Information processing device

The information processing device addresses the challenge of obtaining consent from the correct vehicle owner by re-obtaining consent when necessary and anonymizing data when ownership changes, ensuring proper data utilization and privacy compliance.

JP7910524B2Active Publication Date: 2026-08-25TOYOTA JIDOSHA KK
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023118932
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-07-21
Publication Date
2026-08-25
Estimated Expiration
2043-07-21

AI Technical Summary

Technical Problem

Existing systems face challenges in obtaining appropriate consent for information collection from vehicle owners when vehicle ownership changes or data usage conditions change, potentially contacting the wrong user or requiring unnecessary re-consent.

Method used

An information processing device that includes a control unit to obtain initial consent from a vehicle owner through an in-vehicle device and re-obtain consent if the owner has not changed, or anonymize data if the owner cannot be identified, ensuring that consent is obtained from the correct user.

Benefits of technology

Ensures that consent is appropriately obtained from the correct user, preventing unauthorized data use and enabling effective utilization of vehicle data while respecting privacy concerns.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007910524000001
    Figure 0007910524000001
  • Figure 0007910524000002
    Figure 0007910524000002
  • Figure 0007910524000003
    Figure 0007910524000003
Patent Text Reader

Abstract

To appropriately obtain an agreement about information collection from an information provider.SOLUTION: A consent to collection of first data from a first vehicle is obtained at a first timing from a first user via an on-vehicle device installed on the first vehicle, and when a re-consent from the first user is required to use of the first data collected from the first vehicle, a re-consent request is issued to the on-vehicle device on condition that an owner of the first vehicle has not changed since the first timing.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a technology for collecting information from vehicles.

Background Art

[0002] In recent years, proper management of personal information has been demanded. Regarding this, for example, Patent Document 1 discloses a system for obtaining consent from users for data provision at low cost.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] An object of this disclosure is to appropriately obtain consent for information collection from an information provider.

Means for Solving the Problems

[0005] One aspect of an embodiment of this disclosure is obtaining, from a first user, consent for collecting first data from a first vehicle at a first timing via an in-vehicle device provided in the first vehicle; and when re-consent by the first user is required for the use of the first data collected from the first vehicle, issuing a re-consent request to the in-vehicle device on the condition that the owner of the first vehicle has not changed since the first timing, an information processing apparatus having a control unit that executes the above.

[0006] Also, as another aspect, there are a method executed by the above device, a program for causing a computer to execute the method, or a computer-readable storage medium that non-temporarily stores the program. [Effects of the Invention]

[0007] According to this disclosure, it is possible to appropriately obtain consent from information providers for the collection of information. [Brief explanation of the drawing]

[0008] [Figure 1] A schematic diagram of the vehicle system according to the first embodiment. [Figure 2] A diagram showing the components of an in-vehicle device and a server device. [Figure 3] An example of data stored by in-vehicle devices and server devices. [Figure 4] A flowchart of the processes performed by the in-vehicle device. [Figure 5] An example of a screen used to request consent for data provision. [Figure 6] A flowchart of the processes performed by the server device. [Modes for carrying out the invention]

[0009] In recent years, attempts have been made to utilize data collected from automobiles. It is expected that using vehicle-based data as big data will enable the provision of a variety of services. On the other hand, data transmitted from vehicles may include personal information or information similar to personal information. This type of data includes not only personal information itself, but also location data and other information that, when linked to an individual, can raise privacy concerns.

[0010] Therefore, attempts are being made to explain the collection and use of data to users (e.g., vehicle owners and drivers) in advance, obtain their consent, and then enter into data provision agreements. This explanation and consent can be obtained, for example, through in-vehicle devices installed in the target vehicle.

[0011] On the other hand, there may be cases where previously collected data needs to be used for purposes different from the original agreement. In such cases, where conditions not included in the initial data provision agreement are added later, it is preferable to obtain the user's consent again.

[0012] However, if the vehicle in question is sold, or if the user who previously provided data is different from the user currently using the vehicle, a problem may arise where the person contacting the user via the in-vehicle device is not the same person who previously gave consent. The information processing device relating to this disclosure solves such problems.

[0013] The information processing device relating to the first aspect of this disclosure is: The system includes a control unit that performs the following actions: obtaining consent from a first user via an in-vehicle device installed in the first vehicle at a first timing for collecting first data from the first vehicle; and, when further consent from the first user is required for the use of the first data collected from the first vehicle, issuing a request for further consent to the in-vehicle device, provided that the owner of the first vehicle has not changed since the first timing.

[0014] The first data refers to data acquired by the first vehicle while it is in motion, and includes the driver's personal information and data related to the first vehicle's operation (e.g., location information, speed information, and images from the onboard camera). The first data is also referred to as sensor data. The control unit obtains consent to provide the first data from the first user of the first vehicle via the in-vehicle device at the first timing.

[0015] On the other hand, there are cases where renewed consent from the primary user is required for the use of the primary data that has already been collected. For example, this may occur if the purpose for which the primary data was used is subsequently changed. However, if the owner of the first vehicle has changed since the timing when the initial consent was obtained, even if the user is contacted via the in-vehicle device mounted on the first vehicle, there is a high possibility that it will reach a person different from the original user. Therefore, in such a case, the control unit re-acquires consent on the condition that the owner of the first vehicle has not changed since the first timing. According to such a configuration, it is possible to avoid contacting a user different from the user who gave the initial consent.

[0016] In addition, if the owner of the first vehicle has changed since the first timing, the control unit may resolve the issue regarding consent by performing a predetermined process. For example, the control unit may search for the contact information of the owner of the first vehicle at the first timing using a predetermined database. Thereby, the user who owned the first vehicle at that time can be identified.

[0017] In addition, when the user who owned the first vehicle at that time cannot be identified or when consent cannot be obtained again from the user, the control unit may perform anonymization processing on the collected first data. That is, instead of obtaining consent, the first data may be anonymized to a level where consent is not required. That is, instead of obtaining consent, the first data may be anonymized to a level where consent is not required.

[0018] Hereinafter, specific embodiments of the present disclosure will be described based on the drawings. The hardware configuration, module configuration, functional configuration, etc. described in each embodiment are not intended to limit the technical scope of the disclosure only to those unless otherwise specified.

[0019] (First Embodiment) The outline of the vehicle system according to the first embodiment will be described with reference to FIG. 1. The vehicle system according to the present embodiment includes a vehicle 10 equipped with an in-vehicle device 100 and a server device 200. There may be a plurality of vehicles 10 (in-vehicle devices 100) included in the system.

[0020] Vehicle 10 is a probe vehicle for collecting data. Vehicle 10 is configured to collect data related to driving and data related to the occupants, and can transmit the collected data to the server device 200 via the onboard device 100. Examples of data related to driving include vehicle speed, direction of travel, location information, information on driving operations, information on vehicle behavior, or image data captured by on-board cameras. Examples of data related to occupants include personal identifiers, gender, or age. In the following explanation, the data collected by vehicle 10 will be referred to as sensor data. Sensor data is an example of "first data," but the data collected by vehicle 10 does not necessarily have to be obtained through sensing.

[0021] The server device 200 is a device that provides predetermined services based on sensor data collected from the vehicles 10. For example, by collecting location information and speed information from multiple vehicles 10, it can generate congestion information and traffic information and provide it to other vehicles. Furthermore, by collecting data on the occupants of the vehicles, it becomes possible to provide information tailored to individuals. In addition, by collecting images captured by on-board cameras, it becomes possible to generate road map data. The server device 200 requests multiple vehicles 10 to transmit predetermined sensor data, and the vehicles 10 (onboard devices 100) respond by transmitting the sensor data.

[0022] The server device 200 may be a device that provides services to vehicle 10 (or other vehicles) based on sensor data collected from vehicle 10, or it may be a device that relays sensor data collected from vehicle 10 to further external devices. For example, if there are multiple types of sensor data collected from vehicle 10, the server device 200 may relay the sensor data for each type of sensor data to different external devices under the management of different operators.

[0023] Furthermore, the server device 200 obtains consent from the user associated with the vehicle 10 (for example, the driver) to provide sensor data (i.e., to transmit sensor data to the server device 200). Whether or not consent has been given is stored in both the server device 200 and the in-vehicle device 100. The in-vehicle device 100 transmits data to the server device 200 only if consent has been given for data provision. The in-vehicle device 100 has a database that stores whether or not consent has been given for each type of sensor data, and based on this database, it determines whether or not the user has consented to the transmission of certain sensor data (whether they have consented in the past).

[0024] Furthermore, the server device 200 will check the usage conditions, etc., of the sensor data collected in the past. If the system is modified, it will be configured to have a function to obtain renewed consent from the user at the time (i.e., the user who previously gave consent).

[0025] In the vehicle system according to this embodiment, multiple in-vehicle devices 100 and server devices 200 are interconnected by a network. The network may include, for example, a Wide Area Network (WAN), which is a global public communication network such as the Internet, or other communication networks. The network may also include a telephone communication network such as a mobile phone network, or a wireless communication network such as Wi-Fi (registered trademark).

[0026] Each element that makes up the system will be explained. Figure 2 shows the system configuration of the in-vehicle device 100 and the server device 200.

[0027] First, let's explain the configuration of server device 200. The server device 200 can be configured as a computer having a processor such as a CPU or GPU, main memory such as RAM or ROM, and auxiliary storage such as EPROM, hard disk drive, or removable media. The auxiliary storage contains an operating system (OS), various programs, various tables, etc., and by executing the programs stored therein, various functions that match a predetermined purpose, as described later, can be realized. However, some or all of the functions may be realized by hardware circuits such as ASICs or FPGAs. The server device 200 may consist of a single computer or multiple computers that cooperate with each other.

[0028] The server device 200 is comprised of a control unit 201, a storage unit 202, and a communication unit 203.

[0029] The control unit 201 is a computing device that manages the control performed by the server device 200. The control unit 201 can be implemented by a computing device such as a CPU. The control unit 201 is configured with three functional modules: a consent acquisition unit 2011, a data acquisition unit 2012, and a re-consent acquisition unit 2013. Each functional module may be implemented by the CPU executing a program stored in an auxiliary storage means.

[0030] Prior to acquiring sensor data from the vehicle 10, the consent acquisition unit 2011 obtains consent from the user of the vehicle 10 for data provision. The server device 200 is configured to acquire or store data related to the intended use of the sensor data to be acquired (hereinafter referred to as "intended use data"). The intended use data includes data related to the intended use of the sensor data, the destination of the sensor data, the conditions for acquiring the sensor data, the timing of the transmission of the sensor data, the entity (business operator) that will use the sensor data, and the conditions related to the data provision contract. The consent acquisition unit 2011 presents this information to the user of the vehicle 10 via the in-vehicle device 100.

[0031] The consent acquisition unit 2011 determines whether consent to data provision exists for each type of sensor data, based on the response from the user of the vehicle 10. Furthermore, if the consent acquisition unit 2011 receives a response from the user in response to an inquiry, it stores the presence or absence of consent in both the server device 200 and the in-vehicle device 100. Note that if there are multiple types of sensor data to be provided, or if there are multiple businesses using the sensor data, comprehensive consent may be obtained, or consent from multiple parties may be obtained. Furthermore, once the user of vehicle 10 has consented to the provision of data, it can be considered that a data provision agreement has been established between the user and the business operator receiving the sensor data.

[0032] The data acquisition unit 2012 requests the transmission of sensor data from each of the multiple vehicles 10 (onboard devices 100). For example, the server device 200 requests the transmission of sensor data from the images captured by the vehicle 10. If the service involves generating road map data based on the data, the server device 200 requests the vehicle 10 to transmit image data. The type of sensor data requested by the server device 200 may vary depending on the service performed by the server device 200. The data acquisition unit 2012 receives sensor data from multiple vehicles 10 (onboard devices 100) and stores it in the storage unit 202. The stored sensor data is used to provide a predetermined service.

[0033] The re-consent acquisition unit 2013 executes a process to obtain renewed consent from the user of the vehicle 10 regarding the use of sensor data previously collected by the server device 200. For example, consider a case where images from an in-vehicle camera were previously provided under the condition that they would be used for map generation. In this case, the provided images cannot be used for any purpose other than map generation. If it is desired to use the sensor data outside of this condition, the user of vehicle 10 must be given renewed consent. The re-consent acquisition unit 2013 executes a process to obtain renewed consent from the user in such a case. A specific example will be described later.

[0034] The storage unit 202 comprises a main memory and an auxiliary storage device. The main memory is the memory where programs executed by the control unit 201 and data used by said control programs are stored. The auxiliary storage device is the device where programs executed by the control unit 201 and data used by said control programs are stored. Sensor data collected from the vehicle 10 is stored in the storage unit 202.

[0035] Furthermore, the aforementioned usage data is stored in the memory unit 202. Figure 3(A) shows an example of the usage data 202A. Usage data is data related to the handling of sensor data, and includes information such as the sensor data identifier (data ID), the type of sensor data, the destination of the sensor data, the conditions for acquiring the sensor data, the transmission cycle of the sensor data, and the conditions for using the provided sensor data. The destination of the sensor data may be represented by a network address or the like. Examples of conditions for acquiring sensor data include: "an image is captured at a specific location," "video is captured in a specific section," and "location information is acquired every second during a specific time period."

[0036] Furthermore, the memory unit 202 stores data for managing the user's consent to provide sensor data (hereinafter referred to as consent data). Here, we will explain consent data. Consent data is data that records whether or not the provision of sensor data has been authorized by the user of vehicle 10, for each user, destination of the sensor data, and type of sensor data. Consent data can be generated, for example, based on the results of interaction with the user of vehicle 10.

[0037] Figure 3(B) shows an example of consent data 202B. As illustrated, the consent data includes the following fields: User ID, Vehicle ID, Date, Data ID, Destination, Terms of Use, and Availability. The User ID field stores an identifier that uniquely identifies the user who has consented to the provision of data. The Vehicle ID field stores the identifier of the vehicle 10 on which the in-vehicle device 100, which the user consented to, is installed. The Date field stores the date on which consent was given. The Data ID field stores information that identifies the type of sensor data. The Destination field stores information that identifies the destination of the sensor data. The Terms of Use field stores information about the conditions under which the operator will use the provided sensor data. The Availability field stores whether consent has been given to the provision of the sensor data ("Allowed" or "Denyed").

[0038] Furthermore, the storage unit 202 stores data (vehicle data) related to the owner of the vehicle 10. Figure 3(C) shows an example of vehicle data 202C. As illustrated, the vehicle data includes the following fields: Vehicle ID, User ID, Vehicle ID, and Update Date. The Vehicle ID field stores an identifier that uniquely identifies the vehicle. The User ID field stores an identifier that uniquely identifies the owner of the vehicle. The Update Date is the date the data was updated.

[0039] The communication unit 203 is a communication interface for connecting the server device 200 to a network. The communication unit 203 is comprised of, for example, a network interface board and a wireless communication circuit for wireless communication.

[0040] Next, the in-vehicle device 100 will be described. Vehicle 10 is a connected car that has the ability to communicate with an external network. Vehicle 10 is equipped with an in-vehicle device 100.

[0041] The in-vehicle device 100 is a computer for collecting information. In this embodiment, the in-vehicle device 100 has a plurality of sensors for collecting information related to the driving of the vehicle 10, and transmits the collected sensor data to the server device 200 at a predetermined timing. The in-vehicle device 100 may be a device that provides information to the occupants of the vehicle 10 (for example, a car navigation system), or it may be an electronic control unit (ECU) of the vehicle 10. Alternatively, the in-vehicle device 100 may be a data communication module (DCM) with communication functions.

[0042] The in-vehicle device 100 can be configured as a computer having a processor such as a CPU or GPU, main memory such as RAM or ROM, and auxiliary storage such as an EPROM, hard disk drive, or removable media. The auxiliary storage contains an operating system (OS), various programs, various tables, etc., and by executing the programs stored therein, various functions that match a predetermined purpose, as described later, can be realized. However, some or all of the functions may be realized by hardware circuits such as ASICs or FPGAs.

[0043] The in-vehicle device 100 comprises a control unit 101, a storage unit 102, a communication unit 103, and an input / output unit 104. The in-vehicle device 100 is also connected to a sensor group 110.

[0044] The control unit 101 is a computing unit that realizes various functions of the in-vehicle device 100 by executing a predetermined program. The control unit 101 may be implemented by, for example, a CPU. The control unit 101 is configured as a functional module comprising a data acquisition unit 1011, a management unit 1012, and a data transmission unit 1013. Each functional module may be implemented by executing a stored program using a CPU.

[0045] The data acquisition unit 1011 acquires sensor data from one or more sensors included in the sensor group 110 at predetermined timings and stores it in the sensor DB 102A of the storage unit 102. If multiple sensor data can be acquired, the data acquisition unit 1011 may acquire all of them. The sensor DB 102A is a database that stores sensor data collected from sensors on the vehicle 10.

[0046] Figure 3(D) shows an example of data stored in the sensor DB102A. In addition to sensor data, the sensor DB102A also contains the user identifier of vehicle 10 and the date on which the sensor data was acquired. At that time, the location where the sensor data was acquired (location information) and the ID of the sensor data are stored.

[0047] Based on the consent obtained from the user of the vehicle 10, the management unit 1012 determines which sensor data stored in the sensor DB 102A should be transmitted to the server device 200. Specifically, the management unit 1012 performs the following processes.

[0048] (1) Processing to receive usage data from server device 200 The server device 200 requests data from the vehicle 10 by transmitting the aforementioned usage data to the in-vehicle device 100. In other words, the usage data also functions as data to request the vehicle 10 to transmit specific sensor data. As mentioned above, the usage data includes the sensor data identifier (data ID), the type of sensor data (data type), the destination of the sensor data, the conditions for acquiring the sensor data, and the transmission cycle of the sensor data. The usage data may also include information about the purpose of the sensor data, the business operator using the sensor data, and the usage conditions. The usage data transmitted from the server device 200 is stored in the storage unit 102.

[0049] (2) Processing to manage user consent regarding the transmission of sensor data to external parties. External transmission refers to sending sensor data to a device located outside the vehicle 10 (for example, a server device 200) (i.e., providing sensor data to an external party). The management unit 1012 obtains from the driver whether or not they consent to the provision of specific sensor data included in the usage data received from the server device 200, and generates the aforementioned consent data. The consent data is stored in the storage unit 102 (consent data 102B), and is also transmitted to the server device 200 and stored in the storage unit 202 (consent data 202B). The management unit 1012 determines whether or not to transmit the sensor data requested by the server device 200, based on the consent data and the driver detection results.

[0050] (3) Process to identify sensor data that has been requested by the server device 200 and for which consent has been obtained for external transmission. The management unit 1012 determines, based on the consent data and usage data, whether or not the requested sensor data is permitted to be transmitted externally, and if transmission is permitted, it decides to transmit the sensor data.

[0051] For example, the management unit 1012 determines whether the in-vehicle device 100 possesses the sensor data specified by the request data. The management unit 1012 recognizes what type of sensor data is requested by referring to the data ID included in the request data. The management unit 1012 also determines whether the in-vehicle device 100 possesses matching sensor data by comparing the acquisition conditions included in the request data with the records recorded in the sensor DB 102A.

[0052] If the in-vehicle device 100 possesses the sensor data specified by the request data, and consent has been given for the provision of said sensor data, the management unit 1012 determines that said sensor data should be transmitted. If the user of vehicle 10 has no history of authorizing external transmission of the target sensor data, the management unit 1012 may inquire with the user of vehicle 10 about the permission to transmit the data and update the consent data based on the result.

[0053] The data transmission unit 1013 acquires the sensor data determined by the management unit 1012 from the storage unit 102 and transmits it to the server device 200.

[0054] The storage unit 102 is a memory device that includes a main memory and an auxiliary storage device. The auxiliary storage device stores the operating system (OS), various programs, various tables, etc., and by loading the programs stored therein into the main memory and executing them, various functions that match a predetermined purpose, as described later, can be realized. Main memory may include RAM (Random Access Memory) and ROM (Read Only Memory). Auxiliary storage may include EPROM (Erasable Programmable ROM) and hardware. This may include disk drives (HDD, Hard Disk Drive). Furthermore, auxiliary storage devices may also be included. This may include removable media, i.e., portable recording media.

[0055] The communication unit 103 is a wireless communication interface for connecting the in-vehicle device 100 to a network. The communication unit 103 is configured to communicate with the server device 200 using communication standards such as a mobile communication network, wireless LAN, or Bluetooth®.

[0056] The input / output unit 104 is a means for receiving input operations performed by the user of the device and presenting information. In this embodiment, the input / output unit 104 consists of a single touch panel display. That is, it is composed of a liquid crystal display and its control means, and a touch panel and its control means.

[0057] The sensor group 110 is a collection of multiple sensors on the vehicle 10. These multiple sensors may include, for example, a speed sensor, an acceleration sensor, and a GPS module, which acquire data related to the vehicle's movement. Alternatively, these multiple sensors may include an image sensor, an illuminance sensor, and a rain sensor, which acquire data related to the vehicle's driving environment. The sensor group 110 may also include sensors for collecting data about the driver or occupants of the vehicle 10. For example, the occupants of the vehicle can be identified based on images obtained by capturing images of the interior of the vehicle, and data about those occupants can be transmitted as sensor data.

[0058] Furthermore, the sensor group 110 may also include an in-vehicle camera mounted facing outwards. Images acquired by the in-vehicle camera can also be considered as part of the sensor data.

[0059] Note that the configuration shown in Figure 2 is just one example, and all or part of the illustrated functions may be performed using specially designed circuits. Furthermore, program storage and execution may be performed using combinations of main memory and auxiliary memory other than those shown.

[0060] Next, we will describe the details of the processes performed by the in-vehicle device 100. Figure 4 is a flowchart illustrating the process by which the in-vehicle device 100 transmits sensor data to the server device 200 based on the application data received from the server device 200. The illustrated process is executed periodically while the vehicle 10 is in motion.

[0061] In parallel with the execution of the illustrated process, the data acquisition unit 1011 periodically acquires sensor data from the sensors included in the sensor group 110 and stores it in the sensor DB 102A of the storage unit 102.

[0062] Furthermore, in parallel with the execution of the illustrated process, the management unit 1012 will execute a process to receive usage data from the server device 200. For example, the management unit 1012 queries the server device 200 to determine whether or not there is any usage data to be received. Whether or not there is any usage data to be received can be determined, for example, based on the last update date and version number of the usage data. Therefore, the server device 200 may notify the in-vehicle device 100 of the last update date and version number of the usage data. Alternatively, the in-vehicle device 100 may store this information in the storage unit 102. If there is usage data to be received, the management unit 1012 receives the usage data from the server device 200 and stores it in the storage unit 102. At this time, old usage data may be deleted. Furthermore, at the time the process shown in Figure 4 is initiated, the in-vehicle device 100 is assumed to have completed driver identification. Driver identification can be performed, for example, based on images acquired by a camera installed in the driver's seat.

[0063] First, in step S11, the management unit 1012 identifies the sensor data requested by the server device 200 based on the usage data. In this step, the sensor data requested by the server device 200 and stored in the storage unit 102 is identified. Multiple types of sensor data may be identified in this step.

[0064] The processing in steps S12 to S15 is performed for each of the multiple sensor data identified in step S11. First, in step S12, the management unit 1012 determines whether the driver's consent has been obtained to transmit the target sensor data to the server device 200. For example, if there is a record in the consent data 102B that matches the combination of data ID and destination shown in the usage data, and the provision permission field is set to "permitted", then this step is determined to be positive. This step is determined to be negative if the provision permission field is set to "rejected", or if no such record exists (i.e., the driver has not expressed their intention regarding the external transmission of the target sensor data).

[0065] If the result in step S12 is positive, the process proceeds to step S13, and the data transmission unit 1013 transmits the corresponding sensor data.

[0066] If the result in step S12 is negative, the process proceeds to step S14. In step S14, the management unit 1012 determines whether the driver has previously expressed refusal to transmit sensor data with the corresponding data ID. For example, if there is a record in the consent data 102B that matches the combination of data ID and destination shown in the usage data, and the availability field is set to "rejected", then this step results in a positive determination. If the determination in step S14 is positive, the corresponding sensor data will not be transmitted.

[0067] If a negative result is obtained in step S14, it means that the driver has not previously expressed their consent regarding the sensor data for the corresponding data ID. In this case, the process proceeds to step S15, where the driver is asked whether they consented or not.

[0068] In step S15, the management unit 1012 confirms with the driver via the input / output unit 104 whether it is acceptable to provide the appropriate type of sensor data. This confirmation can be performed, for example, via a screen like the one shown in Figure 5. This screen may include information about the type of sensor data, its purpose, destination, acquisition conditions, and the business operator that will use the sensor data. If there are multiple types of sensor data to be transmitted, consent may be obtained on separate screens for each type, or the user may be given the option to consent to the provision of each type of sensor data on the same screen.

[0069] Once the driver provides their response, the result is reflected in consent data 102B and consent data 202B. Based on this information, steps S12 and S13 are repeated.

[0070] Next, the usage conditions for sensor data previously collected by the server device 200 are changed. The following describes the process that the server device 200 executes in such a case. Changes in usage conditions include, for example, a change in the intended use of the sensor data from the time of the contract, or a change in the business operator using the sensor data from the time of the contract. If it becomes necessary to use the sensor data under conditions not included in the original contract, the process shown in Figure 6 is executed by the server device 200. The process in Figure 6 is executed by the re-consent acquisition unit 2013 of the server device 200.

[0071] First, in step S21, it is determined whether the current owner of the vehicle 10 that previously transmitted the target sensor data (hereinafter referred to as the target vehicle) has changed since the time the sensor data was acquired. In this step, first, the consent data is referenced to extract records related to past consents. Then, it is determined whether the owner of the vehicle (target vehicle) indicated by the vehicle ID included in the record has changed since the time the sensor data was acquired. The current owner of the target vehicle can be determined based on the vehicle data 202C stored in the server device 200.

[0072] If the owner of the vehicle in question has not changed since the time the sensor data was acquired, the process proceeds to step S23, and consent is requested again via the in-vehicle device 100 installed in the same vehicle.

[0073] If the owner of the vehicle in question has changed since the time the sensor data was acquired, the process proceeds to step S22. In step S22, it is determined whether a terminal associated with the previous owner of the vehicle (i.e., a user who previously gave consent; hereinafter referred to as the target user) can be identified. For example, if a vehicle currently owned by the target user can be identified, the in-vehicle device 100 installed in that vehicle can be identified as a terminal associated with the target user. The vehicle currently owned by the target user may be identified, for example, by searching the vehicle data 202C. If the result in this step is positive, the process proceeds to step S24. If the result in this step is negative, the process ends.

[0074] In step S24, data is sent to the terminal identified in step S22 requesting renewed consent regarding the use of sensor data. The terminal notifies the user that the conditions for using the sensor data have changed and requests consent for data provision. If consent is obtained, consent data 102B and 202B are updated in the same manner as described above.

[0075] As explained above, in the first embodiment, if the conditions for using previously collected sensor data change, the server device 200 obtains renewed consent via the in-vehicle device 100, provided that the vehicle owner has not changed since the time of the previous consent. This configuration prevents unrelated users (for example, a user who purchased the target vehicle as a used car) from being asked to re-consent to provide data. Furthermore, since it is possible to contact the user who provided the sensor data at the time, it becomes possible to make better use of the sensor data.

[0076] (Modification of the first embodiment) In the first embodiment, the server device 200 identified the terminal currently associated with the target user by referring to vehicle data. Alternatively, the server device 200 may identify the terminal associated with the target user using other data sources. For example, if data for identifying the target user's contact information, email address, mobile device, etc., is available, the target user's contact information can be obtained by accessing that data. Furthermore, if there is a platform separate from the server device 200 for managing consent to data provision, the contact information of the target user may be obtained using that platform.

[0077] (Second Embodiment) In the first embodiment, when the ownership of the target vehicle changed, the terminal associated with the previous owner (for example, an in-vehicle device 100 installed in the vehicle after the change) was identified, and consent was obtained again through the identified terminal.

[0078] On the other hand, there are cases where it is not possible to contact the owner, such as when the owner completely gets rid of the vehicle or when the communication function is unavailable in the vehicle they have switched to. In the second embodiment, the sensor data collected in the past is anonymized so that consent does not need to be obtained in such cases.

[0079] In the second embodiment, if the server device 200 determines in step S22 that it cannot identify the terminal associated with the previous owner, it performs a process to anonymize the target sensor data. Such a process may include, for example, deleting or editing items that can identify a user, or items that can identify a user through a combination of these, thereby making it impossible to identify the user. For example, the data can be anonymized by replacing a unique identifier for each user with an identifier that represents age, gender, or a combination thereof.

[0080] In this example, we showed how to replace user identifiers, but the method is not limited to any specific one, as long as the data can be anonymized. With this configuration, even if it is not possible to contact the previous owner of the vehicle in question, it becomes possible to utilize sensor data collected in the past.

[0081] (modified version) The embodiments described above are merely examples, and this disclosure may be modified as appropriate without departing from its essence. For example, the processes and means described in this disclosure can be freely combined and implemented, as long as no technical inconsistencies arise.

[0082] Furthermore, in the description of the embodiment, the vehicle owner was determined using vehicle data 202C, but the vehicle owner does not necessarily have to be determined using vehicle data 202C. Furthermore, in step S21, it was determined whether the vehicle owner was different or not. However, if it is possible to determine whether the person who previously agreed to provide data and the current user of vehicle 10 are the same person, the person to be determined does not necessarily have to be the "owner of vehicle 10".

[0083] Furthermore, while facial images were used as an example of information for identifying the driver of vehicle 10 in the description of the embodiment, the driver of vehicle 10 may also be identified based on other biometric information. Examples of such biometric information include fingerprints, voiceprints, or iris patterns.

[0084] Furthermore, although the description of the embodiment only illustrates the server device 200 as the destination for sensor data transmission, there may be multiple destinations for sensor data transmission. In this case, the in-vehicle device 100 may receive usage data from each of the multiple external devices. The destination for sensor data transmission may be the manufacturer or related businesses of the vehicle 10, or a third party with whom a data provision agreement has been concluded.

[0085] Furthermore, processes described as being performed by a single device may be divided and executed by multiple devices. This may be done. Alternatively, processes described as being performed by different devices may be performed by a single device. In a computer system, the hardware configuration (server configuration) by which each function is implemented can be flexibly changed.

[0086] The present disclosure can also be realized by supplying a computer program implementing the functions described in the embodiments above to a computer, and having one or more processors in the computer read and execute the program. Such a computer program may be provided to the computer by a non-temporary computer-readable storage medium that can be connected to the computer's system bus, or it may be provided to the computer via a network. Non-temporary computer-readable storage mediums include, for example, any type of disk such as magnetic disks (floppy disks, hard disk drives (HDDs), etc.), optical disks (CD-ROMs, DVDs, Blu-ray discs, etc.), read-only memory (ROM), random access memory (RAM), EPROM, EEPROM, magnetic cards, flash memory, optical cards, and any type of medium suitable for storing electronic instructions. [Explanation of Symbols]

[0087] 10.. Vehicles 100...In-vehicle equipment 200... Server equipment 101,201...Control Unit 102,202...Storage section 103,203... Communications Department 104...Input / output section 110... Sensor group

Claims

1. Consent to collect first data from the first vehicle is obtained from the first user at a first time via an in-vehicle device installed in the first vehicle, When the use of the first data collected from the first vehicle requires renewed consent from the first user, a renewed consent request will be issued to the in-vehicle device, provided that the owner of the first vehicle has not changed since the first time. If the owner of the first vehicle has changed since the first timing, When the terminal associated with the first user can be identified, the collected first data is used to obtain consent again via the terminal associated with the first user without anonymization; when the terminal associated with the first user cannot be identified, the first data is used to anonymize. An information processing device having a control unit that performs the following.

2. The process of identifying the terminal associated with the first user includes the process of searching for the contact information of the owner of the first vehicle at the first timing using a predetermined database. The information processing apparatus according to claim 1.

Citation Information

Patent Citations

  • Data access control program, data access control method and authorization server

    JP2021117807A

  • Information processing apparatus, cps system, information processing method, and program

    JP2022143653A

  • Control device, system, and control method

    JP2023032333A