Sensor Device Anonymization Unit for Real-Time Data Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing sensor devices fail to effectively anonymize sensitive data, such as faces, vehicle ID plates, and house numbers, in real-time before storage, especially in scenarios where data privacy is compromised due to the interlinking of vehicles and traffic infrastructure, and there is a risk of data exposure during transmission or storage.

Innovation Solution

A sensor device equipped with an anonymization unit that includes an analysis module to identify sensitive data using predefined privacy criteria and a replacement module to anonymize it by replacing sensitive information with masking data, ensuring that sensitive data is not stored in non-volatile memory, and utilizing encryption for added security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sensor data is stored in non-volatile memory for later processing, then data availability is improved, but data privacy is compromised due to potential exposure of sensitive information

Engineering Contradiction:
Improvedata availabilityVSAvoiddata privacy exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing anonymization processing before data is stored in non-volatile memory. The anonymization unit identifies and masks sensitive information (faces, license plates, house numbers) in the sensor data stream before it reaches the storage medium, ensuring that even if power is lost or the system fails, the stored data remains privacy-protected. This pre-processing step eliminates the need to store sensitive raw data while maintaining data availability for legitimate purposes.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If data is anonymized after transmission to a server, then processing simplicity is improved, but security is worsened due to exposure during transmission

Engineering Contradiction:
Improveprocessing simplicityVSAvoiddata security during transmission
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by performing anonymization at the source (in the sensor device itself) before any data transmission occurs. The anonymization unit processes the sensor data stream in real-time and masks sensitive information before the anonymized data is stored or transmitted to external servers. This approach maintains processing simplicity while significantly improving security by eliminating the exposure risk during transmission, as sensitive data never leaves the vehicle in its identifiable form.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If real-time anonymization is implemented, then data privacy is improved, but processing time is worsened

Engineering Contradiction:
Improvedata privacy protectionVSAvoidprocessing time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent applies mechanics substitution by replacing complex, time-consuming manual or batch processing methods with automated real-time processing. The anonymization unit continuously analyzes the sensor data stream using predefined privacy criteria and automatically masks sensitive information as data flows through the system. This automated real-time approach maintains high processing speeds while ensuring continuous privacy protection, avoiding the time delays associated with post-processing or batch anonymization.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Object-affected harmful factors

If sensitive data is masked in real-time, then privacy criterion compliance is improved, but data utility is worsened due to loss of information

Engineering Contradiction:
Improveprivacy criterion complianceVSAvoiddata utility
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent applies local quality by selectively applying masking only to specific sensitive regions within the sensor data stream, rather than obscuring entire images or data sets. The anonymization unit identifies precise locations of sensitive information (such as faces, license plates, or house numbers) and applies privacy criteria only to those localized regions. This approach maintains compliance with privacy requirements while preserving the utility of the surrounding non-sensitive data, allowing legitimate analysis and processing of the majority of the sensor data to continue.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3594842B1A sensor device for the anonymization of the sensor data and an image monitoring device and a method for operating a sensor device for the anonymization of the sensor data
Publication Date: 2021.04.07 ARGO AI GMBH
  • EP3594842B1 patent drawingFigure 1
  • EP3594842B1 patent drawingFigure 2

AI summary

The invention is concerned with a sensor device (10) comprising a sensor (12) and an anonymization unit (19), wherein the sensor (12) is designed to generate a sensor data stream (13) and wherein the sensor (12) is coupled to the anonymization unit (19) by a data path (20,21) which contains no digital memory or only a volatile memory (22). The anonymization unit (19) comprises, an analyzation module (23) for identifying pre-defined sensitive data (14,18) in the sensor data stream (13) by means of a pre-defined privacy criterion. The anonymization unit (19) further comprises a replacement module (24) for replacing the sensitive data (14,18) in the sensor data stream (13) with pre-defined masking data such that the sensor data is anonymized in the sensor data stream (13) before any storing in a non-volatile memory (25,26).