed access function based on the user identity and the driving context; The desensitization unit is used to obtain the data to be displayed for the allowed access function, and to desensitize the data to be displayed based on the sensitive data access permission to obtain the secure data for the allowed access function. The generation unit is used to generate target user interface elements based on the access permission function and the security data of the access permission function, and to render the target user interface elements to generate the target user interface.

[0013] According to a third aspect of the embodiments of this application, an electronic device is provided, including a memory and a processor; The memory is connected to the processor and is used to store programs; The processor is used to implement the user interface generation method as described in the first aspect by running a program in the memory.

[0014] According to a fourth aspect of the embodiments of this application, a vehicle is provided, including electronic equipment as described in the third aspect.

[0015] In this application, the user identity and driving context of the target vehicle are determined. Based on the user identity and driving context, permitted access functions and corresponding sensitive data access permissions are determined. Different permitted access functions and sensitive data access permissions are set for different user identities and driving contexts, which can improve the security of the vehicle's user interface. Furthermore, based on the sensitive data access permissions, the data to be displayed for permitted access functions is de-identified to obtain secure data for permitted access functions. Based on the permitted access functions and their secure data, target user interface elements are generated and rendered to create the target user interface. This ensures that the target user interface does not leak sensitive data, and visitors or unauthorized users cannot access or view private information without authorization, further enhancing the security of the vehicle's user interface. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0017] Figure 1 This is a flowchart illustrating a user interface generation method provided in an embodiment of this application.

[0018] Figure 2 This is a flowchart illustrating step 101 provided in an embodiment of this application.

[0019] Figure 3 This is a flowchart illustrating step 102 provided in an embodiment of this application.

[0020] Figure 4 This is a schematic diagram of a process for generating target user interface elements provided in an embodiment of this application.

[0021] Figure 5 This is a schematic diagram of the structure of a user interface generation device provided in the embodiments of this application.

[0022] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0023] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0024] Exemplary Implementation Environment The user interface generation method according to the embodiments of this application can be executed by electronic devices such as terminal devices or servers. The terminal device can be a user device, mobile device, computing device, vehicle-mounted device, etc., and the server can be an independent physical server, a server cluster composed of multiple physical servers, or a cloud server capable of cloud computing. This method can be implemented by a processor calling computer-readable program instructions stored in memory.

[0025] In an exemplary embodiment, the user interface generation method according to the embodiments of this application can be executed by an in-vehicle device. The following embodiments use the execution of the user interface generation method according to the embodiments of this application by an in-vehicle device as an example for explanation and description.

[0026] Exemplary methods Please see Figure 1 In one exemplary embodiment, a user interface generation method is provided. For example... Figure 1 As shown, the user interface generation method mainly includes the following steps: Step 101: Determine the user identity in the target vehicle and the driving context of the target vehicle.

[0027] In the exemplary embodiment, user identities include, but are not limited to, vehicle owners, family members, and visitors.

[0028] In the exemplary embodiment, the driving scenarios include, but are not limited to, high-speed driving and parking.

[0029] In some embodiments, such as Figure 2 As shown, step 101 includes: Step 201: Obtain the user identifier and user biometrics in the target vehicle, and determine the user identity in the target vehicle based on the user identifier and user biometrics.

[0030] In an exemplary embodiment, the user identifier may include a number such as a digital key.

[0031] In the exemplary embodiment, user biometrics may include, but are not limited to, facial features, fingerprints, and voiceprints. Typically, the facial features, fingerprints, and voiceprints of the user in the driver's seat are collected, and then the user's identity in the driver's seat of the target vehicle is identified based on the user identifier in the target vehicle and the facial features, fingerprints, and voiceprints of the user in the driver's seat. Of course, biometrics of users in other locations, such as the front passenger seat or rear seats, can also be collected to identify the user in the front passenger seat or rear seats of the target vehicle; this application does not impose any limitations on this.

[0032] In an exemplary embodiment, if the user's identity in the target vehicle can be accurately determined based on the user identifier and user biometrics, then step 202 is executed. If the user's identity in the target vehicle cannot be accurately determined based on the user identifier and user biometrics, then step 201 is returned to be executed to continue obtaining the user identifier and user biometrics in the target vehicle.

[0033] Since simply using a user identifier cannot accurately determine the identity of the user in the target vehicle, and other people can also use digital keys to unlock the target vehicle, it is necessary to combine the user identifier with the user's biometrics to determine the identity of the user in the target vehicle, with the user's biometrics being the primary criterion.

[0034] Step 202: Obtain the vehicle status and task status of the target vehicle, and determine the driving situation of the target vehicle based on the vehicle status and task status.

[0035] In the exemplary embodiment, vehicle status includes, but is not limited to, vehicle speed, gear position, remaining battery / fuel level, etc.

[0036] In the exemplary embodiment, the task state refers to the function that the target vehicle is currently accessing, including but not limited to navigation, calling, and media.

[0037] In an exemplary embodiment, determining the driving context of the target vehicle based on the vehicle state and the task state may include: determining the driving state of the target vehicle based on the vehicle state, for example, the driving state may include high-speed driving, parking, etc.; determining the function currently accessed by the target vehicle based on the task state; and determining the driving context of the target vehicle based on the driving state of the target vehicle and the function currently accessed by the target vehicle, for example, the driving context of the target vehicle may include the driving state of the target vehicle and the function currently accessed by the target vehicle.

[0038] In an exemplary embodiment, multi-source heterogeneous data can be continuously collected at a high refresh rate. For example, sensor data, CAN (Controller Area Network) bus data, data from biometric hardware interfaces (e.g., cameras, fingerprint modules, etc.), cloud service status, etc. can be collected in real time. Then, the multi-source heterogeneous data can be preprocessed, such as performing time synchronization, noise filtering, data normalization, etc., to generate a real-time context vector. The context vector includes user identifier, user biometric features, vehicle status, and task status.

[0039] In an exemplary embodiment, the user in the driver's seat may collect only facial features, fingerprints, voiceprints, etc.; or the user in the driver's seat may collect not only facial features, fingerprints, voiceprints, etc., but also fatigue level, attention level, emotional state, etc. When determining the driving situation of the target vehicle, it may not only be based on the vehicle status and task status, but also combined with the fatigue level, attention level, emotional state, etc. of the user in the driver's seat to comprehensively determine the driving situation of the target vehicle, and then determine the access permission function.

[0040] In exemplary embodiments, biometric data collection is generally not required for the front passenger seat or rear seats. It is only necessary to determine whether anyone is present in these seats and their condition. When determining the driving context of the target vehicle, it is possible to consider not only the vehicle's and task's states but also the presence and condition of anyone in the front passenger seat and rear seats to comprehensively determine the driving context and thus the permitted functions. For example, whether the user in the front passenger seat or rear seat has an elevated body temperature and needs air conditioning. Another example is that if someone is in the front passenger seat, privacy functions used by the driver can be hidden from the screen and played through headphones.

[0041] Based on user identifiers and user biometrics, the identity of the user in the target vehicle is determined. Based on the vehicle status and task status, the driving context of the target vehicle is determined. In the process of determining the identity of the user in the target vehicle and the driving context of the target vehicle, multi-source data is used, which can accurately identify the identity of the user in the target vehicle and accurately identify various driving contexts of the target vehicle. In turn, it can accurately determine the allowed access functions and the sensitive data access permissions corresponding to the allowed access functions, so as to achieve the accurate generation of the target user interface.

[0042] Step 102: Based on user identity and driving context, determine the allowed access functions and the corresponding sensitive data access permissions.

[0043] In some embodiments, such as Figure 3 As shown, step 102 includes: Step 301: Based on the user's identity and driving context, find the function access permissions and sensitive data access permissions corresponding to each function from the preset permission matrix.

[0044] The preset permission matrix stores the mapping relationship between user identity, driving context, function, function access permission, and sensitive data access permission.

[0045] In the exemplary embodiment, the preset permission matrix defines the function access permissions and sensitive data access permissions for different user identities under different driving scenarios. Function access permissions may include, but are not limited to, allow, deny, and read-only. Sensitive data access permissions may include, but are not limited to, allow all access, allow partial access, and completely deny access.

[0046] Step 302: Based on the function access permissions corresponding to each function, determine the functions that are allowed to be accessed from each function.

[0047] In an exemplary embodiment, the function access permission may include, but is not limited to, allow, deny, read-only, etc., and functions with the function access permission set to allow or read-only are determined as allowed access functions.

[0048] Step 303: From the sensitive data access permissions corresponding to each function, find the sensitive data access permissions corresponding to the functions that are allowed to access.

[0049] Based on user identity and driving context, the system can quickly and accurately determine allowed access functions and the corresponding sensitive data access permissions by searching a preset permission matrix.

[0050] Step 103: Obtain the data to be displayed for the allowed access function, and perform desensitization processing on the data to be displayed based on the sensitive data access permission to obtain the secure data for the allowed access function.

[0051] In an exemplary embodiment, it is necessary to perform desensitization processing on data to be displayed that has insufficient access permissions (e.g., a visitor's home address). For example, if the user is a visitor, the home address and contact information are hidden. Desensitization processing may include masking, abstracting, or deleting sensitive data (such as home addresses and call records). For example, sensitive data can be tokenized, and the sensitive data can be masked with 32 randomly generated numbers. Visitors can only see these numbers, while car owners can see the masked content by clicking on it. This process is reversible.

[0052] Step 104: Based on the allowed access function and the security data of the allowed access function, generate the target user interface element and render the target user interface element to generate the target user interface.

[0053] In some embodiments, such as Figure 4 As shown, based on the allowed access function and the security data of the allowed access function, the target user interface elements are generated, including: Step 401: Based on the access permission function, the security data of the access permission function, and the user interface element template library, generate the predicted user interface elements.

[0054] Among them, the predicted user interface elements include atomic-level user interface elements.

[0055] In an exemplary embodiment, the user interface element template library may include basic atomic-level user interface element templates, color and font specifications, and safety constraints (SCLs) to guide the generative model in ensuring the target user interface complies with safety and aesthetic requirements. Safety constraints ensure that the generated predicted user interface elements conform to driving safety regulations in terms of size, contrast, animation speed, etc.

[0056] In some embodiments, step 401 includes: inputting user identity, driving context, allowed access functions, security data of allowed access functions, and user interface element template library into a generative model to generate predicted user interface elements.

[0057] In an exemplary embodiment, the generative model can be a lightweight generative model, such as a lightweight Transformer, ensuring millisecond-level response times.

[0058] In an exemplary embodiment, the generative model can consider the priority of the current task when generating predictive user interface elements. The priority of each task is preset. For example, the priority of security alerts is higher than the priority of listening to music. Based on the priorities of the multiple tasks currently being executed, it determines which task's corresponding user interface element to generate first.

[0059] Generative models can dynamically predict the simplest, most optimal, and most relevant layout, size, and content of user interface elements for the current user and driving context based on user identity, driving situation, allowed access functions, security data of allowed access functions, and user interface element template library. They output predicted user interface elements, which include atomic user interface elements (e.g., cards, buttons, etc.) and do not contain any traditional menus or hierarchical navigation commands. This avoids traditional multi-level menus, achieves zero-level targeting of the target user interface, and improves the responsiveness of the target user interface.

[0060] Step 402: Perform a security constraint check on the predicted user interface elements, and determine the predicted user interface elements that pass the security constraint check as the target user interface elements.

[0061] Based on the access permission function, the security data of the access permission function, and the user interface element template library, predictive user interface elements are first generated. These predictive user interface elements include atomic user interface elements. Then, the predictive user interface elements that pass the security constraint check are determined as the target user interface elements. This ensures that the target user interface obtained by rendering the target user interface elements will not distract the driver in driving scenarios. Moreover, the predictive user interface elements include atomic user interface elements (e.g., cards, buttons, etc.) and do not contain any traditional menu or hierarchical navigation call commands, avoiding traditional multi-level menus and achieving zero-level target user interface, thereby improving the responsiveness of the target user interface.

[0062] In some embodiments, step 402 includes: Determine whether the predicted user interface elements meet safe driving requirements, whether the functions referenced by the predicted user interface elements are included in the allowed access functions, and whether the data referenced by the predicted user interface elements are included in the safe data of the allowed access functions; If it is determined that the predicted user interface element meets the requirements for safe driving, and the function referenced by the predicted user interface element is included in the allowed access function, and the data referenced by the predicted user interface element is included in the safety data of the allowed access function, then the safety constraint check of the predicted user interface element is determined to be passed. The predicted user interface elements that pass the safety constraint check are identified as the target user interface elements.

[0063] In an exemplary embodiment, safe driving requirements may include: in situations where the vehicle is traveling at high speed, requiring the model to predict the number of user interface elements to be below a preset threshold, and prohibiting the rendering of complex media content that may distract the driver.

[0064] If it is determined that the predicted user interface element meets the requirements for safe driving, the function referenced by the predicted user interface element is included in the allowed access function, and the data referenced by the predicted user interface element is included in the security data of the allowed access function, then the predicted user interface element is determined to pass the safety constraint check. The predicted user interface element that passes the safety constraint check is determined as the target user interface element. This can strictly ensure that the target user interface element will not distract the driver's attention in the driving scenario, and meets the requirements of the current user identity and driving situation.

[0065] In an exemplary embodiment, if the security constraint check fails, the user identity, driving context, allowed access functions, security data of allowed access functions, and user interface element template library can be re-input into the generative model to regenerate the predicted user interface elements.

[0066] In an exemplary embodiment, rendering the target user interface element and generating the target user interface can be achieved by sending the target user interface element to a hardware renderer and calling an atomic-level user interface component library for real-time rendering, thereby achieving extremely fast interface generation and switching. This eliminates the need for traditional multi-level menus and stacked structures, and achieves a "zero-level" or "instant" experience for information acquisition.

[0067] In some embodiments, the user interface generation method further includes: Real-time monitoring of changes in user identity and driving context; If the user identity and / or driving context change, clear the target user interface and regenerate a new target user interface based on the latest user identity and the latest driving context.

[0068] The system monitors user identity and driving context in real time. If these changes occur, the target user interface is cleared, triggering an immediate forced reset. This clears the previous user's cache and data environment, protecting the previous user's privacy and ensuring access control isolation. Based on the latest user identity and driving context, a new target user interface is regenerated. This allows for the dynamic and seamless generation of a zero-level interface with strictly isolated permissions and highly relevant information, enabling seamless identity switching, complete access control isolation, and highly efficient contextualized interaction.

[0069] In the exemplary embodiment, during the process of regenerating a new target user interface based on the latest user identity and driving context, a new permission environment is generated according to the principle of least privilege, achieving seamless yet thorough isolation. The principle of least privilege is a fundamental principle overall; for example, only the basic interface that enables driving functions is displayed to the designated driver.

[0070] In an exemplary embodiment, when the user identity and / or driving context change, a transition animation is used to switch the target user interface to a new target user interface, achieving a seamless visual transition between the old and new target user interfaces.

[0071] In summary, this application determines the user's identity and driving context within the target vehicle. Based on this identity and context, it determines permitted access functions and their corresponding sensitive data access permissions. Setting different permitted access functions and sensitive data access permissions for different user identities and driving contexts enhances the security of the vehicle's user interface. Furthermore, by de-sensitizing the data to be displayed for permitted access functions based on sensitive data access permissions, secure data for these functions is obtained. Based on the permitted access functions and their secure data, target user interface elements are generated and rendered to create the target user interface. This ensures that the target user interface does not leak sensitive data, and that visitors or unauthorized users cannot access or view private information without authorization, further enhancing the security of the vehicle's user interface.

[0072] Exemplary device Accordingly, embodiments of this application also provide a user interface generation apparatus, such as... Figure 5 As shown, the user interface generation apparatus includes: The context awareness unit 501 is used to determine the user identity in the target vehicle and the driving context of the target vehicle; The permission determination unit 502 is used to determine the allowed access function and the sensitive data access permissions corresponding to the allowed access function based on the user identity and the driving context; The desensitization unit 503 is used to obtain the data to be displayed for the allowed access function, and to perform desensitization processing on the data to be displayed based on the sensitive data access permission to obtain the secure data for the allowed access function. The generation unit 504 is used to generate target user interface elements based on the access permission function and the security data of the access permission function, and to render the target user interface elements to generate the target user interface.

[0073] The user interface generation apparatus provided in this embodiment belongs to the same concept as the user interface generation method provided in the above embodiments of this application. It can execute the user interface generation method provided in any of the above embodiments of this application and has the corresponding functional modules and beneficial effects for executing the user interface generation method. Technical details not described in detail in this embodiment can be found in the specific processing content of the user interface generation method provided in the above embodiments of this application, and will not be repeated here.

[0074] The functions implemented by the above-mentioned context-aware unit 501, permission determination unit 502, desensitization unit 503 and generation unit 504 can be implemented by the same or different processors, and this application embodiment does not limit them.

[0075] It should be understood that the units in the above device can be implemented by a processor calling software. For example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of each unit in the device. The processor can be a general-purpose processor, such as a CPU or microprocessor, and the memory can be internal or external to the device. Alternatively, the units in the device can be implemented as hardware circuits. By designing the hardware circuits, some or all of the unit functions can be implemented. The hardware circuits can be understood as one or more processors. For example, in one implementation, the hardware circuit is an ASIC, and the functions of some or all of the above units are implemented by designing the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a PLD, such as an FPGA, which can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files to implement the functions of some or all of the above units. All units in the above device can be implemented entirely by a processor calling software, entirely by hardware circuits, or partially by a processor calling software with the remaining parts implemented by hardware circuits.

[0076] In this application embodiment, a processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a CPU, microprocessor, GPU, or DSP. In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. These logical relationships are fixed or reconfigurable. For example, the processor may be a hardware circuit implemented as an ASIC or PLD, such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the processor loading instructions to implement the functions of some or all of the above units. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as an NPU, TPU, or DPU.

[0077] As can be seen, each unit in the above device can be one or more processors (or processing circuits) configured to implement the above methods, such as: CPU, GPU, NPU, TPU, DPU, microprocessor, DSP, ASIC, FPGA, or a combination of at least two of these processor forms.

[0078] Furthermore, the units in the above devices can be integrated in whole or in part, or they can be implemented independently. In one implementation, these units are integrated together and implemented in the form of a System-on-Chip (SoC). The SoC may include at least one processor for implementing any of the above methods or implementing the functions of the units in the device. The at least one processor may be of different types, such as CPU and FPGA, CPU and artificial intelligence processor, CPU and GPU, etc.

[0079] Exemplary electronic devices One embodiment of this application discloses an electronic device, see [link to relevant documentation] Figure 6 As shown, the device includes: Memory 200 and processor 210; The memory 200 is connected to the processor 210 and is used to store programs; The processor 210 is configured to implement the user interface generation method disclosed in any of the above embodiments by running the program stored in the memory 200.

[0080] Specifically, the aforementioned electronic device may also include: a bus, a communication interface 220, an input device 230, and an output device 240.

[0081] The processor 210, memory 200, communication interface 220, input device 230, and output device 240 are interconnected via a bus. Among them: A bus can include a pathway for transmitting information between various components of a computer system.

[0082] Processor 210 can be a general-purpose processor, such as a general-purpose central processing unit (CPU), a microprocessor, etc., or an application-specific integrated circuit (ASIC), or one or more integrated circuits used to control the execution of the program of the present invention. It can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0083] Processor 210 may include a main processor, as well as a baseband chip, modem, etc.

[0084] The memory 200 stores a program that executes the technical solution of this invention, and may also store an operating system and other key business functions. Specifically, the program may include program code, which includes computer operation instructions. More specifically, the memory 200 may include read-only memory (ROM), other types of static storage devices capable of storing static information and instructions, random access memory (RAM), other types of dynamic storage devices capable of storing information and instructions, disk storage, flash memory, etc.

[0085] Input device 230 may include a device for receiving user input data and information, such as a keyboard, mouse, camera, scanner, light pen, voice input device, touch screen, pedometer, or gravity sensor.

[0086] Output device 240 may include devices that allow information to be output to a user, such as a display screen, printer, speaker, etc.

[0087] The communication interface 220 may include a device that uses any transceiver to communicate with other devices or communication networks, such as Ethernet, Radio Access Network (RAN), Wireless Local Area Network (WLAN), etc.

[0088] The processor 210 executes the program stored in the memory 200 and calls other devices, which can be used to implement the various steps of any of the user interface generation methods provided in the above embodiments of this application.

[0089] Exemplary vehicle One embodiment of this application provides a vehicle that includes the electronic equipment provided in the above embodiments of this application.

[0090] For technical details not described in detail in this embodiment, please refer to the specific processing content of the electronic device provided in the above embodiments of this application, which will not be repeated here.

[0091] Exemplary computer program products and storage media In addition to the methods and apparatus described above, embodiments of this application may also be computer program products, which include computer program instructions that, when executed by a processor, cause the processor to perform the steps in the user interface generation methods according to various embodiments of this application as described in any of the above embodiments of this specification.

[0092] The computer program product can be written in any combination of one or more programming languages ​​to perform the operations of the embodiments of this application. The programming languages ​​include object-oriented programming languages ​​such as Java and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0093] Furthermore, embodiments of this application may also be storage media storing a computer program, which is executed by a processor through steps in the user interface generation method according to various embodiments of this application described above. Specifically, the following steps can be implemented: Step 101: Determine the user identity in the target vehicle and the driving context of the target vehicle.

[0094] Step 102: Based on user identity and driving context, determine the allowed access functions and the corresponding sensitive data access permissions.

[0095] Step 103: Obtain the data to be displayed for the allowed access function, and perform desensitization processing on the data to be displayed based on the sensitive data access permission to obtain the secure data for the allowed access function.

[0096] Step 104: Based on the allowed access function and the security data of the allowed access function, generate the target user interface element and render the target user interface element to generate the target user interface.

[0097] For the foregoing method embodiments, in order to simplify the description, they are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, because according to this application, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0098] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For apparatus embodiments, since they are basically similar to method embodiments, the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

[0099] The steps in the methods of the various embodiments of this application can be adjusted, merged, or deleted in order according to actual needs, and the technical features described in each embodiment can be replaced or combined.

[0100] The modules and sub-modules in the apparatus and terminal in the various embodiments of this application can be merged, divided, and deleted according to actual needs.

[0101] It should be understood that the disclosed terminals, devices, and methods can be implemented in other ways, given the several embodiments provided in this application. For example, the terminal embodiments described above are merely illustrative. For instance, the division of modules or sub-modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple sub-modules or modules may be combined or integrated into another module, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or modules, and may be electrical, mechanical, or other forms.

[0102] The modules or submodules described as separate components may or may not be physically separate. The components that constitute a module or submodule may or may not be physical modules or submodules; that is, they may be located in one place or distributed across multiple network modules or submodules. Some or all of the modules or submodules can be selected to achieve the purpose of this embodiment's solution, depending on actual needs.

[0103] Furthermore, the functional modules or sub-modules in the various embodiments of this application can be integrated into one processing module, or each module or sub-module can exist physically separately, or two or more modules or sub-modules can be integrated into one module. The integrated modules or sub-modules described above can be implemented in hardware or in the form of software functional modules or sub-modules.

[0104] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0105] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software unit executed by a processor, or a combination of both. The software unit can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0106] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0107] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for generating a user interface, characterized in that, include: Determine the user identity in the target vehicle and the driving context of the target vehicle; Based on the user identity and the driving context, determine the allowed access function and the sensitive data access permissions corresponding to the allowed access function; Obtain the data to be displayed for the allowed access function, and perform desensitization processing on the data to be displayed based on the sensitive data access permission to obtain the secure data for the allowed access function; Based on the access permission function and the security data of the access permission function, a target user interface element is generated and rendered to generate the target user interface.

2. The user interface generation method according to claim 1, characterized in that, Determining the user identity in the target vehicle and the driving context of the target vehicle includes: Obtain the user identifier and user biometric features in the target vehicle, and determine the user identity in the target vehicle based on the user identifier and user biometric features; The vehicle status and task status of the target vehicle are obtained, and the driving situation of the target vehicle is determined based on the vehicle status and task status.

3. The user interface generation method according to claim 1, characterized in that, The process of determining permitted access functions and corresponding sensitive data access permissions based on the user identity and the driving context includes: Based on the user identity and the driving context, the function access permissions and sensitive data access permissions corresponding to each function are retrieved from the preset permission matrix; wherein, the preset permission matrix stores the mapping relationship between user identity, driving context, function, function access permissions and sensitive data access permissions; Based on the access permissions corresponding to each function, determine the functions that are allowed to be accessed from each function; Find the sensitive data access permissions corresponding to the allowed access function from the sensitive data access permissions corresponding to each function.

4. The user interface generation method according to claim 1, characterized in that, The generation of target user interface elements based on the allowed access function and the security data of the allowed access function includes: Based on the access permission function, the security data of the access permission function, and the user interface element template library, predictive user interface elements are generated; wherein, the predictive user interface elements include atomic-level user interface elements; The predicted user interface elements are subjected to security constraint checks, and the predicted user interface elements that pass the security constraint checks are determined as the target user interface elements.

5. The user interface generation method according to claim 4, characterized in that, The process of generating predicted user interface elements based on the access permission function, the security data of the access permission function, and the user interface element template library includes: The user identity, the driving scenario, the allowed access functions, the security data of the allowed access functions, and the user interface element template library are input into the generative model to generate predicted user interface elements.

6. The user interface generation method according to claim 4, characterized in that, The step of performing security constraint checks on the predicted user interface elements and determining the predicted user interface elements that pass the security constraint checks as the target user interface elements includes: Determine whether the predicted user interface element meets safe driving requirements, whether the function referenced by the predicted user interface element is included in the allowed access function, and whether the data referenced by the predicted user interface element is included in the security data of the allowed access function; If the predicted user interface element meets the requirements for safe driving, and the function referenced by the predicted user interface element is included in the allowed access function, and the data referenced by the predicted user interface element is included in the security data of the allowed access function, then the safety constraint check of the predicted user interface element is determined to be passed. The predicted user interface elements that pass the safety constraint check are identified as the target user interface elements.

7. The user interface generation method according to any one of claims 1 to 6, characterized in that, The method further includes: Real-time monitoring of whether the user's identity and the driving situation change; If the user identity and / or the driving situation changes, the target user interface is cleared, and a new target user interface is regenerated based on the latest user identity and the latest driving situation.

8. A user interface generation apparatus, characterized in that, include: A context-aware unit is used to determine the user's identity in the target vehicle and the driving context of the target vehicle; The permission determination unit is used to determine the allowed access function and the sensitive data access permissions corresponding to the allowed access function based on the user identity and the driving context; The desensitization unit is used to obtain the data to be displayed for the allowed access function, and to desensitize the data to be displayed based on the sensitive data access permission to obtain the secure data for the allowed access function. The generation unit is used to generate target user interface elements based on the access permission function and the security data of the access permission function, and to render the target user interface elements to generate the target user interface.

9. An electronic device, characterized in that, Including memory and processor; The memory is connected to the processor and is used to store programs; The processor is used to implement the user interface generation method as described in any one of claims 1 to 7 by running a program in the memory.

10. A vehicle, characterized in that, Including the electronic device as described in claim 9.