Data access method and apparatus, and vehicle

By allocating sub-data storage areas and managing access permissions for user accounts in the smart cockpit, the data privacy and security issues when different users use the same display screen are resolved, achieving privacy protection and flexible access to user data, and improving the user experience.

WO2026045271A1PCT designated stage Publication Date: 2026-03-05YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-04-01
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

In a smart cockpit, how can we ensure the privacy and security of user data when different users use the same display screen, and prevent user data from being accessed by other users?

Method used

By allocating a sub-data storage area to each user account and implementing access control during data storage and retrieval, it ensures that only authorized user accounts can access their data, and differentiates data access permissions for privacy-critical and benefit-sharing applications using access path units and public storage areas.

Benefits of technology

It ensures the privacy and security of user data, prevents data leakage, improves the isolation and flexibility of user data, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025086523_05032026_PF_FP_ABST
    Figure CN2025086523_05032026_PF_FP_ABST
Patent Text Reader

Abstract

A data access method and apparatus, and a vehicle. In the present technical solution, each of a plurality of user accounts is associated with one sub-data storage area, and the plurality of sub-data storage areas associated with the plurality of user accounts belong to a same user space. A first user account is one of the plurality of user accounts. When a first application under the first user account is an application that needs to store data by means of a first sub-data storage area, when a request for storing first data of the first application is acquired, the first data is stored by means of the first sub-data storage area. The first sub-data storage area is associated with the first user account, and the plurality of sub-data storage areas comprise the first sub-data storage area. The present solution can be applied to the technical field of computers and / or the field of intelligent vehicles such as new energy vehicles and electric vehicles, and helps ensure data privacy and security under each user account when a plurality of user accounts used for logging in to an in-vehicle system are associated with a same user space.
Need to check novelty before this filing date? Find Prior Art

Description

Data access methods, devices and vehicles

[0001] This application claims priority to Chinese Patent Application No. 202411222010.X, filed with the China National Intellectual Property Administration on August 30, 2024, entitled “Data Access Method, Apparatus and Vehicle”, the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of computer technology, and more specifically, to a data access method, apparatus, and vehicle. Background Technology

[0003] With the increasing intelligence and connectivity of vehicles, vehicle cockpits are gradually evolving into intelligent cockpits centered on human-machine interaction and featuring multi-screen linkage. Currently, the displays in intelligent cockpits may be used by different users at different times. For an application deployed on a display, a user may store some data while using the application, and after that user logs out, they may not want other users to access that stored data. Therefore, how to ensure the privacy and security of user data is the problem that this application's technical solution aims to solve. Summary of the Invention

[0004] This application provides a data access method, apparatus, and vehicle that helps protect the data privacy and security of each user account when multiple user accounts used to log in to the vehicle's infotainment system are associated with the same user space.

[0005] Firstly, a data access method is provided that can be executed by a vehicle, for example, by the vehicle's computing platform, or by a chip or circuitry used in the vehicle.

[0006] The method includes: obtaining information about a first user account, wherein the first user account is one of multiple user accounts, each user account is associated with a sub-data storage area, and the multiple sub-data storage areas associated with the multiple user accounts belong to the same user space; obtaining a first access request of a first application under the first user account, wherein the first access request is used to request the storage of first data; and storing the first data through the first sub-data storage area corresponding to the first user account according to the first access request, wherein the multiple sub-data storage areas include the first sub-data storage area.

[0007] In some implementations, the first sub-data storage area stores the association between each piece of data and the first user account. The association between each piece of data and the first user account can be a field that includes a data identifier and a first user account identifier. Alternatively, the aforementioned association can also be a field that includes a data identifier, an identifier of the application storing the data, and a first user account identifier.

[0008] In the above technical solution, when multiple user accounts used to log in to the vehicle system are associated with the same user space, for applications with data privacy requirements, storing the data requested by the application in the data storage area through the sub-data storage area can prevent applications under other user accounts from reading the data, thus helping to protect the data privacy and security of each user account.

[0009] In conjunction with the first aspect, in some implementations of the first aspect, the multiple user accounts also include a second user account, which is associated with a second sub-data storage area in the multiple sub-data storage areas. The method further includes: obtaining a second access request from a second application of the second user account; and rejecting the second access request when the second access request is used to request to read the first data.

[0010] In some implementations, the first data refers to a first type of data. The method further includes: when a second access request is made to request the reading of the first type of data, reading a first set of data from the data storage area according to the second access request, wherein each item in the first set of data is first type of data, and the first set of data does not include the first data itself. The first type of data can be multimedia data, such as images or videos, or it can be data of categories such as files.

[0011] In the above technical solution, the application under the second user account cannot read the data stored by the first user account through the first sub-data storage area, which helps to achieve data isolation at the user account level, thereby improving the privacy and security of user data.

[0012] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: obtaining a third access request from a third application under the first user account, wherein the third application is an application that does not need to go through the first sub-data storage area when storing data; and rejecting the third access request when the third access request is used to request to read the first data.

[0013] In some implementations, the first data is first type of data. The method further includes: when a third access request is made to request the reading of the first type of data, a second set of data is read from the data storage area according to the second access request, wherein each item in the second set of data is first type of data, and the second set of data does not include the first data.

[0014] It should be noted that the second set of data can be the same as the first set of data, or they can be different.

[0015] In some implementations, the first application is a type of application that requires data isolation. The third application is a type of application that does not require data isolation.

[0016] In the above technical solution, the data stored by the first user account through the first sub-data storage area, that is, the data stored by the first type of application under the first user account, cannot be accessed by the second type of application under the first user account. This can avoid the risk of data leakage by the second type of application under the user account through the first sub-data storage area, and help to further improve the privacy and security of user data.

[0017] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: obtaining a fourth access request from the first application, the fourth access request being used to request the reading of second data, the second data being data stored by the third application; and reading the second data according to the fourth access request.

[0018] In the above technical solution, the first type of application under the first user account can read the data stored in the public storage area for the second type of application under the first user account. This helps to improve the flexibility of the first type of application in reading and writing data while ensuring data privacy and security, thereby improving the user's application experience.

[0019] In conjunction with the first aspect, in some implementations of the first aspect, the second data is stored in a public storage area, and the second data is read according to a fourth access request, including: when the first user account is authorized to access the public storage area, the second data is read according to the fourth access request.

[0020] In the above technical solution, the permission of the first user account can determine whether to respond to the request of the first type of application to read data stored in the public storage area, which helps to further improve data privacy and security. The permissions of the first user account can be determined in response to the user's settings, allowing the user to flexibly modify relevant permissions, which helps to improve the convenience of using the vehicle system and thus improve the user's driving experience.

[0021] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: obtaining a fifth access request from a fourth application under a first user account, the fifth access request being used to request the reading of first data; and when the fourth application is an application that needs to access the first sub-data storage area to store data, reading the first data according to the fifth access request.

[0022] In some implementations, the fourth application is the first type of application.

[0023] In the above technical solution, the fourth application, which is also a first type of application, can read the first data stored by the first application. This helps to improve the flexibility of the first type of application in reading and writing data while ensuring data privacy and security, thereby improving the user experience of using the application.

[0024] Secondly, a data access device is provided, comprising an acquisition unit and a processing unit, wherein the acquisition unit is configured to: acquire information of a first user account, wherein the first user account is one of multiple user accounts, each of the multiple user accounts is associated with a sub-data storage area, and the multiple sub-data storage areas associated with the multiple user accounts belong to the same user space; the acquisition unit is further configured to: acquire a first access request of a first application under the first user account, wherein the first access request is used to request the storage of first data; the processing unit is configured to: store the first data through the first sub-data storage area corresponding to the first user account according to the first access request, wherein the multiple sub-data storage areas include the first sub-data storage area.

[0025] In conjunction with the second aspect, in some implementations of the second aspect, the multiple user accounts also include a second user account, which is associated with a second sub-data storage area in the multiple sub-data storage areas. The acquisition unit is further configured to: acquire a second access request from a second application of the second user account; the processing unit is further configured to: reject the second access request when the second access request is used to request to read the first data.

[0026] In conjunction with the second aspect, in some implementations of the second aspect, the acquisition unit is further configured to: acquire a third access request from a third application under the first user account, wherein the third application is an application that does not need to pass through the first sub-data storage area when storing data; the processing unit is further configured to: reject the third access request when the third access request is for requesting to read the first data.

[0027] In conjunction with the second aspect, in some implementations of the second aspect, the acquisition unit is further configured to: acquire a fourth access request from the first application, the fourth access request being used to request the reading of second data, the second data being data stored by the third application; the processing unit is further configured to: read the second data according to the fourth access request.

[0028] In conjunction with the second aspect, in some implementations of the second aspect, the second data is stored in a public storage area, and the processing unit is used to: read the second data according to the fourth access request when the first user account is authorized to access the public storage area.

[0029] In conjunction with the second aspect, in some implementations of the second aspect, the third application is a second type of application, which is an application that does not require data isolation.

[0030] In conjunction with the second aspect, in some implementations of the second aspect, the acquisition unit is further configured to: acquire a fifth access request from a fourth application under a first user account, the fifth access request being used to request the reading of first data; the processing unit is further configured to: when the fourth application is an application that needs to access the first sub-data storage area to store data, read the first data according to the fifth access request.

[0031] In conjunction with the second aspect, in some implementations of the second aspect, the first application is the first type of application, which is an application that requires data isolation.

[0032] Thirdly, a data access device is provided, the device comprising: a processor for executing a computer program stored in the memory, such that the device performs the method in any possible implementation of the first aspect described above.

[0033] In conjunction with the third aspect, in some implementations of the third aspect, the data access device also includes a memory.

[0034] Fourthly, a computer program product is provided, comprising: computer program code, which, when executed on a computer or processor, causes the computer or processor to perform the method in any possible implementation of the first aspect.

[0035] It should be noted that the above computer program code can be stored in whole or in part on a storage medium, which can be packaged together with the processor or packaged separately from the processor.

[0036] Fifthly, a computer-readable storage medium is provided, the computer-readable medium storing instructions that, when executed by a processor, cause the processor to implement the method in any possible implementation of the first aspect.

[0037] In a sixth aspect, a chip is provided that includes circuitry for performing the method in any of the possible implementations of the first aspect described above.

[0038] In a seventh aspect, a vehicle is provided that includes means as in any possible implementation of the second to third aspects, or the vehicle includes computer-readable storage as in any possible implementation of the fifth aspect, or the vehicle includes a chip as in any possible implementation of the sixth aspect, or the vehicle is loaded with computer program code as in any possible implementation of the fourth aspect.

[0039] In conjunction with the seventh aspect, in some implementations of the seventh aspect, the vehicle is a vehicle in a broad sense, such as a means of transportation (e.g., commercial vehicles, passenger cars, motorcycles, flying cars, trains, etc.), industrial vehicles (e.g., forklifts, trailers, tractors, etc.), engineering vehicles (e.g., excavators, bulldozers, cranes, etc.), agricultural equipment (e.g., lawnmowers, harvesters, etc.), amusement equipment, toy vehicles, etc. In practical implementation, the vehicle can also be a road vehicle, a water vehicle, an air vehicle, industrial equipment, agricultural equipment, or other intelligent driving equipment such as entertainment equipment.

[0040] For the beneficial effects not described in detail in aspects two through seven, please refer to the description in aspect one, which will not be repeated here. Attached Figure Description

[0041] Figure 1 is a functional block diagram of the vehicle provided in an embodiment of this application;

[0042] Figure 2 is a schematic diagram of a vehicle cabin scenario provided in an embodiment of this application;

[0043] Figure 3 is a schematic block diagram of the system architecture provided in an embodiment of this application;

[0044] Figure 4 is another schematic block diagram of the system architecture provided in the embodiments of this application;

[0045] Figure 5 is another schematic block diagram of the system architecture provided in the embodiments of this application;

[0046] Figure 6 is a schematic diagram of the data storage architecture provided in an embodiment of this application;

[0047] Figure 7 is a schematic flowchart of the control method provided in an embodiment of this application;

[0048] Figure 8 is a schematic diagram of the graphical user interface (GUI) provided in an embodiment of this application;

[0049] Figure 9 is another schematic diagram of the GUI provided in the embodiments of this application;

[0050] Figure 10 is another schematic diagram of the GUI provided in the embodiments of this application;

[0051] Figure 11 is another schematic diagram of the GUI provided in the embodiments of this application;

[0052] Figure 12 is another schematic diagram of the GUI provided in the embodiments of this application;

[0053] Figure 13 is a schematic flowchart of the data access method provided in an embodiment of this application;

[0054] Figure 14 is a schematic block diagram of the device provided in an embodiment of this application;

[0055] Figure 15 is another schematic block diagram of the device provided in the embodiments of this application. Detailed Implementation

[0056] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0057] Figure 1 is a functional block diagram of a vehicle provided in an embodiment of this application. As shown in Figure 1, the vehicle 100 may include a display device 130 and a computing platform 150. The display device 130 in the cabin is mainly divided into two categories: the first is an in-vehicle display screen; the second is a projection display screen, such as a head-up display (HUD). An in-vehicle display screen is a physical display screen and an important component of the in-vehicle infotainment system. Multiple displays can be installed in the cabin, such as a digital instrument cluster display screen, a central control screen, a display screen in front of the front passenger (also known as the front row passenger), a display screen in front of the left rear passenger, and a display screen in front of the right rear passenger; even the car window can be used as a display screen. A head-up display, also known as a head-up display system, is mainly used to display driving information such as speed and navigation on a display device (e.g., the windshield) in front of the driver. This reduces the driver's eye movement time, avoids pupil changes caused by eye movement, and improves driving safety and comfort. HUDs include, for example, combiner-HUD (C-HUD) systems, windshield-HUD (W-HUD) systems, and augmented reality HUD (AR-HUD) systems.

[0058] Some or all of the functions of vehicle 100 can be controlled by computing platform 150. Computing platform 150 may include processors 151 to 15n. A processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a central processing unit (CPU), microprocessor, graphics processing unit (GPU) (which can be understood as a type of microprocessor), or digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. These logical relationships are fixed or reconfigurable. For example, the processor may be a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as a field-programmable gate array (FPGA). In reconfigurable hardware circuits, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement related functions. Furthermore, the processor can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), tensor processing unit (TPU), deep learning processing unit (DPU), etc. In addition, the computing platform 150 may also include a memory for storing instructions. Some or all of the processors 151 to 15n can call the instructions in the memory to implement the corresponding functions.

[0059] Optionally, the structure of the vehicle 100 described above is merely illustrative. In actual applications, various components of the vehicle 100 may be added or removed as needed.

[0060] Figure 2 is a schematic diagram of a vehicle cockpit scenario provided in an embodiment of this application. The smart cockpit is equipped with one or more in-vehicle displays (or in-vehicle screens), including but not limited to display screen 201 (or central control screen), display screen 202 (or passenger entertainment screen), display screen 203 (or driver's headrest rear screen), display screen 204 (or passenger headrest rear screen), display screen 205 (or second-row entertainment screen) mounted on the cockpit ceiling, and an instrument panel. Further, displays 201 to 205 can display a graphical user interface (GUI), which may include icons of one or more applications and / or one or more cards. Exemplarily, the display device 130 shown in Figure 1 can be one or more of displays 201 to 205. In some possible implementations, display screen 201 can also be a long, continuous screen extending to the passenger area. Additionally, display screen 205 can also be a projection screen associated with a projector, which can be associated with a desktop launcher to manage applications projected onto the projection screen.

[0061] As shown in Figure 2, one or more cameras can also be installed in the cockpit to capture images inside or outside the cockpit. These could include cameras from a driver monitor system (DMS), a cabin monitor system (CMS), or a dashcam. The cameras used to capture images inside and outside the cockpit can be the same camera or different cameras. In addition, one or more pressure sensors and acoustic sensors are installed in the cockpit to monitor the presence and location of users.

[0062] In this application, based on the function of the display screen relative to the driver, cockpit displays can be divided into safety-critical screens and non-safety-critical screens. Safety-critical screens refer to screens or display devices that are likely to affect the driver and cause driver distraction, such as instrument panel screens and central control screens. Non-safety-critical screens indicate screens that are less likely to cause driver distraction, screens that are not easily observed by the driver, or screens located far from the driver, such as screens near rear passengers and rear entertainment screens.

[0063] It should be understood that the following embodiments are illustrated using a 5-seat vehicle as shown in Figure 2 as an example, and the embodiments of this application are not limited to this. For example, for a 7-seat sport / suburban utility vehicle (SUV), the cabin may include a central control screen, a passenger entertainment screen, a screen behind the driver's headrest, a screen behind the passenger's headrest, entertainment screens in the left-hand area of ​​the third row, and entertainment screens in the right-hand area of ​​the third row. As another example, for a bus, the cabin may include front and rear entertainment screens; or, the cabin may include a display screen in the driver's area and an entertainment screen in the passenger area. Furthermore, the following embodiments are illustrated using a left-hand drive vehicle (i.e., the driver is located on the left side of the vehicle), but in actual implementation, the vehicle may also be a right-hand drive vehicle (i.e., the driver is located on the right side of the vehicle).

[0064] As mentioned above, displays in current smart cockpits may be used by different users at different times. For an application deployed on a display, a user may store data while using the application, and after that user logs out, they may not want other users to access that stored data. Therefore, ensuring the privacy and security of user data has become a pressing issue.

[0065] Therefore, embodiments of this application provide a data access scheme that helps ensure the privacy and security of user data.

[0066] To facilitate understanding of the technical solution of this application, the data access scheme provided by the embodiments of this application will be described in detail below with reference to Figures 3 to 15.

[0067] Figure 3 shows a schematic block diagram of the control system provided in an embodiment of this application. As shown in Figure 3, the control system includes multiple display devices, such as display device 1, display device 2, and display device n (n is a positive integer). These multiple display devices are associated with a single user space. That is, the multiple display devices share a single set of system services. Regardless of which display device the system account logs into the vehicle system through, the functions the user wants to achieve through this system account are supported by the same system service. For example, the system service may include basic services such as a desktop launcher, voice service, and data management. The desktop launcher has functions such as launching applications, managing applications (e.g., installing and / or uninstalling applications), and displaying desktop widgets; the voice service provides voice recognition capabilities; and the data management provides functions for managing multimedia data such as photos, videos, and music (e.g., reading and writing multimedia data in the storage area). It is understood that the storage load required by the system services for each user space, and the computational load (e.g., CPU load) required to start and stop the user space, are both high. If a user space is set up for each display device, the memory load and computational load required by the vehicle system will increase exponentially with the number of display devices. Furthermore, when switching system accounts on each display device, it is necessary to stop a system service (the user space corresponding to the logged-out system account) and start a new system service (the user space corresponding to the newly logged-in system account). Such large-scale starting and stopping of system services can cause system freezes, resulting in choppy displays or long waiting times for newly logged-in system accounts before they can use applications. Therefore, setting up a single user space for multiple display devices helps save on storage and computing costs. When the system account logged into the vehicle system changes, there is no need to stop and start system services, which helps reduce system lag, improves system smoothness, and ultimately enhances the user experience.

[0068] It should be noted that the user space involved in this application can be understood as the application's operating environment. The applications deployed on any two of display devices 1 to n can be the same or different. Furthermore, display devices 1, 2, and n in Figure 3 can be included in display device 130 shown in Figure 1. The placement of display devices 1, 2, and n in the cockpit can be referenced to the placement of displays 201 to 205 shown in Figure 2, and will not be elaborated further here.

[0069] It should also be noted that the applications or application programs mentioned below in this application refer to software running in the vehicle infotainment system. The icon corresponding to an application or application (or application icon, or application icon) refers to the entry point for using or accessing the application. Application login or logout refers to logging in or out of the application account within the application. Application exit refers to closing the application or ending the application-related process. Deploying an application on a specific screen refers to deploying the application's access point on a specific screen; for example, this could be deploying the application or application icon on a specific screen, or deploying the main application or a clone application of the application on a specific screen.

[0070] Figure 4 shows another schematic block diagram of the control system provided in an embodiment of this application. As shown in Figure 4, the system includes a user management unit 410, an application management unit 420, a user center service unit 430, and a public data service unit 440. The functional characteristics of each unit shown in Figure 4 can be implemented by one or more processors in the computing platform 150 shown in Figure 1. More specifically, the functions of each unit in the system are as described in items (i) to (iv) below:

[0071] (I) The user management unit 410 provides users with interfaces for logging into the vehicle infotainment system and setting system account permissions. More specifically, the user management unit 410 includes a login management unit 411 and a permission management unit 412. The login management unit 411 is used to obtain the system account requesting to log into or log out of the vehicle infotainment system. In some implementations, the system account may include at least three types: vehicle owner system account, authorized system account, and guest system account. The vehicle owner system account is the account of the legal owner of the vehicle; the authorized system account is the account authorized by the legal owner of the vehicle; and the guest system account is the account not authorized by the legal owner of the vehicle. The permission management unit 412 is used to obtain the permissions of the system account. The permissions of the system account may be user-set or default to the vehicle infotainment system. In some implementations, the permissions of the system account may include at least one of the following: whether it has permission to install applications, whether it has permission to uninstall applications, which applications are allowed to be uninstalled and / or installed, which applications are prohibited from being uninstalled and / or installed, whether it can access the data storage area, and which applications can access the data storage area. For example, system account 1 has the permission to install applications, including all applications in the app store, and all applications can access the data storage area; system account 2 cannot uninstall privacy-critical applications, and all applications cannot access the data storage area. For instance, the legitimate owner of the vehicle can set permissions for authorized system accounts and guest system accounts. For example, when the owner's system account logs into the vehicle's infotainment system, the user can set permissions for authorized system accounts and guest system accounts through the vehicle's human-machine interface (HMI). The permission management unit 412 can obtain the permissions of the system account entered by the user through the HMI.

[0072] (II) The application management unit 420 provides users with interfaces for logging into applications and accessing data storage areas. More specifically, the application management unit 420 includes an application login management unit 421, a user center management unit 422, and an access management unit 423. The application login management unit 421 manages and controls application logins. It can obtain the application account used to log into a specific application and control that account's login to that application. The user center management unit 422 obtains the currently logged-in system account of the vehicle system and sends this information to the application login management unit 421. The application login management unit 421 can then use the application account associated with the currently logged-in system account to log into one or more applications. The user center management unit 422 can also obtain the system account used to log out of the vehicle system and send this information to the application login management unit 421. The application login management unit 421 can then control the application account associated with the logged-out system account to log out of one or more applications. The access management unit 423 manages the permissions for applications to read data from the data storage area and store data in the data storage area. Access management unit 423 can determine whether to send a data read request or data storage request from the application to public data service unit 440 based on the application's permissions. In one example, if an application has permission to access the data storage area, access management unit 423 sends a data read / storage request to public data service unit 440 to request to read the data required by the application or write the data requested by the application to the data storage area. In another example, if an application does not have permission to access the data storage area, access management unit 423 ignores the application's data read / storage request, that is, it does not send a data read / storage request to public data service unit 440.

[0073] (III) The user center service unit 430 is used for system account management and data access management. More specifically, the user center service unit 430 includes an account management unit 431 and a data management unit 432. The account management unit 431 controls a system account to log in to the vehicle infotainment system based on a request obtained from the user management unit 410; alternatively, it controls a system account to log out of the vehicle infotainment system based on a request obtained from the user management unit 410. Furthermore, after controlling a system account to log in or out of the vehicle infotainment system, the user center service unit 430 can send a login or logout notification to the application management unit 420. The data management unit 432 can obtain the system account's permission information from the user management unit 410, determine the applications that can access the data storage area under that system account based on the permission information, and then send the information about the applications that can access the data storage area under that system account to the public data service unit 440.

[0074] (iv) The public data service unit 440 is used to provide data storage and retrieval services for applications. More specifically, the public data service unit 440 includes a permission management module 441, a media library 442, and a file library 443. The permission management module 441 is used to create access path units for system accounts. Subsequently, one or more applications used under this system account need to read and write data in the data storage area through this access path unit. Specifically, the vehicle system can be associated with one or more system accounts. Access path units are set for system accounts that have permission to access the data storage area. At least one application running under the system account with the set access path unit needs to store data in or read data from the data storage area through the access path unit associated with that system account. A system account cannot read or write data in the data storage area through the access path unit of another system account. For example, if application 1 under system account 1 stores image 1 in the data storage area through access path unit 1 associated with system account 1, while application 1 under system account 2 does not store image 1 in the data storage area through access path unit 2 associated with system account 2, then system account 2 cannot read image 1 from the data storage area. Furthermore, for certain applications (such as those with low privacy or security requirements), data reading and writing can be performed without going through an access path unit. In this case, if such an application stores data A under one system account, data A can also be read under another system account.

[0075] Media library 442 and file library 443 are used to store data. When media library 442 or file library 443 receives a data read / write request (i.e., a data read or write request) from access management unit 423, request permission management module 441 authenticates the data read / write request to determine whether the request has permission to access the requested data. The data read / write request can be an application's access request to a data storage area. If the data read / write request authentication is successful, public data service unit 440 sends the requested data to application management unit 420; or, if the data read / write request authentication is successful, public data service unit 440 stores the requested data in the corresponding area of ​​media library 442 or file library 443; or, if the data read / write request authentication fails, public data service unit 440 sends a data access failure notification to application management unit 420.

[0076] It should be understood that the architecture shown in Figure 4 is merely illustrative. In actual implementation, the system shown in Figure 4 may include more or fewer units. For example, the system shown in Figure 4 may include multiple login management units 411, each corresponding to one of the multiple display devices in the vehicle; or, for another example, the system shown in Figure 4 may also include multiple application management units 420, each application management unit 420 being a login interface and / or data access interface corresponding to an application, and the multiple applications corresponding to the multiple application management units 420 may be deployed on one or more display devices in the vehicle. More specifically, when a user logs into the vehicle system using system account 1 through a display device (such as display device a), the login management unit 411 corresponding to display device a may send a login request to the user center service unit 430, which instructs system account 1 to request login into the vehicle system through display device a. Further, the user center service unit 430, based on the login request, controls system account 1 to log into the vehicle system through display device a. Furthermore, the user center service unit 430 sends a login notification for system account 1 to at least one application management unit. This notification indicates that system account 1 has logged into the vehicle infotainment system via display device a. The at least one application management unit controls the application account associated with system account 1 to log into one or more applications deployed on display device a that are associated with system account 1. The aforementioned at least one application management unit may include application management units 420 corresponding to all applications installed in the vehicle infotainment system, or it may include application management units 420 corresponding only to applications deployed on display device a.

[0077] It is understandable that Figure 4 shows a system architecture within a single user space. In actual implementation, multiple display devices in a vehicle can be associated with multiple user spaces. Specifically, as shown in Figure 5, display device 1, display device 2, and display device n (where n is a positive integer) can be associated with user spaces 1 through n', where n' is an integer greater than or equal to 2. In actual implementation, within the same time period, the runtime environment required by the applications deployed on display devices 1 through n is provided by a single user space. In different time periods, the runtime environment required by the applications deployed on display devices 1 through n can be provided by different user spaces. For example, in time period 1, the runtime environment required by the applications deployed on display devices 1 through n is provided by user space 1, while in time period 2, the runtime environment required by the applications deployed on display devices 1 through n is provided by user space n'. In this scenario, the end time of time period 1 is earlier than the start time of time period 2, or the end time of time period 1 coincides with the start time of time period 2; or the end time of time period 2 is earlier than the start time of time period 1, or the end time of time period 2 coincides with the start time of time period 1. In some implementations, within the same time period, the runtime environment required by applications deployed on display devices 1 to n can be provided by at least two user spaces. For example, the runtime environment required by applications deployed on display device 1 is provided by user space 1, and the runtime environment required by applications deployed on display devices 2 to n is provided by user space n'.

[0078] In actual implementation, in order to ensure the privacy and security of different users in the same user space, the data read and write architecture of this application embodiment is designed, which will be described in detail below with reference to Figure 6.

[0079] Figure 6 illustrates a schematic diagram of the data storage architecture provided in an embodiment of this application. As shown in Figure 6, the database includes an access path management unit and a data sandbox. The database may include the aforementioned media library, file library, etc. The data sandbox is used to store data. The access path management unit may include multiple access path units, each associated with a system account. For example, if system accounts a through N are all associated with the same user space (e.g., system accounts a through N are all registered in this user space, or have all logged into the vehicle system under this user space), the access path management unit may include access path units associated with system accounts a through N, such as system account a access path unit, system account N access path unit, etc. More specifically, system account a can log in to multiple applications, including applications 1 through m. Applications 1 through m need to read and write data through the access path management unit. For example, at least one of applications 1 through m stores image 11, image 21, image 31, and video 111 in the data sandbox through the system account a access path unit. More specifically, when at least one of applications 1 to m stores data, a reference associated with that data is created (e.g., reference to image 11, image 21, image 31, or video 111), and this reference is stored in the access path unit of system account a. This reference includes fields associated with system account a. When an application reads the aforementioned data, it needs to read it through the reference associated with that data. For example, when application m requests to read video 111 from the data sandbox, it needs to read video 111 through the video 111 reference stored in the access path unit of system account a.

[0080] In some implementations, applications 1 to m are privacy-critical applications. Among the multiple applications logged in under system account a, in addition to applications 1 to m, there may be at least one rights-sharing application. When at least one rights-sharing application reads or writes data, it can do so without going through the access path management unit.

[0081] For details on how applications 1' to m' under system account N read data from the data sandbox and store data in the data sandbox, please refer to the relevant descriptions of applications 1 to m reading and writing data. These details will not be repeated here.

[0082] It should be noted that applications under system account a, other than applications 1 to m, cannot read data stored through the access path management unit (such as images 11, 21, 31, and video 111). Furthermore, applications running under one system account cannot read data stored through the access path management unit by applications running under another system account. For example, an application running under system account a cannot read images 12, 22, 32, etc., stored through the access path management unit by an application running under system account N.

[0083] In actual implementation, the data reference stored in the aforementioned access path unit can be in the form of a field, which may include the system account name. For example, when application m' running under system account N stores data a in the data storage area, the "System Account N" field is added to the data storage path (or data reference). A more specific data storage path could be: "System Account N - Application m' - Data a". When application 1' running under system account N reads data a from the data storage area, the "System Account N" field is added to the data read path. A more specific data read path could be: "System Account N - Application 1' - Data a". It should be noted that the field representing the access path unit corresponding to a system account can be managed by the public data service unit 440. This field is not perceived by the application. When the public data service unit 440 receives a data access request from an application, it determines whether to respond to the application's data access request based on which system account the application is running under and whether the application needs to read or write data in the data storage area via the access path unit. Therefore, applications running under system account N that can read and write data to the data storage area without accessing the path unit, as well as applications running under other system accounts, cannot read the data stored by applications 1' to m' running under system account N.

[0084] In some implementations, for applications that can read and write data to the data storage area without going through an access path unit (such as rights-sharing applications), a public storage area can be set up. This public storage area is used for the aforementioned applications to read and write data. It should be noted that when a system account is authorized to access the public storage area, the data in that public storage area can be read by any application running under that system account. It should be understood that the aforementioned data storage area includes this public storage area.

[0085] It should also be noted that the privacy-critical applications and benefit-sharing applications involved in this application are categorized based on the application's data privacy requirements. Privacy-critical applications can also be referred to as clone applications, and benefit-sharing applications can also be referred to as instance applications. More specifically, privacy-critical applications refer to applications with data isolation requirements; for example, users do not want data associated with such applications to be accessed or obtained by other users. Privacy-critical applications can include social applications (such as instant messaging applications, social media platforms, etc.), or e-commerce applications, map navigation applications, etc. Benefit-sharing applications involved in this application refer to applications that do not require data isolation; for example, data associated with such applications can be accessed or obtained by other users, such as weather applications; or benefit-sharing applications can also be applications that require data sharing; for example, for one application, multiple system accounts can share the benefits of the same application account, such as audio and video applications. For example, the data associated with the aforementioned applications can include at least one of the following: data stored by the application, data read by the application, or the application's search history, browsing history, purchase history, etc. Furthermore, for privacy-critical applications, when the same application is deployed on multiple displays, the applications on different displays need to log in with different application accounts within the same time period. For benefit-sharing applications, when the same application is deployed on multiple displays, the applications deployed on multiple displays can log in with the same application account within the same time period. In other words, the benefits of an application account can be shared by applications on multiple displays within the same time period.

[0086] In practice, whether an application is classified as a privacy-critical application or a rights-sharing application can be set by the system default. For example, social applications can be set as privacy-critical applications by default, while audio and video applications can be set as rights-sharing applications by default. Alternatively, for a single application, users can be provided with both privacy-critical application installation packages and rights-sharing application installation packages, allowing users to choose which type of application to deploy in the vehicle's infotainment system.

[0087] The above, in conjunction with Figures 1 to 6, provides a detailed description of the system architecture provided in the embodiments of this application. The following describes in detail the control method provided in the embodiments of this application.

[0088] Figure 7 shows a schematic flowchart of a control method provided in an embodiment of this application. This method can be executed by the system shown in Figure 4, wherein the user management unit, application management unit group, user center service unit, and public data service unit can be respectively a user management unit 410, at least one application management unit 420, a user center service unit 430, and a public data service unit 440 within a user space. The method may include the following steps:

[0089] S711, User Management Unit obtains user permission information 1.

[0090] In one example, when the main user is logged in, the user management unit retrieves user permission information 1 in response to the user's settings.

[0091] In another example, the user management unit obtains user permission information 1 from a vehicle owner application deployed on an electronic device associated with the vehicle. This vehicle owner application may be an application that provides vehicle control to the vehicle owner, and / or an application that provides services such as providing the vehicle owner with information about the vehicle's status. The association between the electronic device and the vehicle may include: the account used to log in to the electronic device and the vehicle being the same; or, although the accounts used to log in to the electronic device and the vehicle are different, both being accounts belonging to an authorized user of the vehicle; or, the electronic device being authorized by an authorized user of the vehicle, thereby establishing an association between the vehicle and the electronic device.

[0092] For example, the main user can be the aforementioned vehicle owner system account; user permission information 1 can include the permissions of each of the multiple system accounts. These multiple system accounts can include one or more authorized system accounts, and can also include one or more guest system accounts. The specific content of the permissions for each system account can be found in the descriptions in the preceding embodiments, and will not be repeated here.

[0093] In some implementations, applications running under a guest system account do not have permission to access the data storage area under that user space.

[0094] S712, the user management unit sends user permission information 1 to the user center service unit.

[0095] S713, the User Center Service Unit performs user permission processing.

[0096] For example, the user center service unit determines the applications that can access the data storage area under each system account based on user permission information 1, and then obtains user permission information 2. User permission information 2 includes information about at least one application and the association between each application and the system account. The at least one application may include one or more applications that can access the data storage area under one or more system accounts.

[0097] S714, The User Center Service Unit sends user permission information 2 to the Public Data Service Unit.

[0098] Furthermore, the public data service unit manages the data access permissions of applications running under each system account based on user permission information 2. For example, the public data service unit determines, based on user permission information 2, which applications can access the data storage area, and under which system accounts these applications can access the data storage area.

[0099] In some implementations, the public data service unit records the applications that can access the data storage area under each system account. When an application not recorded by the public data service unit requests access to the data storage area, the public data service unit rejects its request.

[0100] In some implementations, at least one application includes a privacy-critical application. In this case, the public data service unit establishes an access path unit for the system account associated with the privacy-critical application. The privacy-critical application running under this system account can subsequently read and write data in the data storage area through this access path unit. For a more detailed implementation of how privacy-critical applications read and write data in the data storage area, please refer to the description in the corresponding part of Figure 6 above, which will not be repeated here.

[0101] S721, the user management unit obtains login instruction 1, which is associated with system account A.

[0102] For example, system account A can be the vehicle owner's system account, or it can be an account authorized by the legal owner of the vehicle. System account A can be any of the aforementioned system accounts a to N, or it can be the aforementioned system account 1 or system account 2.

[0103] Login command 1 is associated with system account A, which can be understood as: Login command 1 requests to log in to the vehicle system using system account A, or Login command 1 requests to log in to the vehicle system using system account A through display device A. For example, display device A can be any one of the aforementioned display devices 1 to n.

[0104] S722, the user management unit sends a login request for system account A to the user center service unit.

[0105] S723, the user center service unit performs login processing for system account A.

[0106] For example, the user center service unit logs into the vehicle system using system account A on display device A.

[0107] S724, Application Management Snap-in Login Application 1.

[0108] For example, the application management unit group responds to the user's operation and controls application account 1 to log in to application 1.

[0109] S725, the Application Management Unit group sends a login notification for Application 1 to the User Center Service Unit.

[0110] For example, the login notification of application 1 instructs application account 1 to log in to application 1 under system account A.

[0111] S726, the User Center Service Unit performs the association processing between Application 1 and System Account A.

[0112] For example, the association process can be understood as binding application 1, system account A and application account 1 together, so that when system account A logs into the vehicle system next time, application account 1 can log into application 1 together.

[0113] In some implementations, if application 1 is a privacy-critical application, the user center service unit will perform the association processing between application 1 and system account A when it receives the login notification from application 1.

[0114] In some other implementations, when the user center service unit receives the login notification of application 1, the control prompt device prompts information 1, which prompts the user to determine whether application 1 needs to be associated with system account A. When it is determined that the user chooses to associate application 1 with system account A, S726 is executed.

[0115] It should be noted that S724 to S726 can be operations performed when logging into application 1 for the first time under system account A; or, S724 to S726 can also be operations performed when logging into application 1 for the first time under system account A using application account 1. For example, before executing S724, application 1 is already associated with system account A, but application 1 is associated with system account A while logging in with application account 2. After executing S724 to S726, the association between application 1 and system account A is updated to: when logging in with system account A, application 1 is logged in using application account 1.

[0116] In some implementations, S727 and S728 are executed after S723. For example, if the association between system account A and the application has already been processed, S727 and S728 are executed after S723.

[0117] S727, the User Center Service Unit sends a login notification for System Account A to the Application Management Unit Group.

[0118] For example, the login notification for system account A instructs system account A to log in to the vehicle system through display device A.

[0119] S728, Application management unit group login system account A associated with application group a.

[0120] In some implementations, application group a may include at least one application deployed on display device A and associated with system account A. For each application, the application is logged in using the application account associated with system account A; the application account used to log in to different applications may be different. It is understood that the association between the application, the application account, and the system account can be determined through steps S724 to S726.

[0121] For example, at least one application includes application 3, and application 3 is a rights-sharing application. That is, when application 3 is deployed on display device A, other display devices in the vehicle can deploy applications 3', 3" and so on. When logging into any one of application 3, application 3', or application 3" using an application account, the remaining two applications are also logged in. In other words, application group a can also include applications such as application 3' and application 3" that are associated with application 3 and deployed on other display devices.

[0122] It should be noted that the applications deployed on different display devices may be different. Therefore, when system account A logs into the vehicle system through different display devices, the applications that log in with system account A may be different.

[0123] In some implementations, S724 to S726 can also be executed after S727 and S728. For example, if application group a in S728 includes application 1, when S728 is executed, application account 2 is controlled to log in to application 1. Further, in response to a user action controlling application account 1 to log out of application 1, S724 to S726 are executed. Thus, the next time system account A is logged in, application account 1 is used to log in to application 1 associated with system account A.

[0124] S731, the user management unit obtains logout instruction 1, and logout instruction 1 requests system account A to log out.

[0125] S732, the user management unit sends a logout request for system account A to the user center service unit.

[0126] S733, the User Center Service Unit performs a logout process for system account A.

[0127] For example, the user center service unit logs out system account A on display device A.

[0128] S734, the User Center Service Unit sends a logout notification for System Account A to the Application Management Unit Group.

[0129] S735, the application management unit logs out at least one application in application group a.

[0130] In some implementations, all applications in application group a are logged out.

[0131] In some implementations, application group a includes at least one safety-critical application. Safety-critical applications refer to applications that affect driving safety, such as navigation applications or intelligent driving applications. Intelligent driving applications are those used to control intelligent driving functions, which may include, but are not limited to, the following functions affecting driving safety: automatic parking assist (APA), automatic valet parking (AVP), adaptive cruise control (ACC), lane cruise control (LCC), navigation cruise assist (NCA), forward collision warning, lane departure warning, lane keeping assist, and rear collision warning. Specifically, NCA refers to the function of controlling the vehicle to travel to its destination according to the navigation route and being able to control the vehicle to perform operations such as passing intersections, changing lanes, and shifting gears based on road information such as traffic lights.

[0132] In one example, when the vehicle is in drive or reverse, if the application management unit receives a logout notification for system account A, the application management unit will control the logout of all applications in application group a except for intelligent driving applications. Furthermore, when the vehicle is in park, the intelligent driving applications will be logged out.

[0133] In another example, when a smart driving application is running, if the application management unit receives a logout notification from system account A, the application management unit will control the logout of all applications in application group a except for the running smart driving application. Furthermore, when the smart driving application exits its running state, the application management unit will also be controlled to log out.

[0134] In some implementations, if application group a includes at least one benefit-sharing application, then when the application management unit receives a logout notification for system account A, it controls the logout of all applications in application group a except for the at least one benefit-sharing application. For example, if the at least one benefit-sharing application includes the aforementioned application 3, application 3', and application 3'", then the application management unit controls the logout of all applications in application group a except for application 3, application 3', and application 3'".

[0135] In some implementations, after controlling at least one application in application group a to log out, it is also possible to control at least one application in application group a to exit.

[0136] In practice, when the same system account logs into the vehicle system through different display devices, the system account can be logged out of the vehicle system before logging in again when the system account logs into the vehicle system through the next display device; or the system account can be kept logged into the vehicle system continuously during the aforementioned process.

[0137] S741, the application management unit group sends a data access request to the public data service unit for application 2 associated with system account B.

[0138] In this context, application 2 associated with system account B can be understood as an application running under system account B. For example, if system account 2 logs into the vehicle system through display device B, then application 2 can be an application deployed on display device B. Exemplarily, display device B can be any one of the aforementioned display devices 1 to n.

[0139] For example, a data access request may include a request to read data in a data storage area and / or a request to store data in a data storage area.

[0140] S742, the public data service unit performs authentication processing.

[0141] For example, the public data service unit determines whether application 2 associated with system account B has permission to access the data storage area. When it is determined that application 2 associated with system account B has permission to access the data storage area, the public data service unit also determines which data in the data storage area application 2 can access.

[0142] In some implementations, multiple system accounts can access application 2 when logging into the vehicle's infotainment system via display device B. However, the permissions of application 2 associated with different system accounts vary. For example, application 2 associated with system accounts B and C both have access to the data storage area, while application 2 associated with system account D does not. Furthermore, application 2 associated with system account B can access the public storage area, while application 2 associated with system account C does not have access to the public storage area.

[0143] S743, upon successful authentication, the public data service unit sends the data read / write results to the application management unit group.

[0144] In one example, if system account B is associated with application 2, which needs to access the data storage area through the access path unit, then the public data service unit stores the data requested by application 2 and / or reads the data requested by application 2 through the access path unit.

[0145] In another example, if application 2 associated with system account B can access the data storage area without going through the access path unit, then the public data service unit stores the data requested by application 2 in the public storage area and / or reads the data requested by application 2 from the public storage area.

[0146] S744, when authentication fails, the Public Data Service Unit sends a data access failure notification to the Application Management Unit Group.

[0147] For example, a data access failure notification is used to notify of a failure to store data in a data storage area, or to notify of a failure to read data from a data storage area.

[0148] It should be noted that when system account A and system account B are different and they log into the vehicle system through different display devices, S741 to S744 can be executed synchronously with any one of the following groups: S721 to S723, S724 to S726, S727 to S728, or S731 to S735, or they can be executed before any one of these groups. Furthermore, S741 to S744 can also be executed synchronously with S711 to S714, or S741 to S744 can be executed before S711 to S714.

[0149] It should also be noted that, in this application, "application login or logout" refers to logging into or logging out of an application using an application account; while "vehicle system login or logout" refers to logging into or logging out of a vehicle system using a system account. Furthermore, application logout and application exit are not the same. Application logout refers to the application account logging out of the application, while application exit refers to the termination or exit of all processes related to the application, such as stopping the application's background operation. In other words, after logging out of an application, the application may or may not exit. If the application does not exit, the display screen may show the application's running interface, or the display screen may not show the application's running interface; in this case, the application can run in the background.

[0150] To facilitate understanding of the data access method provided in the embodiments of this application, the application scenarios and GUI involved in this application will be described in detail below with reference to Figures 8 to 12. Among them, the processing actions (such as control, response, etc.) or steps involved in Figures 8 to 12 can be executed by the computing platform 150 shown in Figure 1, or they can also be executed by the system shown above. For example, the processing actions related to data reading and writing can be executed by the public data service unit 440.

[0151] Figure 8 illustrates an example of the GUI provided in this application embodiment. As shown in Figure 8, user A is located in the driver's seat area of ​​the vehicle cabin. At this time, the content displayed on the display screen 201 (i.e., the central control screen) can be as shown in Figure 8(a), including a content display area 1010 and a function bar 1010'. Exemplarily, the content display area 1010 includes: icons for various applications, each application icon being used to enable an application; a login control 1011 (not logged in state) for logging into the vehicle system; and Bluetooth function icons, Wi-Fi function icons, and cellular network signal icons, respectively used to indicate the vehicle's Bluetooth on and / or connection status, Wi-Fi on status, and cellular network signal strength. The function bar 1010' includes a homepage icon, seat controls, air conditioning controls, and volume controls, respectively used to control the content display area 1010 to display the homepage, control the on / off switch of seat ventilation and / or adjust the airflow of seat ventilation, control the on / off switch of air conditioning and / or adjust the air conditioning temperature and heating / cooling status, adjust the in-vehicle air circulation status, and adjust the volume of the sound device.

[0152] For example, when a user clicks on the login control 1011, a prompt box 1012 as shown in Figure 8(b) can be displayed. The prompt box 1012 includes the message "Please select a login method," as well as a face recognition login control, a QR code login control, an account login control, and a cancel control. When a user clicks on the account login control, in response to the user's input system account and login password (or verification code), the system account (hereinafter referred to as User A's system account) is controlled to log in to the vehicle system. It is understood that in actual implementation, the user can also choose other methods to log in to the vehicle system. After User A's system account logs in to the vehicle system, the login control can display the avatar 1013 associated with User A's system account, as shown in Figure 8(c).

[0153] It should be noted that the icons shown in Figure 8 are for illustrative purposes only. In actual implementation, the content display area 1010 and the function bar 1010' may display more or fewer icons. For example, when sliding the interface switching component 1011' in the content display area 1010, the content display area 1010 may switch to other interfaces to display icons for other applications. As another example, the content display area 1010 may display some or all of the Bluetooth, Wi-Fi, and cellular network signal icons, or may not display them, depending on the user's settings. Furthermore, the function bar 1010' may display other styles of icons based on the user's settings for seat ventilation and air conditioning status.

[0154] In some implementations, an application running under user A's system account stores data via the aforementioned access path unit, and applications running under other system accounts cannot read this data. Figures 9 and 10 illustrate a set of GUIs for this scenario.

[0155] For example, taking an instant messaging application that requires data storage via an access path unit under user A's system account as an example, the display screen 201 can respond to the user's operation and display the interface 1030 of the instant messaging application shown in Figure 9(a). The left column of this interface 1030 is a control bar, which includes an avatar 1031, the avatar of the application account logged into the instant messaging application; the control bar also includes chat controls, contact controls, and file controls, used to control the display of the chat module, contact module, and file module, respectively. The current middle column of interface 1030 shows thumbnails of multiple contacts, and the right column of interface 1030 shows the chat interface with a specific contact. For example, as shown in interface 1030, the instant messaging application receives an image 1032 from contact a. Furthermore, when a long press is detected on image 1032, the control display screen 201 displays the interface shown in Figure 9(b). This interface includes a control bar 1033, which includes an edit control, a forward control, and a save control, used for editing the image, forwarding the image to other contacts, and saving the image, respectively. When the save control is clicked, image 1032 is saved. More specifically, when the save control is clicked, the instant messaging application sends a data storage request to the public data service unit. After the public data service unit authenticates the instant messaging application, it stores image 1032 in the data storage area through the access path unit corresponding to user A's system account. For example, the save path for image 1032 is "user A's system account - instant messaging application - image 1032".

[0156] Optionally, when the image 1032 is successfully saved, the display screen 201 can be controlled to display a prompt bar 1034 as shown in Figure 9(c), which includes the prompt message "Image saved".

[0157] Furthermore, when an application running under User B's system account requests access to the image library, the application cannot obtain the aforementioned image 1032. For example, as shown in Figure 10(a), when User B's system account logs into the vehicle system via display screen 204 (i.e., the screen behind the passenger headrest), the login control on display screen 204 displays the avatar 1018 associated with User B's system account, and the instant messaging application interface displays the avatar 1035 of the application account logged into the instant messaging application by User B's system account. If the user wants to send an image to contact C through the instant messaging application running under User B's system account, they can click the image control 1036 to open the "Images and Videos" section 1037 shown in Figure 10(b), and then select an image from the "Images and Videos" section 1037 to send to contact C. More specifically, when the image control 1036 is detected to be clicked, the instant messaging application sends a data read request to the public data service unit, which is used to read images that the instant messaging application can read. In one example, if the instant messaging application running under User B's system account also needs to store data via the access path unit, then a data read request can be used to request images stored via the access path unit. In another example, if User B's system account is authorized to access the public storage area, then a data read request can also be used to request to read images from the public storage area.

[0158] In some implementations, if the images stored in the public storage area include images 6 and 7, and the applications under user B's system account that need to store data through the access path unit store images 1, 2, 3, 4, 5, and 8, and user B's system account is authorized to access the public storage area, then the public data service unit, in response to the data read request from the instant messaging application running under user B's system account, reads images 1 to 8 from the data storage area and controls the "Images and Videos" column 1037 to display these images for the user to select. That is, when the instant messaging application running under user B's system account requests to read images from the data storage area, it can only read images from the public storage area and images stored by applications under user B's system account that need to store data through the access path unit; it cannot read image 1032 stored by the instant messaging application running under user A's system account. Furthermore, Figure 10 illustrates this using an instant messaging application requesting to read data as an example. In actual implementation, when other applications running under user B's system account request to read data, these applications also cannot read image 1032.

[0159] When an application under User A's system account requests access to the image library via the access path unit, that application can obtain the aforementioned image 1032. For example, taking an instant messaging application running under User A's system account that needs to store data via the access path unit as an example, if other applications under User A's system account that need to store data via the access path unit store images a to d, and User A's system account is authorized to access the public storage area, then as shown in Figure 11(a), when the image control 1038 is detected as clicked, the instant messaging application sends a data read request to the public data service unit. This request is used to read images that the instant messaging application can read. Further, when the public data service unit successfully authenticates the data read request from the instant messaging application running under User A's system account, the public data service unit reads image 1032, images a to d, and images 6 and 7 from the data storage area, and controls the "Images and Videos" column 1039 shown in Figure 11(b) to display these images for the user to select.

[0160] When an application under User A's system account requests access to the image library without needing to store data through the access path unit, the application cannot obtain the aforementioned image 1032. Taking a video application under User A's system account that does not need to store data through the access path unit as an example, as shown in Figure 12(a), the interface of the currently shown video application includes a navigation bar 1021, a video playback bar 1022, and a playback history bar 1023, which are used to display various controls, the video playback interface, and playback history information, respectively. Among them, the navigation bar 1021 includes a login control 1024, which can be used to control the application account to log in or out of the video application, or to change the image associated with the application account that is logged into the video application. For example, if the user long-presses the login control 1024, the display screen 201 can be triggered to display the interface shown in Figure 12(b). This interface includes multiple image selection controls, a close window control, and a confirm control, which are used to select an image, close the interface in Figure 12(b), and confirm that the selected image is the image associated with the application account, respectively. More specifically, upon detecting that the login control 1024 has been clicked, the video application sends a data read request to the public data service unit. This request is used to read images that the video application can read. Further, when the public data service unit successfully authenticates the data read request from the video application running under user A's system account, the public data service unit reads images 6 and 7 from the data storage area and controls the interface shown in Figure 12(b) to display these images for the user to select.

[0161] In some implementations, the scenarios shown in Figures 10 and 11 can occur after the scenario shown in Figure 9, and the scenarios in Figures 10 and 11 can occur within the same time period. That is, when the scenarios shown in Figures 10 and 11 occur, the data stored in the data storage area is the same. However, since some applications under different system accounts store data via access path units, this data cannot be read by applications under other system accounts. Therefore, even if the data stored in the data storage area is the same, the instant messaging application running under user B's system account and the instant messaging application running under user A's system account can read different data. This helps protect the privacy and security of user data. Furthermore, the scenario shown in Figure 12 can also occur after the scenario shown in Figure 9, meaning that in this case, the data storage area includes image 1032, as well as images a to d. However, due to the permission settings of the application in Figure 12, it cannot read image 1032 and images a to d.

[0162] It should be noted that Figures 8 to 12 above use images as an example of data for illustration. In actual implementation, the aforementioned stored or retrieved data can also be other data such as videos or files.

[0163] It should also be noted that the aforementioned applications that need to store data through the access path unit can be privacy-critical applications, while the aforementioned applications that do not need to store data through the access path unit can be rights-sharing applications.

[0164] Figure 13 shows a schematic flowchart of a data access method provided in an embodiment of this application. This method 20 can be applied to the vehicle shown in Figure 1, or it can be executed by any of the systems shown in Figures 3 to 5. More specifically, the method includes:

[0165] S21, obtain the information of the first user account. The first user account is one of multiple user accounts. Each user account is associated with a sub-data storage area. The multiple sub-data storage areas associated with multiple user accounts belong to the same user space.

[0166] For example, multiple user accounts may include the aforementioned vehicle owner system account, authorized system account, etc. The sub-data storage area may be the access path unit in the aforementioned embodiments.

[0167] S22, obtain the first access request of the first application under the first user account. The first access request is used to request the storage of the first data.

[0168] For example, the first data may include data such as images, files, and videos.

[0169] In some implementations, the first application is a first-type application, which is an application that requires data isolation. For example, the first-type application is the privacy-critical application in the aforementioned embodiments.

[0170] S23, based on the first access request, the first data is stored in the first sub-data storage area corresponding to the first user account, and the multiple sub-data storage areas include the first sub-data storage area.

[0171] In some implementations, the first access request carries the identifier of the first user account, and further, based on the identifier of the first user account, the first data is stored in the first sub-data storage area corresponding to the first user account.

[0172] For example, taking the first user account as the system account of user A in the aforementioned embodiment and the first application as the instant messaging application running under user A's system account, the first access request can be a data storage request issued by the instant messaging application running under user A's system account. For example, it can be a data storage request generated in response to the click of the save control in the control bar 1033 shown in Figure 9(b). In this scenario, the first data can be the image 1032 shown in Figure 9(a). Further, storing the first data through the first sub-data storage area corresponding to the first user account can be done by storing the first data through the access path unit corresponding to user A's system account. For example, when storing the first data, a reference to the first data (such as a field including user A's system account) is created and stored in the access path unit so that when reading the first data later, it is necessary to read the first data through the reference to the first data stored in the access path unit. For a more specific implementation of storing the first data, please refer to the description of the corresponding part of Figure 6 and the description of the corresponding part of Figure 9, which will not be repeated here.

[0173] In some implementations, the multiple user accounts also include a second user account, which is associated with a second sub-data storage area in the multiple sub-data storage areas. The method further includes: obtaining a second access request from a second application of the second user account; and rejecting the second access request when the second access request is used to request to read the first data.

[0174] In this context, denying the second access request can be understood as refusing to read the first data from the data storage area.

[0175] For example, if the first data is a first type of data, then when the second access request is used to request the reading of the first type of data, the first group of data is read from the data storage area according to the second access request. Each item in the first group of data is first type of data, and the first group of data does not include the first data. When the second access request is used to request the reading of first type of data including the first data, rejecting the second access request can be understood as rejecting the part of the second access request related to reading the first data, but it is still possible to respond to the second access request to read other first type of data besides the first data.

[0176] Taking multimedia data as an example, if the second user account is the system account of user B in the aforementioned embodiment, and the second application is the instant messaging application running under user B's system account, then the second access request can be a data read request issued by the instant messaging application running under user B's system account. For example, it could be a data read request generated in response to the clicking of the image control 1036 shown in Figure 10(a). As can be seen from Figure 10(b), in response to the data read request issued by the instant messaging application, the final read data result does not include the first data (such as image 1032), but includes other first-type data besides the first data (such as images 1 to 8). In the aforementioned scenario, images 1 to 8 can be regarded as an example of the first group of data.

[0177] It should be noted that the second application can be a privacy-critical application or a rights-sharing application.

[0178] In some implementations, the method further includes: obtaining a third access request from a third application under the first user account, wherein the third application is an application that does not need to go through the first sub-data storage area when storing data; and rejecting the third access request when the third access request is used to request to read the first data.

[0179] In this context, denying a third access request can be understood as refusing to read the first data from the data storage area.

[0180] In some implementations, the third application is a type of second-class application, which is an application that does not require data isolation. For example, the second-class application can be a rights-sharing application as described in the foregoing embodiments.

[0181] For example, if the first data is a first type of data, then when a third access request is made to request the reading of the first type of data, a second set of data is read from the data storage area according to the third access request. Each item in the second set of data is first type of data, and the second set of data does not include the first data. When a third access request is made to request the reading of first type of data including the first data, rejecting the third access request can be understood as rejecting the part of the third access request concerning the reading of the first data, but still being able to respond to the third access request to read other first type of data besides the first data.

[0182] Taking multimedia data as an example, if the first user account is the system account of user A in the aforementioned embodiment, and the third application is a video application running under user A's system account, then the third access request can be a data read request issued by the video application running under user A's system account. For example, it could be a data read request generated in response to the clicking of the login control 1024 shown in Figure 12(a). As can be seen from Figure 12(b), in response to the data read request issued by the video application, the final read data result does not include the first data (such as image 1032), but includes other first-type data besides the first data (such as images 6 and 7). In the aforementioned scenario, images 6 and 7 can be considered as an example of the second set of data. It should be noted that the third application can also be other rights-sharing applications.

[0183] In some implementations, the method further includes: obtaining a fourth access request from a first application, the fourth access request being used to request the reading of second data, the second data being data stored by a third application; and reading the second data according to the fourth access request.

[0184] In some implementations, the second data is stored in a public storage area, and the second data is read according to a fourth access request, including: when the first user account is authorized to access the public storage area, the second data is read according to the fourth access request.

[0185] For example, the public storage area can be the public storage area in the aforementioned embodiments, used to store data associated with rights-sharing applications. That is, the second data can be data associated with a second type of application, for example, the second data can be data stored by a second type of application. Taking the first user account as the system account of user A in the aforementioned embodiments and the first application as an instant messaging application running under user A's system account as an example, the second data can include image 6 and / or image 7 shown in FIG11. In the above scenario, the fourth access request can be a data read request issued by the instant messaging application running under user A's system account, for example, a data read request generated in response to the clicking of the image control 1038 shown in FIG11(a). As can be seen from FIG11(b), in response to the data read request issued by the instant messaging application, the final read data result includes the second data (such as image 6 and / or image 7).

[0186] For example, permissions for a first user account to access the public storage area can be set through S711 to S713 in the foregoing embodiments.

[0187] Understandably, when the first user account is not authorized to access the public storage area, the fourth access request from the first application is rejected, meaning the first application cannot read the data in the public storage area.

[0188] In some implementations, the method further includes: obtaining a fifth access request from a fourth application under a first user account, the fifth access request being used to request the reading of first data; and when the fourth application is an application that needs to access the first sub-data storage area to store data, reading the first data according to the fifth access request.

[0189] It is understandable that the fourth application and the first application are of the same type, that is, the fourth application is also a type of first application.

[0190] For example, taking the first user account as the system account of user A in the aforementioned embodiment, and the fourth application as an instant messaging application running under user A's system account, the first application can be any privacy-critical application other than the instant messaging application, and the first application stores at least one of the images a to d shown in FIG11. Therefore, at least one of the images a to d can be considered an example of the first data. In the aforementioned scenario, the fifth access request can be a data read request issued by the instant messaging application running under user A's system account, for example, a data read request generated in response to the clicking of the image control 1038 shown in FIG11(a). As can be seen from FIG11(b), in response to the data read request issued by the instant messaging application, the final read data result includes the first data (such as at least one of the images a to d).

[0191] It should be noted that the type of application involved in this application (such as a privacy-critical application or a rights-sharing application) can be the system default; or it can be set by the user. For example, when deploying the application for the first time, the user can choose the type of application, or the user can change the type of application after the application has been deployed.

[0192] The data access method provided in this application embodiment, when multiple user accounts used to log in to the vehicle system are associated with the same user space, allows applications with data privacy requirements to store the data requested by the application in the data storage area through a sub-data storage area. This can prevent applications under other user accounts from reading the data, thus helping to protect the data privacy and security of each user account.

[0193] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions between the various embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0194] The methods provided by the embodiments of this application have been described in detail above with reference to Figures 1 to 13. The apparatus provided by the embodiments of this application will now be described in detail below with reference to Figures 14 and 15. It should be understood that the descriptions of the apparatus embodiments correspond to the descriptions of the method embodiments; therefore, any content not described in detail can be found in the above method embodiments, and for the sake of brevity, will not be repeated here.

[0195] Figure 14 shows a schematic block diagram of an apparatus 2000 provided in an embodiment of this application. The apparatus 2000 may include units for executing the methods described in the foregoing embodiments. Furthermore, each unit in the apparatus 2000 implements a corresponding process of the above method embodiments. The apparatus 2000 includes an acquisition unit 2010, which can be used to implement corresponding data acquisition or transmission / reception functions. The apparatus 2000 also includes a processing unit 2020, which can be used to implement corresponding processing functions.

[0196] Optionally, the device 2000 further includes a storage unit, which can be used to store instructions and / or data. The processing unit 2020 can read the instructions and / or data in the storage unit so that the device can perform the relevant actions in the aforementioned method embodiments.

[0197] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.

[0198] It should also be understood that the device 2000 described herein is embodied in the form of a functional unit. The terms “module” or “unit” may refer to application-specific ASICs, electronic circuits, processors (e.g., shared processors, proprietary processors, or group processors) and memory for executing one or more software or firmware programs, integrated logic circuits, and / or other suitable components that support the described functions.

[0199] The apparatuses described above are capable of implementing the corresponding steps performed by the computing platform 150 in the methods described above. These functions can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the functions described above; for example, the acquisition unit 2010 can be replaced by a transceiver, and other units, such as processing units, can be replaced by a processor, used to execute the relevant processing operations in each method embodiment.

[0200] Exemplarily, the acquisition unit 2010 and processing unit 2020 can be disposed in the vehicle 100 shown in FIG1, or in any of the systems shown in FIG3 to FIG5. More specifically, the acquisition unit 2010 and processing unit 2020 can be disposed in the public data service unit 440. Exemplarily, the operations performed by the acquisition unit 2010 and processing unit 2020 can be performed by a single processor, or by different processors. In specific implementation, the one or more processors can be processors disposed in the vehicle 100 shown in FIG1; or, the device 2000 can be a chip disposed in the vehicle 100.

[0201] In the specific implementation process, the units in the above device can be fully or partially integrated together, or they can be implemented independently. In one implementation, these units are integrated together and implemented in the form of a system-on-a-chip (SoC).

[0202] Figure 15 is another schematic block diagram of the apparatus provided in an embodiment of this application. The apparatus 2100 shown in Figure 15 may include a processor 2110, a transceiver 2120, and a memory 2130. The processor 2110, transceiver 2120, and memory 2130 are connected via internal interconnection paths. The memory 2130 is used to store instructions, and the processor 2110 is used to execute the instructions stored in the memory 2130 to implement the methods in the above embodiments. Optionally, the memory 2130 may be coupled to the processor 2110 via an interface or integrated with the processor 2110.

[0203] It should be noted that the transceiver 2120 mentioned above may include, but is not limited to, transceiver devices such as input / output interfaces, to realize communication between device 2100 and other devices or communication networks.

[0204] Memory 2130 can be volatile memory and / or non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM includes various forms such as: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).

[0205] Transceiver 2120 uses transceiver devices, such as but not limited to transceivers, to enable communication between device 2100 and other devices or communication networks to receive / send data / information for implementing the methods in the above embodiments.

[0206] This application also provides an intelligent driving device, which includes the device 2000 or device 2100 in the above embodiments.

[0207] This application also provides a computer program product, which includes computer program code. When the computer program code is run on a computer, it causes the computer to implement the methods described in the above embodiments of this application.

[0208] This application also provides a computer-readable storage medium storing computer instructions that, when executed on a computer, cause the computer to implement the methods described in the above embodiments of this application.

[0209] This application also provides a chip, including circuitry, for performing the methods described in the above embodiments of this application.

[0210] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0211] In the description of the embodiments of this application, unless otherwise stated, " / " means "or", for example, A / B can mean A or B; "and / or" in this document describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. In this application, "at least one" means one or more, and "more" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or multiple items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.

[0212] The use of prefixes such as "first" and "second" in this application embodiment is solely for distinguishing different descriptive objects and does not limit the position, order, priority, quantity, or content of the described objects. The use of ordinal numbers and other prefixes to distinguish descriptive objects in this application embodiment does not constitute a limitation on the described objects. The description of the described objects is found in the claims or the context of the embodiments, and the use of such prefixes should not constitute unnecessary restrictions.

[0213] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0214] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions between the various embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0215] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0216] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0217] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A data access method, characterized in that, include: Obtain information about a first user account, which is one of multiple user accounts. Each of the multiple user accounts is associated with a sub-data storage area, and the multiple sub-data storage areas associated with the multiple user accounts belong to the same user space. Obtain the first access request of the first application under the first user account, wherein the first access request is used to request the storage of the first data; Based on the first access request, the first data is stored in the first sub-data storage area corresponding to the first user account, and the plurality of sub-data storage areas include the first sub-data storage area.

2. The method according to claim 1, characterized in that, The plurality of user accounts also includes a second user account, which is associated with a second sub-data storage area within the plurality of sub-data storage areas. The method further includes: Obtain the second access request of the second application of the second user account; When the second access request is used to request the reading of the first data, the second access request is rejected.

3. The method according to claim 1 or 2, characterized in that, The method further includes: Obtain a third access request from a third application under the first user account, wherein the third application is an application that does not need to go through the first sub-data storage area when storing data; When the third access request is made to request to read the first data, the third access request is rejected.

4. The method according to claim 3, characterized in that, The method further includes: Obtain the fourth access request of the first application, the fourth access request being used to request to read the second data, the second data being the data stored by the third application; The second data is read according to the fourth access request.

5. The method according to claim 4, characterized in that, The second data is stored in a public storage area. Reading the second data according to the fourth access request includes: When the first user account is authorized to access the public storage area, the second data is read according to the fourth access request.

6. The method according to any one of claims 3 to 5, characterized in that, The third application is a second type of application, which is an application that does not require data isolation.

7. The method according to any one of claims 1 to 6, characterized in that, The method further includes: Obtain the fifth access request of the fourth application under the first user account, the fifth access request being used to request to read the first data; When the fourth application is an application that needs to access the first sub-data storage area to store data, the first data is read according to the fifth access request.

8. The method according to any one of claims 1 to 7, characterized in that, The first application is a first-category application, which is an application that requires data isolation.

9. A data access device, characterized in that, include: The acquisition unit is used to acquire information about a first user account, which is one of a plurality of user accounts. Each of the plurality of user accounts is associated with a sub-data storage area, and the plurality of sub-data storage areas associated with the plurality of user accounts belong to the same user space. The acquisition unit is further configured to: acquire a first access request of a first application under a first user account, wherein the first access request is used to request storage of first data; The processing unit is configured to store the first data in a first sub-data storage area corresponding to the first user account according to the first access request, wherein the plurality of sub-data storage areas include the first sub-data storage area.

10. The apparatus according to claim 9, characterized in that, The plurality of user accounts also includes a second user account, which is associated with a second sub-data storage area in the plurality of sub-data storage areas. The acquisition unit is further configured to: Obtain the second access request of the second application of the second user account; The processing unit is also used for: When the second access request is used to request the reading of the first data, the second access request is rejected.

11. The apparatus according to claim 9 or 10, characterized in that, The acquisition unit is also used for: Obtain a third access request from a third application under the first user account, wherein the third application is an application that does not need to go through the first sub-data storage area when storing data; The processing unit is also used for: When the third access request is made to request to read the first data, the third access request is rejected.

12. The apparatus according to claim 11, characterized in that, The acquisition unit is also used for: Obtain the fourth access request of the first application, the fourth access request being used to request to read the second data, the second data being the data stored by the third application; The processing unit is also used for: The second data is read according to the fourth access request.

13. The apparatus according to claim 12, characterized in that, The second data is stored in a common storage area, and the processing unit is used for: When the first user account is authorized to access the public storage area, the second data is read according to the fourth access request.

14. The apparatus according to any one of claims 11 to 13, characterized in that, The third application is a second type of application, which is an application that does not require data isolation.

15. The apparatus according to any one of claims 9 to 14, characterized in that, The acquisition unit is also used for: Obtain the fifth access request of the fourth application under the first user account, the fifth access request being used to request to read the first data; The processing unit is also used for: When the fourth application is an application that needs to access the first sub-data storage area to store data, the first data is read according to the fifth access request.

16. The apparatus according to any one of claims 9 to 15, characterized in that, The first application is a first-category application, which is an application that requires data isolation.

17. A data access device, characterized in that, include: A processor for executing a computer program stored in memory to cause the apparatus to perform the method as described in any one of claims 1 to 8.

18. The apparatus according to claim 17, characterized in that, The device also includes the memory.

19. A computer-readable storage medium, characterized in that, It stores instructions that, when executed by a processor, implement the method as described in any one of claims 1 to 8.

20. A chip, characterized in that, The chip includes circuitry for performing the method as described in any one of claims 1 to 8.

21. A computer program product, characterized in that, The computer program product includes: computer program code, which, when executed by a processor, implements the method as described in any one of claims 1 to 8.

22. A vehicle, characterized in that, Includes the apparatus as described in any one of claims 9 to 18, or the computer-readable storage medium as described in claim 19, or the chip as described in claim 20, or the vehicle is equipped with the computer program product as described in claim 21.

Citation Information

Patent Citations

  • A data management method for an in-vehicle driving recorder and its in-vehicle unit

    CN114936360A

  • In-vehicle infotainment device application configuration method, in-vehicle infotainment device one-key connection application method and in-vehicle infotainment device system

    CN115700473A

  • Data processing method and device, equipment and storage medium

    CN116644467A

  • Application account management method and related device

    CN117951663A

  • Method and system for isolating application data access

    US20190005260A1