显示设备、隐私保护方法和相关装置
By collecting environmental data and recognizing scenes through display devices, the system achieves unified synchronization and execution status monitoring of privacy management strategies in smart home systems, solving the privacy leakage problem under multi-device collaboration and improving the system's security and convenience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHENZHEN TAILIWEI INTELLIGENT TECHNOLOGY CO LTD
- Filing Date
- 2026-04-22
- Publication Date
- 2026-07-17
Smart Images

Figure CN122420008A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of displays, and in particular to a display device, a privacy protection method, and related devices. Background Art
[0002] With the deep integration of the Internet of Things and artificial intelligence technologies, the smart home ecosystem has evolved from the intelligence of single devices to a complex scenario of multi-device collaborative linkage. With its natural attribute as a centralized display device in the home, powerful local computing capabilities, and multi-modal interaction capabilities such as voice and vision, smart TVs have gradually evolved into the central control nodes of home smart homes.
[0003] In this scenario, the smart TV needs to coordinate and manage various terminal devices such as smart door locks, security cameras, environmental sensors, smart speakers, lighting systems, and curtains in real time to implement cross-device linkage services such as "going home mode" and "movie viewing mode". However, in this process, the smart TV and its associated devices will continuously collect and process a large amount of multi-dimensional home scenario data. These data are deeply related to users' living habits, family member compositions, work and rest patterns, and even property security, resulting in a significant increase in the risk of privacy leakage. Summary of the Invention
[0004] Embodiments of this application provide a display device, a privacy protection method, and related devices for reducing the risk of user privacy leakage.
[0005] In a first aspect, embodiments of this application provide a display device, including:
[0006] A display configured to display a picture;
[0007] A controller connected to the display, the controller being configured to:
[0008] Obtain current environmental data, perform environmental perception based on the environmental data locally, and determine the target scenario currently located;
[0009] According to the target scenario, obtain the corresponding privacy management policy, and synchronize the privacy management policy to the associated smart home devices;
[0010] Monitor the execution status of the smart home devices executing the privacy management policy, and control the display to display the execution status.
[0011] In some embodiments, the controller is configured to:
[0012] Obtain the level of the privacy management policy, and determine an encryption policy based on the level of the privacy management policy;
[0013] The communication process with the smart home device is encrypted based on the encryption strategy.
[0014] In some embodiments, the controller is configured to:
[0015] When data collection behavior that does not match the privacy management policy is detected, a prompt interface is displayed; the prompt interface includes data collection details and processing controls.
[0016] The data acquisition behavior is processed in response to the user's operation on the processing control.
[0017] In some embodiments, the controller is configured to:
[0018] Acquire the sensing data of the smart home devices;
[0019] The sensed data is desensitized locally to generate a structured first sequence of data;
[0020] The system can be linked with the smart home devices based on the first sequence data, and / or synchronized with the cloud based on the first sequence data.
[0021] In some embodiments, the controller is configured to:
[0022] Generate a second sequence of data that is logically consistent with the first sequence of data in the spatiotemporal dimension; the second sequence of data is fictitious perceptual data;
[0023] The first sequence data and the second sequence data are fused to obtain the target sequence data, and cloud synchronization is performed based on the target sequence data.
[0024] In some embodiments, the controller is configured to:
[0025] An adjustment coefficient is determined based on the perceived data; the adjustment coefficient is used to indicate the relative strength of privacy protection in the current scenario;
[0026] The target privacy budget is determined based on the adjustment coefficient and the baseline privacy budget.
[0027] The second sequence data is generated based on the target privacy budget and the first sequence data; the target privacy budget is used to indicate the proportion of the fictitious perceived data in the target sequence data.
[0028] In some embodiments, the controller is configured to:
[0029] Receive response data from the cloud for the target sequence data;
[0030] The response data is subjected to privacy reverse parsing, and based on the parsing results, it is determined whether the sensitivity feature correlation of the first sequence data determined by the cloud is greater than a preset threshold.
[0031] If so, the adjustment coefficient shall be adjusted.
[0032] In some embodiments, the controller is configured to:
[0033] The display is controlled to show the level of the privacy management policy and the status of the privacy data collected by the smart home device at the target location.
[0034] Secondly, embodiments of this application provide a privacy protection method, including:
[0035] Acquire current environmental data, and perform environmental perception locally based on the environmental data to determine the current target scene;
[0036] Based on the target scenario, obtain the corresponding privacy management policy and synchronize the privacy management policy to the associated smart home devices;
[0037] Monitor the execution status of the privacy management policy by the smart home devices and display the execution status.
[0038] Thirdly, this application provides an electronic device, including: a memory and a processor;
[0039] The memory is used to store computer instructions; the processor is used to execute the computer instructions stored in the memory to implement the method of any one of the first aspects.
[0040] Fourthly, this application provides a computer-readable storage medium having a computer program stored thereon, the computer program being executed by a processor to implement the method of any of the first aspects.
[0041] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the method of any one of the first aspects.
[0042] The display device, privacy protection method, and related apparatus provided in this application integrate environmental data collection, scene recognition, policy acquisition, device synchronization, status monitoring, and result display on a single display device. This makes the display device both a home interaction center and a privacy control hub. Local environmental awareness reduces the risk of original sensitive data being leaked, scene-driven policy matching improves the adaptability of privacy management to changes in the actual home situation, a unified cross-device synchronization mechanism enhances the consistency of execution among smart home devices, and execution status monitoring and display form a complete feedback loop, allowing users to intuitively see on the display whether the policy is effective and which specific devices it applies to. This improves upon the current problems of fragmented policies, delayed responses, invisible status, and inconsistent privacy control across multiple devices in privacy management, enhancing the security, collaboration, and ease of use of smart home systems in home scenarios, and providing users with reliable privacy protection throughout the entire scenario and process. Attached Figure Description
[0043] Figure 1 A scenario diagram provided for an embodiment of this application;
[0044] Figure 2 This is a schematic diagram of the structure of a display device provided in an embodiment of this application;
[0045] Figure 3 A flowchart illustrating a privacy protection method provided in this application embodiment. Figure 1 ;
[0046] Figure 4 A flowchart illustrating a privacy protection method provided in this application embodiment. Figure 2 ;
[0047] Figure 5 A flowchart illustrating a privacy protection method provided in this application embodiment. Figure 3 ;
[0048] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0049] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0050] In the embodiments of the present application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and roles, and the order thereof is not limited. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and the terms such as "first" and "second" do not necessarily mean different.
[0051] It should be noted that in the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the present application should not be construed as more preferred or more advantageous than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.
[0052] With the deep integration of Internet of Things and artificial intelligence technologies, the smart home ecosystem has evolved from the intelligence of single devices to complex scenarios of multi-device collaborative linkage. Display devices (such as smart TVs), with their natural attributes as centralized display devices in the home, powerful local computing capabilities, and multi-modal interaction capabilities such as voice and vision, have gradually evolved into the central control nodes of smart homes. In this scenario, the display device needs to coordinate and manage various terminal devices such as smart door locks, security cameras, environmental sensors, smart speakers, lighting systems, and curtains in real time, to realize cross-device linkage services such as "going home mode" (automatically opening the door, turning on the light, adjusting the temperature) and "movie viewing mode" (closing the curtain, dimming the light).
[0053] However, in this process, the display device and its associated devices will continuously collect and process a large amount of multi-dimensional home scenario data, including voice commands, environmental images, device operation status, and user behavior logs. These data are deeply related to users' living habits, family member composition, work and rest patterns, and even property security, resulting in a significant increase in the risk of privacy leakage.
[0054] For example, in the scenario of "visitors arriving", the user may hope to temporarily disable the camera and voice collection functions, but it is difficult for the existing technology to achieve the synchronization of privacy policies for multi-device collaboration; another example is that when sleeping at night, the user only needs to retain the low-power monitoring of the environmental sensor, but the existing solutions usually can only turn off the functions of each device manually, which is both cumbersome and easy to miss. Therefore, how to achieve the full life cycle protection of privacy data in the multi-device linkage scenario while ensuring the convenience of smart homes has become a key technical problem to be solved urgently.
[0055] In view of this, embodiments of this application provide a display device, method, and related apparatus. By enabling the display device to locally perceive the environmental state, determine the target scene, uniformly synchronize the privacy management strategy, and provide visual feedback on the execution status, a more consistent privacy control process can be formed in multi-device linkage scenarios. This improves the shortcomings of the prior art, such as dispersed strategies, delayed response, and invisible status, and enhances the security, collaboration, and ease of use of the smart home system.
[0056] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0057] Figure 1 This is a schematic diagram of a scenario provided for an embodiment of this application, such as... Figure 1 As shown, display devices (such as smart TVs) can be connected to other smart home devices (such as smart door locks, smart speakers, smart monitors, etc.) via wired or wireless means.
[0058] Display devices can coordinate and manage various smart home devices in real time to achieve cross-device linkage services such as "Home Mode" (automatic door opening, light turning, and temperature adjustment) and "Movie Mode" (closing curtains and dimming lights), thereby providing users with a good living experience.
[0059] Figure 2 This is a schematic diagram of the structure of a display device 20 provided in an embodiment of this application, as shown below. Figure 2 As shown, it includes: display 21 and controller 22.
[0060] Display 21 is configured to display images. For example, it may display the results of interactions with smart home devices.
[0061] The controller 22 is configured to perceive the current scene, determine the privacy management policy to be used based on the perceived scene, and synchronize the privacy management policy to the linked smart home devices so that the smart home devices execute the privacy management policy, thereby reducing the risk of privacy leakage.
[0062] The controller 22 is also configured to monitor the execution status (such as success or failure) of the privacy management policy implemented by the smart home device and control the display 21 to show the execution status.
[0063] The controller is the core processing unit connected to the display. It can be the main control chip of the display device, an embedded processor, a system-on-a-chip, a microcontroller unit, or an edge computing control module with an integrated neural network processing unit. The controller is used to perform functions such as data acquisition, scene recognition, policy retrieval, command issuance, status monitoring, and interface updates.
[0064] The display device provided in this application can have various implementation forms, such as a smart TV, laser projection device, monitor, electronic bulletin board, electronic table, etc. This application does not limit the type of display device.
[0065] The following is combined with Figure 3 The privacy protection method provided in the embodiments of this application is described with the controller as the execution subject.
[0066] Figure 3 This is a flowchart illustrating a privacy protection method provided in an embodiment of this application, such as... Figure 3 As shown, it includes:
[0067] S301. Obtain the current environmental data and perform environmental perception locally based on the environmental data to determine the current target scene.
[0068] In some embodiments, environmental data may include image data, sound data, ambient light data, human presence data, time data, temperature and humidity data, door lock status data, and other data reported by local sensors or associated devices.
[0069] Environmental perception based on environmental data refers to the analysis process by which the controller infers the current environmental state based on environmental data. Its goal is to transform scattered raw perception information into target scene labels with clear meaning.
[0070] The target scene is the scene classification result output by the environmental perception, which may include visitor scenes, nighttime rest scenes, movie-watching scenes, leaving home scenes, or family gathering scenes, etc.
[0071] In one possible implementation, the controller can periodically acquire environmental data through devices such as a local camera, microphone, ambient light sensor, infrared human body sensor module, and system clock module.
[0072] Image data can come from the front-facing camera of the display device or the door camera in the home LAN; sound data can come from the local microphone array; ambient light data can come from the light sensor; time data can be provided directly by the system clock; and door lock status data, doorbell trigger data, and operating status data of each device can be obtained from associated devices via LAN, Wi-Fi, Bluetooth, or wired bus.
[0073] After collecting the above data, the controller can perform local preprocessing on the raw data to improve the accuracy of subsequent scene recognition. For example, it can perform operations such as resolution compression, face region extraction, human contour detection, or moving target analysis on image data; it can perform operations such as endpoint detection, noise suppression, sound pressure statistics, and speech activity detection on sound data; and it can perform threshold normalization processing and map time data to time period labels on ambient light data.
[0074] In some embodiments, environmental perception based on environmental data can be accomplished using a pre-defined rule engine.
[0075] For example, the controller can pre-establish a scene determination rule base locally, match environmental data with the scene determination rules in the scene determination rule base, and determine the target scene.
[0076] For example, when the doorbell is triggered, the door camera detects a stranger's face, and there is high activity in the living room, it is determined to be a visitor scenario; when the time is within a preset nighttime range, the ambient light is in a low range, the room is continuously silent, and the intensity of human activity is below a threshold, it is determined to be a nighttime rest scenario; when the TV is playing, the indoor illuminance is reduced, the curtains are closed, and a stable human body is detected in the user's seating area, it is determined to be a movie-watching scenario.
[0077] In some embodiments, environmental perception based on environmental data can be accomplished using a local machine learning model.
[0078] For example, the controller can deploy lightweight classification models, multimodal fusion neural network models, or feature vector-based scene recognition models. After acquiring environmental data, the corresponding image features, sound features, lighting features, time features, and device status features from the environmental data can be concatenated and input into the deployed model to obtain the model outputs predefined scenes and their corresponding confidence scores. The controller can determine the scene corresponding to the maximum confidence score as the target scene, or maintain the original scene when the maximum confidence score is lower than a set threshold to avoid frequent jittering and switching.
[0079] In some embodiments, since the environmental data may contain sensitive information such as images, voice conversations, and daily routines of family members, the controller extracts, analyzes, and classifies the data locally without uploading the raw audio and video data to an external server. This reduces the risk of data exposure during transmission and cloud storage, and further reduces the risk of privacy leaks.
[0080] S302. Obtain the corresponding privacy management policy according to the target scenario, and synchronize the privacy management policy to the associated smart home devices.
[0081] In some embodiments, a privacy management strategy is a set of control rules corresponding to a target scenario, used to specify the data collection, transmission, processing, storage, and display methods of different smart home devices in the current scenario.
[0082] Privacy management policies can be stored in a local policy library associated with the controller, where a mapping relationship between target scenarios and privacy policies is pre-established.
[0083] For example, the controller can provide users with different levels of privacy policy templates, each template having a corresponding privacy management policy preset.
[0084] For example, the controller has three preset standard privacy policy templates: "high", "medium" and "low".
[0085] High privacy level template: Suitable for scenarios such as visitor arrivals and deep sleep at night. It prohibits the semantic uploading and raw audio capture of all voice commands; prohibits the capture and uploading of video streams from all cameras (including cameras built into and associated with display devices); and only allows the transmission and execution of device control commands (such as "turn on the living room lights" or "adjust the air conditioner to 26°C") from the TV or authorized devices.
[0086] Medium Privacy Level Template: Applicable to everyday family member activities. Voice commands are allowed, but real-time semantic analysis must be performed on the display device's local AI unit, and sensitive information must be anonymized. Only the anonymized command text or structured operation commands should be uploaded to the cloud service or sent to the execution device; video stream collection is prohibited.
[0087] Low privacy level template: Suitable for scenarios where users explicitly trust the platform or there are no external risks. Allows full data collection to support more accurate user habit learning, scenario-based service recommendations, and device-linked optimization.
[0088] Users can bind the above privacy level templates to the corresponding scenarios to form a policy library.
[0089] Optionally, after selecting the privacy level template corresponding to each scenario, users can also perform fine-grained privacy control at the device and data type levels through the "Advanced Settings" options of each privacy level template. For example, users can specify: never allow smart doorbells to upload videos at any level; only allow smart speakers to collect voice data between 3 and 5 pm; allow robot vacuums to upload map data, but prohibit them from uploading images taken by their cameras, etc.
[0090] Associated smart home devices are home terminal devices that are linked to display devices and can receive policy commands. For example, smart home devices may include smart door locks, security cameras, smart speakers, environmental sensors, lighting equipment, air conditioners, curtain controllers, robot vacuum cleaners, and other home IoT devices.
[0091] In one possible implementation, after the controller determines the target scenario, it initiates a policy retrieval request to the local storage unit. The retrieval fields include at least the scenario label, device type, data type, and privacy level.
[0092] For example, if the target scenario is a visitor scenario, the controller can retrieve high privacy-level policies from the policy library. These policies may include turning off the real-time acquisition of the living room camera, turning off the far-field sound pickup of the smart speaker, prohibiting the uploading of raw audio and video to the cloud, allowing the door lock to retain the door opening reminder, allowing the lighting and air conditioning to maintain linkage, and limiting the log retention period to a short period.
[0093] If the target scenario is a nighttime rest scenario, the controller can obtain a silent protection strategy, which may include rules such as disabling unnecessary microphone acquisition, restricting the use of cameras with flashing lights, keeping human presence sensors operating at low frequency, and retaining alarm events for local storage and summarizing and displaying them the next day.
[0094] If the target scenario is a movie-watching scenario, a strategy that prioritizes entertainment while maintaining privacy can be adopted, such as disabling unnecessary voice wake-up, retaining remote control interaction, suppressing background environmental monitoring, and maintaining automatic linkage between lights and curtains.
[0095] In some embodiments, after obtaining the privacy management policy, the controller can also modify it according to the preference parameters preset by family members. For example, it can retain the display of the door video thumbnail for the face scene of authorized family members, and impose stricter audio and video collection restrictions on the children's room device, so that the policy is both matched with the scene and consistent with the specific family configuration.
[0096] In some embodiments, when synchronizing the privacy management policy to the linked smart home devices, the controller converts the acquired privacy management policy into control commands that can be recognized by each device.
[0097] Since different devices may use different communication protocols and command formats, the controller can set up a protocol adaptation layer to map the unified semantic rules in the policy to operation codes, parameter fields and execution time limits for specific devices.
[0098] For example, commands such as "turn off video stream upload", "stop local recording", and "turn off microphone input" can be generated for camera devices; commands such as "disable cloud voice service" and "retain only local keyword recognition" can be generated for voice devices; and commands such as "retain control permissions" and "prohibit uploading user behavior logs" can be generated for environmental control devices. The controller can synchronize policies with the corresponding devices via LAN, Wi-Fi, Bluetooth infrared communication, or wired bus, and the specific synchronization method can be automatically selected according to the device access protocol.
[0099] In some embodiments, the controller can also execute batch synchronization privacy management policies according to device priorities. For example, cameras and microphones that involve the collection of sensitive data are set to high priority, and the controller immediately issues restriction policies to these devices after identifying the target scene; security devices such as door locks and alarms are set to the second highest priority, and their policies focus on retaining security alarms and restricting unnecessary data transmission; environmental devices such as lighting, curtains, and air conditioners retain scene linkage capabilities under the premise of privacy restrictions. This allows for the rapid blocking of the continued collection and transmission of highly sensitive data when the scene changes, and then the gradual adjustment of the collaborative state of other devices, thereby shortening the time for privacy protection to take effect.
[0100] To improve synchronization reliability, the controller can record the transmission timestamp, target device identifier, policy version number, and expected acknowledgment type after sending the policy command. If no acknowledgment is received from the device within the set timeout period, the controller can retry the transmission; if consecutive retries fail, the device is marked as an abnormal device and a backup policy is activated.
[0101] For example, strong controls can cut off cloud connectivity, prompt users to manually check, or retain only local isolation mode.
[0102] By automatically acquiring and synchronizing privacy management policies based on the target scenario, display devices no longer rely on users manually entering the settings interface for each device to make adjustments. Instead, they can automatically complete cross-device privacy collaboration when the target scenario changes. The mapping relationship between scenarios and privacy management policies gives privacy control environmental adaptability, and the unified privacy management policy synchronization mechanism allows various devices to enter a working mode consistent with the current scenario within the same time window, thereby effectively improving the current problems of scattered privacy management policies, inconsistent execution, and delayed response.
[0103] S303. Monitor the execution status of privacy management policies by smart home devices and control the display to show the execution status.
[0104] In some embodiments, the execution status may refer to the result information returned by the associated smart home device after receiving and processing the privacy management policy, and may include statuses such as executed, executing, execution failed, partially executed, and timed out.
[0105] The controller continuously monitors the execution status to conduct a closed-loop confirmation of whether the privacy policy is truly effective, and feeds the results back to the display.
[0106] In one possible implementation, the controller can use a combination of status acknowledgments and polling to monitor the execution status of smart home devices.
[0107] For example, after receiving a privacy management policy instruction, a smart home device first returns a receipt confirmation message, indicating that it has received and begun execution; then, upon completion of execution, it returns a result message containing the device identifier, policy version number, execution result code, and timestamp. For smart home devices that do not actively report results, the controller can send status query requests according to a preset polling cycle to query their current data acquisition switch status, upload status, local processing mode, and log policy mode.
[0108] The controller can compare the status returned by smart home devices with the target policy to determine the execution status of the privacy management policy. For example, if a camera reports that the video capture switch is off and there is no data output from the video stream upload channel, it is determined that the camera-related policy has been executed successfully; if a smart speaker reports that the voice capture module is still on, it is determined that the policy has not been fully executed; if the lighting device confirms that the linkage permission is retained, it is determined that the environmental adjustment retention policy has been executed.
[0109] In another possible implementation, the controller can use a combination of event subscription and heartbeat monitoring to monitor the execution status of smart home devices.
[0110] For example, for devices that support message subscription, the controller subscribes to events related to changes in their privacy status. Once a device switches its collection permissions, transmission mode, or storage mode, it pushes an event notification to the controller. For devices that do not have event push capabilities, the controller monitors their online status through heartbeat messages, attaching the current policy hash or policy version digest to the heartbeat. If the digest is inconsistent with the target policy, it triggers resynchronization or an anomaly flag.
[0111] In some embodiments, the controller may automatically perform corrective measures when it detects that a smart home device has failed to execute, partially executed, or failed to execute within a timeout period.
[0112] Corrective measures may include redistributing the original strategy, reducing the complexity of instructions and redistributing them in stages, switching to a more compatible backup strategy, temporarily isolating abnormal devices from external network communication, generating pending prompts on the display and recording fault logs.
[0113] Taking a camera device as an example, if the device does not return a successful state after the first "stop acquisition and stop uploading" policy is issued, the controller can first issue a "stop uploading" command separately, and then issue a "stop acquisition" command. If it still fails, the controller will block its outbound connection on the home gateway side and notify the user that the device needs to be checked. This ensures that the privacy protection goal is still achieved as much as possible when the device has insufficient compatibility or there is a momentary communication anomaly.
[0114] When monitoring the execution status of each smart home device, the controller converts the monitoring results into graphical interface elements that are easy for users to understand and drives the display to update in real time.
[0115] For example, the controller can display the execution status on the display through text information, color status, icon information, list information, progress bars, or animations.
[0116] For example, when most devices have completed policy execution while a few are still synchronizing, the display can show "Visitor scenario identified, 5 devices have taken effect, 1 device is synchronizing"; when a camera fails to execute, the display can show "Bedroom camera policy not effective, reason: device offline," along with a retry prompt. For high-priority devices, the controller can use top-level display or pop-up prompts to ensure users are promptly aware of potential privacy risks. To improve interaction consistency, the display can also simultaneously show the target scenario label and the current privacy level, such as "Nighttime rest—Privacy protection level medium-high—Microphone localization processing enabled," allowing users to understand the logical relationship between state changes and scenario changes.
[0117] This application continuously monitors the effectiveness of policies executed by various smart home devices and then displays the results in real time on a screen, providing users with verifiable and traceable execution feedback. This closed-loop mechanism not only improves the visibility of multi-device collaborative control but also triggers remedial actions promptly when anomalies are detected, reducing privacy gaps caused by device disconnection, protocol incompatibility, or execution failures.
[0118] The privacy protection method provided in this application integrates environmental data collection, scene recognition, policy acquisition, device synchronization, status monitoring, and result display on a single display device. This makes the display device both a home interaction center and a privacy control hub. Local environmental awareness reduces the risk of original sensitive data being leaked, scene-driven policy matching improves the adaptability of privacy management to changes in the actual home situation, a unified cross-device synchronization mechanism enhances the consistency of execution among smart home devices, and execution status monitoring and display form a complete feedback loop, allowing users to intuitively see on the display whether the policy is effective and which specific devices it applies to. This improves upon the current problems of fragmented policies, delayed responses, invisible status, and inconsistent privacy control across multiple devices in privacy management, enhancing the security, collaboration, and ease of use of smart home systems in the home environment, and providing users with reliable privacy protection throughout the entire scenario and process.
[0119] Based on the above embodiments, the following is combined with Figure 4 The privacy protection method provided in the embodiments of this application will be further explained.
[0120] Figure 4 A flowchart illustrating another privacy protection method provided in this application embodiment is shown below. Figure 4 As shown, it includes:
[0121] S401. Obtain the current environmental data and perform environmental perception locally based on the environmental data to determine the current target scene.
[0122] S402. Obtain the corresponding privacy management policy based on the target scenario.
[0123] The specific implementation methods shown in S401 and S402 in the embodiments of this application are the same as those shown in the embodiments of this application. Figure 3 The specific implementation methods for the corresponding steps are similar, and will not be repeated here.
[0124] S403. Obtain the encryption policy for communicating with smart home devices, and synchronize the privacy management policy to the associated smart home devices based on the encryption policy.
[0125] In some embodiments, the controller may determine the encryption rate based on the level of the privacy management policy.
[0126] For example, the privacy management policy level is obtained, and an encryption policy is determined based on the privacy management policy level; the communication process with smart home devices is encrypted based on the encryption policy.
[0127] The privacy management policy level is used to characterize the strength of privacy protection in the current scenario. The encryption policy refers to the encryption scheme determined according to the privacy management policy level, including encryption algorithms, key length, authentication strength, and key update mechanisms used in communication between the display device and smart home devices, thereby ensuring that data exchange between the display device and smart home devices has a security level that matches current privacy requirements.
[0128] For example, after obtaining the privacy management policy level, the controller first parses the level identifier and matches it with a pre-stored encryption mapping table to determine the corresponding encryption policy. The encryption mapping table can be stored in the controller's local storage unit, and it establishes a correspondence between multiple privacy levels (high, medium, and low) and different encryption strengths.
[0129] For example, any commands transmitted at a high privacy level use high-strength encryption algorithms such as the Chinese national standard SM4 / AES-256. De-identified commands transmitted at a medium privacy level use AES-128 encryption. Non-sensitive device status data transmitted at a low privacy level can be encrypted using the more efficient TLS standard channel. Encryption keys can be generated and managed by the display device based on a hardware security module (such as a TEE) to ensure end-to-end security.
[0130] During the encrypted communication between the display device and the smart home device, the controller first organizes the control commands, execution confirmation frames, status feedback frames and policy synchronization data to be sent into plaintext, then completes the encryption and encapsulation according to the determined encryption policy, and then sends them to the smart home device through the corresponding communication interface.
[0131] After receiving an encrypted message, the smart home device decrypts and verifies it based on the key information or session key pre-shared with the controller, then executes the corresponding control logic and returns the encrypted confirmation information.
[0132] In some embodiments, for devices that support two-way authentication, the controller can also perform identity verification and session negotiation before communication begins to ensure that the identities of both communicating parties are trustworthy and that the session key is valid. For devices involving sensitive data, such as cameras, microphones, and door locks, the controller can enable stricter encryption protection at a high privacy level to enhance the anti-eavesdropping capability of the transmission link; for low-sensitivity devices such as lighting and air conditioning, a lightweight encryption strategy can be adopted to maintain good real-time control performance.
[0133] Through the above methods, the controller can dynamically determine the encryption strategy based on the privacy management policy level and encrypt the communication process with smart home devices, thereby ensuring that the communication protection strength is consistent with current privacy requirements. This approach not only improves the security of control commands and status feedback during transmission but also avoids the resource waste or insufficient protection issues caused by fixed encryption methods, thereby enhancing the security, stability, and adaptability of multi-device interconnected communication in smart home scenarios.
[0134] S404. Monitor the execution status of privacy management policies by smart home devices and control the display to show the execution status.
[0135] The specific implementation method shown in S404 of this application embodiment is the same as Figure 3 The specific implementation methods for the corresponding steps are similar, and will not be repeated here.
[0136] S405. Control the display to show the level of the privacy management policy and the status of the smart home device collecting privacy data at the target location.
[0137] In some embodiments, the target location refers to a pre-defined privacy information display area on the display. For example, the target location may be located in the top status bar, side floating area, corner mark area, or fixed card area of the interface, and is used to present privacy-related information without obscuring the main display content.
[0138] The privacy management policy level is used to characterize the privacy protection strength corresponding to the current policy. It can be displayed as "high", "medium", "low" or corresponding graphic symbols so that users can quickly judge the control strength in the current home scenario.
[0139] The status of smart home devices collecting privacy data is used to indicate whether devices such as cameras, microphones, door lock linkage units, and environmental sensors are collecting data, whether they are turned off, whether they are only allowed to process locally, or whether they are in a restricted collection mode. This status can be indicated by text labels, icon colors, or dynamic markers.
[0140] After obtaining the privacy management policy corresponding to the target scenario, the controller maps the policy level to a displayable interface element, and generates display content in the target location by combining the real-time data collection status of each smart home device, so that the user can simultaneously confirm the policy level and device execution status on the same display interface.
[0141] By displaying policy levels and device data collection status at target locations, privacy management results are transformed from abstract control outcomes into intuitive, user-friendly interface information. Users can confirm the current policy strength and whether a device is still collecting sensitive data without having to access each device's settings interface individually. This display method can promptly expose differences in device execution after scene switching. When a device fails to disable data collection according to the policy, users can quickly identify the anomaly and take appropriate action through the interface. This improves the visibility of the privacy management process, enhances the consistency of multi-device collaborative control, and reduces the risk of privacy exposure due to unseen status.
[0142] S406. When data collection behavior that does not match the privacy management policy is detected, a prompt interface is displayed, and the data collection behavior is processed in response to the user's operation of the processing controls in the prompt interface.
[0143] In some embodiments, the notification interface refers to an interactive page that pops up on the display after abnormal data collection is detected, used to notify the user of the current privacy anomaly and provide an entry point for handling it. The notification interface may include data collection details and processing controls.
[0144] Data collection details are a visual description of abnormal data collection behavior, typically including at least the data collection device identifier, data type, collection time, collection status, and the reason for incompatibility with the current privacy management policy. Processing controls are interface elements that allow users to directly issue processing commands; they can be presented as buttons, menu items, or confirmation options, and their purpose is to enable users to have immediate control over abnormal data collection behavior.
[0145] For example, the controller can continuously receive collection status information from cameras, microphones, sensors, or other associated devices and compare it with the currently effective privacy management policy. When the comparison result shows that a device is still collecting data restricted by the policy, or that the collection scope, collection period, or upload method is inconsistent with the policy requirements, the controller generates a prompt interface and displays the corresponding device name, abnormal data type, and reason for violation as a data collection detail in the prompt interface.
[0146] The processing controls can correspond to operations such as "stop collection", "pause collection", "local processing only", "allow once", "modify policy" or "add to whitelist". After the user triggers any control, the controller sends a control command to the corresponding device according to the selected operation, or updates the collection permission parameters in the local policy library synchronously, thereby restricting, pausing, terminating, downgrading or allowing the data collection behavior.
[0147] When abnormal data acquisition involves video streams, audio streams, or environmental sensing data, the controller can also confirm the handling result by combining the device's current online status, communication receipts, and data stream status to ensure that the user's operation has actually taken effect on the corresponding data acquisition behavior. If the device experiences a response delay or command execution failure, the controller can prompt the user again and retain the current abnormal information so that the user can continue to select other processing controls to complete the intervention.
[0148] Through this method, the controller can promptly present abnormal details to the user when it detects inconsistencies between the privacy management policy and actual data collection behavior, and provide a direct and actionable entry point for handling the issue. This allows the user to quickly block, adjust, or allow abnormal data collection behavior. This approach improves the visibility and controllability of abnormal data collection, reduces the risk of continued collection and leakage of sensitive data without authorization, and enhances the timeliness and interactivity of privacy management in smart home scenarios.
[0149] In some embodiments, when the display device is linked with smart home devices or when the display device is synchronized with the cloud, in order to further reduce the risk of privacy leakage, the controller may also perform linkage control and / or cloud synchronization based on the de-identified data.
[0150] For example, the sensor data of the smart home device is acquired; the sensor data is de-identified locally to generate a structured first sequence of data; the smart home device is linked based on the first sequence of data, and / or the cloud is synchronized based on the first sequence of data.
[0151] In some embodiments, perceived data may refer to raw environmental or status information output by smart home devices. Examples include camera images, audio clips, human presence information, door lock status, lighting status, and device operation logs.
[0152] De-identification is the process of removing privacy markers or reducing information from raw data to reduce the risk of directly exposing sensitive content. For example, the controller can de-identify perceived data locally by blurring facial regions, weakening voice features, replacing identity markers, truncating address information, generalizing time trajectories, or stripping fields.
[0153] The first sequence of structured data is a set of computable data formed after desensitization. Its function is to organize the sensing results into data items with timestamps, device identifiers, event tags, and status summaries, which facilitates subsequent linkage control and cloud synchronization.
[0154] For example, the controller can set up a local perception access module, a privacy processing module, and a serialized output module. The perception access module receives the data reported by each smart home device through a local area network, wireless communication, or a bus. The privacy processing module performs local analysis on the received data and removes content that can identify personal identity. The serialized output module organizes the processed results into first-sequence data according to preset fields.
[0155] For example, if the perception data comes from a camera, the controller can only retain the human body contour, movement direction, or scene label. If the perception data comes from a speaker, only the voice command category or wake-up state can be retained. If the perception data comes from an environmental sensor, non-sensitive fields such as temperature, humidity, illumination, and switch state can be retained.
[0156] When performing linkage with smart home devices based on the first-sequence data, the controller can input the first-sequence data as a linkage trigger condition into the local control logic and generate control commands for lighting, air conditioning, curtains, door locks, or security devices accordingly, so as to achieve collaborative response between devices.
[0157] When performing cloud synchronization based on the first-sequence data, the controller only uploads the desensitized structured data, rather than the original perception data, enabling the cloud to complete remote status display, cross-device viewing, or model update while maintaining the protection of home privacy information.
[0158] The controller first completes the access and desensitization processing of perception data locally and then organizes the results into structured sequence data, so that both linkage control and cloud synchronization are executed based on low-sensitivity information. This method enables the linkage between smart home devices to be carried out based on unified and standardized data descriptions, reducing the adaptation cost caused by inconsistent data formats between different devices. At the same time, local desensitization reduces the possibility of leakage of original audio-video and status trajectories. Thereby improving the privacy protection ability and linkage consistency of display devices and reducing the leakage risk of sensitive data during transmission and storage.
[0159] In some embodiments, to further reduce the risk of privacy leakage, the controller can also adopt a strict data life cycle management strategy for data management.
[0160] For example, for the audio-video cache files stored locally in the display device and associated devices for temporary processing, an automatic cleaning period (such as every 24 hours) is set. The user can also manually trigger "clean immediately".
[0161] For the desensitized data or event logs that need to be uploaded to the cloud, a life cycle label is added when storing in the cloud. The system default setting is to retain the data for 90 days, notify the user before the expiration date, and automatically perform a secure erasure.
[0162] The display device provides a "Privacy Data Clear" entry, allowing users to initiate a command with one click to request all associated local devices and cloud servers to delete all historical privacy-related data associated with the user's identity, and providing a deletion completion report.
[0163] In some embodiments, the display device may also provide a privacy protection log interface to clearly display all policy automatic switching records, user intervention records, and data clearing records, making the entire privacy management process auditable and traceable.
[0164] In some embodiments, after the display device synchronizes structured information to the cloud, if the cloud uses a large inference model to perform complex intent inference, it may still infer the event flow of the user's home from the structured information, thereby leaking the user's privacy. To further reduce the risk of privacy leakage, the controller can also perform illusion injection on the synchronized content during the synchronization process to the cloud.
[0165] The following is combined with Figure 5 This section explains the process of injecting illusions into the synchronized content during the synchronization process from the controller to the cloud.
[0166] Figure 5 A flowchart illustrating a privacy protection method provided in this application embodiment. Figure 3 ,like Figure 5 As shown, it includes:
[0167] S501, Generate a second sequence of data that is logically consistent with the first sequence of data in the spatiotemporal dimension; the second sequence of data is fictional perceptual data.
[0168] In some embodiments, the second sequence data is a simulated sensing sequence (i.e., a non-real event sequence) generated by the controller based on the first sequence data, the temporal relationship of the devices, and the spatial distribution relationship. It maintains logical consistency with the first sequence data in terms of temporal sequence, spatial location, and event association, thereby avoiding obvious contradictions between fictional content and real content.
[0169] In one possible implementation, the controller can first analyze the timestamps, spatial tags, device identifiers, and event fields in the first sequence data to extract their rhythmic and distribution characteristics, and then generate the second sequence data accordingly, so that the second sequence data has a reasonable transition relationship between adjacent time slices and matches the device location relationship in the same scene.
[0170] In one possible implementation, the controller can also generate fictional fragments based on historical scene templates. For example, in a nighttime rest scene, it can generate simulated presence data with low activity levels; in a visitor arrival scene, it can generate short-term dwell time data at the doorway, so that the sequence received in the cloud presents a continuous and natural characteristic.
[0171] In one possible implementation, the controller can determine an adjustment coefficient based on the perceived data; the adjustment coefficient is used to indicate the relative strength of privacy protection in the current scenario; a target privacy budget is determined based on the adjustment coefficient and the baseline privacy budget; a second sequence of data is generated based on the target privacy budget and the first sequence of data; the target privacy budget is used to indicate the proportion of fictitious perceived data in the target sequence of data.
[0172] The adjustment coefficient is used to characterize the level of privacy risk and the strength of masking in the current scenario. After the controller performs scenario fusion on different perception data, it generates a coefficient value corresponding to the scenario risk.
[0173] The baseline privacy budget provides a default level of privacy protection. It can be pre-stored in the local policy library and set by the user in the family member configuration interface to suit different families' needs for balancing data availability and privacy protection.
[0174] The target privacy budget is the actual budget parameter calculated based on the baseline privacy budget and an adjustment coefficient. It is used to control the proportion of the second sequence data in the target sequence data, thereby controlling the perturbation intensity of the cloud-synchronized content.
[0175] For example, after acquiring the sensing data, the controller first performs feature extraction and scene discrimination on the sensing data, and determines the range of adjustment coefficient values based on scene types such as visitor arrival, nighttime rest, leaving home or family gathering.
[0176] When a scenario with high privacy sensitivity is identified, the controller increases the adjustment coefficient and adds a corresponding budget increment to the baseline privacy budget to obtain a larger target privacy budget; when the scenario with low privacy sensitivity is identified, the target privacy budget is reduced to reduce the proportion of fictitious perceived data introduced.
[0177] The controller then determines the number of fictitious events to be included in the second sequence of data based on the target privacy budget and the number of events included in the first sequence of data. Events are then generated based on the determined number of fictitious events to obtain the second sequence of data. After obtaining the second sequence of data, the first sequence of data can be arranged to insert fictitious events from the second sequence of data while maintaining spatiotemporal continuity, thus generating the second sequence of data. This makes the second sequence of data structurally consistent with the real data, while providing a controllable privacy masking effect in terms of content.
[0178] By constraining the proportion of fictitious events with a target privacy budget, the second-sequence data can be dynamically adjusted according to changes in the scenario. This enhances privacy masking capabilities in highly sensitive scenarios while maintaining high data availability in less sensitive scenarios, thereby improving the flexibility and consistency of privacy protection during cloud synchronization.
[0179] S502. Integrate the first sequence data and the second sequence data to obtain target sequence data, and perform cloud synchronization based on the target sequence data.
[0180] In some embodiments, when integrating, the controller may use methods such as time - slice insertion, field replacement, ratio mixing, or event splicing to combine the first sequence data and the second sequence data into target sequence data, and uniformly perform consistency verification on the integrated fields to avoid time inversion, spatial conflicts, or event mutations.
[0181] After obtaining the target sequence data, the controller can upload the target sequence data to the cloud server for cloud - state backup, cross - device linkage analysis, or service invocation. Since the cloud receives the target sequence data including fictional events, it can not only maintain the integrity of the data structure required for the service in the cloud, but also make it impossible to directly restore the real behavior trajectories of family members, thus enhancing the privacy protection level while ensuring the availability of cloud synchronization, and improving the security and privacy of the cloud synchronization process in the smart home scenario.
[0182] S503. Receive the response data from the cloud for the target sequence data.
[0183] S504. Perform privacy reverse parsing on the response data, and based on the parsing result, determine whether the sensitivity feature correlation degree of the first sequence data determined by the cloud is greater than a preset threshold. If so, adjust the adjustment coefficient.
[0184] In some embodiments, the response data may include the cloud's classification result, feature vector, confidence information, statistical summary, or control receipt for the target sequence data.
[0185] Privacy reverse parsing may refer to the process of the controller's leakage risk assessment of the response data, the purpose of which is to reverse - infer from the cloud feedback whether the cloud has identified the real events included in the target sequence data, that is, the first sequence data.
[0186] The sensitivity feature correlation degree of the first sequence data is used to characterize the association strength between the cloud's recognition result and the first sequence data. That the sensitivity feature correlation degree of the first sequence data is greater than the preset threshold may indicate that the cloud has identified the real event.
[0187] For example, after the controller receives the response data returned by the cloud, it first performs field parsing and semantic alignment on the response data, maps the cloud output to a feature description corresponding to the first sequence, and then calculates the correlation index in combination with the known structural features of the first sequence.
[0188] The relevance index can be composed of similarity, matching degree, confidence weighted value or statistical correlation coefficient. The controller compares it with a preset threshold. When it is determined that the cloud has a high degree of recognition of the data sensitive features of the first sequence, it means that the ability to mask the fictional perception data in the current target sequence data is insufficient.
[0189] When the correlation of sensitive features exceeds a preset threshold, the controller can adjust the adjustment coefficient. For example, increasing the adjustment coefficient can improve the privacy budget for subsequent targets, thereby increasing the proportion or perturbation intensity of fictitious perceived data in the target sequence data.
[0190] Through this method, the controller can dynamically evaluate the privacy masking effect based on cloud responses and promptly increase the privacy protection strength when it detects that the cloud has a strong correlation with the sensitive features of the first sequence data, thereby reducing the risk of inferring real sensitive information. Simultaneously, this method allows the generation of target sequence data to no longer employ a fixed protection level, but rather to adaptively adjust based on cloud feedback, improving the balance between privacy protection and data availability.
[0191] This application also provides an electronic device.
[0192] Figure 6 This is a schematic diagram of the structure of the electronic device 60 provided in the embodiments of this application, such as... Figure 6 As shown, the electronic device may include: a transceiver 601, a processor 602, and a memory 603. The electronic device may be a controller as described in any of the above embodiments.
[0193] The processor 602 executes computer execution instructions stored in the memory, causing the processor 602 to perform the scheme in the above embodiments. The processor 602 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0194] The memory 603 is connected to the processor 602 via the system bus and completes communication between them. The memory 603 is used to store computer program instructions.
[0195] Transceiver 601 can perform the functions of receiving and sending data and instructions.
[0196] Optionally, the electronic device 60 may also include a communication interface to communicate and interact with external or internal devices, such as client devices (e.g., mobile phones, tablets). In specific implementations, if the communication interface, memory 603, and processor 602 are implemented independently, they can be interconnected via a bus to complete communication with each other.
[0197] The system bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The system bus can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in the diagram, but this does not indicate that there is only one bus or one type of bus. Transceivers are used to enable communication between database access devices and other computers (e.g., clients, read-write libraries, and read-only libraries). Memory may include random access memory (RAM) and may also include non-volatile memory.
[0198] Optionally, in a specific implementation, if the communication interface, memory 603, and processor 602 are integrated on a single chip, then the communication interface, memory 603, and processor 602 can communicate through an internal interface.
[0199] This application also provides a chip for executing instructions, which is used to execute the technical solutions of the methods described in the above embodiments.
[0200] This application also provides a computer-readable storage medium storing a computer program thereon. When the computer program is executed by a processor, it implements the technical solution of the above method embodiment. Its implementation principle and technical effect are similar, and will not be repeated here.
[0201] In one possible implementation, a computer-readable medium may include random access memory (RAM), read-only memory (ROM), compact discread-only memory (CD-ROM) or other optical disc storage, disk storage or other magnetic storage devices, or any other medium targeted to carry or to store the required program code in the form of instructions or data structures, and accessible by a computer. Furthermore, any connection is appropriately referred to as a computer-readable medium. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, Digital Subscriber Line (DSL), or wireless technologies such as infrared, radio, and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. As used herein, disks and optical discs include optical discs, laser discs, optical discs, Digital Versatile Discs (DVDs), floppy disks, and Blu-ray discs, where disks typically reproduce data magnetically, while optical discs optically reproduce data using lasers. Combinations of the above should also be included within the scope of computer-readable media.
[0202] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the technical solution of the above method embodiments. Its implementation principle and technical effects are similar, and will not be repeated here.
[0203] In the specific implementation of the aforementioned terminal device or server, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of this application can be directly manifested as execution by a hardware processor, or execution by a combination of hardware and software modules within the processor.
[0204] Those skilled in the art will understand that all or part of the steps in any of the above method embodiments can be implemented by hardware associated with program instructions. The aforementioned program can be stored in a computer-readable storage medium, and when the program is executed, all or part of the steps in the above method embodiments are performed.
[0205] If the technical solution of this application is implemented in software form and sold or used as a product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the technical solution of this application can be embodied in the form of a software product, which is stored in a storage medium and includes a computer program or several instructions. This computer software product enables a computer device (which may be a personal computer, server, network device, or similar electronic device) to execute all or part of the steps of the methods in the embodiments of this application.
[0206] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0207] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0208] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.
[0209] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.
[0210] When integrated units / modules are implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.
[0211] If the integrated unit / module is implemented as a software program module and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0212] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.
[0213] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A display device, characterized in that, The display device includes: The monitor is configured to display images; A controller connected to the display is configured to: Acquire current environmental data, and perform environmental perception locally based on the environmental data to determine the current target scene; Based on the target scenario, obtain the corresponding privacy management policy and synchronize the privacy management policy to the associated smart home devices; Monitor the execution status of the privacy management policy by the smart home device, and control the display to show the execution status.
2. The display device according to claim 1, characterized in that, The controller is configured to: Obtain the level of the privacy management policy, and determine the encryption policy based on the level of the privacy management policy; The communication process with the smart home device is encrypted based on the encryption strategy.
3. The display device according to claim 1, characterized in that, The controller is configured to: When data collection behavior that does not match the privacy management policy is detected, a prompt interface is displayed; the prompt interface includes data collection details and processing controls. The data acquisition behavior is processed in response to the user's operation on the processing control.
4. The display device according to any one of claims 1-3, characterized in that, The controller is configured to: Acquire the sensing data of the smart home devices; The sensed data is desensitized locally to generate a structured first sequence of data; The system can be linked with the smart home devices based on the first sequence data, and / or synchronized with the cloud based on the first sequence data.
5. The display device according to claim 4, characterized in that, The controller is configured to: Generate a second sequence of data that is logically consistent with the first sequence of data in the spatiotemporal dimension; the second sequence of data is fictitious perceptual data; The first sequence data and the second sequence data are fused to obtain the target sequence data, and cloud synchronization is performed based on the target sequence data.
6. The display device according to claim 5, characterized in that, The controller is configured to: An adjustment coefficient is determined based on the perceived data; the adjustment coefficient is used to indicate the relative strength of privacy protection in the current scenario; The target privacy budget is determined based on the adjustment coefficient and the baseline privacy budget. The second sequence data is generated based on the target privacy budget and the first sequence data; the target privacy budget is used to indicate the proportion of the fictitious perceived data in the target sequence data.
7. The display device according to claim 6, characterized in that, The controller is configured to: Receive response data from the cloud for the target sequence data; The response data is subjected to privacy reverse parsing, and based on the parsing results, it is determined whether the sensitivity feature correlation of the first sequence data determined by the cloud is greater than a preset threshold. If so, the adjustment coefficient shall be adjusted.
8. The display device according to any one of claims 1-3, characterized in that, The controller is configured to: The display is controlled to show the level of the privacy management policy and the status of the privacy data collected by the smart home device at the target location.
9. A privacy protection method, characterized in that, include: Acquire current environmental data, and perform environmental perception locally based on the environmental data to determine the current target scene; Based on the target scenario, obtain the corresponding privacy management policy and synchronize the privacy management policy to the associated smart home devices; Monitor the execution status of the privacy management policy by the smart home devices and display the execution status.
10. The method according to claim 9, characterized in that, include: Acquire the sensing data of the smart home devices; The sensed data is desensitized locally to generate a structured first sequence of data; Generate a second sequence of data that is logically consistent with the first sequence of data in the spatiotemporal dimension; the sequence of data is fictitious perceptual data; The first sequence data and the second sequence data are fused to obtain the target sequence data, and cloud synchronization is performed based on the target sequence data.
11. A computer-readable storage medium, characterized in that, It stores a computer program thereon, which is executed by a processor to implement the method of any one of claims 9-10.
12. A computer program product, characterized in that, It includes a computer program that, when executed by a controller, implements the method of any one of claims 9-10.