Vehicle information output device and vehicle information output method
The vehicle information output device and method address the challenge of balancing privacy protection and information management by determining occupant states and selecting appropriate data protection modes, ensuring secure and accessible data handling.
Patent Information
- Application Number
- JP2024051080
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-27
- Publication Date
- 2025-10-09
Smart Images

Figure 2025150273000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a vehicle information output device and a vehicle information output method. [Background technology]
[0002] There is known a technique for encrypting or abstracting data that can identify an individual, such as image data including a face or body, from information obtained by observing a passenger, as data that requires conversion (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent Publication No. 2021-43571 Summary of the Invention [Problem to be solved by the invention]
[0004] The personal information that is kept secret in the technology described in Patent Document 1 includes facial images and iris information of occupants that can identify individuals, as well as images such as vehicle license plates and addresses printed on signs. However, privacy is not limited to what can be determined by whether or not an individual can be identified. In order to simultaneously protect the privacy of vehicle occupants and manage vehicle driving information, it is necessary to provide appropriate information protection.
[0005] The present disclosure has been made in consideration of the above, and provides a vehicle information output device and a vehicle information output method that can select a protection mode for data that records vehicle driving information based on first information related to the vehicle, and can achieve both appropriate protection of the privacy of vehicle occupants and appropriate management of driving information related to the vehicle's driving. [Means for solving the problem]
[0006] In order to achieve the above-mentioned object, the vehicle information output device of the present disclosure comprises a vehicle information acquisition unit that acquires vehicle information regarding the vehicle, a data generation unit that generates data including the vehicle information, an occupant information acquisition unit that acquires information regarding the relationship between the driver and passengers of the vehicle, a protection mode selection unit that selects a protection mode including whether or not the data needs to be protected based on first information regarding the vehicle, a data processing unit that processes the data in the protection mode, and an output unit that outputs the processed data to a memory unit or to an external device via a communication unit not shown, wherein the first information is information regarding the relationship between the driver and passengers.
[0007] In order to achieve the above-mentioned object, the vehicle information output method of the present disclosure is a method in which a computer executes the following steps: a vehicle information acquisition step of acquiring vehicle information regarding a vehicle; a data generation step of generating data including the vehicle information; an occupant information acquisition step of acquiring information regarding the relationship between the driver and passengers of the vehicle; a protection mode selection step of selecting a protection mode including whether or not the data needs to be protected based on first information regarding the vehicle; a data processing step of processing the data in the protection mode; and an output step of outputting the processed data to a memory unit or to an external device via a communication unit, wherein the first information is information regarding the relationship between the driver and passengers. [Effects of the Invention]
[0008] According to the present disclosure, it is possible to provide a vehicle information output device and a vehicle information output method that select a protection mode for data that records vehicle driving information based on first information related to the vehicle, thereby achieving both appropriate protection of the privacy of vehicle occupants and appropriate management of driving information related to the vehicle's driving. [Brief explanation of the drawings]
[0009] [Figure 1] 1 is a block diagram showing an example of the configuration of a vehicle information output device according to a first embodiment. [Figure 2]4 is a flowchart showing an example of a processing procedure of a vehicle information output method according to the first embodiment. [Figure 3] FIG. 10 is a block diagram showing an example of the configuration of a vehicle information output device according to a second embodiment. [Figure 4] 10 is a flowchart showing an example of a processing procedure of a vehicle information output method according to a second embodiment. [Figure 5] FIG. 10 is a block diagram showing an example of the configuration of a vehicle information output device according to a third embodiment. [Figure 6] 10 is a flowchart showing an example of a processing procedure of a vehicle information output method according to a third embodiment. [Figure 7] FIG. 10 is a block diagram showing an example of the configuration of a vehicle information output device according to a fourth embodiment. [Figure 8] 10 is a flowchart showing an example of a processing procedure of a vehicle information output method according to a fourth embodiment. [Figure 9] FIG. 10 is a block diagram showing an example of the configuration of a vehicle information output device according to a fifth embodiment. [Figure 10] 10 is a flowchart showing an example of a processing procedure of a vehicle information output method according to a fifth embodiment. [Figure 11] FIG. 13 is a block diagram showing an example of the configuration of a vehicle information output device according to a sixth embodiment. [Figure 12] 13 is a flowchart showing an example of a processing procedure of a vehicle information output method according to a sixth embodiment. [Figure 13] FIG. 13 is a block diagram showing an example of the configuration of a vehicle information output device according to a seventh embodiment. [Figure 14] 13 is a flowchart showing an example of a processing procedure of a vehicle information output method according to a seventh embodiment. [Figure 15] FIG. 13 is a block diagram showing an example of the configuration of a vehicle information output device according to an eighth embodiment. [Figure 16] 13 is a flowchart showing an example of a processing procedure of a vehicle information output method according to an eighth embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] The present disclosure will be described below through embodiments of the invention, but the invention according to the claims is not limited to the following embodiments. Furthermore, not all of the configurations described in the embodiments are necessarily essential means for solving the problems. For clarity of explanation, the following description and drawings have been omitted and simplified as appropriate.
[0011] <Embodiment 1> A first embodiment of the present disclosure will be described with reference to Fig. 1. Fig. 1 is a block diagram showing an example of the configuration of a vehicle information output system 1 according to the first embodiment. In the first embodiment, information relating to the state of a vehicle occupant determined by an occupant state determination unit 13, which will be described later, is used as the first information relating to the vehicle.
[0012] The vehicle information output system 1 includes a vehicle information output device 10, a camera 20, a microphone 30, and a storage unit 40.
[0013] The camera 20 is a camera that is placed inside or outside the vehicle and captures images of the vehicle's surroundings and the area including the vehicle's interior, for example, images of the vehicle's occupants. In this case, the images may be either still images or moving images. The camera 20 may be a single camera or may be configured as a group of multiple cameras. The camera 20 may also be a portable device carried by the vehicle occupant.
[0014] The microphone 30 is a microphone that is placed inside, outside, and around the vehicle and picks up sounds around the vehicle, sounds inside the vehicle, and voices of the vehicle occupants. The microphone 30 may be a single microphone or may be configured as a group of multiple microphones. The microphone 30 may also be a portable device carried by the vehicle occupant.
[0015] The storage unit 40 records vehicle information related to the vehicle. Examples of the storage unit 40 include a storage medium such as a memory card provided in the vehicle, a non-volatile memory such as a flash memory, or a storage device such as a hard disk drive or SSD (Solid State Drive). The storage unit 40 may be configured integrally with the vehicle information output device 10, or may be a device separate from the vehicle information output device 10. The storage unit 40 stores data output by the output unit 16, which will be described later. The data may be a file, which is an example of a management unit or storage unit. In the following description, the data will be simply referred to as "data." The storage unit 40 may be provided in an external device that is connected to the vehicle information output device 10 via communication.
[0016] The vehicle information output device 10 includes a vehicle information acquisition unit 11, a data generation unit 12, an occupant status determination unit 13, a protection mode selection unit 14, a data processing unit 15, and an output unit 16. The vehicle information output device 10 is typically installed in a commercial vehicle and balances the protection of the privacy of the vehicle occupants with the appropriate management of driving information related to the vehicle's driving while the vehicle is in operation. For example, in a commercial vehicle such as a truck traveling long distances, it is expected that the vehicle occupants may take a nap, change clothes, or have a private call with an outsider inside the vehicle. The vehicle information output device 10 determines that privacy should be respected in such a case and can output vehicle information in a manner that appropriately protects the privacy of the vehicle occupants. When the vehicle is in operation or in a business-related state even while the vehicle is stopped, the vehicle information output device 10 outputs vehicle information in a manner that can be easily viewed by the vehicle or business manager, thereby enabling appropriate management of business-related information. The vehicle information output device 10 may be provided in a general vehicle and may appropriately protect the privacy of each vehicle occupant.
[0017] The vehicle information acquisition unit 11 acquires vehicle information related to the vehicle. For example, the vehicle information acquisition unit 11 acquires images of the periphery of the vehicle and the interior of the vehicle from the camera 20. In addition to this, the vehicle information acquisition unit 11 may acquire audio picked up around the vehicle or inside the vehicle from the microphone 30, acquire current position information of the vehicle calculated based on a received GNSS (Global Navigation Satellite System) signal from a current position information acquisition unit (not shown), acquire information about the vehicle such as acceleration information of the vehicle detected by an acceleration sensor (not shown), or acquire information about the vehicle's traveling from other sensors. The vehicle information acquisition unit 11 may acquire information about the vehicle from the vehicle via a controller area network (CAN), such as whether the vehicle is traveling or stopped, whether the vehicle engine is stopped, whether the parking brake is applied, the vehicle speed, whether the vehicle doors are open / closed or locked, and information about the control status of a driving assistance device or an automatic driving device equipped in the vehicle. The vehicle information acquisition unit 11 outputs the acquired vehicle information related to the vehicle to the data generation unit 12. The vehicle information acquisition unit 11 may also output the acquired vehicle information related to the vehicle to the occupant state determination unit 13.
[0018] The data generation unit 12 generates data including vehicle information related to the vehicle acquired by the vehicle information acquisition unit 11. The data generation unit 12 generates, for example, images of the periphery of the vehicle or the interior of the vehicle acquired by the vehicle information acquisition unit 11 as image data of a predetermined format. The image data may include various types of data such as audio data, position information, and acceleration information. The data generation unit 12 may be configured to include an image compression unit (not shown) that compresses images using a predetermined method such as H.264 AVC (Advanced Video Coding). The data generated by the data generation unit 12 is not limited to image data, and various types of vehicle information acquired by the vehicle information acquisition unit 11 may be generated as data such as audio data. The data generating unit 12 outputs the generated data including the vehicle information to the data processing unit 15.
[0019] The occupant state determination unit 13 determines the state of the vehicle occupant, and sets information related to the determined state of the vehicle occupant as first information related to the vehicle. The occupant state determination unit 13, for example, determines whether the vehicle occupant is in a state in which their privacy should be respected. The occupant state determination unit 13 determines the state of the vehicle occupant, such as whether the vehicle occupant is engaged in work, such as driving the vehicle, or is in a private state outside of work, such as taking a break or sleeping, based on, for example, an image captured inside the vehicle and audio collected inside the vehicle acquired by the vehicle information acquisition unit 11. The occupant state determination unit 13 preferably includes an image recognition unit (not shown) and an audio recognition unit (not shown) for determining the state of the vehicle occupant from images and audio.
[0020] The occupant state determination unit 13 may determine whether the vehicle occupant is driving or whether the vehicle is in a state unrelated to vehicle driving, based on information regarding the vehicle driving state acquired by the vehicle information acquisition unit 11. A state unrelated to vehicle driving may be determined, for example, when the vehicle engine is stopped and the parking brake is engaged. The occupant state determination unit 13 may determine the alertness and brain activity of the vehicle occupant based on information from a biosensor (not shown) worn or used by the vehicle occupant, and may determine the state of the vehicle occupant by analyzing whether the vehicle occupant is sleeping or has an active brain. In this case, the vehicle occupant typically refers to the vehicle driver, but is not limited to this and may also refer to a passenger or all occupants in the vehicle. The state of the vehicle occupant determined by the occupant state determination unit 13 may be the state of the vehicle driver, the state of a predetermined passenger in the vehicle, the state of all vehicle occupants, the average state of all vehicle occupants, or the state of the vehicle with the largest number of occupants. The occupant state determination unit 13 outputs the determined state of the vehicle occupant to the protection mode selection unit 14.
[0021] The occupant status determination unit 13 may determine various states of the vehicle occupants using known methods in addition to the above-described methods. The occupant status determination unit 13 may determine the state of the vehicle occupants based on a signal indicating whether the vehicle occupants are on duty or on rest, which is manually input by the vehicle occupants or other persons via an input unit (not shown). The occupant status determination unit 13 may determine the state of the vehicle occupants by comparing a pre-registered work schedule of the vehicle occupants with the current time to determine whether the vehicle occupants are working or on rest. It is preferable that the occupant status determination unit 13 determine the state of the vehicle occupants by combining information acquired by the various vehicle information acquisition units 11 described above, information acquired from other sensors and input units, and pre-registered information.
[0022] The occupant state determination unit 13 may determine whether the vehicle occupant is speaking or whether the vehicle occupant is talking to an outside person using a communication device using known image recognition or voice recognition technology, or may determine whether the vehicle occupant is having a private conversation and whether privacy should be prioritized by recognizing the voice spoken by the vehicle occupant or obtaining information about the call recipient. The occupant state determination unit 13 may determine the degree to which privacy should be prioritized as one of several levels based on the facial expression, behavior, vocalization, call recipient information, etc. For example, when the vehicle occupant is taking a break and not engaged in work, the occupant state determination unit 13 may determine the degree to which privacy should be prioritized based on the wakefulness of the vehicle occupant. If the wakefulness is high, the degree to which privacy should be prioritized may be set to a "low level," and if the wakefulness is low, the degree to which privacy should be prioritized may be set to a "high level," thereby distinguishing between an awake state and a dozing state. The degree to which the privacy of the vehicle occupant should be emphasized may be determined based on whether or not the vehicle occupant is speaking and the content of the speech.
[0023] The protection mode selection unit 14 selects a protection mode, including whether data protection is necessary, based on the state of the vehicle occupant determined by the occupant state determination unit 13. For example, when the state of the vehicle occupant is such that privacy should be respected, such as when the occupant is resting, the protection mode selection unit 14 determines that the privacy of the vehicle occupant is likely to be captured in the images of the vehicle's surroundings and interior and the audio acquired by the vehicle information acquisition unit 11, and that protection of this image data and audio data is necessary. In addition, the protection mode selection unit 14 appropriately selects a protection key for protecting data, such as an encryption key for encrypting data or a password for password-protecting data, as the data protection mode, and selects a data protection mode, such as encrypting data with the selected encryption key or restricting third-party access to the data by applying the selected password.
[0024] For example, when the vehicle occupant is resting, the protection mode selection unit 14 selects a protection key known to the vehicle occupant so that the data is protected and output in a manner that allows the vehicle occupant to decrypt or access the data but prevents a third party from decrypting or accessing it, and selects a mode for protecting the data using the protection key. For example, the protection mode selection unit 14 may select a protection key for protecting data based on the degree to which the vehicle occupant's privacy is valued, as determined by the occupant status determination unit 13. When the degree to which the vehicle occupant's privacy is valued is high, the protection mode selection unit 14 may select a protection key known only to the vehicle occupant. When the degree to which the vehicle occupant's privacy is valued is low, the protection mode selection unit 14 may select a protection key known to multiple people, including the vehicle occupant, thereby achieving both strength of data protection and ease of data access. For example, when the vehicle occupant is engaged in work, the protection mode selection unit 14 may detect that image data captured around the vehicle or inside the vehicle and audio captured by the data generation unit 12 may be evidence of work-related matters, such as a traffic accident or near-miss involving the vehicle. In order to output data including such vehicle information in a format that can be easily viewed by vehicle and business managers, it is determined that data protection is unnecessary, and a format in which the data is not protected is selected. The protection mode selection unit 14 outputs the protection mode including whether the selected data needs to be protected to the data processing unit 15 .
[0025] Here, protecting data refers to, for example, encrypting data using a method such as a symmetric key cryptosystem or a public key cryptosystem so that only those who know the selected encryption key can decrypt the data. Protecting data may involve restricting access to the data using a password, which is the selected protection key, or applying mosaic or masking to an image to make the image content difficult to recognize. In this case, it is preferable that a password for removing the mosaic or masking is set and selectable. Protecting data may also involve storing the data in a predetermined area of the storage unit 40 or a predetermined storage medium that is accessible only to pre-registered individuals.
[0026] The protection mode selection unit 14 may select various protection modes in addition to the above-described modes. For example, the protection mode selection unit 14 may select a protection mode, such as password protection, shared encryption protection, or public key encryption protection, based on the vehicle occupant status determined by the occupant status determination unit 13. The protection mode selection unit 14 may also select a protection mode related to encryption strength, such as an encryption algorithm including the number of bits of the encryption method. For example, the protection mode selection unit 14 may select an encryption method or an encryption algorithm for encrypting data based on the degree of importance placed on the privacy of the vehicle occupant determined by the occupant status determination unit 13, thereby reducing the possibility of third parties decrypting the data when the degree of importance placed on the privacy of the vehicle occupant is high. By selecting the data protection mode in this way, the protection mode selection unit 14 can select whether stronger data protection or weaker data protection is required based on the vehicle occupant status, thereby achieving both strong data protection and rapid decryption or data access.
[0027] For example, when a vehicle occupant is engaged in work, the protection mode selection unit 14 may determine that data protection is necessary and select a mode of protecting the data in a form that can be decrypted or accessed by the vehicle's work manager. In other words, the protection mode selection unit 14 may select a protection key associated with the vehicle or work manager and select a protection mode that protects the data using this protection key.
[0028] The data processing unit 15 processes the data generated by the data generation unit 12 in the data protection mode selected by the protection mode selection unit 14. For example, the data processing unit 15 performs processing to protect an image of the interior of a vehicle generated by the data generation unit 12 using the protection key and protection mode selected by the protection mode selection unit 14. For example, when the protection mode selection unit 14 determines that protection is necessary and selects common key encryption using an encryption key known to the vehicle occupants as the protection mode, the data processing unit 15 performs processing to encrypt the data using the selected encryption key in a common key system. For example, when the protection mode selection unit 14 determines that protection is unnecessary, the data processing unit 15 performs processing to output the data generated by the data generation unit 12 to the output unit 16 as is without protecting it. The data processing unit 15 outputs the processed data to the output unit 16 .
[0029] The data processing unit 15 preferably includes various encryption processing units (not shown), such as those for common key encryption and public key encryption, and an access restriction unit (not shown) that restricts access to data using a password. The encryption processing unit preferably allows selection of the number of bits (key length) of the encryption key related to encryption strength. The encryption processing unit can select various algorithms with different key lengths, such as AES (Advanced Encryption Standard) 128 and AES 256, as common key encryption methods.
[0030] The output unit 16 outputs the data processed by the data processing unit 15 to the storage unit 40, or to an external device such as an external server, monitor, or image processing device via a communication unit (not shown). If the storage unit 40 is provided in an external server connected via the communication unit, the output unit 16 may transmit data to the storage unit 40 via the communication unit.
[0031] Next, the processing procedure of the safe driving support device 10 according to the first embodiment will be described with reference to the flowchart shown in FIG.
[0032] First, in step S10, the vehicle information acquisition unit 11 acquires vehicle information related to the vehicle, for example, an image captured by the camera 20. The vehicle information acquisition unit 11 outputs the acquired vehicle information related to the vehicle to the data generation unit 12, and the process proceeds to step S11.
[0033] In step S11, the data generation unit 12 generates data, for example, compressed image data, including vehicle information related to the vehicle acquired by the vehicle information acquisition unit 11. The data generation unit 12 outputs the generated data including the vehicle information to the data processing unit 15, and the process proceeds to step S12.
[0034] In step S12, the occupant state determination unit 13 determines the state of the vehicle occupant. The occupant state determination unit 13 outputs the determined state of the vehicle occupant, for example, that the occupant is resting, to the protection mode selection unit 14, and the process proceeds to step S13.
[0035] In step S13, the protection mode selection unit 14 selects a protection mode, including whether data protection is necessary, based on the state of the vehicle occupant. For example, when the state of the vehicle occupant is resting, the protection mode selection unit 14 selects that data protection is necessary and that the protection mode is data protection with the selected protection key, outputs the selected data protection mode to the data processing unit 15, and proceeds to step S14.
[0036] In step S14, data processing unit 15 processes the data generated by data generation unit 12 in the data protection mode selected by protection mode selection unit 14. Data processing unit 15 performs processing to protect the image data with the selected protection key, for example. Data processing unit 15 outputs the processed data to output unit 16, and the process proceeds to step S15.
[0037] In step S15, the output unit 16 outputs the data processed by the data processing unit 15 to the storage unit 40 or to an external device via the communication unit. The output unit 16 transmits, for example, encrypted image data to a predetermined server via the communication unit. The flow then ends.
[0038] As described above, according to the first embodiment, the vehicle information output device 10 can determine the state of the vehicle occupants, select a protection mode for data including vehicle information based on the state of the occupants, and output the data protected in the selected mode. By configuring the vehicle information output device 10 in this manner, it is possible to switch between outputting information related to the privacy of vehicle occupants while appropriately protecting it in a selected protection mode and outputting driving information related to the vehicle's driving in an appropriately manageable mode, based on the determined driver's state, and achieve both. For example, images captured and audio recorded while a vehicle occupant is taking a break or a nap in the vehicle may not be personally identifiable, but they are records of private time during which the vehicle occupant's privacy should be respected. If such images and audio are accessible to third parties or to vehicle or business managers, this could constitute a violation of privacy, and if they are leaked to the public, this could pose a serious problem. Therefore, it is preferable to appropriately protect such images and audio with a protection key.
[0039] <Embodiment 2> A second embodiment of the present disclosure will be described with reference to Fig. 3. A vehicle information output system 1a according to the second embodiment includes a vehicle information output device 10a. The vehicle information output device 10a has a configuration that differs from the vehicle information output device 10 according to the first embodiment in the following respects. That is, the vehicle information output device 10a includes an occupant authentication unit 17 and a protection mode selection unit 14a. The vehicle information output device 10a has the same configuration and functions as the vehicle information output device 10 according to the first embodiment except for the inclusion of the occupant authentication unit 17 and the protection mode selection unit 14a, and therefore detailed description thereof will be omitted.
[0040] The occupant authentication unit 17 performs personal authentication processing to identify vehicle occupants as specific individuals. For example, the occupant authentication unit 17 performs image recognition of the vehicle occupant's face from an image captured inside the vehicle, and then determines whether the recognized facial features of the vehicle occupant match those of a person registered in a database (not shown) that stores pre-stored facial images or facial features, thereby authenticating the individual. For example, the occupant authentication unit 17 extracts features such as the relative positions, sizes, eyes, nose, and chin shape of facial parts from the facial image, and calculates the degree of match between the extracted features and the registered features to determine whether the person's facial image matches the facial image or facial features pre-stored in the database. If the vehicle occupant is identified as a registered person, the occupant authentication unit 17 identifies the matched person's personal information, such as name, employee number, and electronic certificate number, from the database. The occupant authentication unit 17 outputs the authentication result of the vehicle occupant, that is, personal information that can identify the vehicle occupant, to the protection mode selection unit 14a.
[0041] The occupant authentication unit 17 may use various methods other than those described above to personally authenticate vehicle occupants. The occupant authentication unit 17 may personally authenticate a person using known methods such as iris authentication or voiceprint authentication. The occupant authentication unit 17 may personally authenticate a vehicle occupant using a signal indicating personal information such as an employee number and a set password that is manually input by the vehicle occupant or another person using an input unit (not shown). The occupant authentication unit 17 may personally authenticate a vehicle occupant using methods such as logging in to a predetermined system or comparing a work schedule with the current time.
[0042] The protection mode selection unit 14a determines whether data protection is necessary based on the status of the vehicle occupant determined by the occupant status determination unit 13, and selects, as an encryption mode, a protection mode in which the data is protected using a protection key based on the person authenticated by the occupant authentication unit 17. The protection mode selection unit 14a references a protection key database (not shown) that stores registered persons and their respective protection keys in association with each other, and selects a protection key associated with the person authenticated by the occupant authentication unit 17. For example, if the vehicle occupant is resting, the protection mode selection unit 14a determines that the image of the vehicle interior generated by the data generation unit 12 is likely to include the vehicle occupant's privacy and that this image data needs to be protected. Thereafter, the protection mode selection unit 14a selects, as a data protection mode, a protection key associated with the authenticated person, i.e., the vehicle occupant, and selects to protect the data using this protection key. For example, when the vehicle occupant is engaged in work, the protection mode selection unit 14a determines that protection of the data generated by the data generation unit 12 is necessary, selects a protection key associated with a vehicle or business manager who is different from the authenticated vehicle occupant, and selects to protect the data with this protection key, as the data protection mode. In this way, the protection mode selection unit 14a can set the data protection mode to an appropriately selected protection key set and managed by the vehicle occupant or manager, and can select a data protection mode that appropriately reduces the number of people who can decrypt or access the data. The protection mode selection unit 14a outputs to the data processing unit 15 the protection mode including whether the selected data needs to be protected or not.
[0043] The protection mode selection unit 14a may, for example, refer to a protection mode database that stores registered persons and their respective protection modes in association with each other, and select a protection mode associated with the person authenticated by the occupant authentication unit 17. The protection mode in this case may be, for example, various protection modes such as protection by password, protection by a shared encryption method, or protection by a public key encryption method. The protection mode selection unit 14a may select a protection mode related to encryption strength, such as the number of bits in the encryption method. For example, when the protection mode selection unit 14a determines that the vehicle occupant is resting and that image data captured inside the vehicle needs to be protected, the protection mode selection unit 14a selects a protection mode associated with the authenticated person, such as a mode of encryption using a public key system, as the data protection mode, and selects to protect the data using this protection mode. In this way, the protection mode selection unit 14a can set the strength of the data protection mode to the strength set by the vehicle occupant, and can select a data protection mode that suits the individual's preferences for privacy protection.
[0044] The processing of the data processing unit 15 and the output unit 16 is the same as in the first embodiment, and therefore a detailed description thereof will be omitted.
[0045] Next, the processing procedure of the vehicle information output device 10a according to the second embodiment will be described with reference to the flowchart shown in Fig. 4. Note that steps that are the same as those in the first embodiment will be given the same step numbers, and detailed descriptions thereof will be omitted.
[0046] After step S12, in step S21, the occupant authentication unit 17 performs personal authentication of the vehicle occupant. For example, the occupant authentication unit 17 recognizes the vehicle occupant as a specific person from an image of the interior of the vehicle, outputs the authentication result to the protection mode selection unit 14a, and proceeds to step S22.
[0047] In step S22, the protection mode selection unit 14a determines whether data protection is necessary based on the status of the vehicle occupant, and if data protection is necessary, selects a protection key to protect the data based on the person authenticated by the occupant authentication unit 17. For example, when the vehicle occupant is resting, the protection mode selection unit 14a determines that image data protection is necessary, and selects the protection mode as data protection using a protection key associated with the authenticated vehicle occupant. The protection mode selection unit 14a outputs the selected data protection mode to the data processing unit 15, and the process proceeds to step S14.
[0048] The processing from step S14 onwards is the same as that in the first embodiment, and therefore a detailed description thereof will be omitted.
[0049] As described above, according to the second embodiment, the vehicle information output device 10a can determine the status of the vehicle occupants, personally authenticate the vehicle occupants, and protect data that needs to be protected using a protection key or protection mode based on the authenticated vehicle occupant, and output the data. By configuring the vehicle information output device 10a in this manner, information related to the privacy of the vehicle occupant can be protected using a protection key linked to the vehicle occupant and managed by the vehicle occupant, or a protection mode selected by the vehicle occupant. Furthermore, when the vehicle information output device 10a is installed in a commercial vehicle or a general vehicle in which multiple people ride or drive, it can determine the status of the vehicle occupant and output information related to the privacy of the vehicle occupant as data protected using a different protection key for each vehicle occupant or data protected using a different protection mode for each vehicle occupant.
[0050] <Embodiment 3> A third embodiment of the present disclosure will be described with reference to Fig. 5. A vehicle information output system 1b according to the third embodiment includes a vehicle information output device 10b. The vehicle information output device 10b has a configuration that differs from the vehicle information output device 10 according to the first embodiment in the following respects. That is, the vehicle information output device 10b includes a driving safety determination unit 18, an occupant state determination unit 13b, and a protection mode selection unit 14b. Except for the fact that the vehicle information output device 10b includes the driving safety determination unit 18, the occupant state determination unit 13b, and the protection mode selection unit 14b, the vehicle information output device 10b has the same configuration and functions as the vehicle information output device 10 according to the first embodiment, and therefore detailed description thereof will be omitted. In the third embodiment, information related to the safety of vehicle driving determined by the driving safety determination unit 18 is used as the first information related to the vehicle.
[0051] The vehicle information output device 10b according to the third embodiment of the present disclosure is typically installed in a general-purpose vehicle. When the vehicle is traveling in an unsafe condition, the vehicle information output device 10b both reduces the possibility that recorded data of the vehicle's traveling information becomes undecryptable or inaccessible, and appropriately protects the privacy of the vehicle's occupants. For example, if a vehicle is involved in a traffic accident, the vehicle occupants may be hospitalized for a long period of time or lose their memory after the accident. If the recorded data of the traveling information in this case is protected with a protection key known only to the vehicle occupants, decryption of the recorded data may be slow or impossible. The vehicle information output device 10b both reduces this risk and protects the privacy of the vehicle occupants when the vehicle is unlikely to cause an accident. Furthermore, the vehicle information output device 10b can reduce the risk that the vehicle occupants conceal, conceal, or tamper with vehicle traveling information, such as images of the interior of the vehicle, which serve as evidence of the accident, for example, when a traffic accident occurs while the vehicle occupants are distracted or driving the vehicle in a low level of alertness.
[0052] The occupant state determination unit 13b determines the state of the vehicle occupant. For example, the occupant state determination unit 13b determines whether the vehicle occupant is asleep, unconscious, or unable to drive the vehicle based on an image of the interior of the vehicle captured by the vehicle information acquisition unit 11 or audio captured inside the vehicle. The occupant state determination unit 13b preferably includes an image recognition unit (not shown) and an audio recognition unit (not shown) for determining the state of the vehicle occupant from the image or audio. The occupant state determination unit 13b may determine the level of alertness or brain activity based on information from a wearable biosensor (not shown) worn by the vehicle occupant, and determine whether the vehicle occupant is asleep or has an active brain. The occupant state determination unit 13b may determine whether the vehicle occupant is drunk or under the influence of alcohol based on information from an alcohol detector. The occupant state determination unit 13b outputs the determined state of the vehicle occupant to the protection mode selection unit 14b.
[0053] The occupant state determination unit 13b may determine various states of the vehicle occupants in addition to those described above. It is preferable that the occupant state determination unit 13b determines the state of the vehicle occupants by using a combination of information acquired by the various vehicle information acquisition units 11 described above and information acquired from other sensors. The occupant status determination unit 13b may determine the status of the vehicle occupant based on a signal that is manually input by the vehicle occupant or another person using an input unit (not shown) and indicates an emergency situation in which the vehicle occupant is unconscious or in some other state.
[0054] The driving safety determination unit 18 obtains vehicle information from the vehicle information acquisition unit 11 and the state of the vehicle occupant from the occupant state determination unit 13b. The vehicle information obtained from the vehicle information acquisition unit 11 is information indicating the driving state of the vehicle, such as whether the vehicle is driving or stopped, whether the vehicle engine is stopped, whether the parking brake is applied, etc. The state of the vehicle occupant obtained from the occupant state determination unit 13b is information relating to the state of the vehicle occupant, such as whether the vehicle occupant is asleep or unconscious, or whether it is difficult to drive the vehicle. The driving safety determination unit 18 determines the driving safety of the vehicle, and sets the determined information relating to the driving safety of the vehicle as first information related to the vehicle.
[0055] For example, when the vehicle is traveling and the vehicle occupant is unconscious, the traveling safety determination unit 18 determines that there is a high possibility of the vehicle running out of control and determines the traveling safety of the vehicle to be low. For example, when the vehicle engine is stopped, the parking brake is applied, and the vehicle occupant is asleep, the traveling safety determination unit 18 determines that the vehicle occupant has taken appropriate measures to stop the vehicle and is taking a nap and determines the traveling safety of the vehicle to be high. The traveling safety determination unit 18 may determine the traveling safety of the vehicle into multiple stages. In this case, it is preferable to classify the level of traveling safety of the vehicle using known technology that uses the traveling speed of the vehicle, the frequency of braking, the width of the road on which the vehicle is traveling, the curvature and congestion of curves, the wakefulness of the vehicle occupant, body temperature, the degree of eye opening, etc. The traveling safety determination unit 18 outputs the determined traveling safety of the vehicle to the protection mode selection unit 14b.
[0056] In addition to the above, the driving safety determination unit 18 may determine various other vehicle driving safety conditions that can be determined from the vehicle occupant's status and vehicle information. The driving safety determination unit 18 preferably determines the level of vehicle driving safety in multiple stages based on various vehicle information, such as whether the vehicle is driving at a high speed, driving slowly, stopped by applying the brakes, stopped by the parking brake, the engine is stopped, the door is open, and no occupant is seated in the driver's seat, as well as the vehicle occupant's status, such as whether the occupant is gazing at the vehicle's direction of travel, has their hands on the steering wheel, is looking away, has their eyes closed, or has their head down. For example, if the vehicle engine is running and the vehicle is stopped and the occupant's level of alertness is low, the driving safety determination unit 18 determines that the occupant is dozing off while the vehicle is stopped at a red light or the like, and determines the vehicle driving safety to be at a medium level.
[0057] The protection mode selection unit 14b selects a protection mode, including whether data protection is necessary, based on the vehicle driving safety determined by the driving safety determination unit 18. For example, when the vehicle driving safety is lower than a predetermined reference level, the protection mode selection unit 14b prioritizes outputting information about the vehicle driving in a decrypted or accessible state over the privacy of the vehicle occupants, and therefore either does not require data protection or selects a protection mode for the data using a protection key based on a person other than the vehicle occupants, in other words, a person not riding in the vehicle. When the vehicle driving safety is low, the protection mode selection unit 14b may select a mode for protecting data using a specific protection key known to multiple predetermined people. For example, when the vehicle driving safety is higher than the predetermined reference level, the protection mode selection unit 14b selects a mode for protecting data using a specific protection key known only to the vehicle occupants, in order to prioritize the privacy of the vehicle occupants. The protection mode selection unit 14b outputs to the data processing unit 15 the protection mode including whether the selected data needs to be protected or not.
[0058] The processing of the data processing unit 15 and the output unit 16 is the same as in the first embodiment, and therefore a detailed description thereof will be omitted.
[0059] Next, the processing procedure of the vehicle information output device 10b according to the third embodiment will be described with reference to the flowchart shown in Fig. 6. Note that steps that are the same as those in the first embodiment will be given the same step numbers, and detailed descriptions thereof will be omitted.
[0060] After step S11, in step S31, the occupant state determination unit 13b determines the state of the vehicle occupant, for example, whether the vehicle occupant is asleep, unconscious, or has difficulty driving the vehicle. The occupant state determination unit 13b outputs the determined state of the vehicle occupant to the driving safety determination unit 18, and the process proceeds to step S32.
[0061] In step S32, the driving safety determination unit 18 determines the driving safety of the vehicle. For example, when the vehicle is driving and the vehicle occupant is unconscious, the driving safety determination unit 18 determines the driving safety of the vehicle to be low. The driving safety determination unit 18 outputs the determined driving safety of the vehicle to the protection mode selection unit 14b, and proceeds to step S33.
[0062] In step S33, the protection mode selection unit 14b selects a data protection mode, including whether data protection is necessary, based on the safety of the vehicle's travel. For example, when the safety of the vehicle's travel is at a low level, the protection mode selection unit 14b selects a mode of protecting the data using a predetermined specific protection key known to multiple people. The protection mode selection unit 14b outputs the selected data protection mode to the data processing unit 15, and the process proceeds to step S14.
[0063] The processing from step S14 onwards is the same as that in the first embodiment, and therefore a detailed description thereof will be omitted.
[0064] As described above, according to the third embodiment, the vehicle information output device 10b can determine the safety of the vehicle's driving, select a protection mode for data including vehicle information based on the safety of the vehicle's driving, and output data protected in the selected mode. By configuring the vehicle information output device 10b in this manner, it is possible to switch between appropriately protecting and outputting information related to the privacy of vehicle occupants in a selected protection mode and outputting driving information related to vehicle driving in an appropriately manageable mode based on the determined driving safety, and to achieve both. For example, when the safety of the vehicle driving is high and the possibility of a traffic accident is low, the vehicle information output device 10b selects a protection mode for the data using a protection key based on the vehicle occupants, assuming that this is private time in which the privacy of the vehicle occupants should be respected. For example, when the safety of the vehicle driving is low and the possibility of a traffic accident is high, the vehicle information output device 10b prioritizes outputting information related to the vehicle driving in a decryptable or accessible state and selects a protection mode for the data using a protection key based on a person other than the vehicle occupants, in other words, a person not riding in the vehicle. By using different protection keys to protect data when the safety of the vehicle driving is low or high, it is possible to ensure that the protected data can be decrypted or accessed by appropriate persons.
[0065] <Embodiment 4> A fourth embodiment of the present disclosure will be described with reference to Fig. 7. A vehicle information output system 10c according to the fourth embodiment includes a vehicle information output device 10c. The vehicle information output device 10c has a configuration that differs from the vehicle information output device 10 according to the first embodiment in the following respects. That is, the vehicle information output device 10c includes a protection mode selection unit 14c. Except for the protection mode selection unit 14c, the vehicle information output device 10c has the same configuration and functions as the vehicle information output device 10 according to the first embodiment, and therefore detailed description thereof will be omitted. In the fourth embodiment, vehicle information acquired by the vehicle information acquisition unit 11, for example, information relating to the opening and closing of the vehicle doors, is used as the first information relating to the vehicle.
[0066] The vehicle information output device 10c according to the fourth embodiment of the present disclosure is typically installed in a commercial vehicle and simultaneously preserves vehicle information when occupants, including passengers, are getting in and out of the vehicle or when the vehicle is loading or unloading luggage, while protecting the privacy of the vehicle occupants. For example, when the vehicle door is open, occupants are often getting in and out of the vehicle or when the vehicle is loading or unloading luggage. Images captured around the vehicle and audio captured therein are often records of work. Therefore, it is preferable to output vehicle information in a format that can be easily viewed by vehicle and business managers, thereby enabling appropriate management of business-related information. However, in the occupant status determination unit 13 of the vehicle information output device 10 according to the first embodiment described above, when the driver of the vehicle is near the vehicle, the camera 20 capturing images of the vehicle's surroundings may not necessarily capture the appropriate area. This may result in inappropriate determination of the occupant status. Even in such a case, the vehicle information output device 10c can both appropriately manage the travel information related to the travel of the vehicle and protect the privacy of the vehicle occupants.
[0067] The protection mode selection unit 14c uses the vehicle information acquired by the vehicle information acquisition unit 11 as first information and selects a protection mode including whether data protection is necessary based on the first information. For example, the protection mode selection unit 14c selects a protection mode including whether data protection is necessary based at least on whether the acquired vehicle information indicates an open state of the vehicle door. When the acquired vehicle information indicates an open state of the vehicle door, the protection mode selection unit 14c either does not require data protection or selects a data protection mode using a protection key known by the vehicle manager or multiple persons so that the data can be easily decrypted or accessed by the vehicle manager or multiple persons. When the acquired vehicle information indicates a closed state of the vehicle door, the protection mode selection unit 14c selects a data protection mode using a protection key known by the vehicle occupants so that the data cannot be decrypted or accessed by a third party. It is preferable that the protection key be selected by referring to correspondence information that associates each vehicle information with a protection key. The corresponding information is information indicating the protection key information corresponding to, for example, when the vehicle information indicates the door open state and when the vehicle information indicates the door closed state. The protection mode selection unit 14c outputs the protection mode including whether the selected data needs to be protected to the data processing unit 15.
[0068] In this case, the vehicle door is not limited to a door used for passengers getting in and out of the vehicle, but also includes a rear gate of the vehicle, a trunk cover (lid) of the vehicle, and an emergency exit of a bus, etc. The vehicle door may be a part of the exterior of the vehicle that can be opened and closed, including an engine room cover of the vehicle, and may include a part where it is prohibited or not recommended to drive with the part open, or a part where it is not desirable for passengers to leave the vehicle with the part open.
[0069] When these doors are open, it is likely that vehicle occupants are getting in and out of the vehicle, that luggage is being loaded and unloaded from the vehicle, or that the condition of the vehicle's engine and related components is being checked or maintenance is being performed. In such situations, there is a possibility that the occupants may be injured or luggage may be damaged. Furthermore, if the vehicle is a commercial vehicle, it is likely that the vehicle is in the midst of commercial operations. For example, when the vehicle doors are open, the protection mode selection unit 14c may eliminate the need for data protection, or may select a data protection mode using a protection key known to the vehicle administrator or multiple persons, since the vehicle administrator or multiple persons can easily decrypt or access the data. For example, when the vehicle doors are closed and the vehicle engine is stopped, the protection mode selection unit 14c may select a data protection mode using a protection key known to the vehicle occupants, since this is a private time in which the privacy of the vehicle occupants should be respected, thereby preventing the vehicle administrator and third parties from easily decrypting or accessing the data.
[0070] The protection mode selection unit 14c may select a protection mode, including whether or not data protection is required, based at least on whether the acquired vehicle information indicates a locked state of the vehicle doors. When the vehicle doors are not locked, this often means that the vehicle occupant has not left the vehicle, and it is highly likely that the vehicle occupant is working near the vehicle. Therefore, the protection mode selection unit 14c selects a mode in which data protection is unnecessary or in which the data is protected in a form that can be decrypted or accessed by the vehicle administrator.
[0071] The processing of the data processing unit 15 and the output unit 16 is the same as in the first embodiment, and therefore a detailed description thereof will be omitted.
[0072] Next, the processing procedure of the monitoring device according to the above-mentioned fourth embodiment will be described with reference to the flowchart shown in Fig. 8. Note that steps that are the same as those in the first embodiment will be given the same step numbers, and detailed descriptions thereof will be omitted.
[0073] After step S11, in step S41, the protection mode selection unit 14c selects a data protection mode, including whether data protection is required, based on the acquired vehicle information. For example, when the vehicle information indicates that the vehicle door is open, the protection mode selection unit 14c selects a mode for protecting the data using a predetermined specific protection key known to multiple people. The protection mode selection unit 14c outputs the selected data protection mode to the data processing unit 15, and the process proceeds to step S14.
[0074] The processing from step S14 onwards is the same as that in the first embodiment, and therefore a detailed description thereof will be omitted.
[0075] As described above, according to the fourth embodiment, the vehicle information output device 10c can select a protection mode for data including vehicle information based on the acquired vehicle information, and output data protected in the selected mode. By configuring the vehicle information output device 10c in this way, when the vehicle is in a business-related state or when there is a possibility of injury to an occupant or damage to luggage, it is possible to switch between outputting driving information related to the driving of the vehicle in an appropriately manageable manner and outputting information related to the privacy of the vehicle occupants after appropriately protecting it in a selected protection manner, thereby achieving both.By using different protection keys to protect data when the vehicle doors are open and when they are closed, it is possible to ensure that only appropriate persons can decrypt or access the protected data, while preventing inappropriate persons from easily decrypting or accessing it.
[0076] <Embodiment 5> A fifth embodiment of the present disclosure will be described with reference to Fig. 9. A vehicle information output system 10d according to the fifth embodiment includes a vehicle information output device 10d. The vehicle information output device 10d has a configuration that differs from the vehicle information output device 10 according to the first embodiment in the following respects. That is, the vehicle information output device 10d includes an occupant information acquisition unit 19 and a protection mode selection unit 14d. Except for the inclusion of the occupant information acquisition unit 19 and the protection mode selection unit 14d, the vehicle information output device 10d has the same configuration and functions as the vehicle information output device 10 according to the first embodiment, and therefore detailed description thereof will be omitted. In the fifth embodiment, information about the vehicle occupants acquired by the occupant information acquisition unit 19, for example, information about the relationship between the driver and passengers of the vehicle, is used as the first information about the vehicle.
[0077] A vehicle information output device 10d according to a fifth embodiment of the present disclosure selects a protection mode predetermined for each relationship between the driver and passengers of a vehicle based on the relationship between the driver and passengers, and preserves vehicle information in the selected protection mode. The vehicle information output device 10d can use different data protection modes depending on the situation, such as when only the driver is in the vehicle, when family members including the driver are in the vehicle, or when the driver and acquaintances of the driver are in the vehicle. In this case, it is preferable that the data protection mode be such that all vehicle occupants can decrypt or access the data, but that persons other than the occupants cannot decrypt or access the data. As described above, the fifth embodiment has a problem that is partially different from the first to fourth embodiments. The fifth embodiment has a problem of appropriately managing vehicle information for each relationship between vehicle occupants, and has the configuration described below as a means for solving this problem.
[0078] The occupant information acquisition unit 19 acquires information regarding the relationship between the driver and passengers of the vehicle, and defines the acquired information regarding the relationship between the driver and passengers of the vehicle as first information regarding the vehicle. The occupant information acquisition unit 19 acquires information regarding the driver of the vehicle and the passengers riding in the vehicle, and acquires information regarding the relationship between the driver and passengers of the vehicle using correspondence information, described below, that associates the relationship between the driver and passengers of the vehicle. The occupant information acquisition unit 19 outputs the acquired information regarding the relationship between the driver and passengers of the vehicle to the protection mode selection unit 14d.
[0079] The occupant information acquisition unit 19 acquires information about the vehicle driver and passengers riding in the vehicle by, for example, performing personal authentication on the driver and passengers from images of the interior of the vehicle acquired by the vehicle information acquisition unit 11 or audio collected inside the vehicle. The occupant information acquisition unit 19 may acquire information about the personal names and relationships of the driver and passengers using an input unit (not shown), such as an audio input unit that performs audio input. The occupant information acquisition unit 19 may acquire information about the driver and passengers of the vehicle as information such as personal names and nicknames entered by the driver and passengers via a touch panel. In this case, the touch panel may display buttons indicating relationships such as "Occupant A alone," "Occupant A's family," "Occupant A's acquaintance group," and "Occupant B's colleague group." By pressing any button on the touch panel, the relationship between the driver and passengers of the vehicle is directly acquired. The occupant information acquisition unit 19 may acquire information about the vehicle driver and passengers using ID information acquired from the mobile devices each owned by the vehicle driver and passengers, such as information received from Bluetooth (registered trademark) identification information transmitted by a smartphone, and person association information that associates people with the received identification information.
[0080] The occupant information acquisition unit 19 preferably acquires information about the relationship between the driver and passengers of the vehicle using information about the driver and passengers of the vehicle and relationship correspondence information that associates the relationship between the driver and passengers of the vehicle. The relationship correspondence information is information that defines the relationship between people acquired as personal information. The relationship correspondence information is information that registers and associates each person, such as the driver or passenger, with relationships such as occupant A, occupant B who is married to occupant A, occupant C and occupant D who are family members of occupant A and occupant B, a friend of occupant A, or a colleague of occupant B. The person correspondence information and relationship correspondence information are preferably stored in the vehicle information output device 10d or the storage unit 40.
[0081] The protection mode selection unit 14d selects a protection mode, including whether data needs to be protected, based on the relationship between the driver and the passenger acquired by the occupant information acquisition unit 19. The protection mode selection unit 14d selects a data protection mode using a protection key known by the vehicle driver and the passenger, which is predetermined for each relationship between the driver and the passenger, thereby preventing a third party from easily decrypting or accessing the data. The protection key is preferably selected by referring to correspondence information that associates the relationship between the driver and the passenger with the protection key. The correspondence information is information that indicates, for example, information on a protection key that corresponds to a relationship between the driver alone, a relationship between the driver and the passenger, or the like. The protection mode selection unit 14d outputs the selected protection mode, including whether data needs to be protected, to the data processing unit 15.
[0082] For example, when the relationship acquired by the occupant information acquisition unit 19 is "occupant A's acquaintance group," the protection mode selection unit 14d selects a mode of protecting data in a protection mode predetermined for "occupant A's acquaintance group." The protection mode predetermined for "occupant A's acquaintance group" means, for example, determining that data protection is necessary and selecting a data protection mode using a protection key known to occupant A and fellow passenger acquaintances. When the acquired relationship is "occupant A's family," the protection mode selection unit 14d may select a data protection mode using a protection key known to all or a predetermined portion of occupant A's family, or may determine that data protection is unnecessary.
[0083] The processing of the data processing unit 15 and the output unit 16 is the same as in the first embodiment, and therefore a detailed description thereof will be omitted.
[0084] Next, the processing procedure of the monitoring device according to the fifth embodiment will be described with reference to the flowchart shown in Fig. 10. Note that steps that are the same as those in the first embodiment will be given the same step numbers, and detailed descriptions thereof will be omitted.
[0085] In step S51 after step S11, the occupant information acquisition unit 19 acquires information about the occupants of the vehicle, and further acquires information about the relationship between the driver and passengers of the vehicle. The occupant information acquisition unit 19 outputs the acquired information about the relationship between the driver and passengers of the vehicle to the protection mode selection unit 14d, and then proceeds to step S52.
[0086] In step S52, the protection mode selection unit 14d selects a protection mode, including whether data protection is required, based on the acquired relationship between the driver and passengers of the vehicle. If the acquired relationship is "acquaintance group of occupant A," the protection mode selection unit 14d selects a mode for protecting data in a protection mode predetermined for "acquaintance group of occupant A." The protection mode selection unit 14d outputs the selected data protection mode to the data processing unit 15, and the process proceeds to step S14.
[0087] The processing from step S14 onwards is the same as that in the first embodiment, and therefore a detailed description thereof will be omitted.
[0088] As described above, according to the fifth embodiment, the vehicle information output device 10d can select a protection mode for data including vehicle information based on the relationship between the driver and passengers of the acquired vehicle, and output the data protected in the selected mode. By configuring the vehicle information output device 10d in this manner, vehicle information can be appropriately managed for each relationship between vehicle occupants. The vehicle information output device 10d protects and outputs information related to the privacy of the driver and passengers in the vehicle in a protection manner determined in advance for each relationship between the driver and passengers. The vehicle information output device 10d can protect data in a manner that prevents persons other than those in the vehicle from easily viewing vehicle driving information. By using different protection keys to protect data for each relationship between vehicle occupants, the vehicle information output device 10d can ensure that only appropriate persons can decrypt or access the protected data, while preventing inappropriate persons from easily decrypting or accessing it.
[0089] <Embodiment 6> A sixth embodiment of the present disclosure will be described with reference to Fig. 11. A vehicle information output system 10e according to the sixth embodiment includes a vehicle information output device 10e. The vehicle information output device 10e has a configuration that differs from the vehicle information output device 10 according to the first embodiment in the following respects. That is, the vehicle information output device 10e includes a condition acquisition unit 21 and a protection mode selection unit 14e. Except for the inclusion of the condition acquisition unit 21 and the protection mode selection unit 14e, the vehicle information output device 10e has the same configuration and functions as the vehicle information output device 10 according to the first embodiment, and therefore detailed description thereof will be omitted. In the sixth embodiment, information on the first condition and the second condition acquired by the condition acquisition unit 21 is used as the first information related to the vehicle.
[0090] The vehicle information output device 10e according to the sixth embodiment of the present disclosure is typically installed in a vehicle, such as a rental car or a leased vehicle, where the vehicle manager and the vehicle occupants are different. The vehicle information output device 10e simultaneously protects the privacy of the vehicle occupants under conditions they desire to keep confidential and preserves vehicle information in the event that the vehicle occupants cause an accident or damage the vehicle. For example, when an occupant of a rented vehicle parks the vehicle at home, images captured around the home are acquired as vehicle information. This vehicle information may identify the home. Furthermore, conversations between vehicle occupants inside the vehicle are private and, in some cases, may be sensitive. For this reason, the vehicle occupants may not want the images or content of their conversations to be shared with the vehicle manager, such as the rental car company. However, if this vehicle information is protected by a protection key known to the vehicle occupants, the vehicle occupants may be unable to decrypt or access data containing vehicle information, and the vehicle occupants may conceal the data. For this reason, vehicle managers desire to preserve vehicle information so that it can be decrypted or accessed in case the vehicle is involved in an accident, is damaged, or is involved in a criminal act inside or outside the vehicle. As such, the sixth embodiment has a problem that is partially different from the above-mentioned first to fifth embodiments. The sixth embodiment has as its problem how to appropriately select a mode for protecting vehicle information under conditions where vehicle occupants wish to protect their privacy, and has the configuration described below as a means for solving this problem.
[0091] The condition acquisition unit 21 acquires a first condition and a second condition related to the protection of the generated data, and sets the acquired first condition and second condition as first information related to the vehicle. The condition acquisition unit 21 preferably includes an input unit (not shown) for inputting the first condition and the second condition. The input unit may be, for example, a voice input unit for voice input or a touch panel. The input unit may be a receiving unit that receives the first condition and the second condition set in a mobile device carried by a vehicle occupant or other external device via a communication unit (not shown). The condition acquisition unit 21 may acquire conditions pre-stored in the vehicle information output device 10e or the storage unit 40 as the first condition and the second condition. The condition acquisition unit 21 outputs the acquired first condition and second condition to the protection mode selection unit 14e.
[0092] The first conditions acquired by the condition acquisition unit 21 are preferably, but not limited to, conditions related to vehicle information, vehicle occupants, and the surrounding environment in which the vehicle is traveling, designated by the vehicle occupant. The first conditions are conditions designated by the vehicle occupant as conditions that the vehicle occupant wishes to keep secret. For example, the first conditions may be an area on a map including the vehicle occupant's home or destination, where the vehicle occupant wishes to keep images captured within that area, their address, or places of interest secret as much as possible. The first conditions may be, for example, conditions related to whether the vehicle occupant is speaking or whether a specific object is recognized in an image captured by the camera 20. The vehicle occupant designates the first conditions when they wish to protect confidential information, such as the content of conversations with fellow passengers or information that can identify the location or environment in which the vehicle is traveling. The first conditions may include a form that is predetermined to not impose any special restrictions.
[0093] The second condition acquired by the condition acquisition unit 21 is a condition related to data protection, such as a condition set by a vehicle administrator that determines the encryption strength level of the data protection mode to be protected. The second condition is a condition set by the vehicle administrator when protecting the privacy of vehicle occupants, and determines the protection strength of the data to be protected, such as the encryption strength when encrypting the data. The second condition may also specify an encryption algorithm for encrypting the data to be protected. The second condition is preferably a condition that provides encryption strength at a predetermined level or higher to protect the privacy of vehicle occupants, and is also preferably a condition that is vulnerable and allows decryption or access with necessary effort. This ensures that data can be decrypted or accessed with sufficient effort, even if the occupant is lost after a vehicle accident and forgets the protection key that protects the data, or if the occupant commits a criminal act inside or outside the vehicle and attempts to conceal data that serves as evidence. The second condition may be, for example, a protection mode that allows decryption or access using a supercomputer but is practically difficult to decrypt or access using commonly available computers.
[0094] The second condition may be set as a password option when protecting data with a password or prohibiting access. In other words, the second condition may be a limiting condition for limiting the options for a protection key for protecting data. For example, a vehicle administrator may set the second condition by limiting the password for protecting vehicle driving information to a four-digit number, and the vehicle occupant may choose a password at will from the options. In this case, for example, the vehicle administrator can find a password for protecting data through a brute force test of up to 10,000 times. The second condition is preferably set based on the type of data to be protected or the content of the first condition set by the vehicle occupant. For example, if the vehicle occupant wants to protect all information acquired by the vehicle and sets the first condition to "unlimited," the second condition can be set as a protection mode that allows relatively easy decryption or access.
[0095] The protection mode selection unit 14e selects a protection mode, including whether or not the data generated by the data generation unit 12 needs to be protected, based on at least the first condition and the second condition. For example, the protection mode selection unit 14e compares the vehicle information acquired by the vehicle information acquisition unit 11 with the first condition acquired by the condition acquisition unit 21. If the acquired vehicle information satisfies the first condition, the protection mode selection unit 14e, for example, determines to protect the data and selects a protection mode based at least on the second condition. The protection mode selection unit 14e may compare information acquired or determined in other embodiments of the present disclosure, such as the occupant status determined by the occupant status determination unit 13 or the occupant information acquired by the occupant information acquisition unit 19, with the first condition acquired by the condition acquisition unit 21. The protection mode selection unit 14e outputs the selected protection mode, including whether or not the data needs to be protected, to the data processing unit 15.
[0096] For example, when a predetermined area on a map is designated as the first condition by a vehicle occupant and the acquired current position of the vehicle is within that area, the protection mode selection unit 14e determines to protect data including vehicle information such as images, audio, and the current position of the vehicle acquired by the vehicle information acquisition unit 11. When the first condition is designated as a vehicle ID such as the vehicle registration number of the vehicle and the vehicle ID acquired by the vehicle information acquisition unit 11 indicates that the vehicle is the designated vehicle, the protection mode selection unit 14e determines that the first condition is met and determines to protect data including vehicle information.
[0097] Next, the protection mode selection unit 14e selects a protection mode for the data determined to be protected based on a second condition. For example, if the vehicle administrator specifies, as the second condition, that encryption be performed using an encryption algorithm with a vulnerability, the protection mode selection unit 14e selects a mode in which the generated data is encrypted using the selected encryption algorithm, and also selects a data protection mode using a protection key set by the vehicle occupant. In this case, a vulnerable encryption algorithm refers to an encryption algorithm with a small number of bits in its key length, an algorithm for which vulnerabilities have been discovered, or an algorithm whose use is not recommended. If the vehicle administrator has limited options for protection keys for protecting data, the protection mode selection unit 14e selects, from the options, a data protection mode using a protection key selected by the vehicle occupant.
[0098] For example, the protection mode selection unit 14e sets the data protection mode when the vehicle information acquired by the vehicle information acquisition unit 11 does not satisfy the first condition to either not protecting the data or to using a protection key known to the vehicle administrator or multiple people.
[0099] The processing of the data processing unit 15 and the output unit 16 is the same as in the first embodiment, and therefore a detailed description thereof will be omitted.
[0100] Next, the processing procedure of the monitoring device according to the sixth embodiment will be described with reference to the flowchart shown in Fig. 12. Note that steps that are the same as those in the first embodiment will be given the same step numbers, and detailed descriptions thereof will be omitted.
[0101] After step S11, in step S61, the condition acquisition unit 21 acquires a first condition. The condition acquisition unit 21 also acquires a second condition related to data protection. The condition acquisition unit 21 outputs the acquired first condition and second condition to the protection mode selection unit 14e, and proceeds to step S62.
[0102] In step S62, for example, if the vehicle information satisfies the first condition, the protection mode selection unit 14e selects a protection mode including whether data protection is necessary based on the second condition. For example, if the vehicle is located within an area set by the vehicle occupant, the protection mode selection unit 14e determines that data protection is necessary and selects a protection mode with a protection key set based on the second condition. The protection mode selection unit 14e outputs the selected data protection mode to the data processing unit 15, and the process proceeds to step S14.
[0103] The processing from step S14 onwards is the same as that in the first embodiment, and therefore a detailed description thereof will be omitted.
[0104] As described above, according to the sixth embodiment, for example, when the vehicle's driving information satisfies a first condition, the vehicle information output device 10e can select a protection mode for data including vehicle information based on a second condition specified by the vehicle manager, and output the data protected in the selected mode. By configuring the vehicle information output device 10e in this manner, a vehicle occupant, for example, a rental car user, can protect data, including vehicle information, under conditions for which privacy is desired. The protection mode is based on a second condition specified by the vehicle administrator, such as a protection mode with a vulnerability or a protection mode that protects data using a protection key with limited options. If an accident or damage occurs to the vehicle and the vehicle occupant attempts to conceal data that serves as evidence, the vehicle administrator can decrypt or access the data by exploiting the vulnerability of the encryption algorithm specified as the second condition. When the vehicle occupant specifies the first condition, the vehicle information output device 10e protects the data using a protection key based on the second condition specified by the vehicle administrator, thereby preventing inappropriate persons from easily decrypting or accessing the protected data. If necessary, the vehicle information output device 10e can take measures such as a brute force test to ensure that appropriate persons can decrypt or access the protected data.
[0105] <Embodiment 7> A seventh embodiment of the present disclosure will be described with reference to Fig. 13. A vehicle information output system 10f according to the seventh embodiment includes a vehicle information output device 10f. The vehicle information output device 10f has a configuration that differs from the vehicle information output device 10 according to the first embodiment in the following respects. That is, the vehicle information output device 10f includes a vehicle information acquisition unit 11a and a protection mode selection unit 14f. Except for the inclusion of the vehicle information acquisition unit 11a and the protection mode selection unit 14f, the vehicle information output device 10f has the same configuration and functions as the vehicle information output device 10 according to the first embodiment, and therefore detailed description thereof will be omitted. In the seventh embodiment, vehicle position information acquired by the vehicle information acquisition unit 11a, for example, information about the current position or destination of the vehicle, is used as the first information about the vehicle.
[0106] A vehicle information output device 10f according to a seventh embodiment of the present disclosure is typically installed in a commercial vehicle. When confidentiality of the vehicle's current location or destination is required, the device selects a predetermined protection mode for each current location or destination and preserves vehicle information in the selected protection mode. A commercial vehicle travels to multiple client locations, and may load and unload cargo or engage in business-related conversations at each client location. Images of these activities, audio recordings of conversations, and location information of the client facilities are preferably managed for each client location. Vehicle location information while traveling is also preferably managed because it can be used to estimate the location of a client location or a route to that client location. In such cases, vehicle information must be appropriately managed. Appropriate management here means, for example, providing a protection mode that allows access only to limited parties, such as the person in charge of the client location. Thus, the seventh embodiment has a problem that is partially different from the first to sixth embodiments described above. The seventh embodiment addresses the problem of appropriately managing vehicle information for each region, which is the vehicle's current location or destination. To solve this problem, the seventh embodiment employs the configuration described below.
[0107] The vehicle information acquisition unit 11a acquires location information including the current location of the vehicle as vehicle information, and regards the acquired vehicle location information as first information related to the vehicle. The vehicle information acquisition unit 11a may acquire information on the current location of the vehicle using a configuration similar to that of the above-described vehicle information acquisition unit 11, or may be configured to include a destination information acquisition unit (not shown) that acquires information on the set destination of the vehicle. In this case, the destination may be a general term that includes intermediate points along the way to the destination. The destination information acquisition unit is, for example, connected via a wired or wireless connection to a navigation device (not shown) installed in the vehicle, and acquires information on the vehicle's destination set in the navigation device. It is preferable that the destination information acquisition unit includes an input unit (not shown) for inputting the destination. The input unit may be, for example, a voice input unit for voice input or a touch panel.
[0108] The protection mode selection unit 14f selects a protection mode, including whether the data needs to be protected, based at least on the vehicle's location information. For example, when the vehicle's current location is within a predetermined area, the protection mode selection unit 14f selects a data protection mode using a protection key known by a person predetermined for that area. For example, when the vehicle's current location is not within the predetermined area, the protection mode selection unit 14f prioritizes outputting information about the vehicle's traveling in an easily decryptable or accessible state, and therefore selects either no data protection or a data protection mode using a protection key known by the vehicle administrator or multiple people. The protection key is preferably selected by referring to corresponding information of the protection key associated with each area. The corresponding information is information indicating information on the protection key determined for each area, such as protection key A when the vehicle's location is within the area and protection key B when the vehicle's location information is within a second area. The protection mode selection unit 14f outputs the selected protection mode, including whether the data needs to be protected, to the data processing unit 15.
[0109] The above-mentioned predetermined area is preferably, for example, the inside of a facility to be visited, or an area predetermined for each customer, as a range within which the location of the facility or the route to the facility can be estimated. For example, for customer A, an area within a predetermined distance from the facility location of customer A may be set as area A corresponding to customer A, and for facility B, an area from point B on the route to the facility location of facility B to facility B may be set as area B corresponding to facility B. Also, for example, if rest area C is the destination, the inside of rest area C may be set as area C. As described above, an area is an area that is automatically or manually determined in advance for each customer or location, and is preferably stored in advance in the vehicle information output device 10f or the storage unit 40.
[0110] The processing of the data processing unit 15 and the output unit 16 is the same as in the first embodiment, and therefore a detailed description thereof will be omitted.
[0111] Next, the processing procedure of the monitoring device according to the seventh embodiment will be described with reference to the flowchart shown in Fig. 14. Note that steps that are the same as those in the first embodiment will be given the same step numbers, and detailed descriptions thereof will be omitted.
[0112] After step S11, in step S71, the vehicle information acquisition unit 11a acquires position information regarding at least one of the current position of the vehicle and the destination and / or intermediate points from the GNSS or navigation device. The vehicle information acquisition unit 11a outputs the acquired vehicle position information to the protection mode selection unit 14e, and then proceeds to step S72.
[0113] In step S72, the protection mode selection unit 14f selects a protection mode, including whether or not the data needs to be protected, based at least on whether the acquired location information is within a predetermined area. For example, if the acquired location information is within a predetermined area, the protection mode selection unit 14f determines to protect the data, and selects a mode for protecting the data using a protection key predetermined to correspond to the area. The protection mode selection unit 14f outputs the selected data protection mode to the data processing unit 15, and proceeds to step S14.
[0114] The processing from step S14 onwards is the same as that in the first embodiment, and therefore a detailed description thereof will be omitted.
[0115] As described above, according to the seventh embodiment, the vehicle information output device 10f can select a protection mode, including whether or not data needs to be protected, based at least on the vehicle information including the acquired vehicle location information, and output data protected in the selected mode. By configuring the vehicle information output device 10f in this manner, when the vehicle's location information is within a predetermined area, the data can be protected and output in a protection mode predetermined for each area. The vehicle information output device 10f can protect the data so that people other than those predetermined for each area cannot easily view the vehicle's driving information. By using different protection keys to protect the data for each area predetermined as the vehicle's current location or destination, the vehicle information output device 10f can ensure that only appropriate people can decrypt or access the protected data, while preventing inappropriate people from easily decrypting or accessing it.
[0116] <Embodiment 8> An eighth embodiment of the present disclosure will be described with reference to Fig. 15. A vehicle information output system 10g according to the eighth embodiment includes a vehicle information output device 10g. The vehicle information output device 10g has a configuration that differs from the vehicle information output device 10 according to the first embodiment in the following respects. That is, the vehicle information output device 10g includes an abnormality determination unit 22 and a protection mode selection unit 14g. Except for the abnormality determination unit 22 and the protection mode selection unit 14g, the vehicle information output device 10g has the same configuration and functions as the vehicle information output device 10 according to the first embodiment, and therefore detailed description thereof will be omitted. In the eighth embodiment, information related to an abnormality that has occurred in the vehicle and that is determined by the abnormality determination unit 22 is used as the first information related to the vehicle.
[0117] The vehicle information output device 10g according to the eighth embodiment of the present disclosure simultaneously preserves vehicle information when an abnormality occurs in the vehicle and protects the privacy of the vehicle occupants. When an abnormality occurs in the vehicle, the vehicle information output device 10g outputs the vehicle information in a manner that can be easily viewed by vehicle and business managers, thereby enabling appropriate management of information related to the vehicle. Furthermore, when no abnormality occurs in the vehicle, the vehicle information output device 10g can protect data recording the driving information at that time in a protective manner that can protect the privacy of the vehicle occupants, for example.
[0118] The abnormality determination unit 22 determines an abnormality that has occurred in the vehicle from the vehicle information acquired by the vehicle information acquisition unit 11, and sets information regarding the determined abnormality as first information regarding the vehicle's traveling. For example, the abnormality determination unit 22 determines that an abnormality, such as an accident or impact, has occurred in the vehicle when the acquired acceleration sensor value is equal to or greater than a predetermined value. The abnormality determination unit 22 may, for example, detect the approach of a suspicious person or the occurrence of a fire from the acquired image and determine an abnormality. The abnormality determination unit 22 may also determine an abnormality that has occurred in the vehicle using known abnormality determination techniques, such as detecting an impact sound or scream, detecting smoke detection, or vehicle engine trouble. Regarding the occurrence of an abnormality, the abnormality determination unit 22 may determine not only the presence or absence of an abnormality but also the type of abnormality, for example, as described above. The abnormality determination unit 22 outputs information regarding whether an abnormality has been determined to the protection mode selection unit 14g.
[0119] The protection mode selection unit 14g selects a protection mode, including whether the data needs to be protected, based at least on whether the abnormality determination unit 22 has determined an abnormality. When the abnormality determination unit 22 has determined an abnormality, the protection mode selection unit 14g either eliminates the need for data protection or selects a data protection mode using a protection key known by the vehicle manager or multiple persons so that the vehicle manager or multiple persons can easily decrypt or access the data. When the abnormality determination unit 22 has not determined an abnormality, the protection mode selection unit 14g selects a data protection mode using a protection key known by the vehicle occupants so that the vehicle manager or multiple persons cannot easily decrypt or access the data. The protection key is preferably selected by referring to correspondence information of protection keys associated with the presence or absence of a vehicle abnormality. The protection key may also be selected by referring to correspondence information of protection keys associated with the type of vehicle abnormality. The protection mode selection unit 14g outputs the selected protection mode, including whether the data needs to be protected, to the data processing unit 15.
[0120] The protection mode selection unit 14g preferably sets the protection mode of information related to vehicle traveling when the abnormality determination unit 22 has not determined an abnormality to the mode of protecting data selected in another embodiment of the present disclosure. In other words, the eighth embodiment is preferably implemented in combination with another embodiment of the present disclosure. For example, when the abnormality determination unit 22 has not determined an abnormality and the occupant state determination unit 13 has determined that the privacy of the vehicle occupants should be respected, the protection mode selection unit 14g determines that data protection is necessary.
[0121] The processing of the data processing unit 15 and the output unit 16 is the same as in the first embodiment, and therefore a detailed description thereof will be omitted.
[0122] Next, the processing procedure of the monitoring device according to the above-mentioned eighth embodiment will be described with reference to the flowchart shown in Fig. 16. Note that steps that are the same as those in the first embodiment will be given the same step numbers, and detailed descriptions thereof will be omitted.
[0123] In step S81 after step S11, the abnormality determination unit 22 determines whether or not an abnormality has occurred in the vehicle based on the vehicle information acquired by the vehicle information acquisition unit 11. The abnormality determination unit 22 outputs the determination result to the protection mode selection unit 14g, and the process proceeds to step S82.
[0124] In step S82, the protection mode selection unit 14g selects a protection mode including whether data protection is necessary, based at least on whether an abnormality has occurred in the vehicle. When an abnormality has occurred in the vehicle, the protection mode selection unit 14g selects, for example, a protection mode in which data protection is unnecessary. When no abnormality has occurred in the vehicle, the protection mode selection unit 14g determines that data protection is necessary, and selects, for example, a protection mode in which data is protected with a protection key that prioritizes the privacy of the vehicle occupants. The protection mode selection unit 14g outputs the selected data protection mode to the data processing unit 15, and the process proceeds to step S14.
[0125] The processing from step S14 onwards is the same as that in the first embodiment, and therefore a detailed description thereof will be omitted.
[0126] As described above, according to the eighth embodiment, the vehicle information output device 10g can select a protection mode for data including vehicle information based on whether or not an abnormality has occurred in the vehicle, and output the data protected in the selected mode. By configuring the vehicle information output device 10g in this manner, when an abnormality occurs in the vehicle, it is possible to both output driving information related to the vehicle's driving in an appropriately manageable manner and output information related to the privacy of the vehicle occupants in an appropriately protected manner. When an abnormality occurs in the vehicle, the vehicle information output device 10g protects data recording the abnormality in a protected manner that can be decrypted or accessed by the vehicle manager, the manager of the business using the vehicle, or other parties involved in the abnormality, and outputs the protected data. When no abnormality occurs in the vehicle, the vehicle information output device 10g protects and outputs the data in a protected manner selected, for example, in another embodiment of the present disclosure. By using different protection keys to protect the data when an abnormality occurs in the vehicle and when no abnormality occurs, it is possible to allow appropriate persons to decrypt or access the protected data, while preventing inappropriate persons from easily decrypting or accessing it.
[0127] <Other embodiments> The specific examples and the like shown in the above-described embodiments 1 to 8 in this disclosure are merely examples to facilitate understanding of the invention, and do not limit the present invention unless otherwise specified. The present disclosure is not limited to the first to eighth embodiments, and can be modified as appropriate without departing from the spirit of the present disclosure. Furthermore, the present invention may be implemented by appropriately combining the respective embodiments.
[0128] <Example of variation> In the specific examples shown in the first to eighth embodiments of the present disclosure, the embodiments are implemented in a vehicle, and the problem to be solved is to appropriately protect vehicle information. Modifications are not limited to this embodiment, and the problem may be to appropriately protect information to be protected. For example, the term "vehicle occupant" in the first to eighth embodiments may be replaced with "person." For example, the occupant status determination unit 11 in the first embodiment may be a person status determination unit that determines the status of a person present in a specific area. While the data to be protected in the first to eighth embodiments is "vehicle information," the data may be general "information," such as images of people or scenery, captured audio, location information, or other arbitrarily acquired information. In this case, the vehicle information acquisition unit 11 may be a protected information acquisition unit that acquires information to be protected. Similarly, the occupant authentication unit 17 and the driving safety determination unit 18 may be replaced with a person authentication unit, a safety determination unit, and a person information acquisition unit, respectively, and the information may not be limited to information about vehicle occupants or vehicle driving safety, but may be information about people or the safety of a specific area. In a modified example of the first embodiment, for example, the protection mode for protecting data including images taken in a specified area such as a room or a premises can be selected depending on the status of people present in the area.
[0129] In the first to eighth embodiments of the present disclosure, the data generation unit 12 may generate data separated by the timing of a change in the state of a vehicle occupant determined by the occupant state determination unit 13 or the occupant state determination unit 13b. The data generation unit 12 may acquire information related to the state of a vehicle occupant as the first information from the occupant state determination unit 13 or the occupant state determination unit 13b, close the generated data in accordance with the timing of a change in the state of the vehicle occupant, and open new data, thereby generating multiple pieces of data. In this case, each piece of data is linked to the state of a single vehicle occupant. By configuring the data generation unit 12 in this way, the correspondence between each piece of data and the first information becomes clear. In other words, each piece of data is linked to a single piece of first information. This is preferable because it makes it easier to select the protection mode for each piece of data and reduces the possibility of a mismatch between the protection mode for each piece of data and the first information.
[0130] In the above-described embodiment, the present disclosure has been described as a hardware configuration, but the present disclosure is not limited to this. Any processing of the present disclosure can also be realized by causing a processor to execute a computer program.
[0131] In the above example, the program can be stored and supplied to a computer using various types of non-transitory computer-readable media. Non-transitory computer-readable media include various types of tangible recording media, such as magnetic recording media such as hard disk drives, optical recording media, magneto-optical recording media, and semiconductor memories. Semiconductor memories can be various types of rewritable read-only memories (ROMs) and random access memories (RAMs), and also include those provided as solid-state drives (SSDs). Furthermore, the program may be supplied to a computer by various types of temporary computer-readable media via wired communication paths such as electric wires and optical fibers, or wireless communication paths, including, for example, electrical signals, optical signals, and electromagnetic waves.
[0132] The order of execution of each process in the apparatus and method shown in the claims, specification, and drawings may be implemented in any order. For convenience, the use of terms such as "first" and "next" in the operational flow in the claims, specification, and drawings does not mean that the process must be implemented in this order. [Explanation of symbols]
[0133] 1, 1a, 1b, 1c, 1d, 1e, 1f, 1g Driving information output system 10, 10a, 10b, 10c, 10d, 10e, 10f, 10g Driving information output device 11, 11a Vehicle information acquisition unit 12 Data Generation Unit 13, 13b Occupant status determination unit 14, 14a, 14b, 14c, 14d, 14e, 14f, 14g protection mode selection section 15 Data Processing Unit 16 Output section 17 Crew Authentication Unit 18 Driving Safety Assessment Department 19. Occupant information acquisition unit 21 Condition acquisition section 22 Abnormality determination section 20 Camera 30. Mike 40 Storage section
Claims
1. a vehicle information acquisition unit that acquires vehicle information related to the vehicle; a data generation unit that generates data including the vehicle information; an occupant information acquisition unit that acquires information regarding the relationship between a driver and a passenger of the vehicle; a protection mode selection unit that selects a protection mode including whether or not the data needs to be protected based on first information about the vehicle; a data processing unit that processes the data in the protection mode; an output unit that outputs the processed data to a storage unit or to an external device via a communication unit; Equipped with The first information is information regarding the relationship between the driver and passengers of the vehicle. Vehicle information output device.
2. a vehicle information acquisition step of acquiring vehicle information related to the vehicle; a data generation step of generating data including the vehicle information; an occupant information acquisition step of acquiring information regarding a relationship between a driver and a passenger of the vehicle; a protection mode selection step of selecting a protection mode including whether or not the data needs to be protected based on first information about the vehicle; a data processing step of processing the data in the protected manner; an output step of outputting the processed data to a storage unit or to an external device via a communication unit; A method of performing The first information is information regarding the relationship between the driver and passengers of the vehicle. Vehicle information output method.
Citation Information
Patent Citations
Information processing device, mobile device, and information process system, method and program
JP2021043571A