System including a quantitative assessment model of privacy infringement risk using object identification information

KR103000171B1Active Publication Date: 2026-08-05EDITOR CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
EDITOR CO LTD
Filing Date
2026-03-12
Publication Date
2026-08-05

Smart Images

  • Figure 112026030359709-PAT00001_ABST
    Figure 112026030359709-PAT00001_ABST
Patent Text Reader

Abstract

The present invention relates to the field of image processing and data security technology, and more specifically, to a system and method of operation that protects individual privacy from video data collected in real time within a facility using artificial intelligence-based object identification technology, and simultaneously intelligently detects potential dangerous situations such as falls or wandering and securely transmits encrypted information to a designated recipient.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The present invention relates to the field of image processing and data security technology, and more specifically, to a system and method of operation that protects individual privacy from video data collected in real time within a facility using artificial intelligence-based object identification technology, and simultaneously intelligently detects potential dangerous situations such as falls or wandering and securely transmits encrypted information to a designated recipient. Background Technology

[0002] With the recent increase in social demand for safety and security, there has been a surge in the installation of video surveillance systems within various facilities, such as hospitals, nursing homes, and smart homes. These systems provide a foundation for preventing safety accidents within facilities and enabling a rapid response in the event of emergencies.

[0003] In this regard, privacy protection technology that detects the faces or body parts of individuals within a video and uniformly applies blur or mosaic processing has been known in the past. However, such conventional technology had several clear limitations.

[0004] Conventional technology applied de-identification processing of a uniform intensity without considering the context of the situation. For example, by applying the same level of masking to an everyday situation of simply walking down a hallway and a sensitive situation of falling in a bathroom, there was a problem in that it caused unnecessary and excessive information loss in the former case and failed to guarantee sufficient privacy in the latter case.

[0005] Conventional danger detection systems primarily relied on simple motion detection or emergency button activation. Consequently, they failed to distinguish between a normal state of lying in bed and a critical state of collapsed, immobile on the floor, resulting in a high false alarm rate. Furthermore, they had limitations in that they could not detect danger at all in situations where the user was unconscious or unable to press a button.

[0006] Privacy protection features and risk alarm functions were not organically integrated. In the event of an emergency, the information transmitted to the administrator was mostly either original video footage that could seriously infringe on individual privacy, or simple text alerts that were of no help whatsoever in understanding the situation.

[0007] Therefore, there is a growing demand for new technologies that can actively protect user privacy according to the situation while accurately recognizing various forms of risk and safely delivering necessary information. The problem to be solved

[0008] The present invention has been devised to solve the problems of the prior art described above, and its main purpose is to provide a system that can maximize the efficiency of safety management while ensuring the privacy of personnel within the facility to the maximum extent.

[0009] The specific problems that the present invention aims to solve are as follows.

[0010] It provides a context-adaptive privacy protection function that comprehensively analyzes various factors such as the type, size, and number of objects present in the image and dynamically adjusts the intensity of anonymization processing according to the sensitivity of the current situation.

[0011] It provides an intelligent situational analysis function that analyzes complex information, such as a person's posture, the duration of specific postures, and the location of occurrence, to detect potential hazardous situations like falls, wandering, and prolonged immobility with high accuracy and minimize false alarms.

[0012] In the event of a dangerous situation, a useful and secure information transmission system is provided that combines visual information (e.g., masked thumbnails) that has been safely anonymized to prevent the exposure of an individual's identity with text describing the specific situation, enabling an administrator to quickly grasp the severity of the situation.

[0013] It provides means for users or their representatives to directly set and manage privacy protection levels and the scope of information disclosure, thereby guaranteeing the self-determination rights of data subjects and improving trust in the system.

[0014] Conventional systems focused solely on protecting the video data itself, leaving them vulnerable to operational security threats such as unauthorized access, malicious attacks, or misuse by insiders. In particular, they lacked a proactive response system capable of automatically detecting anomalies and immediately blocking access.

[0015] The conventional method of storing and analyzing original video on a central server carried a fundamental risk that all stored sensitive video information could be leaked in large quantities if the central server were exposed to hacking or insider threats. This necessitated a new architecture capable of fundamentally eliminating the risk of data leakage. means of solving the problem

[0017] In a system for protecting privacy and managing dangerous situations based on video information within a facility according to an embodiment of the present invention for solving the above problem,

[0018] Video acquisition unit that captures video in real time;

[0019] An object identification module that receives image data from the image acquisition unit, identifies objects within the image, and generates metadata including the type and location information of the identified objects;

[0020] A situation analysis module that quantitatively evaluates the potential for privacy infringement and risk situations of a video based on the above metadata to calculate a privacy protection index and a risk situation score;

[0021] A policy-based transmission module that determines a transmission policy based on the above-determined indices, controls the anonymization processing of the image data according to the above-determined policy, and encrypts and transmits the processed data to a designated recipient; and

[0022] A privacy setting management module that provides an interface for a user to control privacy-related settings of the above system;

[0023] Includes more,

[0024] The above situation analysis module is,

[0025] For each sensitive object detected within a video frame, a step of calculating an area-based influence value based on the screen occupancy ratio of the object;

[0026] A step of calculating individual object sensitivity values ​​by multiplying the area-based influence value calculated above by a sensitivity coefficient preset according to the type of object;

[0027] A step of deriving a total sensitivity value by summing all the individual object sensitivity values ​​calculated for all sensitive objects within the frame;

[0028] A step of calculating a stabilized sensitivity value by performing a log transformation on the total sensitivity value derived above; and

[0029] It is characterized by performing a first control logic that calculates the privacy protection index by multiplying the stabilized sensitivity value by a user protection preference coefficient set by the user through the privacy setting management module, and

[0030] The above first control logic is,

[0031] In the step of calculating the area-based influence value, a non-linear transformation function including trigonometric functions and square operations is used to receive the screen occupancy area ratio as input and output a non-linearly amplified result value, and

[0032] In the step of calculating the stabilized sensitivity value, by performing a logarithmic transformation by adding 1 to the total sensitivity value and taking the natural logarithm,

[0033] It is characterized by ensuring that the influence is exponentially amplified when the area occupied by an object on the screen exceeds a certain level, and preventing the privacy protection index value from becoming excessively large even when multiple sensitive objects exist.

[0034] The above sensitivity coefficient is,

[0035] It is determined objectively based on statistical data collected in advance,

[0036] Specifically, the method is characterized by conducting a user study targeting multiple evaluators to measure the level of privacy protection awareness regarding the de-identification processing of specific object types as a scale, and, based on the results of the statistical analysis of the user study, differentially assigning high sensitivity coefficients to object types with statistically significant high levels of privacy infringement awareness and low sensitivity coefficients to object types with relatively low levels of infringement awareness, and storing these values ​​in advance in the system's database.

[0037] The above system is,

[0038] An intrusion detection and response module that analyzes data access logs in real time to detect abnormal access patterns violating predefined security rules, sends a security alert to a system administrator upon detection, and blocks the access; and

[0039] It further includes masking control logic that determines the type and intensity of masking to be applied to the actual video based on the above privacy protection index, and

[0040] The above masking control logic is,

[0041] Using preset 'first threshold' and 'second threshold', a first condition for determining whether the privacy protection index exceeds the 'first threshold' and a second condition for determining whether the index further exceeds the 'second threshold' when the first condition is satisfied are evaluated sequentially, and

[0042] The policy-based transmission module controls the image processing module to apply 'Level 1 masking' when only the first condition is satisfied, and 'Level 2 masking' when both the first and second conditions are satisfied, according to the above evaluation results.

[0043] The above 'first threshold' and 'second threshold' are,

[0044] Through user experience testing performed during the system development phase, the "average index value at which a pre-set percentage (e.g., 80%) or higher of test participants responded that they 'started to perceive' a privacy infringement" is set as the "first threshold," and the "average index value at which a percentage or higher of participants responded that it was a 'serious privacy infringement'" is set as the "second threshold."

[0045] It is characterized by periodically analyzing feedback data regarding masking results received from an administrator during the operation of the above system and automatically correcting the threshold values.

[0046] The object identification module and the situation analysis module are implemented as an Edge AI processing unit integrated into the image acquisition unit, and

[0047] The above Edge AI processing unit is,

[0048] After analyzing the collected video data on internal volatile memory to extract metadata including the privacy protection index and the risk situation score, the original video data for which the analysis is completed is not stored but is immediately discarded, and

[0049] It may be characterized by transmitting only the extracted metadata to the policy-based transmission module. Effects of the invention

[0051] According to the present invention for solving the above-mentioned problems, the following effects can be expected.

[0052] According to the first control logic and masking control logic of the present invention, unlike conventional technology that applies uniform masking to all situations, the intensity of the de-identification process is dynamically optimized according to the sensitivity of the situation. As a result, unnecessary information loss is minimized in everyday situations, and strong privacy protection is provided in sensitive situations, thereby significantly enhancing the privacy rights and interests of users.

[0053] The second control logic (danger situation score calculation logic) of the present invention comprehensively analyzes multidimensional information such as a person's posture, duration, and location, so the reliability of judgment regarding danger situations is very high compared to simple motion detection methods. This has the effect of significantly reducing false alarms, such as mistaking a normal sleep state for danger, and increasing the detection rate of actual emergency situations, thereby greatly improving the safety management level of facilities.

[0054] The policy-based transmission module of the present invention combines anonymized visual information and text information and transmits them in encryption, allowing administrators to quickly and intuitively identify the urgency of the scene without concerns regarding privacy infringement. This provides the effect of maximizing the efficiency of the initial response (golden time) to emergency situations.

[0055] By granting users control over their information through the privacy settings management module, the right to self-determination of data subjects is respected, and users' psychological acceptance and trust in the system can be enhanced. This has the effect of minimizing privacy-related conflicts arising from the adoption of technology and contributing to the smooth operation and expansion of the system.

[0056] The present invention establishes a multi-layered security architecture that secures security at the system operation level, going beyond the protection of the data itself—such as data encryption and anonymization—by including an intrusion detection and response module. By detecting abnormal access patterns in real time and responding automatically, it guarantees the reliability and integrity of the system itself against external hacking attempts or threats of internal information leakage, thereby providing a significant effect of continuously maintaining a safe operating environment.

[0057] The 'Edge AI-based original data storage-free processing structure' according to another embodiment of the present invention provides a groundbreaking effect that fundamentally blocks the risk of video data leakage. By analyzing original video at the data collection terminal (Edge) and immediately discarding it without storing it on a central server, the original data itself does not exist to be leaked even if the central server is compromised. This implements the principle of 'design-based privacy' at the physical architecture level and possesses a technical advantage that guarantees the highest level of data security, particularly in medical and nursing facilities where security requirements are very high. Brief explanation of the drawing

[0059] Figure 1 illustrates an overall relationship diagram according to the present invention. FIG. 2 illustrates a flowchart of the organic operation mechanism between components according to the present invention. FIG. 3 illustrates a flowchart of the first control logic (privacy protection index calculation) according to the present invention. FIG. 4 illustrates a flowchart of the second control logic (calculation of risk situation score) according to the present invention. FIG. 5 illustrates a flowchart of the third control logic (transmission priority score calculation) according to the present invention. Specific details for implementing the invention

[0060] Hereinafter, various embodiments are described in more detail with reference to the attached drawings. The embodiments described in this specification may be modified in various ways. Specific embodiments may be depicted in the drawings and described in detail in the detailed description. However, specific embodiments disclosed in the attached drawings are intended only to facilitate understanding of various embodiments. Accordingly, the technical concept is not limited by specific embodiments disclosed in the attached drawings, and it should be understood that it includes all equivalents or substitutions that fall within the spirit and scope of the invention.

[0061] Terms including ordinal numbers, such as first, second, etc., may be used to describe various components, but these components are not limited by the aforementioned terms. The aforementioned terms are used solely for the purpose of distinguishing one component from another.

[0062] Functions related to artificial intelligence according to the present disclosure are operated through a processor and memory. The processor may be composed of one or more processors. In this case, the one or more processors may be general-purpose processors such as CPUs, APs, and DSPs (Digital Signal Processors), graphics-dedicated processors such as GPUs and VPUs (Vision Processing Units), or artificial intelligence-dedicated processors such as NPUs. The one or more processors control the processing of input data according to predefined operation rules or artificial intelligence models stored in memory. Alternatively, if the one or more processors are artificial intelligence-dedicated processors, the artificial intelligence-dedicated processors may be designed with a hardware structure specialized for processing a specific artificial intelligence model.

[0063] The predefined operating rules or artificial intelligence models are characterized by being created through learning. Here, being created through learning means that a predefined operating rules or artificial intelligence models configured to perform a desired characteristic (or objective) are created by a basic artificial intelligence model being trained using a number of training data by a learning algorithm. Such learning may be performed on the device itself where the artificial intelligence according to the present disclosure is executed, or it may be performed through a separate server and / or system. Examples of learning algorithms include supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but are not limited to the examples described above.

[0064] An artificial intelligence model can be composed of multiple neural network layers. Each of the multiple neural network layers has multiple nodes and weight values, and performs neural network operations through calculations between the results of previous layers and the multiple weights. The multiple weights possessed by the multiple neural network layers can be optimized based on the learning results of the artificial intelligence model. For example, multiple weights can be updated so that the loss value or cost value obtained by the artificial intelligence model during the learning process is reduced or minimized. Additionally, to minimize the loss value or cost value, multiple weights can be updated in a direction that minimizes the gradient associated with the loss value or cost value. Artificial neural networks may include deep neural networks (DNNs), such as Convolutional Neural Networks (CNNs), Deep Neural Networks (DNNs), Recurrent Neural Networks (RNNs), Restricted Boltzmann Machines (RBMs), Deep Belief Networks (DBNs), Bidirectional Recurrent Deep Neural Networks (BRDNNs), or Deep Q-Networks, but are not limited to the examples mentioned above.

[0065] A network is a network that serves as a transmission path for web pages; it may be a closed network such as a LAN (Local Area Network) or WAN (Wide Area Network), but it is desirable for it to be an open network such as the Internet. The Internet refers to a global open computer network structure that provides the TCP / IP protocol and various services existing at its upper layers, namely HTTP (HyperText Transfer Protocol), Telnet, FTP (File Transfer Protocol), DNS (Domain Name System), SMTP (Simple Mail Transfer Protocol), SNMP (Simple Network Management Protocol), NFS (Network File Service), and NIS (Network Information Service).

[0066] Terminals can be implemented in various forms. For example, the terminals described in this specification may include mobile terminals such as smartphones, tablet PCs, PDAs, portable multimedia players, and MP3 players, as well as fixed terminals such as smart TVs and desktop computers.

[0067] In this specification, terms such as “comprising” or “having” are intended to specify the existence of the features, numbers, steps, actions, components, parts, or combinations thereof described in the specification, and should be understood as not precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof. When a component is described as being “connected” or “connected” to another component, it should be understood that it may be directly connected to or connected to that other component, or that there may be other components in between. On the other hand, when a component is described as being “directly connected” or “directly connected” to another component, it should be understood that there are no other components in between.

[0068] Meanwhile, a "module" or "part" for a component as used in this specification performs at least one function or operation. Furthermore, a "module" or "part" may perform a function or operation by hardware, software, or a combination of hardware and software. Additionally, a plurality of "modules" or a plurality of "parts," excluding a "module" or "part" that must be performed on specific hardware or on at least one processor, may be integrated into at least one module. A singular expression includes a plural expression unless the context clearly indicates otherwise.

[0069] In addition, power, power transmission, and control therefor for the following assembly configurations and embodiments, including "by control," follow conventional technology including terminals, applications, hardware control modules, etc., so they are omitted to avoid redundancy.

[0070] In addition, the operation embodiments and configurations described in a general manner without being explained in detail below follow the prior art and are omitted in order to focus on describing the purpose of the present invention and the resulting effects.

[0071] Furthermore, in describing the present invention, if it is determined that a detailed description of related known functions or configurations may unnecessarily obscure the essence of the invention, such detailed description is abbreviated or omitted.

[0072] A 'system including a quantitative evaluation model of the risk of privacy infringement using object identification information' for implementing the present invention may be broadly composed of a data processing unit that collects and processes image data, a policy control unit that determines and transmits a policy based on the processed data, and an interface unit responsible for interaction with a user.

[0073] Specifically, the system includes an image acquisition unit (100), an object identification module (200), a situation analysis module (300), an image processing module (400), a data encryption module (500), an access control module (600), a key management unit (700), a policy-based transmission module (800), a user interface unit (900), a privacy setting management module (1000), and an intrusion detection and response module (1100).

[0074] The above-mentioned image acquisition unit (100) refers to a hardware device installed in one or more places inside a facility to capture and collect video streams in real time.

[0075] The image acquisition unit (100) converts optical information into electrical signals using a built-in image sensor and generates them in the form of a continuous stream of digital image data frames. Subsequently, it performs the function of transmitting the generated image data in real time to an object identification module (200) through an internal network.

[0076] The object identification module (200) above refers to a software module that detects and classifies specific objects that are predefined within input image data.

[0077] Method of performing the function: The object identification module (200) uses a deep learning-based object detection algorithm (e.g., YOLO, SSD) to identify objects such as 'person', 'face', 'document', 'medical equipment', etc. within an image frame. For each identified object, metadata is generated including bounding box information containing the type (class) and location coordinates of the object, and a detection confidence score.

[0078] The above-mentioned situation analysis module (300) refers to a software module that quantitatively evaluates the possibility of privacy infringement and potential risk situations by analyzing identified object information and temporal changes.

[0079] The above-mentioned situation analysis module (300) performs sub-functions such as posture analysis, activity tracking, and object attribute analysis, and thereby executes the first control logic (calculation of privacy protection index) and the second control logic (calculation of risk situation score) described above in this specification.

[0080] The above image processing module (400) refers to a software module that processes specific areas of image data for anonymization according to control commands of the policy-based transmission module (800).

[0081] The above image processing module (400) incorporates multiple masking techniques such as 'blur', 'pixelation', 'black box processing', and 'avatar replacement'. The module receives information regarding the coordinates of the object to be masked, the type and intensity of the masking to be applied, from the policy-based transmission module (800), and applies the de-identification processing specified for the corresponding area of ​​the original image data in real time.

[0082] The above data encryption module (500) refers to a software module that encrypts data to be transmitted externally to ensure the confidentiality of information.

[0083] The above module receives data to be transmitted (e.g., masked thumbnail, context description text) from a policy-based transmission module (800). Then, it requests and obtains an encryption key from a key management unit (700) and uses it to convert the data into ciphertext using a standard encryption algorithm such as AES-256.

[0084] The above access control module (600) refers to a software module that controls data access according to the user's role and authority.

[0085] The above module stores and manages role-based access control (RBAC) policies pre-configured by an administrator in a database. When a data decryption request is received from an external source, it verifies the requester's identity information (e.g., ID) and role, and compares this with the stored policy to determine whether the requester has access rights to the requested data. Only if the requester has the authority, it requests the key management unit (700) to generate a decryption key for the user.

[0086] The above key management unit (700) refers to a hardware security module (HSM) that securely handles the entire lifecycle of keys used for encryption and decryption, including generation, storage, management, and disposal.

[0087] The key management unit (700) generates and stores encryption keys in a physically isolated and tamper-proof environment. When it receives a key request from a data encryption module (500) or an access control module (600), it verifies the validity of the request and then provides the necessary keys through a secure channel.

[0088] The above policy-based transmission module (800) refers to a core control software module of a system that synthesizes the results of situation analysis to finally determine whether to transmit, the content, the target, and the form, and controls related modules.

[0089] The above module executes the third control logic (calculation of transmission priority score) described later in this specification, and transmits control commands to the image processing module (400) and the data encryption module (500) according to the result, thereby overseeing the processing and transmission of data.

[0090] The above user interface unit (900) refers to a hardware device that supports a user within the facility to interact with the system through voice commands, etc.

[0091] The unit collects the user's voice through a built-in microphone, converts it into text, and interprets it as a system control command (e.g., 'request help', 'emergency call'). The interpreted command is transmitted to a policy-based transmission module (800) to enable immediate action.

[0092] The above privacy setting management module (1000) refers to a software module that provides a graphical user interface (GUI) so that a user or agent can directly control the privacy-related settings of the system through the web or an application.

[0093] The user can set a 'user protection preference coefficient' or specify the scope of information disclosure, the recipient of notifications, etc. through the above module. The above module receives the user's setting value and stores it in a system database, and enables the situation analysis module (300), etc., to operate by referencing the value.

[0094] The above intrusion detection and response module (1100) refers to a security monitoring software module that detects abnormal access attempts to the system or acts violating internal policies in real time and automatically performs response measures according to the set policy.

[0095] The above module includes real-time log analysis, abnormal behavior detection, automatic response, auditing, and reporting functions.

[0096] The above module receives and monitors data access request logs from the access control module (600) and data transmission logs from the policy-based transmission module (800) in real time.

[0097] The above module determines that a pattern violating a predefined security rule is detected as an anomaly. Examples of the above security rules may include "when there are 5 or more login failures for the same account within 1 minute," "when an attempt is made to access data by an administrator-level account during a non-business time period that is not previously permitted (e.g., 00:00 to 06:00)," or "when 10 or more different user accounts are attempted to access from a single IP address."

[0098] When the above abnormal signs are detected, a security alert notification (SMS, email, etc.) is immediately sent to the system chief administrator via the policy-based transmission module (800). At the same time, the intrusion detection and response module (1100) transmits a control command to the access control module (600) to block the IP address or user account that attempted access for a pre-set time (e.g., 30 minutes). In addition, according to the pre-set emergency response policy, emergency response procedures can be performed, such as requesting the key management unit (700) to invalidate the decryption key of specific data or permanently deleting stored non-identifiable video files.

[0099] The above module securely stores audit logs containing detailed information on all detection and response measures (time, IP address, account, action details, etc.) in a separate security database, and automatically generates weekly or monthly security status reports based on this to provide to the administrator.

[0100] The system of the present invention operates according to the following organic data transmission and reception and control flow.

[0101] Step 1: In data collection and analysis, the image acquisition unit (100) transmits real-time image data to the object identification module (200).

[0102] The object identification module (200) detects objects within the image and transmits metadata containing object type and location information to the situation analysis module (300) along with the original image data.

[0103] The above situation analysis module (300) retrieves the 'user protection preference coefficient' value from the privacy setting management module (1000) and performs a first control logic and a second control logic based on the received metadata to calculate the 'privacy protection index' and the 'risk situation score'.

[0104] The two calculated index values ​​are transmitted to the policy-based transmission module (800) along with the original image data.

[0105] Step 2: In policy decision and data processing, the policy-based transmission module (800) performs a third control logic using the received index values ​​as input and calculates a 'transmission priority score'.

[0106] The above module compares the calculated transmission priority score with a preset policy to determine whether to finally transmit, the transmission target, and the level of detail (masking intensity, etc.) of the information to be transmitted.

[0107] If it is determined that transmission is necessary, the policy-based transmission module (800) transmits the coordinates of the object requiring masking and the masking intensity information to the image processing module (400) as a control command.

[0108] The image processing module (400) de-identifies the corresponding area of ​​the original image according to a control command and returns the processed image data (or thumbnail) to the policy-based transmission module (800).

[0109] Step 3: In encryption and transmission, the policy-based transmission module (800) transmits the final data to be transmitted, such as processed image data and context description text, to the data encryption module (500).

[0110] The data encryption module (500) receives an encryption key from the key management unit (700), encrypts the data, and then securely transmits it to a designated recipient (e.g., a manager terminal).

[0111] Meanwhile, if an emergency call is detected through the user interface unit (900), the information is immediately transmitted to the policy-based transmission module (800) to trigger the procedures of steps 2 and 3 with the highest priority.

[0112] In this way, each component of the present invention performs a clearly defined role and interacts organically through multi-stage control logic based on real-time data and user settings, thereby effectively achieving the two goals of privacy protection and safety assurance.

[0113] Another embodiment of the present invention features an 'Edge AI-based original non-storage processing structure' in which, to maximize the privacy and security level of data, the analysis and processing of image data are all completed at a data collection terminal (Edge) rather than a central server, and the original image data is not transmitted to or stored at a central server but is immediately discarded.

[0114] In the other embodiment above, the image acquisition unit (100), object identification module (200), and situation analysis module (300) can be implemented as a single integrated hardware device called an ‘Edge AI processing unit’.

[0115] The above 'Edge AI processing unit' is characterized by having a high-performance neural processing unit (NPU, Neural Processing Unit) specialized for image processing, and simultaneously performing object identification and situation analysis (execution of first and second control logic) for the image while collecting the image.

[0116] The above 'Edge AI Processing Unit' captures video in real time and temporarily loads it into internal volatile memory (RAM).

[0117] The above unit immediately performs object identification and situation analysis on the image data loaded into the volatile memory, and extracts only the final results, the 'privacy protection index' and 'risk situation score,' in the form of metadata.

[0118] The original video data frame for which the above analysis is completed is not stored on a non-volatile storage device such as a hard disk, and is immediately and permanently overwritten on the volatile memory.

[0119] Afterwards, only the metadata extracted through the above analysis and the thumbnail image with completed masking processing are transmitted to the policy-based transmission module (800) acting as a central server, only when there is a request from the policy-based transmission module (800).

[0120] According to this 'Edge AI-based original non-repository processing structure,' even if the central server is compromised by hacking or other breaches, the original footage itself does not exist to be leaked, thereby providing a significant effect in fundamentally blocking the risk of video data leakage. This offers a technical advantage that can guarantee the highest level of data security, particularly in environments such as medical or nursing facilities where sensitive personal information is continuously exposed.

[0121] A policy-based transmission module according to one embodiment of the present invention is characterized by calculating a privacy protection index as a quantitative indicator for determining the type and intensity of masking to be performed by an image processing module. The privacy protection index is calculated by a first control logic that analyzes the complex characteristics of sensitive objects existing within an image frame.

[0122] In the present invention, the process of calculating the privacy protection index through the first control logic is designed based on information theory and human visual perception characteristics.

[0123] From the perspective of information theory, the appearance of sensitive objects within an image can be interpreted as increasing information entropy and thereby raising uncertainty. In this invention, the type of object (sensitivity coefficient) and its size (area ratio) are considered as measurement factors for this amount of information. In particular, rather than a linear approach that is simply proportional to the area, a non-linear transformation function including trigonometric functions and square operations is applied. This is based on the experimental observation that a few dominant large objects have a more decisive impact on privacy infringement than a number of small objects. This is achieved by adopting the 'visual salience' model, in which the human visual system allocates more attention to the center of the screen or large objects.

[0124] In addition, a logarithmic function is applied to resolve the scaling issues that arise when combining multiple information sources. Simply summing the influences of multiple sensitive objects within a frame can distort the overall index by causing the influence of a specific object to become excessively large. Much like the use of decibel scales in acoustic engineering, logarithmic scale transformation stabilizes the influence of each element and allows for a fair comparison of values ​​of different magnitudes. By adopting a method that adds 1 and then takes the natural logarithm, logical consistency is ensured where the result is 0 when the input is 0.

[0125] Therefore, the first control logic of the present invention is not a combination of arbitrary functions, but is inevitably derived by engineeringly combining the principles of a visual perception model and information theory to most rationally quantify the privacy risk within an image.

[0126] The first control logic of the present invention sequentially performs the following steps to calculate a privacy protection index: Step 1: individual object influence calculation step, Step 2: frame total sensitivity calculation step, and Step 3: final index calculation step.

[0127] In the first step, for each sensitive object detected in the image, the screen occupancy ratio of the object is first input into a non-linear transformation function including trigonometric functions and square operations to calculate an area-based influence value. Subsequently, the sensitivity value of each individual object is finally calculated by multiplying the calculated area-based influence value by a sensitivity coefficient determined according to the type of object.

[0128] In the second step, the individual object sensitivity values ​​calculated for all sensitive objects within the frame in the first step are all arithmetically summed to derive the total sensitivity value of the entire frame.

[0129] In the third step, a logarithmic transformation is performed on the total sensitivity value derived in the second step by adding 1 and taking the natural logarithm to calculate a stabilized sensitivity value. Finally, the system calculates the final privacy protection index of the frame by multiplying the stabilized sensitivity value by a user protection preference coefficient set by the user.

[0130] The privacy protection index is a final result value calculated by the first control logic and refers to a quantitative score indicating the risk of privacy infringement of the current video frame. The index is used as a primary criterion for determining the intensity of the de-identification processing to be performed by the video processing module.

[0131] The image processing module dynamically determines the type and intensity of masking by comparing the calculated privacy protection index with a plurality of preset threshold values. For example, the system may be preset to apply strong blur processing when the privacy protection index exceeds 1.5 and to perform black box processing when it exceeds 3.0.

[0132] The User Protection Preference Coefficient refers to a coefficient that reflects the level of personal information protection directly set by the user or their representative through the Privacy Settings Management Module. It serves to customize the level of protection according to the user's explicit intent, even in the same situation.

[0133] The above user protection preference coefficient can be obtained by receiving user selection input through the interface of the privacy setting management module. For example, the system may be configured to obtain a value of 2.0 when the user selects the 'High Protection' mode on the interface, a value of 1.0 when the user selects the 'General Protection' mode, and a value of 0.5 when the user selects the 'Low Protection' mode as the coefficient.

[0134] The sensitivity coefficient refers to a weight assigned differentially based on the type of sensitive object detected by the object identification module. This is intended to reflect the fact that the degree of privacy infringement varies depending on the type of object, even if they have the same physical characteristics.

[0135] The above sensitivity coefficient is obtained by loading values ​​pre-stored in the system's database for each type of object. A person skilled in the art can easily input and manage coefficient values ​​for each object type when configuring the system. At this time, the value of the above sensitivity coefficient is characterized by being set according to the following objective criteria.

[0136] First, the criterion for judging 'statistical significance' is defined as verifying through an independent sample T-test whether the distribution of privacy infringement awareness scores for a specific object type is statistically significant compared to the score distribution of a predefined reference object (e.g., background, furniture, etc.), and when the calculated significance probability (p-value) is less than a pre-set significance level (e.g., 0.05).

[0137] Second, the criterion for a 'high sensitivity coefficient' is defined as the case where, among object types satisfying the statistical significance criteria mentioned above, the average score of the privacy infringement perception exceeds a pre-set first threshold value (e.g., 4.0 out of 5 points). For example, if the average perception score of 'human face' in user research results is calculated to be 4.3 points, a high sensitivity coefficient such as 2.5 is assigned because this exceeds the first threshold value. On the other hand, if the average perception score of 'mobile phone screen' is calculated to be 2.1 points, a low sensitivity coefficient such as 1.0 may be assigned because this is below the first threshold value.

[0138] The area ratio refers to a value representing the relative size of the area occupied by a specific detected sensitive object across the entire screen of the image.

[0139] The object attribute analysis module calculates the area of ​​an object using pixel units based on the bounding box information of a specific object received from the object identification module. The area ratio is calculated by dividing the 'total number of pixels constituting a specific sensitive object' by the 'total number of pixels constituting the entire image frame' and has a value between 0 and 1.

[0140] Conventional privacy protection technologies were limited to simply detecting specific objects (e.g., faces) and performing masking processing with a fixed size or intensity. This approach failed to consider contextual factors such as the size, number, or type of objects; consequently, it suffered from the problem of causing information loss due to excessive masking in minor infringement situations and providing insufficient protection in severe infringement situations. However, through the aforementioned first and masking processing logic, the present invention performs complex operations involving non-linear weighting based on a visual salience model, log-scale stabilization based on information theory, objective sensitivity coefficient setting based on user research, and sequential policy judgment based on multiple thresholds. As a result, unlike conventional technologies, the present invention can dynamically optimize the level of privacy protection according to the unique context of each video frame. This enables sophisticated and efficient de-identification processing that minimizes unnecessary information loss while suppressing the risk of privacy infringement to the maximum extent. Therefore, the present invention definitively provides the significant technical effect of "context-adaptive privacy protection," which could not be achieved by conventional uniform methods.

[0141] The above control logic is characterized by applying trigonometric functions and square operations to the area ratio value. This has a negligible effect on the final index when the area occupied by an object on the screen is small, but causes the influence to be non-linearly amplified when the area increases beyond a certain level, thereby providing the effect of effectively highlighting key objects with a high risk of privacy infringement.

[0142] The above control logic is characterized by applying a logarithmic function to the total sum of the influences of all calculated sensitive objects. This prevents the privacy protection index value from becoming excessively large even if the number of sensitive objects within the screen is very large or their size is very large, and provides the effect of ensuring the stability of the control result so that the system does not react oversensitively to sudden changes.

[0143] The above control logic comprehensively evaluates the risk factors of all sensitive objects within the screen by summing them up, and simultaneously incorporates protection preference coefficients directly set by the user into the final calculation, thereby organically combining the mechanical analysis results with the user's explicit control intent to implement a flexible and reasonable privacy protection policy.

[0144] The present invention further includes a masking processing logic for determining the type and intensity of masking to be applied to an actual image based on a privacy protection index calculated through the first control logic. This is intended to clearly define a technical procedure that leads to specific policy execution, going beyond simple index calculation.

[0145] The above masking processing logic sequentially determines conditions using a plurality of preset masking thresholds, namely a 'first threshold' and a 'second threshold'. Specifically, the system first evaluates a first condition determining whether the privacy protection index exceeds the 'first threshold'. Subsequently, only if the first condition is satisfied, it evaluates a second condition determining whether the index further exceeds the 'second threshold'. The logic determines a masking policy as follows depending on whether the conditions are satisfied. If the privacy protection index is below the 'first threshold', masking is not applied. If the privacy protection index exceeds the 'first threshold' but is below the 'second threshold', 'Level 1 masking (e.g., medium intensity blur processing)' is applied. If the privacy protection index exceeds both the 'first threshold' and the 'second threshold', 'Level 2 masking (e.g., black box or avatar replacement processing)' is applied.

[0146] The above 'first threshold' and 'second threshold' are not arbitrary values, but are set based on the results of large-scale user experience (UX) tests conducted during the system development phase. For example, the 'first threshold (e.g., 1.5)' is set as the "average index value at which 80% or more of the test participants responded that they 'started to recognize' the privacy infringement." Additionally, the 'second threshold (e.g., 3.0)' is set as the "average index value at which 80% or more of the participants responded that it was a 'serious privacy infringement'," ensuring that each threshold reflects the user's actual level of awareness.

[0147] The above thresholds are not fixed values ​​but can be periodically readjusted based on data collected during system operation. The system collects data where an administrator reviews the masking results for a specific image and provides feedback that it is 'inappropriate' or 'excessive'. Subsequently, the system may include a machine learning model that statistically analyzes the accumulated feedback data every three months to automatically correct the above thresholds to a point where both the false positive rate and the false negative rate are minimized.

[0148] Below, the operation of the first control logic and masking processing logic of the present invention in specific situations will be explained through examples.

[0149] The situation is assumed as follows. First, the user has selected 'General Protection' mode. Second, one 'human face' and one 'document' have been detected as sensitive objects in the current video frame. Third, the area ratio of the detected 'human face' is 0.2, and the area ratio of the 'document' is 0.05. Fourth, the sensitivity coefficient for the 'human face' is stored in the database as 2.5, and the sensitivity coefficient for the 'document' is stored as 1.5. Fifth, the '1st threshold' is set to 1.5, and the '2nd threshold' is set to 3.0.

[0150] Under the above assumed situation, the system calculates an individual sensitivity value of 0.375 by multiplying the non-linear transformed value of the area ratio (0.2) for 'human face' (e.g., 0.15) by a sensitivity coefficient (2.5), and calculates an individual sensitivity value of 0.015 by multiplying the non-linear transformed value of the area ratio (0.05) for 'document' (e.g., 0.01) by a sensitivity coefficient (1.5). Subsequently, the two individual sensitivity values ​​are summed to derive a total sensitivity value of 0.39, and a log transformation is performed thereon to produce a stabilized sensitivity value of approximately 0.33. Finally, the stabilized value (0.33) is multiplied by a user protection preference coefficient (1.0) corresponding to the 'general protection' mode to produce a final privacy protection index of 0.33.

[0151] Since the calculated privacy protection index (0.33) is less than or equal to the 'first threshold' (1.5), the masking processing logic controls the image processing module so that masking processing is not performed on the corresponding frame. For comparison, if the area ratio of a 'human face' is detected to be very large at 0.6 in the same situation, the final privacy protection index can be calculated as approximately 1.48. Even in this case, the index does not exceed the 'first threshold,' so masking is not applied. However, if the user selects the 'high protection' mode (user protection preference coefficient = 2.0), the final index becomes 2.96 (1.48 * 2.0), which exceeds the 'first threshold,' so the system applies 'Level 1 masking.' This is an example showing that the present invention operates precisely according to the situation and user intent.

[0152] A policy-based transmission module according to one embodiment of the present invention is characterized by quantitatively evaluating the risk level of a situation occurring within a facility and calculating a risk situation score to determine whether to transmit an alarm based thereon. The risk situation score is calculated by a second control logic that comprehensively analyzes complex situation information, such as the user's posture, the duration of the activity stagnation, the location of occurrence, and the surrounding environment.

[0153] In the present invention, the process of calculating a risk situation score through the second control logic is designed based on the principles of emergency medicine and environmental safety engineering.

[0154] The main parameters used in the second control logic of the present invention, namely 'posture weight', 'time weight', and 'time constant', are objectively set according to the facility's operational policy and the characteristics of the main management targets. For example, in a facility where sudden collapse, such as acute myocardial infarction, is a main management target, it is important to detect changes in posture immediately, so the 'posture weight' can be set higher than the 'time weight' (e.g., posture weight = 0.7, time weight = 0.3). Conversely, in a nursing facility where detecting the immobility of elderly people with limited mobility for a long period is important, the 'time weight' can be set higher.

[0155] In addition, the 'time constant' is set based on the medical 'golden time' of the subject under care. For example, for elderly patients for whom action within 5 minutes of a fall is critical, the time constant can be set to 300 seconds (5 minutes), and the system can be designed so that the risk level increases rapidly from the point when 5 minutes have elapsed. In this way, each parameter is determined based on reasonable grounds to align with the specific operational objectives of the facility.

[0156] The severity of an emergency situation is determined by a combination of multiple factors rather than a single factor. In this invention, the user's 'posture' and 'time' are established as the most critical risk indicators, and a weighted summation method is adopted. In particular, based on the observation that specific postures, such as 'falling,' have a non-linearly much higher risk than postures such as 'lying down,' a square operation is applied to the abnormal posture score. This is intended to more significantly reflect the critical risk associated with specific postures in actual emergency situations.

[0157] Furthermore, the time elapsed since the onset of an emergency is a critical variable directly linked to survival rates. To engineer the concept of the "golden time" in emergency medicine, this invention applies an exponential function to the duration of abnormal postures. This is intended to precisely simulate the characteristics of actual emergency situations, where risk does not increase linearly over time but rather surges exponentially once a specific critical time is exceeded.

[0158] Furthermore, even for the same event, the actual degree of risk varies depending on the environmental characteristics of the 'location' where it occurred and the presence of 'people nearby.' To reflect these contextual factors, the present invention increases the score for predefined risk zones, such as restrooms or stairs, by multiplying them by a location weight. Conversely, assuming that the likelihood of receiving immediate help is high when other people are nearby, a reduction operation modeling the positive aspects of the 'bystander effect' is applied. In this case, a square root is used to design the system so that the risk reduction effect gradually slows down as the number of people nearby increases, thereby preventing excessive score reduction and enhancing the stability of the system's judgment.

[0159] Therefore, the second control logic of the present invention is not a combination of arbitrary operations, but is inevitably derived to most rationally evaluate the actual 'urgency' and 'severity' of the situation by comprehensively analyzing the multifaceted characteristics of the emergency situation.

[0160] The second control logic of the present invention sequentially performs the first step: a basic risk factor calculation step, the second step: a context-corrected risk level calculation step, and the third step: a final risk situation score calculation step in order to calculate a risk situation score.

[0161] In the first step, a 'posture risk factor' is calculated by performing a squaring operation on the posture abnormality score obtained from the posture analysis module, and at the same time, a 'time risk factor' is calculated by applying an exponential function to the abnormal posture duration obtained from the activity tracking module.

[0162] In the second step, the 'posture risk factor' and 'time risk factor' calculated in the first step are multiplied by their respective corresponding weights and then summed to calculate the 'basic risk'. Subsequently, the 'context-corrected risk' is calculated by multiplying the 'basic risk' by a pre-set location weight according to the location where the situation occurred.

[0163] In the third step, a 'bystander reduction coefficient' is calculated based on the number of other people present around the person at risk. Finally, the final risk situation score for the situation is calculated by dividing the 'context-corrected risk' calculated in the second step by the 'bystander reduction coefficient'.

[0164] The risk situation score is a final result value calculated by the second control logic, representing a quantitative score indicating the urgency and severity of the currently occurring situation. The score is used as a primary criterion by the policy-based transmission module to determine whether to transmit an alarm and the level of transmission information.

[0165] Location weighting is a coefficient that reflects the environmental risk of the area where a hazardous situation occurs, and it is used to evaluate the risk differently depending on the location, even for the same event.

[0166] The above location weights are obtained by loading values ​​pre-set by the facility manager for each zone on the facility drawing through the system's manager interface. For example, based on the results of the facility's safety assessment, the manager can objectively assign and store different weights according to the physical risk level of each zone, such as 3.0 for the 'toilet' zone, 4.0 for the 'stairs' zone, 1.5 for the 'bedroom' zone, and 1.0 for the 'living room' zone. At this time, the above location weights are characterized by being calculated based not merely on the manager's subjective judgment, but on (1) statistical data on the frequency of past safety accidents by zone within the facility, (2) a fall risk index according to the 'workplace risk assessment' guidelines provided by an accredited organization such as the U.S. Occupational Safety and Health Administration (OSHA), or (3) data quantifying risk factors specified in the facility's architectural drawings (e.g., stairs, presence or absence of door thresholds, friction coefficient of flooring).

[0167] The postural abnormality score refers to a score obtained by the posture analysis module that quantifies the degree of abnormality by analyzing the user's current posture.

[0168] The posture analysis module extracts skeletal information indicating the locations of a person's major joints from video data in real time. Subsequently, the geometric distribution of the extracted skeletal information is input into a pre-trained posture classification model (e.g., support vector machine, deep neural network) to classify the posture into categories such as 'standing', 'sitting', 'lying down', and 'falling over'. For each of the classified postures, the system automatically obtains a predefined score from a database (e.g., falling over=1.0, lying down=0.6, sitting=0.1, standing=0) and uses it as a posture abnormality score. At this time, the predefined score is statistically calculated by combining the 'medical risk level,' which evaluates the likelihood of each posture leading to an actual emergency situation on a 5-stage basis through consultation with a group of emergency medical experts, and the 'visual risk perception score' from a public evaluation panel regarding thousands of posture data collected through reenactment actors. For example, the 'falling' position receives the highest score in both evaluations and is normalized to 1.0, while the 'lying down' position is set to 0.6 because it has a low medical risk but some visual risk perception score. Each score is determined based on objective data and expert consensus.

[0169] Abnormal posture duration refers to the cumulative time the user remains in a posture deemed dangerous.

[0170] The activity tracking module activates a timer from the point when the above posture abnormality score exceeds a preset threshold (e.g., 0.5, a criterion including 'lying down' and 'falling over' states). Subsequently, when the score drops below the threshold, the timer is stopped, and the accumulated time (in seconds) is calculated and provided as the duration of the abnormal posture.

[0171] The number of people around refers to the number of other people present within the physical proximity radius of the user in a dangerous situation.

[0172] The object attribute analysis module obtains the location coordinates of all objects identified as 'people' within the video frame. Subsequently, based on the party involved in the dangerous situation, it calculates the distance to other 'person' objects to determine the total number of objects located within a preset threshold radius (e.g., 1.5 meters) and uses this as the number of surrounding people.

[0173] The present invention is characterized by applying a square operation to abnormal posture scores. This converts postures with small score differences, such as 'lying down (score 0.6)' and 'falling over (score 1.0)', into risk factor values ​​with significant differences of 0.36 and 1.0, respectively, through a square operation. As a result, critical risk postures such as 'falling over', which are directly related to actual emergency situations, have a much more decisive influence on the final score, thereby providing a technical effect that allows the system to respond more sensitively to critical risk postures than to minor posture changes.

[0174] The present invention is characterized by applying an exponential function to the duration of abnormal postures. This precisely simulates the characteristics of the "golden time" in emergency situations, where the risk level increases gradually over time but explodes exponentially after passing a specific critical time (time constant). As a result, the system has the technical effect of inducing an immediate response by assigning very high scores to dangerous situations that persist for a long time, while avoiding unnecessary alarms for short periods of inactivity.

[0175] The present invention is characterized by multiplying a calculated base risk by a location weight. This ensures that even if the 'falling' posture persists for the same 5 minutes, a risk score three times higher is assigned when it occurs in a 'bathroom (weight 3.0),' which has a higher risk of falls and secondary injuries, compared to when it occurs in a relatively safe 'living room (weight 1.0).' As a result, the system has the technical effect of more accurately evaluating the severity of the situation by considering not only the user's condition but also the unique risk characteristics of the surrounding environment.

[0176] The present invention is characterized by dividing the final risk level by a reduction coefficient based on the number of people around. By applying a square root, the design ensures that the reduction effect when the number of people around increases from 4 to 5 is smaller than the reduction effect when the number of people around increases from 0 to 1. This rationally models a realistic situation where the presence of people around significantly lowers the risk by increasing the likelihood of providing immediate help in the early stages, but beyond a certain number, the effect of such additional help in mitigating the risk gradually slows down. As a result, there is a technical effect of preventing the score of an actual risk situation from being excessively lowered solely because there are many people around, while maintaining the reliability of the system's judgment.

[0177] Conventional risk detection technology has been limited to detecting single events, such as simply "falling down," and suffers from the problem of frequently generating false alarms due to an inability to comprehensively assess the urgency or severity of a situation. However, through the aforementioned second control logic, the present invention non-linearly evaluates key risk factors such as posture and time, comprehensively reflects environmental contexts such as the risk level of the location and the presence of surrounding people, and precisely adjusts the influence of each factor through weights. As a result, the present invention goes beyond merely detecting whether an event has occurred to precisely score the "actual urgency" of a situation. This clearly distinguishes between a situation where a user is lying briefly on a sofa and a situation where they have lost consciousness and collapsed in a bathroom, thereby suppressing unnecessary alarms and enabling selective response only to emergency situations requiring immediate action. Therefore, the present invention provides a significant technical effect known as "context-aware intelligent risk assessment," which was difficult to achieve with conventional technology.

[0178] Below, how the second control logic of the present invention operates in specific situations is explained through examples.

[0179] First assumption (common): The attitude weight is set to 0.4 and the time weight to 0.6. The time constant is set to 300 seconds (5 minutes).

[0180] Second assumption (Example 1: mild situation): The user was in a lying position (posture abnormality score = 0.6) on a sofa in the living room (position weight = 1.0) for 120 seconds (2 minutes), and there were no other people nearby.

[0181] Third assumption (Example 2: Severe situation): The user remained in a collapsed position (posture abnormality score = 1.0) in a restroom (location weight = 3.0) for 600 seconds (10 minutes), and there were no other people nearby.

[0182] The step-by-step calculation process of the second control logic for Example 1 is as follows:

[0183] In the first step (calculation of basic risk factors), the ‘posture risk factor’ is calculated as 0.36, which is the square of the posture abnormality score (0.6).

[0184] The 'time risk factor' is calculated as approximately 0.49 by substituting it into an exponential function based on the duration (120 seconds).

[0185] In the second step (calculation of context-adjusted risk), the 'basic risk' is calculated as approximately 0.44 by calculating (0.36 * 0.4) + (0.49 * 0.6).

[0186] The 'context-corrected risk' is calculated by multiplying the basic risk (0.44) by the living room location weight (1.0), resulting in 0.44.

[0187] In the third stage (calculation of the final risk situation score), since there are 0 people around, the 'people around reduction coefficient' is 1.

[0188] The final risk situation score is calculated as 0.44, which is 0.44 divided by 1.

[0189] The step-by-step calculation process of the second control logic for Example 2 is as follows:

[0190] In the first step (calculation of basic risk factors), the ‘posture risk factor’ is calculated as 1.0, which is the square of the posture abnormality score (1.0).

[0191] The 'time risk factor' is calculated as approximately 6.39 by substituting it into an exponential function based on the duration (600 seconds).

[0192] In the second step (calculation of context-adjusted risk), the 'basic risk' is calculated as approximately 4.23 by calculating (1.0 * 0.4) + (6.39 * 0.6).

[0193] The 'context-corrected risk' is calculated as approximately 12.69 by multiplying the basic risk (4.23) by the toilet location weight (3.0).

[0194] In the third stage (calculation of the final risk situation score), since there are 0 people around, the 'people around reduction coefficient' is 1.

[0195] The final risk situation score is calculated as 12.69, which is 12.69 divided by 1.

[0196] As a result of the two embodiments above, the risk score for a 'minor situation' was calculated to be very low at 0.44, while the score for a 'serious situation' was calculated to be very high at 12.69. If the system's alarm transmission threshold is set to 10 points, the system does not generate unnecessary alarms in the case of Embodiment 1, but immediately transmits an emergency alarm to the administrator in the case of Embodiment 2. This clearly demonstrates that the second control logic of the present invention has an excellent effect of precisely distinguishing the actual risk level of a situation by comprehensively considering various variables.

[0197] One embodiment of the present invention further includes a third control logic that receives a privacy protection index and a risk situation score calculated through the first and second control logics and calculates a transmission priority score to determine whether and how to finally execute information transmission. The third control logic aims to perform the most reasonable and efficient information transmission policy by going beyond simply detecting risks and comprehensively considering complex contextual information such as the sensitivity of the information, the role of the recipient, and the current time zone.

[0198] The third control logic of the present invention is designed based on the principle of striking a reasonable balance between the transmission necessity indicating the 'urgency of the situation' and the 'constraints associated with information transmission'.

[0199] The necessity of transmission is determined by the urgency of the situation and the authority of the recipient to handle it. In this invention, the risk situation score calculated in the second control logic is used as a key indicator representing the urgency, and its influence is amplified through an exponential function to reflect the characteristic that its importance increases exponentially as the severity of the emergency situation increases. At the same time, the concept of 'Role-Based Access Control (RBAC)' in the field of information security is introduced, and the legitimacy of transmission is considered to increase as the recipient's access authority level increases. At this time, by using a sine function to convert the access authority level into an 'approval coefficient' between 0 and 1, the necessity of transmission according to the authority level is rationally modeled.

[0200] In addition, transmission constraints are set considering information sensitivity and human factors. Reflecting the 'privacy protection principle' that the higher the privacy protection index calculated by the first control logic, the more caution must be exercised in information transmission, the invention is designed so that the final priority decreases as the index increases. Furthermore, by introducing the concept of 'alarm fatigue' in the field of human-computer interaction, the need to lower the alarm sensitivity during nighttime hours when the manager's concentration is reduced is reflected. To this end, a periodic sensitivity control coefficient that changes over a 24-hour period is modeled using a cosine function, thereby enabling the system to operate while taking human factors into account.

[0201] Therefore, the third control logic of the present invention is inevitably derived to make the most balanced information delivery decision by engineeringly integrating and coordinating mutually conflicting multidimensional elements such as the urgency of the situation, the sensitivity of the information, the authority of the recipient, and the operating time zone.

[0202] The third control logic of the present invention sequentially performs the first step: a step for calculating the transmission necessity index, the second step: a step for calculating the transmission constraint index, and the third step: a step for calculating the final transmission priority score in order to calculate the transmission priority score.

[0203] In the first step, an exponential function transformation is performed on the risk situation score received from the second control logic to calculate an 'urgency amplification value,' and at the same time, a sine function transformation is performed on the access authority level of the recipient to calculate an 'authority multiplier.' Subsequently, the 'urgency amplification value' and the 'authority multiplier' are multiplied together to calculate a 'transmission necessity index.'

[0204] In the second step, a 'privacy constraint value' is calculated by performing a square root transformation on the privacy protection index received from the first control logic, and at the same time, a 'time zone sensitivity coefficient' is calculated by performing a cosine function transformation based on the current time information. Subsequently, the 'privacy constraint value' and the 'time zone sensitivity coefficient' are multiplied together to calculate the 'transmission constraint condition index'.

[0205] In the third step, the final transmission priority score is calculated by dividing the 'transmission necessity index' calculated in the first step by the 'transmission constraint index' calculated in the second step.

[0206] The transmission priority score is a final result value calculated by the third control logic, representing a quantitative score indicating the overall urgency and validity of information transmission regarding the current situation. This score is used as a key criterion for determining specific transmission actions in the subsequent final transmission policy execution logic.

[0207] Access control levels refer to integer grades assigned differentially based on the roles and responsibilities of the recipients of information.

[0208] The aforementioned access authority levels are obtained by loading pre-mapped level values ​​for each role when the facility manager assigns a role to each user account through the system's administrator interface. For example, the manager may assign Level 4 to the 'Emergency Response Physician' role, Level 3 to the 'Primary Guardian' role, Level 2 to the 'General Nurse' role, and Level 1 to the 'Facility Manager' role, respectively, and store them in the system database. In this case, each level is determined based on the 'Information Access Authority and Responsibility Matrix' specified in the facility's information protection and crisis response management regulations. For instance, the highest level is assigned to the 'Physician,' who holds the final authority to access and take action on patient information under the Medical Service Act, and the next-highest level is assigned to the legal guardian; thus, the aforementioned level values ​​are objectively mapped according to the organization's official roles and responsibilities (R&R).

[0209] Time zone-related variables include the current time and the alarm peak time, which is the reference time when alarm sensitivity should be lowest.

[0210] 'Current time' automatically obtains time information in 24-hour format from the internal clock of the server where the system is running. 'Alarm peak time' is obtained by loading a value set by the administrator when configuring the system, taking into account the shift change time of night shift workers or the average sleep time of users (e.g., 3, meaning 3 AM).

[0211] The present invention further includes a final transmission policy execution logic that receives a transmission priority score calculated through the third control logic, and finally determines and executes a specific transmission action. This is to define a clear rule-based execution procedure that converts a quantitatively calculated score into actual system operation.

[0212] The above-described final transmission policy execution logic is characterized by operating based on a 'transmission policy table' that predefines actions to be performed according to the value range of a transmission priority score. Specifically, when the logic receives a transmission priority score from a third control logic, it determines which of the multiple score ranges defined in the policy table the score corresponds to. Subsequently, it loads policy information such as 'receiving target conditions', 'transmission content', and 'additional measures' mapped to the determined range, and controls each module of the system to perform information transmission according to the corresponding policy.

[0213] The above transmission policy table can be stored in the system database with the following structure.

[0214] Transmission priority score range Recipient criteria (access permission levels) Transmission content Additional measures 0 or more and less than 5 Not applicable Do not transmit (record only internal system logs) doesn't exist 5 or more and less than 15 1 or more Text: Situation summary and time of occurrence doesn't exist 15 or more and less than 30 2 or more Text + Masked Thumbnail Image Send 'Secondary verification required' notification to recipient 30 or more 3 or more Text + Masked Thumbnail Image Activate the 'Two-way Communication Connection' button on the recipient's terminal

[0215] The threshold values ​​(e.g., 5, 15, 30) for each score range defined in the transmission policy table above are set based on the 'response action protocol by information transmission level' predefined by the system operator. For example, 'less than 5 points' is defined as the 'internal recording and monitoring' level, '5 points or more but less than 15 points' as the 'situation awareness and simple reporting' level, '15 points or more but less than 30 points' as the 'situation verification and preparatory measures' level, and '30 points or more' as the 'immediate intervention and highest level of response' level. Through simulation of various scenarios that may occur within the facility, the system statistically determines the optimal threshold value that triggers each response level by mapping the distribution of transmission priority scores calculated for each scenario with the response action protocols defined above. The present invention calculates the necessity of transmission by applying an exponential function to the risk score and a sine function to the access authority. This maintains a low priority score when the risk is low or the receiving authority is low, but in legitimate situations where the risk is high and the receiving authority is high, the synergistic effect of the two functions combines to explosively increase the priority score. As a result, the system has the technical effect of clearly distinguishing between 'important information that must be disclosed' and 'additional information that is for reference only' and processing them differentially.

[0216] The present invention calculates constraints by applying a square root to a privacy index and a cosine function to a time zone. This prevents transmission from becoming fundamentally impossible even if the risk of privacy infringement is very high (square root effect) and ensures flexibility in system operation by smoothly reducing alarm sensitivity during nighttime hours (cosine effect). As a result, the system operates under flexible constraints rather than rigid rules, thereby providing a technical effect of optimizing the balance between privacy protection and operational efficiency.

[0217] Conventional alarm systems were limited to a method of uniformly transmitting the same alert to all configured administrators when a dangerous situation occurred. This approach had problems such as potentially infringing on privacy by failing to consider the sensitivity of information, and increasing work fatigue due to unnecessary alarms during late-night hours by failing to consider the recipient's role or current situation. However, through the aforementioned third control logic and final transmission policy execution logic, the present invention dynamically determines the final transmission policy by considering all four major dimensions: the urgency of the situation, the sensitivity of the information, the recipient's role, and the current time. As a result, the present invention makes it possible to deliver the most appropriate level of information to the most appropriate person at the most appropriate time. Going beyond simple alarm transmission, this provides a significant technical effect not found in conventional technology: 'intelligent context-aware information delivery,' which measures the value and cost of information in real time to make optimal decisions.

[0218] Below, the third control logic and final transmission policy execution logic of the present invention will be explained through examples in specific situations.

[0219] First assumption (common situation): Similar to 'Example 2: Severe situation' of the second control logic above, the risk situation score was calculated as 12.69. In addition, the privacy protection index calculated through the first control logic based on sensitive objects within the corresponding video frame is 2.5.

[0220] Second assumption (Example 1: Daytime, High privilege): The current time is 3:00 PM (h=15), and the alarm recipient is the 'primary guardian' (access privilege level=3). The maximum access privilege level of the system is set to 4.

[0221] Third assumption (Example 2: Night, low authority): The current time is 3:00 AM (h=3), and the alarm recipient is the 'Facility Manager' (access authority level=1). Other conditions are the same as in Example 1.

[0222] The step-by-step calculation process of the third control logic for Example 1 is as follows:

[0223] In the first step (calculation of transmission necessity index), when the ‘urgency amplification value’ is calculated based on the risk situation score (12.69), approximately 12.0 is obtained.

[0224] When calculating the ‘authority multiplier’ based on the access authority level (3), it yields approximately 0.92.

[0225] The 'transmission necessity index' is calculated by multiplying the two values ​​(12.0 * 0.92) to get a final value of approximately 11.04.

[0226] In the second step (calculation of transmission constraint index), when the ‘privacy constraint value’ is calculated based on the privacy protection index (2.5), approximately 1.87 is calculated.

[0227] When calculating the 'time zone sensitivity coefficient' based on the current time (15:00), a value of approximately 0.5 is obtained due to the characteristics of the cosine function (the effect of increasing priority as the denominator becomes smaller).

[0228] The 'transmission constraint index' is calculated by multiplying the two values ​​(1.87 * 0.5) to get a final value of approximately 0.94.

[0229] In the third step (calculation of the final transmission priority score), the final transmission priority score is calculated as approximately 11.74 by dividing the 'transmission necessity index' (11.04) by the 'transmission constraint index' (0.94).

[0230] In Example 2, the step-by-step calculation process of the third control logic is as follows:

[0231] In the first stage (calculation of transmission necessity index), the 'urgency amplification value' is calculated to be approximately 12.0 because the risk situation score is the same.

[0232] When calculating the ‘authority multiplier’ based on the access authority level (1), it is approximately 0.38.

[0233] The 'transmission necessity index' is calculated by multiplying the two values ​​(12.0 * 0.38) to get a final value of approximately 4.56.

[0234] In the second step (calculation of transmission constraint index), the 'privacy constraint value' is calculated to be approximately 1.87 because the privacy index is the same.

[0235] When calculating the 'time zone sensitivity coefficient' based on the current time (3 o'clock, alarm peak time), a value of approximately 1.5 is obtained due to the characteristics of the cosine function (an effect where the priority is lowered as the denominator increases).

[0236] The 'transmission constraint index' is calculated by multiplying the two values ​​(1.87 * 1.5) to get a final value of approximately 2.81.

[0237] In the third step (calculation of the final transmission priority score), the final transmission priority score is calculated as approximately 1.62 by dividing the 'transmission necessity index' (4.56) by the 'transmission constraint index' (2.81).

[0238] In the case of Example 1, the calculated transmission priority score is 11.74. This corresponds to the range of ‘5 or more and less than 15’ of the ‘transmission policy table’. Accordingly, the final transmission policy execution logic controls the system to transmit situation summary information in the form of ‘text’ to the ‘primary guardian’ (access authority level 3 ≥ 1).

[0239] In the case of Example 2, the calculated transmission priority score is 1.62. This corresponds to the range of ‘0 or greater, less than 5’ of the ‘transmission policy table’. Therefore, the final transmission policy execution logic controls the system to record only internal system logs without transmitting any information regarding the situation.

[0240] Through a comparison of the two embodiments above, it can be clearly seen that the present invention performs a highly intelligent and differentiated operation in which, even though an equally serious danger situation has occurred, an immediate text alarm is sent when it is daytime and the recipient has high authority, whereas an alarm is not sent when it is nighttime and the recipient has low authority, taking into consideration work fatigue caused by unnecessary alarms. This is an example that clearly demonstrates that the third control logic and the final transmission policy execution logic of the present invention have a significant effect of performing optimal information delivery by comprehensively judging various contexts.

[0241] Although preferred embodiments of the present invention have been illustrated and described above, the present invention is not limited to the specific embodiments described above. Various modifications are possible by those skilled in the art without departing from the essence of the invention as claimed in the claims, and such modifications should not be understood individually from the technical spirit or perspective of the present invention. Explanation of the symbols

[0242] Video acquisition unit (100) Object identification module (200) Situation analysis module (300) Image processing module (400) Data encryption module (500) Access control module (600) Key Management Unit (700) Policy-based transmission module (800) User interface unit (900) Privacy setting management module (1000) Intrusion detection and response module (1100)

Claims

Claim 1 A video acquisition unit that captures video in real time; an object identification module that receives video data from the video acquisition unit, identifies objects within the video, and generates metadata including the type and location information of the identified objects; a situation analysis module that quantitatively evaluates the potential for privacy infringement and risk situations of the video based on the metadata to calculate a privacy protection index and a risk situation score; and a policy-based transmission module that determines a transmission policy based on the calculated indices, controls the anonymization processing of the video data according to the determined policy, and encrypts and transmits the processed data to a designated recipient. A system comprising a privacy setting management module that provides an interface for a user to control privacy-related settings of the system; wherein the situation analysis module performs a first control logic for calculating an area-based influence value based on the screen occupancy ratio of each sensitive object detected within a video frame; calculating an individual object sensitivity value by multiplying the calculated area-based influence value by a sensitivity coefficient preset according to the type of the object; deriving a total sensitivity value by summing all the individual object sensitivity values ​​calculated for all sensitive objects within the frame; calculating a stabilized sensitivity value by performing a log transformation on the derived total sensitivity value; and calculating a privacy protection index by multiplying the stabilized sensitivity value by a user protection preference coefficient set by the user through the privacy setting management module. Claim 2 In claim 1, the first control logic utilizes a non-linear transformation function including trigonometric functions and square operations, which receives the screen occupancy ratio as input and outputs a non-linearly amplified result value in the step of calculating the area-based influence value, and performs a logarithmic transformation by adding 1 to the total sensitivity value and taking the natural logarithm in the step of calculating the stabilized sensitivity value, thereby causing the influence to be amplified exponentially when the area occupied by an object on the screen increases beyond a certain level, and preventing the privacy protection index value from becoming excessively large even if multiple sensitive objects exist; the system further includes a masking control logic that determines the type and intensity of masking to be applied to the actual image based on the privacy protection index, and the masking control logic sequentially determines whether the privacy protection index exceeds the 'first threshold' using a preset 'first threshold' and 'second threshold', and determines whether the index additionally exceeds the 'second threshold' when the first condition is satisfied. A system including a quantitative evaluation model of privacy infringement risk using object identification information, characterized in that the policy-based transmission module controls the image processing module to evaluate and, according to the evaluation result, apply 'Level 1 masking' if only the first condition is satisfied, and 'Level 2 masking' if both the first and second conditions are satisfied.

Citation Information

Patent Citations

  • A evaluation method for managemental aspect security level based-on weight

    KR1020110053150A

  • Intelligent video surveillance system

    KR1020180001356A

  • Image processing system comprising image transmitter and image receiver based on internet of things, and image processing method using the same

    KR1020190081297A

  • Method, device, and program for real-time video data anonymization processing and selective restoration

    KR1020260099821A