Autonomous Vehicle Trip Data Retention for User Privacy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Autonomous driving vehicles face challenges in protecting user privacy, as they may record sensitive information such as user names, addresses, credit card details, video, and audio recordings during trips, without adequate user control over data storage.

Innovation Solution

Implementing a system where users can select through a user interface which data items to store persistently and which to keep only in volatile memory, with optional encryption, based on their privacy preferences, allowing control over data retention during trips.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If the autonomous driving vehicle stores all trip data in persistent storage for future reference and analysis, then the data availability and service improvement are enhanced, but user privacy protection deteriorates due to sensitive information being stored long-term

Engineering Contradiction:
Improvedata availabilityVSAvoidprivacy risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent segments trip data into two distinct categories: persistent storage data (non-sensitive information like trip routes, timestamps, and aggregated statistics) and volatile storage data (sensitive information like video recordings, audio recordings, and real-time location data). This segmentation allows the system to maintain data availability for service improvement while protecting user privacy by limiting long-term storage of sensitive information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the storage duration parameter for different types of data. Sensitive data is stored only in volatile memory for the duration of the trip and immediately deleted afterward, while non-sensitive aggregated data is stored persistently for long-term analysis. This parameter change resolves the contradiction by adjusting data retention time based on data sensitivity rather than applying a uniform storage policy.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If the vehicle collects and stores comprehensive user information including names, addresses, and payment details for personalized service, then service quality and user experience are improved, but privacy protection worsens due to accumulation of sensitive personal data

Engineering Contradiction:
Improveservice personalizationVSAvoidprivacy exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive personal information (names, addresses, payment details) from the main data storage system and handles it separately through secure authentication protocols. Instead of storing these sensitive details in the vehicle's persistent storage, the system uses encrypted authentication credentials that verify user identity without retaining actual personal information. This extraction principle allows personalized service while minimizing privacy exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication system that mediates between the need for personalized service and privacy protection. Rather than directly storing and processing sensitive user information, the system uses encrypted authentication tokens and credentials as intermediaries to verify user identity and authorize services. This intermediary layer enables service personalization without exposing or storing actual sensitive personal data.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If video and audio recordings are stored during autonomous trips for safety and accountability purposes, then safety monitoring and incident investigation are enhanced, but privacy protection deteriorates due to continuous recording of user activities

Engineering Contradiction:
Improvesafety accountabilityVSAvoidsurveillance intrusion
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamic storage policies for video and audio recordings. Instead of continuous persistent storage, the system dynamically manages recording data in volatile memory, keeping it only for the duration of the trip and automatically deleting it afterward. The system can access recordings in real-time for safety monitoring and incident investigation, but the dynamic deletion policy ensures that surveillance data does not persist longer than necessary, reducing privacy intrusion while maintaining accountability.

Inventive Principle:
Principle #15Dynamics

4Productivity

If all trip data is retained in the vehicle's storage system for analysis and improvement, then service optimization and pattern recognition are improved, but device complexity increases due to data management and security requirements

Engineering Contradiction:
Improveservice optimizationVSAvoiddata management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the data management system into simple volatile storage operations (automatic deletion after trips) and selective persistent storage of only aggregated, anonymized statistics. This segmentation eliminates the need for complex data management systems that would be required to securely manage and delete individual user records, while still enabling service optimization through analysis of aggregated patterns. The segmentation principle reduces device complexity by simplifying the data retention policy.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10916077B2User privacy protection on autonomous driving vehicles
Publication Date: 2021.02.09 BAIDU USA LLC
  • US10916077B2 patent drawing
  • US10916077B2 patent drawing
  • US10916077B2 patent drawing

AI summary

In one embodiment, one or more first data items associated with a planned trip of a user riding in an autonomous driving vehicle (ADV) are displayed on a display device within the ADV. Each of the first data items is associated with a user selectable option to indicate whether the user wishes or allows the ADV to store each of the first data items in a persistent storage device. User inputs are received via a user interface such as touch screen of the display device, including a first selection indicating that the user wishes to store a first subset of the first data items. In response to the first selection, the first subset of the data items is stored in the persistent storage device of the ADV.