Privacy Enforcement Module for Secure Vehicular Data Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of electronic communication systems in vehicles raises privacy concerns as operational data, including operator identification, is recorded and potentially shared with various entities, leading to reluctance in data dissemination due to privacy preferences.

Innovation Solution

A device with a communication module and a privacy enforcement module (PEM) secured in a trusted execution environment (TEE) filters operational data based on privacy settings, replacing or removing identifying information to generate filtered data for transmission, ensuring operator anonymity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If operational data including operator identification is recorded and freely disseminated to various entities, then societal benefits such as vehicle maintenance tracking and statistical analysis are improved, but operator privacy is compromised leading to reluctance in data sharing

Engineering Contradiction:
Improvedata dissemination valueVSAvoidprivacy concern
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and removes identifying information from operational data through a privacy enforcement module. The system separates personal identifiers from vehicular operational data, allowing valuable operational information to be shared while extracting and protecting the harmful identifying elements that cause privacy concerns.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a privacy enforcement module as an intermediary between the vehicular control architecture and external entities. This mediator processes operational data to remove identifying information before dissemination, enabling data sharing while protecting operator privacy through an intermediate processing layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If identifying information is removed or replaced to protect operator anonymity, then privacy protection is improved, but data utility for identification purposes is reduced

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata utility
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent creates anonymized copies of operational data where identifying information is replaced with pseudonyms or removed entirely. These copied datasets maintain the operational utility for analysis and tracking while eliminating the ability to identify specific operators, preserving data utility without compromising privacy.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent changes the parameter of operator identification from specific personal identifiers to anonymized representations. By transforming the identification parameter from named entities to pseudonymous or aggregated forms, the system maintains data utility for statistical and operational analysis while protecting individual operator privacy.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3084676B1Secure vehicular data management with enhanced privacy
Publication Date: 2022.04.20 INTEL CORP
  • EP3084676B1 patent drawingFigure 1
  • EP3084676B1 patent drawingFigure 2
  • EP3084676B1 patent drawingFigure 3

AI summary

The present disclosure is directed to secure vehicular data management with enhanced privacy. A vehicle may comprise at least a vehicular control architecture (VCA) for controlling operation of the vehicle and a device. The VCA may record operational data identifying at least one vehicle operator and vehicular operational data recorded during operation of the vehicle by the at least one vehicle operator. The device may include at least a communication module and a trusted execution environment (TEE) including a privacy enforcement module (PEM). The PEM may receive the operational data from the VCA via the communication module, may generate filtered data by filtering the operational data based on privacy settings and may cause the filtered data to be transmitted via the communication module. The filtered data may be transmitted to at least one data consumer. The privacy settings may be configured in the PEM by the at least one operator.