Access restriction of vehicle-associated information

JP2024065065A5Active Publication Date: 2025-07-24BLACKBERRY LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023183755
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-10-28
Filing Date
2023-10-26
Publication Date
2025-07-24
Estimated Expiration
2043-10-26

AI Technical Summary

Technical Problem

Existing access control methods for vehicle-related information provide either excessive exposure or insufficient access, leading to privacy and security concerns due to coarse granularity of permissions.

Method used

A system that employs a vehicle-related information filtering engine to control access based on machine learning usage criteria, vehicle motion status, person identification, and geofence associations, using access control rules to restrict or allow access to vehicle data based on predefined criteria.

Benefits of technology

Enhances data privacy by reducing the sampling rate of vehicle information and ensuring secure access, while maintaining the functionality of machine learning models and applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To restrict access to vehicle-associated information based on privacy criteria.SOLUTION: In some examples, a system receives vehicle-associated information from a data source associated with a vehicle, and restricts access to the vehicle-associated information based on at least one privacy criterion selected from among a machine learning use criterion relating to the use of the vehicle-associated information by a machine learning model, a vehicle motion criterion relating to a movement status of the vehicle, and a person identification information criterion relating to identification information of a person in the vehicle.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Background technology]

[0001] Detailed Description of the Invention A vehicle may contain or receive data from sources that provide vehicle-related information. The data sources may be internal or external to the vehicle. An entity may attempt to access vehicle-related information regardless of whether it is internal or external to the vehicle.

[0002] It may be desirable to limit access to vehicle-related information, to protect privacy (e.g., privacy of passengers in a vehicle, privacy of an owner of a vehicle, etc.), to provide security, or for other purposes. In some examples, access to vehicle-related information may be based on a permission associated with a requesting entity, such as a user, a program, or a machine. The access permission may specify whether an entity is authorized to access the vehicle-related information. The access permission may be an all-or-none permission, i.e., a requesting entity may have either full access to the vehicle-related information or no access to the vehicle-related information. Coarse-grained access control using permissions may result in either too much vehicle-related information being exposed or too little vehicle-related information being provided.

[0003] Examples of vehicle-related information may include any or a combination of the following: data from the vehicle's sensors (e.g., a speedometer to measure the vehicle's speed, an accelerometer to measure the vehicle's acceleration, vehicle fluid monitoring sensors, tire pressure sensors, temperature sensors, pressure sensors, humidity sensors, engine speed sensors, etc.), vehicle location data, still or video images (inside or outside the vehicle), data stored in a storage medium within the vehicle, identification information related to the vehicle's occupants (driver or passengers), data related to the use of the vehicle's safety devices (e.g., seat belts, anti-lock brakes, crash avoidance control systems, etc.), data related to facial recognition or other biometric data, data related to the vehicle's occupants (e.g., weight, seat position, etc.), or any other vehicle-related information.

[0004] The vehicle-related information can originate from a data source within the vehicle, or alternatively or additionally, can be generated by a data source external to the vehicle. For example, the data source can be part of a roadside unit (RSU), a remote server, or the like. Examples of RSUs can include traffic lights, electronic road signs, or any other electronic device located on or near a roadway over which the vehicle travels. A remote server can refer to a computer system (including a computer or multiple computers), such as a computer system that is part of a cloud, a data center, a web environment, or the like. The present invention provides, for example, the following items. (Item 1) A non-transitory machine-readable storage medium comprising instructions that, upon execution, cause a system to: Receiving vehicle-related information from a data source associated with the vehicle; restricting access to the vehicle-related information based on at least one privacy criterion selected from among machine learning usage criteria related to use of the vehicle-related information by a machine learning model, vehicle movement criteria related to a movement status of the vehicle, or person identity criteria related to identity of persons within the vehicle; A non-transitory machine-readable storage medium that causes (Item 2) The instructions, when executed, cause the system to limit the access to the vehicle-related information based on the machine learning usage criteria by reducing a sampling rate of the vehicle-related information for the machine learning model. (Item 3) The instructions, when executed, cause the system to further restrict access to the vehicle-related information by blocking access to the vehicle-related information based on location-based criteria if the vehicle has a specified association with a geofence. (Item 4) The instructions, upon execution, cause the system to: receiving a request from an entity to access the vehicle-related information; determining that the entity has permission to access the vehicle-related information; In response to the entity determining that it has the permission, determining whether the vehicle has a specified association with the geofence; and blocking said entity from accessing said vehicle-related information if said vehicle has said defined association with said geofence. A non-transitory machine-readable storage medium according to any one of the preceding items, which causes the following to be performed: (Item 5) The instructions, upon execution, cause the system to: enabling said entity to access said vehicle-related information if said vehicle does not have said defined association with said geofence; A non-transitory machine-readable storage medium according to any one of the preceding items, which causes the following to be performed: (Item 6) The non-transitory machine-readable storage medium of any one of the preceding items, wherein the instructions, when executed, cause the system to restrict access to the vehicle-related information by blocking access to the vehicle-related information based on the vehicle motion criteria if the vehicle is moving. (Item 7) The non-transitory machine-readable storage medium of any one of the preceding items, wherein the instructions, when executed, cause the system to restrict access to the vehicle-related information by preventing access to the vehicle-related information based on the vehicle motion criteria if the vehicle is not moving. (Item 8) The instructions, when executed, cause the system to restrict access to the vehicle-related information by blocking access to the vehicle-related information based on the vehicle motion criteria when the speed of the vehicle has a specified relationship to a speed threshold. (Item 9) The vehicle-related information comprises image data captured by a camera of the vehicle, and the instructions, when executed, cause the system to restrict access to video data based on the vehicle motion criteria. (Item 10) The instructions, when executed, cause the system to restrict access to the vehicle-related information based on the person identification information criteria by blocking access to the vehicle-related information if the identification information of the person in the vehicle matches a specified identification information. (Item 11) The instructions, when executed, cause the system to restrict access to the vehicle-related information by allowing access to the vehicle-related information based on the person identification information criteria if the identification information of the person in the vehicle differs from the specified identification information. (Item 12) A non-transitory machine-readable storage medium according to any one of the preceding items, wherein the specified identification information of the personal identification information standard relates to a driver or passenger of the vehicle. (Item 13) The non-transitory machine-readable storage medium of any one of the preceding items, wherein the instructions, upon execution, cause the system to restrict access to the seat belt information based on seat belt information access criteria that specify that seat belt information is not provided for a specified category of driver or passenger. (Item 14) The non-transitory machine-readable storage medium of any one of the preceding items, wherein the instructions, when executed, cause the system to restrict access to the vehicle-related information by obscuring personal identification information in the vehicle-related information. (Item 15) 2. The non-transitory machine-readable storage medium of any one of the preceding items, wherein the system is a part of the vehicle. (Item 16) The non-transitory machine-readable storage medium of any one of the preceding items, wherein the system is located remotely from the vehicle. (Item 17) 2. The non-transitory machine-readable storage medium of any one of the preceding items, wherein the data source is present inside the vehicle. (Item 18) 2. The non-transitory machine-readable storage medium of any one of the preceding items, wherein the data source is external to the vehicle. (Item 19) A computer system, comprising: one or more hardware processors; A non-transitory storage medium storing instructions executable on the one or more hardware processors, the instructions comprising: Receiving vehicle-related information from a data source associated with the vehicle; restricting access to the vehicle-related information based on at least one privacy criterion selected from among machine learning usage criteria related to use of the vehicle-related information by a machine learning model, vehicle movement criteria related to a movement status of the vehicle, or person identity criteria related to identity of persons within the vehicle; A non-transitory storage medium that A computer system comprising: (Item 20) 1. A method of a computer system comprising: receiving vehicle related information from a data source associated with the vehicle, in the computer system; restricting access to the vehicle-related information based on at least one privacy criterion selected from among machine learning usage criteria related to use of the vehicle-related information by a machine learning model, vehicle movement criteria related to a movement status of the vehicle, or person identity criteria related to identity of persons within the vehicle; A method comprising: (Summary) In some embodiments, the system receives vehicle-related information from a data source associated with the vehicle and restricts access to the vehicle-related information based on at least one privacy criterion selected from among machine learning usage criteria related to use of the vehicle-related information by a machine learning model, vehicle motion criteria related to a movement status of the vehicle, or person identity criteria related to identity of persons within the vehicle. [Brief description of the drawings]

[0005] Some implementations of the present disclosure are described with respect to the following figures.

[0006] [Figure 1] FIG. 1 is a block diagram of a vehicle and vehicle-related information filtering engine, according to some embodiments.

[0007] [Diagram 2]FIG. 2 is a flow diagram of a process according to some embodiments.

[0008] [Diagram 3] FIG. 3 is a block diagram of a computer system according to some embodiments.

[0009] Throughout the drawings, the same reference numbers designate similar, but not necessarily identical, elements. The figures are not necessarily to scale, and the size of some parts may be exaggerated to more clearly illustrate the embodiments shown. Furthermore, the drawings provide examples and / or implementations that are consistent with the description, however, the description is not limited to the examples and / or implementations provided in the drawings. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0010] Detailed Description In this disclosure, use of the terms "a," "an," or "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. Also, as used in this disclosure, the terms "includes," "including," "comprises," "comprising," "have," or "having" specify the presence of the stated elements but do not exclude the presence or addition of other elements.

[0011] FIG. 1 is a block diagram of an example arrangement, including a vehicle 102 having a vehicle-related information filtering engine 104, according to some implementations of the present disclosure. The vehicle-related information filtering engine 104 is used to control access by entities (users, programs, and / or machines) of vehicle-related information from various data sources. Entities that may request access to vehicle-related information may include entities inside the vehicle 102 or outside the vehicle 102. Access control of vehicle-related information to various entities may provide some or all of the following benefits: data privacy is enhanced by reducing the sampling rate at which the vehicle-related information is provided to the entities, data privacy is enhanced by controlling the time at which the vehicle-related information is made available to the entities based on one or more criteria (e.g., vehicle motion status or engine ignition status, vehicle speed, time, location, occupant identity, etc.), etc.

[0012] 1 illustrates the vehicle-related information filtering engine 104 inside the vehicle 102, in other embodiments, the vehicle-related information filtering engine 104 can be located outside the vehicle 102. For example, the vehicle-related information filtering engine 104 can be a component of the RSU 116, a remote server 118, or the like.

[0013] As used herein, an "engine" may refer to a hardware processing circuit, which may include any or some combination of a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or another hardware processing circuit. Alternatively, an "engine" may refer to a combination of a hardware processing circuit and machine-readable instructions (software and / or firmware) executable on the hardware processing circuit.

[0014] Various exemplary data sources of vehicle-related information are depicted in Figure 1. The data sources may be located within the vehicle 102 and include sensors 106, cameras 108, data loggers 109, a Global Positioning System (GPS) receiver 110 for receiving location data from GPS satellites, a storage system 112, or other data sources. Data sources external to the vehicle 102 that may provide vehicle-related information may be components such as an RSU 116, a remote server 118, etc.

[0015] The sensors 106 in the vehicle 102 may be coupled to individual vehicle subsystems 107, such as any or some combination of the following: vehicle engine, vehicle transmission, brakes, tires, sound systems, battery, suspension, navigation system, climate control system, seat belts, airbags, crash avoidance systems, or any other vehicle subsystem.

[0016] The sensors 106 are used to measure metrics that are indicative of characteristics of the vehicle subsystem 107, including characteristics related to the operation of the vehicle subsystem 107, wear of the vehicle subsystem 107, errors or failures within the vehicle subsystem 107, and the like.

[0017] In further examples, the sensors 106 may be used to take environmental measurements of the environment either inside the vehicle 102 and / or outside the vehicle 102. Examples of environmental metrics that may be measured by the environmental sensors include any or a combination of the following: temperature, pressure, humidity, etc. The sensors may also be used to detect the condition of the road over which the vehicle 102 travels, such as whether potholes are present in the road, whether the road is paved or unpaved, etc.

[0018] The camera 108 of the vehicle 102 is used to capture images, including still and / or video images. The camera 108 may be used to capture images of objects within the vehicle 102 (e.g., occupants within the vehicle 102, inanimate objects within the vehicle 102, etc.) or images of objects outside the vehicle 102 (e.g., the environment on the four sides of the vehicle 102, including any other vehicles or people that may be in proximity to the vehicle 102).

[0019] The data logger 109 may include hardware or machine-readable instructions for logging various data for the vehicle 102, such as data related to the operation of the vehicle. The data logger 109 may store the logged data in a storage system 112.

[0020] The GPS receiver 110 can provide location data related to the vehicle 102. Although depicted as a GPS receiver, in other embodiments, a location receiver (different from a GPS receiver) can receive location data, such as from other types of satellites or from other location systems, such as base stations of a cellular network.

[0021] The storage system 112 of the vehicle 102 may be used to store vehicle-related information 114, which may be provided by various data sources, including the sensors 106, the cameras 108, the data logger 109, and the GPS receiver 110. The storage system 112 may be implemented using one or more storage devices, such as disk-based storage devices, solid-state drives, etc.

[0022] The vehicle-related information 114 stored in the storage system 112 may also include vehicle-related information received from data sources external to the vehicle 102, including the RSU 116 and the remote server 118. Examples of vehicle-related information that may be received from the RSU 116 include any or a combination of the following: the current status of a traffic light (e.g., whether the traffic light is displaying red, yellow, or green), images obtained by a camera of the RSU 116, traffic information related to the roadway, etc. The RSU 116 may be located at an intersection of multiple roadways, along the side of the roadway, or at other locations near the roadway.

[0023] Vehicle-related information that may be provided by the remote server 118 may include any or a combination of the following: roadway traffic information, control information for controlling the orientation of the vehicle 102, and the like.

[0024] The RSU 116 and the remote server 118 may communicate with the vehicle 102 via respective wireless links 120 and 122, such as wireless links over a cellular network, a wireless local area network (WAN), or the like.

[0025] Vehicle 102 includes a communication interface 124 that enables vehicle 102 to communicate wirelessly with other endpoints, such as RSU 116 and remote server 118. Communication interface 124 may include a signal transceiver for transmitting and receiving signals, and one or more protocol layers that govern the protocol of the information communicated over wireless links 120 and 122.

[0026] The vehicle 102 includes a vehicle network 125 to allow various components of the vehicle 102 to communicate with each other. The vehicle network 125 may include a wired network and / or a wireless network.

[0027] According to some implementations of the present disclosure, the vehicle-related information filtering engine 104 controls access to vehicle-related information from various data sources, including any of the above.

[0028] The vehicle-related information filtering engine 104 may use access control rule information 126 stored in a memory 128 of the vehicle 102. The memory 128 may be implemented using one or more memory devices, such as a dynamic random access memory (DRAM) device, a static random access memory (SRAM) device, a flash memory device, or the like.

[0029] The access control rule information 126 includes various access rules governing access of various pieces of vehicle-related information provided by any or some combination of internal or external data sources. In response to a request from an entity (internal or external to the vehicle 102) for a given piece of vehicle-related information, or when an entity requests to be notified when the vehicle-related information changes state, the vehicle-related information filtering engine 104 accesses one or more access rules of the access control rule information 126 to determine whether and when to grant the entity access to the given piece of vehicle-related information. In some cases, the entity may be an application or program internal or external to the vehicle 102. The access control rule information 126 may include separate access control rules for different entities.

[0030] The access control rule information 126 may be provided to the vehicle 102 from an external source, such as a remote server 118. The access control rule information 126, in some embodiments, may be dynamically updated over time.

[0031] Examples of various access rules are provided below.

[0032] Access rules for machine learning behavior

[0033] The vehicle 102 also includes a computer 130 in which a machine learning (ML) model 132 is executable. A machine learning model refers to a model that can make a prediction based on input data, such as based on input vehicle-related information 134 from one or more data sources. The machine learning model 132 can generate an output that includes a prediction based on the input vehicle-related information 134. For example, the machine learning model 132 can classify the input vehicle-related information 134 into a selected category of a plurality of different categories. As another example, the machine learning model 132 can generate an output value that makes a prediction (e.g., the vehicle 102 may experience a malfunction, the vehicle 102 may be about to collide with another object, whether an object is proximate to the vehicle 102, the identity or presence of an occupant in the vehicle 102), an indication of an action to be taken (e.g., make a payment when the vehicle 102 approaches an exit gate of a parking lot, apply the brakes, etc.), and the like.

[0034] The machine learning model 132 can be trained to perform its predictions. The training can be based on training data including various pieces of vehicle-related information and labels assigned to the pieces of vehicle-related information. The assigned labels can be provided by a human or other entity and can indicate a category associated with each piece of vehicle-related information, an output value associated with each piece of vehicle-related information, etc. In an embodiment, the training data can be provided to the computer 130 and the machine learning model 132 can be trained based on the training data. The machine learning model 132 can be trained and updated continuously.

[0035] According to some implementations of the present disclosure, the vehicle-related information filtering engine 104 may control characteristics of the input vehicle-related information 134 provided as input to the machine learning model 132 based on the machine learning model-related access rules of the access control rule information 126. For example, the machine learning model-related access rules may include an access rule that specifies that only a specified subset of the vehicle-related information should be provided to the machine learning model 132.

[0036] In some applications, the machine learning model 132 does not need to be provided with all of the specified vehicle-related information in order to perform the computations of the machine learning model 132. As an example, the specified vehicle-related information may include images (still and / or video images) of the environment surrounding the vehicle 102. The machine learning model 132 may be a theft detection machine learning model for predicting whether a theft has occurred to the vehicle 102.

[0037] To predict whether a theft is occurring, the theft detection machine learning model can detect the presence of one or more persons around the vehicle based on images acquired by the camera 108 and can receive sensor data indicative of an intrusion, such as sound data indicative of shattered glass, door opening without the use of a key or fob, etc. The output provided by the theft detection machine learning model is a theft indicator, which can be set to a "true" value (to indicate that a vehicle theft event exists) or a "false" value (to indicate that a vehicle theft event does not exist). To make its prediction, the theft detection machine learning model may not need to be provided with all of the images or all of the sensor data acquired by the camera 108. Rather, the theft detection machine learning model may be able to make its prediction in effect based on a sampling of the images and / or sensor data. A "sampling" of data refers to a selection of less than all samples of the data that are available. Providing a sampling of data to the theft detection machine learning model reduces the amount of personal information made available to an application that invokes the theft detection machine learning model, while still allowing the theft detection machine learning model to provide its prediction.

[0038] As an example, the machine learning model-related access rule may specify a sampling rate for the specified vehicle-related information (including, for example, the image and / or sensor data referred to above) to be provided to the theft detection machine learning model. The sampling rate may be defined as a percentage, e.g., the vehicle-related information filtering engine 104 may select a specified percentage of all samples of the specified vehicle-related information to be provided to the theft detection machine learning model. For example, if the machine learning model-related access rule specifies a sampling rate of 10%, the vehicle-related information filtering engine 104 may provide one out of all ten samples of the specified vehicle-related information as the vehicle-related information 134 input to the theft detection machine learning model. In some cases, the sampling rate may vary based on factors such as the current time, the location of the vehicle, or whether there are moving objects around the vehicle. If the vehicle is in an area with a high crime rate or the current time is within a time period during which vehicle thefts frequently occur (e.g., 12:00 a.m. to 5:00 a.m.), the sampling rate may be increased. Otherwise, a low sampling rate may be used. If the vehicle sensors detect objects moving around a parked, unoccupied vehicle, the sampling rate can be increased to better capture potential theft events.

[0039] Providing all available samples of the specified vehicle-related information to the theft detection machine learning model may raise privacy concerns, as an excessive amount of information may be provided to the theft detection machine learning model. In addition, the theft detection machine learning model may be running within an application (e.g., synthetic sensor) that covertly collects information for other purposes. By limiting the data available to the application, better privacy is achieved. The theft detection machine learning model may accurately predict the presence of a theft event based on only a subset of all available samples of the specified vehicle-related information.

[0040] In other examples, other types of machine learning models 132 may be executed by computer 130, with corresponding access rules defined in access control rule information 126 for such other types of machine learning models 132. Examples of other types of machine learning models 132 may include machine learning models for detecting the presence and / or identity of occupants in vehicle 102, or for making decisions when making payments, etc. Access control rule information 126 may include access rules that specify different sampling rates for different machine learning models 132 executed by computer 130.

[0041] In other applications, such as when the machine learning model 132 is used to detect whether a collision with another vehicle or a human is imminent, the machine learning model 132 may be provided with a continuous stream of vehicle-related information (i.e., all available samples of vehicle-related information, such as images captured by the camera 108 of objects in front of the vehicle 102).

[0042] In further examples, alternative or additional access rules may be included in the access control rule information 126 for the machine learning model. As examples, the access rules for the machine learning model may include any or some combination of the following: types of vehicle-related information to be provided to the machine learning model (e.g., a first type of vehicle-related information should be provided, but a second type of vehicle-related information should not be provided), times when the vehicle-related information should be provided to the machine learning model, start and stop criteria for providing the vehicle-related information to the machine learning model (e.g., when the start criterion is met, provide the vehicle-related information to the machine learning model, and when the stop criterion is met, do not provide the vehicle-related information), etc. For example, the access rules for the machine learning model may specify that, when using the vehicle 102 during the day, in order to protect the privacy of the driver or other users of the vehicle 102, the specified vehicle-related information should not be provided during the day, but will be provided at night.

[0043] Movement-Based Access Rules

[0044] In further examples, the access control rule information 126 may include access rules based on the motion status of the vehicle 102 ("motion-based access rules"). For example, an application (which may be launched within the vehicle 102 or outside the vehicle 102) may base its operation by detecting objects within or outside the vehicle while the vehicle is stopped. For example, the application may record images collected by the camera 108 while the vehicle 102 is stopped (e.g., parked in a parking lot, etc.). As another example, an application (such as a machine learning model) may perform theft detection of the vehicle 102 by capturing the behavior of people moving around the vehicle 102 while the vehicle 102 is stopped.

[0045] In such an embodiment, the motion-based access rules may specify that an application (e.g., a theft detection application) should provide images collected by the camera 108 when the vehicle 102 is not moving, but that the application should not provide images collected by the camera 108 when the vehicle 102 is moving or when the engine ignition is on (but the vehicle is not moving).

[0046] The vehicle-related information filtering engine 104 can monitor the speed of the vehicle 102 based on sensor data (such as from a speedometer) and can provide images (or other vehicle-related information) to the application only when the vehicle 102 is not moving (i.e., the speed of the vehicle 102 is zero).

[0047] In other examples, an additional application (which may be launched within the vehicle 102 or external to the vehicle 102) may perform a calculation if the vehicle 102 is moving (e.g., has a speed greater than a specified threshold). For example, the additional application may calculate an average speed of the vehicle 102 when the vehicle is moving (although the calculated average speed would not take into account the zero speed of the vehicle 102 while it is stopped). In such examples, the motion-based access rules may specify that if the speed of the vehicle 102 is greater than a specified threshold, then speed data should be provided to the additional application.

[0048] Driver identity-based access rules

[0049] In a further example, a driver behavior program (running within the vehicle 102 or external to the vehicle 102) may track the driving behavior of a driver of the vehicle 102. The driving behavior of the driver of the vehicle 102 may be based on measurement data from sensors 106 of the vehicle 102 (e.g., the sensors 106 may indicate the speed and acceleration of the vehicle 102, which may indicate the aggressiveness of the driver). The driver behavior program may also track the location of the vehicle 102 to determine where the driver has driven the vehicle 102.

[0050] In some examples, the ability to track a driver's driving behavior can be based on the driver's identity. The access control rule information 126 can include a driver identity-based access rule that prevents the driver behavior program from accessing specified vehicle-related information (such as speed, acceleration, and location) if the driver has a first identity (e.g., an adult in the family), but allows access to specified vehicle-related information for any other driver with a different identity (e.g., a minor in the family). In that case, parents can use the driver behavior program to monitor whether the minor has good driving behavior.

[0051] Thus, the vehicle-related information filtering engine 104 can use the driver identity-based access rules to prevent the specified vehicle-related information from being provided to the driver behavior program in response to detecting that the driver has a first identity (e.g., based on facial recognition of the driver, based on biometric data such as fingerprint data of the driver). The vehicle-related information filtering engine 104 can use the driver identity-based access rules to communicate the specified vehicle-related information to the driver behavior program in response to detecting that the driver has an identity different from the first identity.

[0052] Speed-Based Access Rules

[0053] As a further example, the access control rule information 126 may include a speed-based access rule that disables access of vehicle speed information (from a speedometer) if the speed of the vehicle 102 exceeds a first threshold. In other words, based on the speed-based access rule, the vehicle-related information filtering engine 104 may allow a speed monitoring program (running within the vehicle 102 or external to the vehicle 102) to access the vehicle speed information if the speed of the vehicle 102 does not exceed the first threshold. The vehicle-related information filtering engine 104 may disable access of the speed information by the speed monitoring program if the speed of the vehicle 102 exceeds the first threshold.

[0054] In another embodiment, the access control rule information 126 may include a speed-based access rule that disables access of vehicle speed information (from the speedometer) if the speed of the vehicle 102 is slower than a second threshold. In some cases, different applications / programs may have different access control rules (e.g., different filtering requirements). Each application / program may send its filtering requirements (e.g., filtering start / stop criteria, sampling rate) to the access control rule information 126 so that the vehicle-related information filtering engine 104 can provide corresponding filtered data. Some applications / programs may not be associated with an access control rule, and thus such applications / programs receive unfiltered data (i.e., data that is not subject to filtering by the vehicle-related information filtering engine 104).

[0055] Occupant Identifier-Based Access Rules

[0056] In a further embodiment, an occupant tracking program (running within the vehicle 102 or external to the vehicle 102) may track the identities of occupants inside the vehicle 102, such as for identification purposes. In some cases, it may not be desirable to track the identities of certain occupants of the vehicle 102, such as for privacy reasons.

[0057] The access control rule information 126 may include occupant identifier-based access rules that provide that if an occupant in the vehicle 102 has a first identity, then user identity data (e.g., user identity derived from an image of the interior of the vehicle 102, a biometric or facial recognition process, etc.) is not provided to occupant tracking.

[0058] Thus, the vehicle-related information filtering engine 104 can use occupant identity-based access rules to prevent designated vehicle-related information from being provided to the occupant tracking program in response to detecting that an occupant within the vehicle 102 has a first identity. The vehicle-related information filtering engine 104 can use occupant identity-based access rules to communicate designated vehicle-related information to the occupant tracking program in response to detecting that all occupants inside the vehicle 102 have identities different from the first identity.

[0059] Seatbelt Information Access Rules

[0060] In further examples, a seat belt tracking program (running within the vehicle 102 or external to the vehicle 102) may want to verify that occupants within the vehicle 102 are wearing their seat belts. In some examples, certain categories of drivers or passengers may be exempt from having to wear seat belts.

[0061] In such an embodiment, the access control rule information 126 may include seat belt information access rules that provide that seat belt information is not provided for specified categories of drivers or passengers.

[0062] The vehicle-related information filtering engine 104 can identify any occupants of the vehicle 102 that fall into a specified category and can use seat belt information access rules to block seat belt information (e.g., information from a seat belt sensor indicating whether a seat belt is engaged) from being communicated to a seat belt tracking program for any occupants in the specified category. The vehicle-related information filtering engine 104 can perform recognition of the occupant's identity and, based on the recognized identity, determine (e.g., using correlation information) whether the occupant with the identity falls into a specified category.

[0063] The vehicle-related information filtering engine 104 may enable communication of seat belt information for any occupant that does not fall into a specified category to the seat belt tracking program.

[0064] Geofence-based access rules

[0065] In some examples, a location determination program (running within the vehicle 102 or external to the vehicle 102) can query the location information (e.g., GPS information) to determine the location of the vehicle 102. For privacy reasons, it may be undesirable to allow the location of the vehicle 102 to be communicated to the location determination program unless the vehicle 102 is inside (or outside) a geofence. A "geofence" may refer to information that defines a geographic area (which may consist of a single geographic region or multiple geographic regions).

[0066] The access control rule information 126 may include geofence-based access rules that control communication of vehicle location data to a location determination program based on the relevance of the current location of the vehicle 102 to a geofence. For example, the geofence-based access rules may provide that vehicle location data is not communicated to a location determination program if the vehicle 102 is inside or outside a geofence.

[0067] The vehicle-related information filtering engine 104 can use geofence-based access rules to prevent vehicle location data from being communicated to a location determination program if the vehicle 102 is currently inside or outside a geofence. However, the vehicle-related information filtering engine 104 can use geofence-based access rules to allow communication of vehicle location data to a location determination program if the vehicle 102 is currently outside or inside a geofence. Restricting the provision of vehicle location data to a location determination program according to geofence-based access rules can be used to achieve a goal of preventing a location determination program from receiving data for determining a location of a home, work, etc.

[0068] person Obfuscating Personally Identifiable Information (PII)

[0069] In further examples, the vehicle-related information filtering engine 104 can obscure a portion of the person-identifying information (PII) when certain criteria are met. Examples of PII can include any or a combination of the following: a user's identity, an image of a user's face, a user's biometric data, etc. Obscuring a portion of the PII can include deleting a portion of the PII, replacing a portion of the PII with different data, obscuring a portion of the PII, etc. For example, if the PII falls into a specified category, the portion of the PII is obscured.

[0070] Further Examples

[0071] It should be noted that the vehicle-related information filtering engine 104 may apply multiple different access rules (e.g., any of those described above) in the access control rule information 126 to restrict communication of vehicle-related information to entities, whether inside or outside the vehicle 102.

[0072] 2 is a flow diagram of a process 200 according to some embodiments that may be implemented by a computer system. The computer system may include a single computer or multiple computers and may be internal or external to a vehicle (e.g., vehicle 102).

[0073] Process 200 includes receiving (at 202) vehicle-related information from a data source associated with the vehicle. The data source associated with the vehicle may be internal or external to the vehicle. It is also noted that the vehicle-related information from the data source may be stored in a storage system prior to use by an entity internal or external to the vehicle.

[0074] Process 200 includes receiving (at 204) a request from an entity for access to vehicle-related information. In some examples, the entity may include the machine learning model 132 of FIG. 1 or any of the programs discussed above.

[0075] In response to the request, process 200 includes retrieving (at 206) access control rule information (e.g., 126 in FIG. 1 ) and determining (at 208) whether the entity should be authorized to access the vehicle-related information based on the access control rule information. Tasks 206 and 208 may be performed, for example, by vehicle-related information filtering engine 104.

[0076] Based on the determination, process 200 may restrict (at 210) access to the vehicle-related information in accordance with the access control rule information. In some examples, the access control rule information includes at least one privacy criterion selected from among machine learning usage criteria related to use of the vehicle-related information by a machine learning model, vehicle movement criteria related to a movement status of the vehicle, or person identity criteria related to identity of persons within the vehicle. In other examples, the access control rule information may include additional or alternative criteria related to access of the vehicle-related information.

[0077] In some examples, the machine learning usage criteria may include access rules related to machine learning operations, such as any of those discussed above. The vehicle motion criteria may include motion-based access rules, such as any of those discussed above. The person identity criteria may include driver identity-based access rules and / or passenger identifier-based access rules, such as any of those discussed above.

[0078] In further examples, the access control rule information includes location-based criteria, such as geofence-based access rules. Process 200 can restrict access to vehicle-related information by preventing access to vehicle-related information based on location-based criteria if the vehicle has a defined association with (either inside or outside) a geofence.

[0079] In further such examples, process 200 may receive a request from an entity to access vehicle-related information, determine that the entity has permission to access the vehicle-related information, and, in response to determining that the entity has permission, determine whether the vehicle has a specified association with the geofence, and prevent the entity from accessing the vehicle-related information if the vehicle has the specified association with the geofence.

[0080] Process 200 allows an entity to access vehicle-related information if the vehicle does not have a defined association to a geofence.

[0081] In some embodiments, process 200 restricts access to vehicle related information by blocking access to the vehicle related information based on vehicle movement criteria if the vehicle is moving. In further embodiments, process 200 restricts access to vehicle related information by blocking access to the vehicle related information based on vehicle movement criteria if the vehicle is not moving.

[0082] In some embodiments, process 200 restricts access to vehicle-related information by blocking access to vehicle-related information based on vehicle motion criteria if the vehicle's speed has a specified relationship to (exceeds or is slower than) a speed threshold.

[0083] In some embodiments, process 200 restricts access to vehicle-related information by blocking access to the vehicle-related information based on a person identity criterion if the identity of the person in the vehicle matches a predetermined identity, and process 200 allows access to the vehicle-related information if the identity of the person in the vehicle differs from the predetermined identity.

[0084] In some embodiments, process 200 restricts access to seat belt information based on seat belt information access criteria that specify that seat belt information will not be provided to specified categories of drivers or passengers.

[0085] Figure 3 is a block diagram of a computer system 300 that may be part of or external to a vehicle, such as vehicle 102 of Figure 1. Computer system 300 includes one or more hardware processors 302. The hardware processor may include a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or another hardware processing circuit.

[0086] The computer system 300 includes a non-transitory machine-readable or computer-readable storage medium 304 that stores machine-readable instructions executable on one or more hardware processors 302 to perform various tasks. The machine-readable instructions include vehicle-related information filtering instructions 306 for performing access control of vehicle-related information. The vehicle-related information filtering instructions 306 can be, for example, instructions of the vehicle-related information filtering engine 104 of FIG. 1.

[0087] The vehicle-related information filtering instructions 306 may implement access control of the vehicle-related information based on access control rule information 308 stored in a memory 310 of the computer system 300 .

[0088] The storage medium (e.g., 304) may include any or a combination of the following: dynamic or static random access memory (DRAM or SRAM), erasable and programmable read-only memory (EPROM), electrically erasable and programmable read-only memory (EEPROM), and semiconductor memory devices such as flash memory or other types of non-volatile memory devices; magnetic disks such as fixed, floppy, and removable disks; other magnetic media including tape; optical media such as compact disks (CDs) or digital video disks (DVDs); or other types of storage devices. It should be noted that the instructions discussed above may be provided on one computer-readable or machine-readable storage medium, or alternatively, may be provided on multiple computer-readable or machine-readable storage media, possibly distributed in a larger system having multiple nodes. Such computer-readable or machine-readable storage medium or media are considered to be parts of an article (or article of manufacture). An article or article of manufacture may refer to any manufactured single component or multiple components. The storage medium or media may be located either within the machine that executes the machine-readable instructions, or at a remote facility from which the machine-readable instructions can be downloaded over a network for execution.

[0089] In the preceding description, numerous details have been set forth to provide an understanding of the subject matter disclosed herein. However, implementations may be practiced without some of these details. Other implementations may include modifications and variations from the details discussed above. It is intended that the appended claims cover such modifications and variations.

Claims

1. A non-transitory machine-readable storage medium, the non-transitory machine-readable storage medium comprising instructions that, when executed, cause a system to receive vehicle-related information from a data source associated with a vehicle, and restrict access to the vehicle-related information based on at least one privacy criterion including a machine learning usage criterion related to the use of the vehicle-related information by a machine learning model such that restricting access to the vehicle-related information by the machine learning model includes permitting, based on the machine learning usage criterion, the provision of a first type of information as an input to the machine learning model, and preventing, based on the machine learning usage criterion, the provision of a second type of information as an input to the machine learning model, the second type of information being different from the first type of information A non-transitory machine-readable storage medium including the above.

2. The instructions, when executed, cause the system to restrict access to the vehicle-related information based on the machine learning usage criterion by controlling a sampling rate of the vehicle-related information that is an input to the machine learning model. Controlling the sampling rate includes setting a first sampling rate of the vehicle-related information that is an input to the machine learning model based on a first location of the vehicle, and setting a second sampling rate of the vehicle-related information that is an input to the machine learning model based on a second location of the vehicle, the second location being different from the first location and the second sampling rate being different from the first sampling rate The non-transitory machine-readable storage medium according to claim 1 including the above.

3. The instructions, when executed, cause the system to further restrict access to the vehicle-related information by blocking access to the vehicle-related information based on a location-based criterion when the vehicle has a defined relevance to a geopreference. The non-transitory machine-readable storage medium according to claim 1.

4. The instructions, when executed, cause the system to receive a request from an entity to access the vehicle-related information, and determine that the entity has permission to access the vehicle-related information In response to determining that the entity has the permission, determining whether the vehicle has the specified relevance to the geopence; When the vehicle has the specified relevance to the geopence, blocking access by the entity to the vehicle-related information; The non-transitory machine-readable storage medium according to claim 3, which causes the above to be performed.

5. In response to the execution, the command causes the system to When the vehicle does not have the specified relevance to the geopence, enable access by the entity to the vehicle-related information; The non-transitory machine-readable storage medium according to claim 4, which causes the above to be performed.

6. In response to the execution, the command causes the system to further restrict access to the vehicle-related information by blocking access to the vehicle-related information based on vehicle motion criteria when the vehicle is moving, and the vehicle motion criteria are included in the at least one privacy criterion. The non-transitory machine-readable storage medium according to claim 1.

7. In response to the execution, the command causes the system to further restrict access to the vehicle-related information by blocking access to the vehicle-related information based on vehicle motion criteria when the vehicle is not moving, and the vehicle motion criteria are included in the at least one privacy criterion. The non-transitory machine-readable storage medium according to claim 1.

8. In response to the execution, the command causes the system to further restrict access to the vehicle-related information by blocking access to the vehicle-related information based on vehicle motion criteria when the speed of the vehicle has a specified relevance to a speed threshold, and the vehicle motion criteria are included in the at least one privacy criterion. The non-transitory machine-readable storage medium according to claim 1.

9. The command causes the system to restrict the access to the vehicle-related information based on machine learning usage criteria by controlling a sampling rate of the vehicle-related information that is an input to the machine learning model in response to the execution. Controlling the sampling rate includes adjusting the sampling rate of the vehicle-related information that is an input to the machine learning model according to the current time. The non-transitory machine-readable storage medium according to claim 1.

10. In response to execution, the command causes the system to restrict access to the vehicle-related information based on the machine learning usage criteria by controlling the sampling rate of the vehicle-related information that is an input to the machine learning model. Controlling the sampling rate includes: setting a first sampling rate of the vehicle-related information that is an input to the machine learning model based on the vehicle sensor detecting a moving object around the vehicle; and setting a second sampling rate of the vehicle-related information that is an input to the machine learning model based on the vehicle sensor not detecting the moving object around the vehicle, the second sampling rate being different from the first sampling rate. The non-transitory machine-readable storage medium according to claim 1, comprising the above.

11. In response to execution, the command causes the system to further restrict access to the vehicle-related information based on a person identification information criterion by comparing the identification information of a person in the vehicle with specified identification information and controlling access to the vehicle-related information. The person identification information criterion is included in the at least one privacy criterion. The non-transitory machine-readable storage medium according to claim 1.

12. The non-transitory machine-readable storage medium according to claim 11, wherein the specified identification information of the person identification information criterion relates to a driver or a passenger of the vehicle.

13. In response to execution, the command causes the system to restrict access to the seat belt information based on a seat belt information access criterion that defines that the seat belt information is not provided to a driver or a passenger in a specified category. The non-transitory machine-readable storage medium according to claim 1.

14. In response to execution, the command causes the system to restrict access to the vehicle-related information by obscuring the person identification information within the vehicle-related information. The non-transitory machine-readable storage medium according to claim 1.

15. The system is a component of the vehicle or is located remotely from the vehicle. The non-transitory machine-readable storage medium according to claim 1.

16. The command, in response to execution, causes the system to restrict access to the vehicle-related information based on the machine learning usage criteria by controlling a sampling rate of the vehicle-related information that is an input to the machine learning model, and controlling the sampling rate includes detecting that the vehicle is parked and unoccupied, and increasing the sampling rate of the vehicle-related information that is an input to the machine learning model based on detecting that the vehicle is parked and unoccupied The non-transitory machine-readable storage medium according to claim 1, comprising:

17. The data source is located inside the vehicle or outside the vehicle, the non-transitory machine-readable storage medium according to claim 1.

18. A computer system, the computer system comprising: one or more hardware processors; and a non-transitory storage medium storing instructions, the instructions comprising: receiving vehicle-related information from a data source associated with a vehicle; and restricting access to the vehicle-related information based on at least one privacy criterion including a machine learning usage criterion related to use of the vehicle-related information by a machine learning model, wherein restricting access to the vehicle-related information by the machine learning model includes controlling a sampling rate of the vehicle-related information that is an input to the machine learning model according to a current time a non-transitory storage medium executable on the one or more hardware processors to perform the above; and comprising Controlling the sampling rate includes setting a first sampling rate of the vehicle-related information that is an input to the machine learning model based on the current time being within a first time period; and setting a second sampling rate of the vehicle-related information that is an input to the machine learning model based on the current time being within a second time period, wherein the second time period is different from the first time period and the second sampling rate is different from the first sampling rate The computer system comprising:

19. A method of a computer system, comprising: receiving vehicle-related information from a data source associated with a vehicle in the computer system The computer system restricts access to the vehicle-related information based on at least one privacy criterion including a machine learning usage criterion related to the use of the vehicle-related information by a machine learning model, wherein restricting the access to the vehicle-related information by the machine learning model includes controlling a sampling rate of the vehicle-related information that is an input to the machine learning model, and controlling the sampling rate includes setting a first sampling rate of the vehicle-related information that is an input to the machine learning model based on the vehicle sensor detecting a moving object around the vehicle; and setting a second sampling rate of the vehicle-related information that is an input to the machine learning model based on the vehicle sensor not detecting the moving object around the vehicle, wherein the second sampling rate is different from the first sampling rate, including including a method. The computer system according to claim 18, wherein the instructions are executable on the one or more hardware processors to further adjust the sampling rate based on the vehicle sensor detecting a moving object around the vehicle.