Networked Lighting Control Privacy Protection via Data Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Networked Lighting Control Systems (NLCS) face privacy concerns as they collect and store sensitive data, such as occupancy and location information, which can infringe on users' privacy rights and lead to legal issues, necessitating a solution to protect user privacy while maintaining system functionality.
Innovation Solution
Implementing user-controlled data aggregation and storage options, allowing users to choose how their data is processed, including de-identification and restricted use, to ensure privacy while allowing operational data to be used for Total Light Management purposes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If NLCS collects and stores occupancy and location data to enable Total Light Management, then system functionality and energy savings are improved, but user privacy is compromised and legal compliance is violated
Solution Approach 1:
The patent segments data processing into distinct categories (operational data vs. personally identifiable data) and applies different handling rules to each. Operational data is collected and stored for light management, while PII is either excluded, de-identified, or separately managed with user consent. This segmentation allows the system to maintain functionality while protecting privacy.
Solution Approach 2:
The patent introduces de-identification and anonymization techniques as intermediary processes between data collection and data usage. These intermediaries transform personally identifiable data into aggregated or pseudonymous data that retains analytical value while removing direct individual identification, thus mediating between functionality and privacy protection.
2Object-affected harmful factors
If user privacy controls and data aggregation options are implemented, then privacy protection is improved, but system complexity increases
Solution Approach 1:
The patent implements preliminary user education and notification before data collection occurs. Users are informed about what data is collected, how it will be used, and their privacy options in advance. This preliminary action allows users to make informed decisions without requiring complex real-time interfaces, thereby protecting privacy while managing complexity through advance information provision.
Solution Approach 2:
The patent changes the parameter of data aggregation from fixed to flexible by allowing users to select their preferred level of data collection (e.g., aggregated vs. individual-level data). This parameter change enables the system to adapt its data handling based on user preferences, protecting privacy without imposing a single complex configuration on all users.
3Loss of energy
If operational data is used for light management purposes, then energy efficiency is improved, but data security risks increase
Solution Approach 1:
The patent extracts and separates personally identifiable information from operational data used for light management. By taking out PII from the operational datasets, the system maintains energy efficiency through continued use of operational data while eliminating the security risks associated with storing and protecting sensitive user information.
Solution Approach 2:
The patent creates copies or aggregates of operational data that do not directly identify individuals. Aggregated datasets serve as copies that retain the analytical value needed for energy management while removing direct links to individual users, thus reducing security risks while maintaining functionality.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
A method and corresponding system is disclosed for use in a Networked Lighting Control System whereby an individual can determine various privacy settings for data collected that relates to an area in which he/she is being monitored. These various settings include selecting by the individual what specific types of data can be/ cannot be collected; whether he/she can be linked to the collected data; and limiting the purpose for which the data can be used.