Sensor Device Anonymization Unit for Real-Time Data Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing sensor devices fail to effectively anonymize sensitive data, such as faces, vehicle ID plates, and house numbers, in real-time before storage, especially in scenarios where data privacy is compromised due to the interlinking of vehicles and traffic infrastructure, and there is a risk of data exposure during transmission or storage.
Innovation Solution
A sensor device equipped with an anonymization unit that includes an analysis module to identify sensitive data using predefined privacy criteria and a replacement module to anonymize it by replacing sensitive information with masking data, ensuring that sensitive data is not stored in non-volatile memory, and utilizing encryption for added security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sensor data is stored in non-volatile memory for later processing, then data availability is improved, but data privacy is compromised due to potential exposure of sensitive information
Solution Approach 1:
The patent applies preliminary action by performing anonymization processing before data is stored in non-volatile memory. The anonymization unit identifies and masks sensitive information (faces, license plates, house numbers) in the sensor data stream before it reaches the storage medium, ensuring that even if power is lost or the system fails, the stored data remains privacy-protected. This pre-processing step eliminates the need to store sensitive raw data while maintaining data availability for legitimate purposes.
2Device complexity
If data is anonymized after transmission to a server, then processing simplicity is improved, but security is worsened due to exposure during transmission
Solution Approach 1:
The patent implements preliminary action by performing anonymization at the source (in the sensor device itself) before any data transmission occurs. The anonymization unit processes the sensor data stream in real-time and masks sensitive information before the anonymized data is stored or transmitted to external servers. This approach maintains processing simplicity while significantly improving security by eliminating the exposure risk during transmission, as sensitive data never leaves the vehicle in its identifiable form.
3Object-affected harmful factors
If real-time anonymization is implemented, then data privacy is improved, but processing time is worsened
Solution Approach 1:
The patent applies mechanics substitution by replacing complex, time-consuming manual or batch processing methods with automated real-time processing. The anonymization unit continuously analyzes the sensor data stream using predefined privacy criteria and automatically masks sensitive information as data flows through the system. This automated real-time approach maintains high processing speeds while ensuring continuous privacy protection, avoiding the time delays associated with post-processing or batch anonymization.
4Object-affected harmful factors
If sensitive data is masked in real-time, then privacy criterion compliance is improved, but data utility is worsened due to loss of information
Solution Approach 1:
The patent applies local quality by selectively applying masking only to specific sensitive regions within the sensor data stream, rather than obscuring entire images or data sets. The anonymization unit identifies precise locations of sensitive information (such as faces, license plates, or house numbers) and applies privacy criteria only to those localized regions. This approach maintains compliance with privacy requirements while preserving the utility of the surrounding non-sensitive data, allowing legitimate analysis and processing of the majority of the sensor data to continue.
Data Source
Figure 1
Figure 2
AI summary
The invention is concerned with a sensor device (10) comprising a sensor (12) and an anonymization unit (19), wherein the sensor (12) is designed to generate a sensor data stream (13) and wherein the sensor (12) is coupled to the anonymization unit (19) by a data path (20,21) which contains no digital memory or only a volatile memory (22). The anonymization unit (19) comprises, an analyzation module (23) for identifying pre-defined sensitive data (14,18) in the sensor data stream (13) by means of a pre-defined privacy criterion. The anonymization unit (19) further comprises a replacement module (24) for replacing the sensitive data (14,18) in the sensor data stream (13) with pre-defined masking data such that the sensor data is anonymized in the sensor data stream (13) before any storing in a non-volatile memory (25,26).