Information processing device and information processing method
The information processing apparatus addresses inefficiencies in data provision by determining user access rights and converting data accordingly, ensuring rapid and secure delivery based on user access levels.
Patent Information
- Application Number
- JP2023217389
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2025-07-03
AI Technical Summary
Existing data processing systems face challenges in providing data quickly while ensuring security, particularly when different users have varying access rights, leading to inefficient processing and potential delays in data provision.
An information processing apparatus that acquires first data, generates second data through common processing, determines user access rights, and transmits either the second data to unrestricted users or converted third data to restricted users, incorporating a control unit to manage these processes.
The apparatus achieves fast and secure data provision by collectively performing common processing and selectively applying access restriction measures based on user type, enhancing both speed and security in data delivery.
Smart Images

Figure 2025100192000001_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to data processing.
Background Art
[0002] Numerous techniques for processing data according to demand are known. In this regard, for example, Patent Document 1 discloses a data processing apparatus including an arithmetic unit that determines the use of data and, when it becomes necessary to simultaneously perform processing on a plurality of data with different uses, determines the degree of demand for processing and processes data starting from the data with a high degree of demand for processing.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] An object of this disclosure is to achieve both speed and security in data provision.
Means for Solving the Problems
[0005] One aspect of an embodiment of this disclosure is Obtaining first data collected via an in-vehicle network, generating second data by performing a first process on the first data, determining, in response to a request for data provision from a terminal associated with a user, whether the user is a first user whose access to the second data is not restricted or a second user whose access to at least a part of the second data is restricted, transmitting the second data to a terminal associated with the first user when it is determined that the user is the first user, and when it is determined that the user is the second user, converting the second data into third data that does not include data with restricted access by performing a second process on the second data and transmitting the third data to a terminal associated with the second user, and including a control unit that executes the above. It is an information processing apparatus.
[0006] Moreover, one aspect of the embodiment of the present disclosure is a step of obtaining first data collected via an in-vehicle network, a step of generating second data by performing a first process on the first data, a step of determining, in response to a request for data provision from a terminal associated with a user, whether the user is a first user whose access to the second data is not restricted or a second user whose access to at least a part of the second data is restricted, a step of transmitting the second data to a terminal associated with the first user when it is determined that the user is the first user, and a step of converting the second data into third data that does not include data with restricted access by performing a second process on the second data and transmitting the third data to a terminal associated with the second user when it is determined that the user is the second user, and including the above steps. It is an information processing method.
[0007] In addition, as another aspect, there are a method executed by the above-described apparatus, a program for causing a computer to execute the method, or a computer-readable storage medium that non-temporarily stores the program.
Advantages of the Invention
[0008] According to the present disclosure, it is possible to achieve both speed and security in data provision.
Brief Description of the Drawings
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Modes for Carrying Out the Invention
[0010] Devices for processing data are known.
[0011] For example, consider the case of acquiring various data from the vehicle 10. First, the device communicates with the vehicle 10 to acquire various data on the in-vehicle network. Then, the device processes the various data as necessary. For example, the device processes the acquired data into a data format that can be processed by various devices, or deletes or masks information such as personal information that is not suitable for providing to those without viewing authority. At this time, the device starts the data processing when a need for data provision occurs.
[0012] However, if the device performs data processing each time a need for data provision arises, duplicate processing may be performed, or the time required for data processing may increase. For this reason, there is a problem that data that requires prompt data provision cannot be provided smoothly. Also, while ensuring the speed of providing data that requires prompt data provision, there is also a need to perform appropriate processing according to the access rights of the users at the data provision destination. To address such problems, it is preferable that the device collectively performs the processing that is commonly required for the users at the data provision destination, and individually determines whether to perform the processing for each user regarding the data subject to access restrictions. The information processing apparatus in this embodiment solves such problems.
[0013] An information processing apparatus according to an aspect of the present disclosure acquires first data collected via an in-vehicle network, generates second data by performing a first process on the first data, and determines, in response to a data provision request from a terminal associated with a user, whether the user is a first user whose access to the second data is not restricted or a second user whose access to at least a part of the second data is restricted; when it is determined that the user is the first user, transmits the second data to a terminal associated with the first user; and when it is determined that the user is the second user, converts the second data into third data that does not include the data with restricted access by performing a second process on the second data, and transmits the third data to a terminal associated with the second user, and includes a control unit that executes the above.
[0014] The first user is typically a user whose access to the second data is not restricted. The first user is a user who can access all the data included in the second data. The first user is a user who can access data for which access is restricted for specific users such as personal information.
[0015] The second user is typically a user whose access to at least a part of the second data is restricted. The second user is a user who cannot access data included in the second data for which access is permitted only to some users such as personal information.
[0016] The first data is data obtained from an in-vehicle network before the first processing is performed.
[0017] The first processing is processing performed on the first data. The first processing is processing that is commonly required when the first user and the second user use the data. The first processing may be, for example, data formatting processing or processing such as data format conversion.
[0018] The second data is data on which processing (first processing) that is commonly required when the first user and the second user use the data is performed on the first data.
[0019] The second processing is typically processing for removing information for which the second user's access is restricted from the second data.
[0020] The third data is data on which processing (second processing) such as removing information for which the second user's access is restricted is performed on the second data.
[0021] The second processing may be, for example, processing for deleting or masking data for which access is restricted, such as personal information, included in the second data.
[0022] When the control unit determines that the user is the first user, it transmits the second data to the terminal associated with the first user. Further, when the control unit determines that the user is the second user, it performs a second process on the second data to generate third data and transmits the third data to the terminal associated with the second user. Therefore, the control unit can switch whether to perform the processing of the data subject to access restriction according to the type of the user.
[0023] As a result, the information processing apparatus according to the present disclosure can increase the data providing speed and ensure data security according to the demand.
[0024] Further, in the first process, the control unit may generate the second data by processing the first data so as to be available at least at the terminal associated with the first user and the terminal associated with the second user.
[0025] As a result, the information processing apparatus according to the present disclosure can collectively perform the data processing that is commonly required when the first user and the second user use the data. Therefore, the information processing apparatus according to the present disclosure may be able to prevent the time required to provide data to the user from becoming long.
[0026] Further, when the user is included in the list of users whose access to the second data is not restricted, the control unit determines that the user is the first user, and when the user is not included in the list of users whose access to the second data is not restricted, the control unit may determine that the user is the second user.
[0027] As a result, the information processing apparatus according to the present disclosure can switch the execution of the processing of the data subject to access restriction according to whether the user has access restriction.
[0028] Further, in the second process, the access by the second user is restricted The third data may be generated by deleting or masking the information included in the second data from the second data.
[0029] As a result, the information processing apparatus according to the present disclosure can provide the corresponding user with information that does not include information to which the user's access is restricted among the second data.
[0030] Further, the information processing method according to the present disclosure includes a step of acquiring first data collected via an in-vehicle network, a step of generating second data by performing a first process on the first data, and in response to a request for providing data from a user's terminal, determining whether the user is a first user whose access to the second data is not restricted or a second user whose access to at least a part of the second data is restricted, and when it is determined that the user is the first user, transmitting the second data to a terminal associated with the first user, and when it is determined that the user is the second user, performing a second process on the second data to convert the second data into third data that does not include the data to which the access is restricted, and transmitting the third data to a terminal associated with the second user.
[0031] As a result, the information processing method according to the present disclosure can achieve the same effects as the above information processing apparatus.
[0032] Hereinafter, specific embodiments of the present disclosure will be described with reference to the drawings. The hardware configuration, module configuration, functional configuration, etc. described in each embodiment are not intended to limit the technical scope of the disclosure only to those unless otherwise specified.
[0033] (Embodiment) The outline of the processing performed by the server device according to the embodiment will be described with reference to FIG. 1. FIG. 1 is a diagram showing the outline of the processing executed by the server device 100 according to the embodiment. Here, the server device 100 is an example of the information processing device according to the present disclosure. The server device 100 acquires various data from the vehicle 10, appropriately processes the acquired data, and provides it to the user. The server device 100 is configured to be communicable with the vehicle 10 and a terminal associated with the user.
[0034] First, the server device 100 communicates with the vehicle 10 and acquires first data, which is various data on the in-vehicle network of the vehicle 10. The various data may include, for example, an identifier of the user of the vehicle 10, the speed of the vehicle 10, the destination, the driving history, and the like.
[0035] Next, the server device 100 generates second data, which is data obtained by converting the acquired first data into a form that can be used by the user's terminal. Since the first data is the data itself generated by a sensor or an ECU or the like flowing on the in-vehicle network of the vehicle 10, the user's terminal cannot directly view the first data. In addition to various driving data, the second data also includes personal information such as an identifier of the user of the vehicle 10 and the driving history as they are.
[0036] Next, the server device 100 determines whether the user to whom the data is to be provided is a first user 200 who is not restricted from accessing the second data or a second user 300 who is restricted from accessing the second data. Here, the first user 200 is typically a user of a connected car or the like, and is a user who requests the provision of data such as driving information such as vehicle speed as needed. Also, the second user 300 is typically a user who develops a system using the driving data of the vehicle 10 or the like, and is a user who requests data provision for use in system development.
[0037] When the server device 100 determines that the user is the first user 200, it provides the second data as it is to the terminal associated with the first user 200. Since the server device 100 provides the second data to the first user 200 without performing any new processing on the second data, it can provide the data quickly.
[0038] When the server device 100 determines that the user is the second user 300, it generates third data in which items of information for which the second user 300 is restricted from accessing in the second data are deleted or masked. Then, the server device 100 provides the third data, rather than the second data, to the terminal associated with the second user 300.
[0039] In this way, the server device 100 switches whether to perform processing of data subject to access restrictions according to whether the user is subject to access restrictions. As a result, the server device 100 can quickly provide data for which a high provision speed is required, and can process and provide items for which security is required with access restrictions set.
[0040] According to such a configuration, the server device 100 can increase the data provision speed and ensure data security according to demand.
[0041] Next, each element constituting the system will be described in detail. FIG. 2 is a diagram for explaining the components included in the server device 100 according to the embodiment.
[0042] The server device 100 according to the present embodiment includes a control unit 110, a storage unit 120, and a communication unit 130.
[0043] The control unit 110 is implemented by a processor such as a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit) and a memory. The control unit 110 includes, as functional modules, an acquisition unit 111, a generation unit 112, a determination unit 113, and a transmission unit 114. These functional modules may be realized by executing a program by the control unit 110.
[0044] The acquisition unit 111 acquires first data, which is various data on the in-vehicle network of the vehicle 10, from the vehicle 10. The various data may include, for example, an identifier of a user of the vehicle 10, the speed of the vehicle 10, a departure place and a destination, the number of times of braking, an image of an in-vehicle camera, a driving history, and the like. The acquisition unit 111 communicates with the vehicle 10 via a communication unit 130 described later and acquires the first data.
[0045] The generation unit 112 generates second data by performing a first process on the first data. Here, the first process is a process of processing the first data so as to be available on a terminal associated with a user who is the target to whom the data is provided. The second data is, for example, data in a format that can be used on terminals associated with each of a first user 200 and a second user 300.
[0046] In addition, when the determination unit 113 described later determines that the user is the second user 300, the generation unit 112 converts the second data into third data by performing a second process on the second data. Here, the second process is a process of deleting or masking items of information for which access by the second user 300 is restricted from the second data. The third data is data that does not include data for which access by the second user 300 is restricted and is generated based on the second data.
[0047] The determination unit 113 determines whether the user is the first user 200 or the second user 300. Here, the first user 200 is a user whose access to the second data is not restricted, and the second user 300 is a user whose access to at least a part of the second data is restricted. The determination unit 113 makes the above determination when a request for providing the second data is received from a terminal associated with the user. Specifically, when the user who has sent the request for providing the second data is included in the list of users whose access to the second data is not restricted, the determination unit 113 may determine that the user is the first user 200. Also, when the user who has sent the request for providing the second data is not included in the list of users whose access to the second data is not restricted, the determination unit 113 may determine that the user is the second user 300.
[0048] The transmission unit 114 transmits the second data to the terminal associated with the first user 200. And the transmission unit 114 transmits the third data to the terminal associated with the second user 300. The transmission unit 114 communicates with the terminal associated with the first user 200 or the terminal associated with the second user 300 via a communication unit 130 described later, and transmits the target data.
[0049] The storage unit 120 is a main storage device such as a RAM or a ROM, an EPROM, a hard disk drive, and an auxiliary storage device such as a removable medium. The auxiliary storage device stores an operating system (OS), various programs, various tables, etc., and by executing the programs stored therein, each function that matches the predetermined purpose of each part of the control unit 110 can be realized. However, some or all of the functions may be realized by a hardware circuit such as an ASIC or an FPGA.
[0050] The storage unit 120 stores data etc. used or generated in the processes performed by the control unit 110. Also, the storage unit 120 may temporarily store the first data acquired from the vehicle 10.
[0051] The communication unit 130 is composed of a communication circuit that performs wireless communication. The communication unit 130 may be, for example, a communication circuit that performs wireless communication using 4G (4th Generation), or may be a communication circuit that performs wireless communication using 5G (5th Generation). Also, the communication unit 130 may be a communication circuit that performs wireless communication using LTE (Long Term Evolution), or may be a communication circuit that performs communication by LPWA (Low Power Wide Area). Also, the communication unit 130 may be a communication circuit that performs wireless communication using Wi-Fi (registered trademark).
[0052] Next, the specific content of the processing performed by the server device 100 will be described. FIG. 3 is a flowchart of the processing executed by the control unit 110 of the server device 100 according to the embodiment.
[0053] For example, when the server device 100 receives a data provision request from a terminal associated with a user, it may start the processing shown in FIG. 3.
[0054] First, in step S10, the acquisition unit 111 acquires first data from the vehicle 10. The acquisition unit 111 communicates with the vehicle 10 via the communication unit 130 and acquires first data including the driving data of the vehicle 10 and the user information of the vehicle 10, etc.
[0055] Next, in step S11, the generation unit 112 performs a first process on the first data to generate second data. Specifically, the generation unit 112 may process the first data so as to be available on at least a terminal associated with the first user 200 or a terminal associated with the second user 300, and generate second data.
[0056] Specifically, the first process may include flattening hierarchical data, deleting rows without values, deleting unnecessary labels, removing outliers or abnormal values from latitude and longitude data, correcting timestamps, aggregating or deleting duplicate data. Further, the first process may further include converting label names, deleting abnormal values, linearly interpolating data and performing left-right flipping processing of data, zero-point correction, and data shaping processing such as smoothing processing, or processing such as data format conversion. The terminal associated with the user cannot directly view the first data itself, and can only view the second data after the first process is performed on the first data.
[0057] Next, in step S12, the determination unit 113 determines whether the user is either the first user 200 or the second user 300. As described above, the first user 200 is a user whose access to the second data is not restricted. The second user 300 is a user whose access to at least a part of the second data is restricted, as described above.
[0058] If it is determined in this step that the user is the first user 200, the process proceeds to step S13.
[0059] If it is determined in this step that the user is the second user 300, the process proceeds to step S14.
[0060] When the process proceeds to step S13, the transmission unit 114 transmits the second data to the terminal associated with the first user 200. The transmission unit 114 transmits the second data to the terminal associated with the first user 200 via the communication unit 130.
[0061] When the process transitions to step S14, the generation unit 112 performs a second process on the second data to generate third data. Here, the second process is a process of converting the second data into third data that does not include information restricted from access by the second user 300. Specifically, the generation unit 112 may delete or mask information from the second data that is restricted from access by the second user 300.
[0062] In step S14, in response to a request from the user, each time the third data is generated, the capacity of the storage unit 120 that stores the third data can be reduced.
[0063] Next, in step S15, the transmission unit 114 transmits the third data to the terminal associated with the second user 300. The transmission unit 114 transmits the third data to the terminal associated with the second user 300 via the communication unit 130.
[0064] Thereby, the server device 100 can collectively perform common necessary processing on the acquired data for the users who are data recipients. And the server device 100 can switch whether to perform the processing based on whether there is an access restriction for the user regarding the processing of data with an access restriction set. That is, the server device 100 can quickly provide data for which a high provision speed is required, and can provide the data after performing data processing for data that requires measures for personal information, etc. Therefore, the server device 100 can increase the data provision speed or ensure data security according to the demand.
[0065] Next, the determination unit 113 of the control unit 110 of the server device 100 will explain the process of determining the user type. FIG. 4 is a flowchart of the process of determining the first user 200 and the second user 300 executed by the control unit 110 of the server device 100 according to the embodiment. The process described in FIG. 4 is a detailed description of the process of step S12 described in FIG. 3. is.
[0066] First, in step S20, the determination unit 113 determines whether the user who sent the data provision request is restricted from accessing the second data. If, in this step, the determination unit 113 determines that the user is restricted from accessing the second data, it is an affirmative determination.
[0067] For example, if the user who sent the data provision request is included in the list of users whose access to the second data is not restricted, which the determination unit 113 refers to, it may be determined that the user is the first user 200. And if the user is not included in the list of users whose access to the second data is not restricted, which the determination unit 113 refers to, it may be determined that the user is the second user 300. The acquisition unit 111 may acquire a list of users whose access to the second data is not restricted and is stored in an external device. Also, the storage unit 120 may store the list acquired by the acquisition unit 111. And the determination unit 113 may refer to the list stored in the storage unit 120.
[0068] If an affirmative determination is made in this step, the process transitions to step S22.
[0069] If a negative determination is made in this step, the process transitions to step S21.
[0070] When the process transitions to step S21, the determination unit 113 determines that the user is the first user 200. Thereafter, the process transitions to S13 in FIG. 3.
[0071] When the process transitions to step S22, the determination unit 113 determines that the user is the second user 300. Thereafter, the process transitions to S14 in FIG. 3.
[0072] Thereby, the server device 100 can switch the execution of the processing of the data subject to access restriction according to whether or not there is an access restriction for the user.
[0073] (Modification example) The above embodiment is merely an example, and the present disclosure can be implemented with appropriate modifications without departing from the gist thereof.
[0074] For example, the processes and means described in the present disclosure can be freely combined and implemented as long as no technical contradiction occurs.
[0075] Also, the process described as being performed by one device may be shared and executed by a plurality of devices. Alternatively, the process described as being performed by different devices may be executed by one device. In a computer system, it is possible to flexibly change how each function is realized by what hardware configuration (server configuration).
[0076] The present disclosure can also be realized by supplying a computer program that implements the functions described in the above embodiment to a computer and causing one or more processors included in the computer to read and execute the program. Such a computer program may be provided to a computer by a non-transitory computer-readable storage medium connectable to a computer system bus, or may be provided to a computer via a network. The non-transitory computer-readable storage medium includes, for example, any type of disk such as a magnetic disk (floppy (registered trademark) disk, hard disk drive (HDD), etc.), an optical disk (CD-ROM, DVD disk, Blu-ray disk, etc.), a read-only memory (ROM), a random access memory (RAM), an EPROM, an EEPROM, a magnetic card, a flash memory, an optical card, and any type of medium suitable for storing electronic instructions.
Explanation of reference numerals
[0077] 10 ··· Vehicle 100 ··· Server device 111 ··· Acquisition unit 112 ··· Generation unit 113 ··· Determination unit 114... Transmission unit 120... Memory unit 130... Communication unit 200... First user 300... Second user
Claims
1. Obtaining first data collected via an in-vehicle network; Generating second data by performing a first process on the first data; Determining, in response to a request for data provision from a terminal associated with a user, whether the user is a first user whose access to the second data is not restricted or a second user whose access to at least a part of the second data is restricted; When it is determined that the user is the first user, transmitting the second data to a terminal associated with the first user; When it is determined that the user is the second user, converting the second data into third data that does not include the data with restricted access by performing a second process on the second data, and transmitting the third data to a terminal associated with the second user; An information processing apparatus comprising a control unit that executes the above; An information processing apparatus.
2. The control unit: In the first process, generates the second data by processing the first data so as to be available at least at a terminal associated with the first user and a terminal associated with the second user. The information processing apparatus according to claim 1.
3. The control unit: When the user is included in a list of users whose access to the second data is not restricted, determines that the user is the first user; When the user is not included in a list of users whose access to the second data is not restricted, determines that the user is the second user. The information processing apparatus according to claim 1 or 2.
4. The control unit: In the second process, generates the third data by deleting or masking information restricted from access by the second user from the second data. The information processing apparatus according to claim 1 or 2.
5. A step of obtaining first data collected via an in-vehicle network; A step of generating second data by performing a first process on the first data; A step of determining, in response to a request for data provision from a terminal associated with a user, whether the user is a first user whose access to the second data is not restricted or a second user whose access to at least a part of the second data is restricted; When it is determined that the user is the first user, the second data is transmitted to the terminal associated with the first user. When it is determined that the user is the second user, the second data is converted into third data which does not include data with restricted access by performing second processing on the second data, and the third data is transmitted to the terminal associated with the second user. An information processing method.
Citation Information
Patent Citations
System and method for sharing information
JP2004145483A
Image forming apparatus, network system, and control method and control program thereof
JP2006197022A
Image distribution device, image distribution system, and image distribution method
JP2018037886A
Recording device, recording method, and program
JP2018082390A
Dynamic view for implementing data access control policies
US20210141920A1