Vehicle Sensor Data Anonymization via Traffic Density Probability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anonymization methods for vehicle sensor data transmission do not effectively assess the probability of successful anonymization, as they focus on anonymization measures rather than their effects, leading to uncertainty about the environment's impact on data privacy.

Innovation Solution

A method that determines sensor data anonymization probability by calculating the likelihood of other vehicles generating the data based on traffic density and location, using statistical methods like Poisson distribution, and randomly generating anonymized time and location within predetermined intervals, ensuring that sensor data can only be transmitted if the probability meets a predetermined condition, thereby preventing unambiguous assignment to a specific vehicle.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anonymization measures are applied to sensor data, then data privacy is improved, but the ability to assess anonymization effectiveness deteriorates

Engineering Contradiction:
Improvedata privacyVSAvoidanonymization effectiveness assessment
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces traffic density and environmental context as intermediary elements that enable assessment of anonymization effectiveness without compromising data privacy. By using these intermediaries to calculate probability values, the system can evaluate whether anonymization succeeded without revealing information about the original data source or specific vehicles.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If sensor data is transmitted with precise time and location information, then data utility is improved, but the risk of identifying the source vehicle increases

Engineering Contradiction:
Improvedata utilityVSAvoidanonymization security
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent applies preliminary action by calculating the anonymization probability before data transmission occurs. The system evaluates traffic density and environmental factors in advance to determine whether anonymization conditions are met, and only transmits data when the probability indicates successful anonymization, thus preventing identification risks before they can materialize.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes parameters by introducing probability thresholds and traffic density metrics as dynamic criteria for data transmission. Instead of always transmitting or never transmitting, the system adjusts transmission decisions based on calculated probability values that reflect current environmental conditions, balancing data utility with anonymization security.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If anonymization probability calculation is performed, then anonymization effectiveness is improved, but computational complexity increases

Engineering Contradiction:
Improveanonymization effectivenessVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs cheap short-living objects by using readily available traffic density data and environmental information that can be obtained through standard sensors and communication channels. These inexpensive, easily accessible data sources enable probability calculation without requiring complex or expensive computational resources, making the solution practical for real-world deployment.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12028704B2Method for the anonymized transmission of sensor data of a vehicle to a vehicle-external receiving unit, anonymizing system, motor vehicle, and vehicle-external receiving unit
Publication Date: 2024.07.02 AUDI AG
  • US12028704B2 patent drawing
  • US12028704B2 patent drawing
  • US12028704B2 patent drawing

AI summary

The present disclosure invention relates to a method for the anonymized transmission of sensor data of a vehicle to a vehicle-external receiving unit, to an anonymizing system, and to a receiving unit, the method including the following steps: determining the sensor data at a measurement location at a measurement time, determining a traffic density in an environment of the measurement location, determining an anonymized time and/or an anonymized location, calculating an anonymization probability of the vehicle, which results from the traffic density and the anonymized time and/or location, determining whether the anonymization probability meets a predetermined anonymization condition, and if the anonymization condition is met, transmitting the sensor data to the external receiving unit, the anonymized time being indicated as a measurement time indication and/or the anonymized location being indicated as a measurement location indication.