Vehicle Data Anonymization for PII-Safe Simulation Files

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for autonomous vehicles lack robust testing and validation frameworks to handle the complex and sensitive data, i.e., PII (Personally Identifiable Information) is not available for the MDC server, which is not accessible by users that have special authorization, and OpenScene files are not able to be created based on the data that includes PII.

Innovation Solution

A method for anonymizing data in a database on a server includes storing data from a vehicle, removing the vehicle identification number, and changing specific parameters to create anonymized data, enabling the creation of simulation files without access to sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If data including PII is stored in the MDC database for simulation file creation, then data completeness is improved, but data security and access control deteriorate

Engineering Contradiction:
Improvedata completenessVSAvoiddata security risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and removes PII fields (vehicle identification number, timestamp information) from the collected data before storing it in the MDC database. This extraction process separates sensitive information from useful simulation data, allowing complete data retention for simulation purposes while eliminating security risks associated with PII storage and access.

Inventive Principle:
Principle #2Taking out (Extraction)

2Object-affected harmful factors

If special authorization is required to access sensitive data, then data security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiddata access convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent creates anonymized copies of the original data by removing PII while preserving the structural and functional characteristics needed for simulation. These anonymized copies can be freely accessed by users without special authorization, eliminating access restrictions while maintaining data security through the unavailability of personally identifiable information.

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If PII is removed from the database, then data privacy is improved, but data utility for simulation deteriorates

Engineering Contradiction:
Improvedata privacyVSAvoidsimulation data utility
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent applies local quality by selectively removing only the specific PII fields (vehicle identification number, timestamp) while preserving all other data characteristics such as sensor readings, environmental conditions, and driving patterns. This targeted approach maintains data privacy by eliminating identifiable information while preserving the local qualities and features necessary for effective simulation and validation.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250298922A1Anonymizing data in database on a server
Publication Date: 2025.09.25 TOYOTA JIDOSHA KK
  • US20250298922A1 patent drawing
  • US20250298922A1 patent drawing
  • US20250298922A1 patent drawing

AI summary

A method, device, and non-transitory computer-readable media for anonymizing data in a database on a server. Data obtained from a vehicle is stored in a database of a server. A vehicle identification number is removed from the data in the database. At least one specific parameter included in the data in the database is changed to create anonymized data. Access to the anonymized data is provide to the user. One or more files for a simulation are created using the anonymized data.