Motor Vehicle Data Anonymization via Server-Side Deletion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for transmitting data from motor vehicles to server backends do not adequately protect user-related data, leading to potential misuse and data safety concerns, as all data is transmitted and anonymized centrally, leaving room for identification.
Innovation Solution
A method where user-related data is deleted by a first server system after anonymization, and the anonymized dataset is communicated to a second server system, ensuring that user-related data is never present on the server system that provides the anonymized data, thus enhancing data safety by requiring unauthorized access to two separate systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If all user related data and non-user related data is communicated to the server backend for anonymization, then complete data is available for processing, but data transmission security deteriorates and user privacy is exposed
Solution Approach 1:
The patent extracts and removes user-related data (communication data, position data, time stamps, vehicle identification data) from the dataset before transmission to the server backend. Only the anonymized portion of the dataset is communicated, eliminating the security risk of transmitting sensitive user information while preserving necessary non-user related data for processing.
Solution Approach 2:
The anonymization process is performed in advance at the vehicle computing unit before data transmission. By preprocessing the data to remove user-related information upfront, the system ensures that sensitive data never enters the transmission channel or reaches the server backend, thus preventing potential security breaches while maintaining data utility.
2Ease of manufacture
If user related data is transmitted via air interface for anonymization, then anonymization can be performed, but data safety and data protection compliance deteriorate
Solution Approach 1:
User-related data elements are extracted and removed from the dataset at the vehicle computing unit before transmission. This ensures that only anonymized data is communicated via the air interface to the server backend, eliminating the risk of exposing sensitive information during wireless transmission while maintaining the ability to perform necessary anonymization operations.
Solution Approach 2:
The vehicle computing unit acts as an intermediary that processes and anonymizes data locally before transmission. This intermediary function ensures that user-related data is filtered out at the source, preventing its exposure during air interface transmission while still enabling the server backend to receive and process the necessary anonymized dataset.
3Reliability
If user related data is removed from the dataset before transmission, then data safety is improved, but data processing flexibility deteriorates
Solution Approach 1:
The patent selectively extracts only the necessary user-related data elements (communication data, position data, time stamps, vehicle identification data) that are required for anonymization, while preserving all other non-user related data in the dataset. This selective removal maintains data safety while retaining sufficient information for various processing applications.
Solution Approach 2:
The system changes the parameter state of the dataset by removing specific user-related attributes while maintaining the overall data structure and non-user related information. This parameter modification approach ensures data safety through anonymization while preserving the dataset's versatility for different processing purposes such as weather mapping, traffic flow analysis, and danger spot identification.
Data Source
AI summary
Technologies and techniques for anonymously providing data of a motor vehicle. A first dataset is generated by a motor vehicle, and the first dataset is anonymized using a vehicle computing unit. User related data and the anonymized first dataset are communicated to a first server system using the vehicle computing unit and the communicated user related data is deleted using the first server system. The anonymized first dataset is communicated to a second server system using the first server system after deletion of the user related data.

