A method and system for protecting location privacy in the Internet of Vehicles
By using the PageRank algorithm to calculate the sensitive attribute values of position points and distribute differential privacy budgets in the Internet of Vehicles, the problem of low execution efficiency and low security of the Internet of Vehicles location privacy protection algorithm is solved, and efficient privacy protection and data utilization are achieved.
Patent Information
- Application Number
- CN202110110926.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-01-26
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2041-01-26
AI Technical Summary
The existing Internet of Vehicle Location Privacy Protection Algorithm has low execution efficiency, low security and poor data availability.
The PageRank algorithm is used to calculate the sensitive attribute values of the position points on the trajectory, and the privacy budget is allocated based on the sensitive attribute values, and the user's position points are protected through differential privacy budgets and Laplace noise mechanisms.
Improves privacy protection efficiency, ensures location privacy security, and improves data utilization.
Smart Images

Figure CN112861173B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet of Vehicles (IoV) security, and particularly to a method and system for protecting location privacy in the Internet of Vehicles. Background Art
[0002] The Internet of Vehicles is a large network that realizes wireless communication and information exchange between vehicles - X (X: vehicles, roads, pedestrians, Internet, etc.) according to specific communication protocols, and is also an integrated network that can realize intelligent transportation and dynamic information services. The early services for the Internet of Vehicles mainly focused on safe driving and intelligent transportation. With the development of the Internet of Vehicles and cloud computing, more and more security problems in the Internet of Vehicles have emerged. The increasing Location - Based Services (LBS) applications in the Internet of Vehicles have collected a large amount of trajectory data of vehicle users while facilitating the lives of users. These trajectory data may expose privacy information such as users' hobbies, social relationships, and physical conditions to attackers, thus posing a serious threat to users' lives. For example, through the analysis of a certain trajectory, attackers may, based on the background knowledge they possess, analyze the home addresses, workplaces of Internet of Vehicles users, and even analyze private information such as users' behavior patterns. Therefore, location privacy protection has become a common concern for Internet of Vehicles users and researchers, and existing location privacy protection algorithms for the Internet of Vehicles still face problems such as low execution efficiency, low security, and poor data availability. Summary of the Invention
[0003] The purpose of the present invention is to provide a method and system for protecting location privacy in the Internet of Vehicles to solve the problems of low execution efficiency, low security, and poor data availability of existing location privacy protection algorithms for the Internet of Vehicles.
[0004] To achieve the above object, the present invention provides the following solutions:
[0005] A method for protecting location privacy in the Internet of Vehicles, comprising:
[0006] Predicting all user location points in the Internet of Vehicles using sequence location point background knowledge to generate a location point directed graph;
[0007] Based on the location point directed graph, calculating the sensitive attribute value of each user location point using the PageRank algorithm;
[0008] Dividing all user location points according to the sensitive attribute value to determine multiple regions;
[0009] Obtain the vehicle inflow and outflow conditions in each of the regions, and calculate the structure coefficient of each region according to the vehicle inflow and outflow conditions; the structure coefficient is the influence of the region on the importance of the user location point;
[0010] Calculate the sensitivity of each user location point according to the sensitive attribute value and the structure coefficient;
[0011] Allocate differential privacy budgets for the sensitivities to determine the differential privacy budget of each region;
[0012] Based on the differential privacy budget of each region, use the Laplace mechanism to add Laplace noise to the user location points, and use the user location points after adding Laplace noise to replace the original user location points.
[0013] Optionally, calculating the sensitive attribute value of each user location point by using the PageRank algorithm based on the location point digraph specifically includes:
[0014] Based on the location point digraph, use the formula to calculate the sensitive attribute value of each user location point; where, PR(L j , j , i , i , j , j , i , i ) is the sensitive attribute value of the i-th user location point L i ; N is the number of all user location points; M(L i ) is the set of locations with out-links of L i ; PR(L j ) is the sensitive attribute value of the j-th user location point L j ; Out(L j ) is the number of out-links of L j , and d is the probability of aiming at the location of the privacy protection vehicle node, and 1 - d is the probability of randomly jumping to other locations.
[0015] Optionally, dividing all the user location points according to the sensitive attribute values to determine multiple regions specifically includes:
[0016] Merge the user location points corresponding to the sensitive attribute values with a similarity less than the similarity threshold to determine multiple regions; each region has multiple user location points, and the similarity of the sensitive attribute values of the user location points within each region is less than the similarity threshold.
[0017] Optionally, obtaining the vehicle inflow and outflow conditions in each of the regions, and calculating the structure coefficient of each region according to the vehicle inflow and outflow conditions specifically includes:
[0018] The structure coefficient is:
[0019]
[0020]
[0021] Among them, is the sum of the internal degrees of any one of the said regions; is the sum of the external degrees of any one of the said regions; A nn is the total number of edges connecting region n and region n in the adjacency matrix, where n is the region serial number.
[0022] Optionally, calculating the sensitivity of each user location point according to the sensitive attribute value and the structure coefficient specifically includes:
[0023] According to the structure coefficient, use the formula to determine the structure coefficient vector; where I (n) is the structure coefficient vector;
[0024] According to the sensitivity attribute value and the structure coefficient vector, use the formula to calculate the sensitivity of each user location point; where P x is the sensitivity of each user location point, and x is the user location point.
[0025] Optionally, based on the differential privacy budget of each region, using the Laplace mechanism to add Laplace noise to the user location point, and using the user location point after adding Laplace noise to replace the original user location point, specifically includes:
[0026] Obtain the differential privacy budget of each region, use the Laplace mechanism to add Laplace noise with a radius of r and an angle of θ to the user location point, and generate a user location point after adding Laplace noise; the Laplace noise with a radius of r and an angle of θ satisfies the formula Among them, is the probability distribution function; ε is the differential privacy budget; x 0 is the actual user location point; π is 180°.
[0027] A vehicle networking location privacy protection system includes:
[0028] A location point directed graph generation module, configured to predict all user location points in the vehicle networking by using the sequence location point background knowledge, and generate a location point directed graph;
[0029] A sensitive attribute value calculation module, configured to calculate the sensitive attribute value of each user location point based on the location point directed graph by using the PageRank algorithm;
[0030] A region division module, configured to divide all user location points according to the sensitive attribute value to determine multiple regions;
[0031] A structure coefficient calculation module, configured to obtain the vehicle inflow and outflow conditions in each of the regions, and calculate the structure coefficient of each of the regions according to the vehicle inflow and outflow conditions; the structure coefficient is the influence of the region on the importance of the user location point;
[0032] A sensitivity calculation module, configured to calculate the sensitivity of each of the user location points according to the sensitive attribute value and the structure coefficient;
[0033] A differential privacy budget determination module, configured to perform differential privacy budget allocation on the sensitivity, and determine the differential privacy budget of each of the regions;
[0034] A Laplace noise addition module, configured to add Laplace noise to the user location points based on the differential privacy budget of each of the regions by using the Laplace mechanism, and use the user location points after adding Laplace noise to replace the original user location points.
[0035] Optionally, the sensitive attribute value calculation module specifically includes:
[0036] A sensitive attribute value calculation unit, configured to calculate the sensitive attribute value of each of the user location points based on the location point directed graph by using the formula where PR(L i ) is the sensitive attribute value of the i-th user location point L i ; N is the number of all user location points; M(L i ) is the set of locations with out-links of L i ; PR(L j ) is the sensitive attribute value of the j-th user location point L j ; Out(L j ) is the number of out-links of L j ; d is the probability of aiming at the location of the privacy protection vehicle node, and 1 - d is the probability of randomly jumping to other locations.
[0037] Optionally, the region division module specifically includes:
[0038] A region division unit, configured to merge the user location points corresponding to the sensitive attribute values with a similarity less than the similarity threshold, and determine multiple regions; each of the regions has multiple user location points, and the similarity of the sensitive attribute values of the user location points in each of the regions is less than the similarity threshold.
[0039] Optionally, the structure coefficient in the structure coefficient calculation module is:
[0040]
[0041]
[0042] Among them, is the sum of the internal degrees of any of the said regions; is the sum of the external degrees of any of the said regions; A nn is the total number of edges connecting region n and region n in the adjacency matrix, where n is the region number.
[0043] According to the specific embodiments provided by the present invention, the following technical effects are disclosed by the present invention: The present invention provides a method and system for protecting location privacy in a vehicle networking, which uses the PageRank algorithm to calculate the sensitive attribute values of location points on a trajectory, and then allocates privacy budgets based on the sensitive attribute values, solving the problem of low privacy protection efficiency of traditional location privacy protection methods. The present invention protects the entire user trajectory by adding noise to the user location points on the user trajectory to replace the original user location points, and based on the difference in sensitivity, allocates different privacy budget values and adds different intensities of noise, improving data utilization while protecting privacy information from being leaked. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention, and for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0045] Figure 1 is the flow chart of the method for protecting location privacy in a vehicle networking provided by the present invention;
[0046] Figure 2 is the graph of vehicle inflow and outflow of adjacent regions of the present invention;
[0047] Figure 3 is the structure diagram of the system for protecting location privacy in a vehicle networking provided by the present invention;
[0048] Figure 4 is the schematic diagram of the analysis of the algorithm execution efficiency of the present invention;
[0049] Figure 5 is the schematic diagram of the change of MAE when ε of the present invention changes;
[0050] Figure 6 is the schematic diagram of the analysis of the privacy protection effects of three algorithms of the present invention;
[0051] Figure 7 is the schematic diagram of the comparison of the probability distributions of r under different ε of the present invention;
[0052] Figure 8Cumulative probability distribution C under different ε of the present invention ε (r) Comparison schematic diagram Specific implementation manner
[0053] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0054] The purpose of the present invention is to provide a vehicle networking location privacy protection method and system, which improves the privacy protection efficiency and, while protecting the privacy information from being leaked, improves the data utilization rate.
[0055] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.
[0056] Figure 1 It is a flowchart of the vehicle networking location privacy protection method provided by the present invention, as Figure 1 shown. A vehicle networking location privacy protection method includes:
[0057] Step 101: Predict all user location points in the vehicle networking using the background knowledge of sequence location points to generate a location point directed graph; the background knowledge of sequence location points is that an attacker continuously collects the historical information of users using emerging technologies such as big data and social networks, and can obtain various types of data such as the location of users or non-location related to the location from more channels.
[0058] Step 102: Based on the location point directed graph, calculate the sensitive attribute value of each user location point using the PageRank algorithm.
[0059] PageRank is an algorithm for evaluating the quality of a certain page, and it can be considered as a probability representation. In the road network environment, it can be used to sort the importance of location points. Calculate the sensitive attribute value (PR value) of the location point based on the PageRank algorithm and sort according to the PR value. The PR value of the location point is calculated based on the PageRank algorithm based on the location point directed graph; the location point directed graph is composed of location points that can be inferred by the attacker to reach based on the background knowledge of sequence location points.
[0060] Therefore, if a location has a high sensitive attribute value adjacent to it, then this location is more sensitive. The specific content of step 102 includes: based on the location point directed graph, using the formula Calculate the sensitive attribute value of each of the user location points; where, PR(L i ) is the sensitive attribute value of the i-th user location point L i ; N is the number of all user location points; M(L i ) is the set of locations with out-links for L i ; PR(L j ) is the sensitive attribute value of the j-th user location point L j ; Out(L j ) is the number of out-links of L j ; d is the probability of aiming at the location of the privacy protection vehicle node, and 1 - d is the probability of randomly jumping to other locations.
[0061] Step 103: Divide all the user location points according to the sensitive attribute values to determine multiple regions.
[0062] Based on the PR value of each location point, merge the cells with similar PR values. Divide the road network of the vehicle networking user activity area into grids based on the background knowledge of the sequence location points. Based on the background knowledge of the sequence location points, the possible location points that the user may reach can be inferred, and then these location points form a directed graph; where, Figure 2 (a) is the graph of vehicle inflow and outflow between adjacent regions, and simplify Figure 2 (a) to Figure 2 (b), and then calculate the sensitivity of each location point, and merge the cells with similar sensitivities.
[0063] The specific steps of Step 103 include: merge the user location points corresponding to the sensitive attribute values with a similarity less than the similarity threshold to determine multiple regions; each of the regions has multiple user location points, and the similarity of the sensitive attribute values of the user location points within each region is less than the similarity threshold.
[0064] Step 104: Obtain the vehicle inflow and outflow conditions within each of the regions, and calculate the structure coefficient of each of the regions according to the vehicle inflow and outflow conditions; the structure coefficient is the influence of the region on the importance of the user location point. In a specific practical application, the structure coefficient is measured based on the location edge connection structure characteristics within a region and the number of connection edges of another region to reflect the influence of the region on the importance of the location point.
[0065] Define the adjacency matrix A.
[0066]
[0067]
[0068] Where, A ij represents the weight of the connection edge of the super location point, that is, Aij is the sum of the edge weights of all position point pairs connecting region i to region j, so A ij is the total number of connecting edges between two regions; T ij is the total number of connecting edges between region i and region j; when i = j, it is the same region; A nn is the total number of connecting edges between region n and region n in the adjacency matrix, where n is the region number.
[0069] Measure the influence of the importance of position points in a region based on the position connection structure characteristics within a region and the number of connecting edges in another region. If the number of internal connecting edges of a position point is large, the user tends to move within the region. If the number of connecting edges with other regions is large, the user tends to move to other regions. Therefore, the present invention regards the connection situation between the inside and outside of the region as the region structure coefficient. See the following formula for details:
[0070]
[0071]
[0072] Among them, is the sum of the degrees inside region C n ; is the sum of the degrees outside region C n . Simplify the above formula. Then, for the supernode aggregation adjacency matrix A, the simplified formula is:
[0073]
[0074]
[0075] Step 105: Calculate the sensitivity of each user position point according to the sensitive attribute value and the structure coefficient.
[0076] Normalize the value calculated based on the PageRank algorithm and then calculate it with the region structure coefficient vector to obtain the sensitivity of the position point.
[0077] Actually, it is the value obtained by summing each row of the adjacency matrix separately and then subtracting the internal degree. Its meaning is the total number of external edges connecting all regions C n . Calculate the internal degree and external degree of region C n respectively, and calculate the region structure coefficient vector I = ( (1) , I (2) , …, I (n) ) T , where each component I (n) is the region structure coefficient of each region C n ; T is the transpose matrix.
[0078]
[0079] Since the vector I is calculated from the number of internal and external connecting edges of a region, I can represent the tightness of internal and external connections of a region, measure the flow of messages inside and outside the region, and thus measure the connectivity of a certain region. The internal and external connection conditions of the region will both affect the propagation ability of a region. Therefore, such a regional structure coefficient can measure the status of a region in the map.
[0080] Normalize the PageRank value of each location point and calculate the sensitivity of the location point:
[0081]
[0082] where P x represents the sensitivity of the location point.
[0083] Step 106: Allocate the differential privacy budget for the sensitivity and determine the differential privacy budget for each region.
[0084] The differential privacy budget ε represents the strength of privacy protection. The smaller the value of ε, the more noise is added, the higher the degree of privacy protection, and the lower the data utilization rate. Based on the sensitivity of the location point and combined with the total privacy budget, the differential privacy budget for each location point is obtained.
[0085] When ε approaches 0, the results output by the query function on the two data sets are basically the same, and no location information of the data set will be leaked at this time. The privacy budget ε is a data volume used to represent the privacy protection level or degree based on the differential privacy model. The ε settings for each location point are different, and the smaller the ε is set for regions with greater sensitivity.
[0086] Calculate the differential privacy budget parameter ε i .
[0087]
[0088] where ε is the total privacy budget; ε i is the privacy budget for region i.
[0089] Step 107: Based on the differential privacy budget of each region, use the Laplace mechanism to add Laplace noise to the user location point, and use the user location point after adding Laplace noise to replace the original user location point.
[0090] Based on the privacy protection budget ε and the actual user location point x 0, calculate the probability function of the noise to be added for location differential privacy, and obtain that the location x after adding the noise satisfies ε-location differential privacy protection; convert the probability distribution function into a polar coordinate function, and then add random noise to the polar coordinate function to achieve the purpose of location differential privacy protection.
[0091] is the probability function of the noise to be added to satisfy location differential privacy. Given the privacy protection budget ε and the actual location x 0 , if the location x after adding the noise satisfies the probability distribution function, then it satisfies ε-location differential privacy protection.
[0092] The probability distribution function is
[0093] From the probability distribution function, it can be seen that when d(x 0 , x)>0, the probability of x decreases as the distance from x to x 0 increases, and the probability distribution is only related to the distance from x to x 0 . To simplify the implementation, convert this function into a polar coordinate function as shown below:
[0094]
[0095] Among them, is the distribution function of x in polar coordinates, r represents the distance from x to x 0 , θ is the angle between x and the polar axis in polar coordinates. For the convenience of solving, decompose into the radius r and the angle θ to get:
[0096]
[0097]
[0098] According to the decomposed formula, random noise with a radius of r and an angle of θ can be added to x 0 = (s, t) to generate x' 0 = (s + r cosθ, t + r sinθ) to achieve the purpose of location differential privacy protection.
[0099] Integrating over [0, +∞) can obtain the cumulative probability distribution C ε (r) of the distance r, and then obtain Z is a random number uniformly distributed on [0, 1].
[0100]
[0101] Among them, θ is a random number between [0, 2π).
[0102] Figure 3 The structure diagram of the vehicle networking location privacy protection system provided by the present invention is as follows. Figure 3 As shown, a vehicle networking location privacy protection system includes:
[0103] A location point directed graph generation module 301, configured to predict all user location points in the vehicle networking by using sequence location point background knowledge, and generate a location point directed graph; the sequence location point background knowledge means that an attacker continuously collects historical information of users by using emerging technologies such as big data and social networks, and can obtain various types of data such as the location of users or non-location data related to the location from more channels.
[0104] A sensitive attribute value calculation module 302, configured to calculate the sensitive attribute value of each user location point based on the location point directed graph by using the PageRank algorithm.
[0105] The sensitive attribute value calculation module 302 specifically includes:
[0106] A sensitive attribute value calculation unit, configured to calculate the sensitive attribute value of each user location point based on the location point directed graph by using the formula ; where PR(L i ) is the sensitive attribute value of the i-th user location point L i ; N is the number of all user location points; M(L i ) is the set of locations with out-links of L i ; PR(L j ) is the sensitive attribute value of the j-th user location point L j ; Out(L j ) is the number of out-links of L j ; d is the probability of aiming at the location of the privacy protection vehicle node, and 1 - d is the probability of randomly jumping to other locations.
[0107] A region division module 303, configured to divide all user location points according to the sensitive attribute values to determine multiple regions.
[0108] The region division module 303 specifically includes:
[0109] A region division unit, configured to merge user location points corresponding to sensitive attribute values with a similarity less than the similarity threshold to determine multiple regions; each region has multiple user location points, and the similarity of the sensitive attribute values of the user location points within each region is less than the similarity threshold.
[0110] A structure coefficient calculation module 304, configured to obtain the inflow and outflow conditions of vehicles within each region, and calculate the structure coefficient of each region according to the inflow and outflow conditions of vehicles; the structure coefficient is the influence of the region on the importance of user location points.
[0111] The structure coefficient in the structure coefficient calculation module 304 is as follows:
[0112]
[0113]
[0114] Wherein, is the sum of the internal degrees of any one of the said regions; is the sum of the external degrees of any one of the said regions; A nn is the total number of connecting edges between region n and region n in the adjacency matrix, and n is the region serial number.
[0115] The sensitivity calculation module 305 is used to calculate the sensitivity of each user location point according to the sensitive attribute value and the structure coefficient.
[0116] The differential privacy budget determination module 306 is used to allocate the differential privacy budget for the sensitivity and determine the differential privacy budget of each region.
[0117] The differential privacy budget determination module 306 specifically includes: a location sensitivity determination unit, which is used to calculate the location sensitivity by using the above-mentioned sensitive attribute value calculation module 302 and structure coefficient calculation module 304; a differential privacy budget allocation unit, which is used to allocate different differential privacy budget parameters for each location based on the total privacy budget and the location sensitivity, which can better protect the user location privacy, which can better protect the user location privacy.
[0118] The Laplace noise addition module 307 is used to add Laplace noise to the user location points based on the differential privacy budget of each region by using the Laplace mechanism, and use the user location points after adding Laplace noise to replace the original user location points.
[0119] The Laplace noise addition module 307 specifically includes: a Laplace noise generation unit, which is used to generate noise based on the given privacy protection budget and the actual location; a random noise generation unit, which is used to generate random noise based on the Laplace noise, and replace the original location point with the noisy location point to complete the location privacy protection of the vehicle networking, to complete the location privacy protection of the vehicle networking.
[0120] The superiority of the performance of the present invention can be further illustrated by the following simulation experiments:
[0121] To verify the location privacy security and location data availability of the method proposed in the present invention, the experimental design is divided into two levels: horizontal and vertical. Horizontally, the method proposed in the present invention is compared with other methods, with the same environment and the same parameters set, and the performance and performance of the three methods in terms of execution efficiency, data availability and security are compared to verify their advantages and disadvantages. Vertically, different parameters are set to verify the method proposed in the present invention, and the performance of the method proposed in the present invention under different parameters and different environments is tested to find the best performance.
[0122] All the data sets for this experiment come from Microsoft Research Asia. The data sets used contain 17,621 paths, with a total travel distance of 1,293,951 kilometers and a time of 50,176 hours. Sampling is taken every 1 - 1.5 seconds or every 5 - 10 meters, and the algorithm is implemented using Python programming.
[0123] In the present invention, the execution efficiency mainly refers to the time required for privacy protection processing. We compared the PR-Diff algorithm with the CLM algorithm and the DPLRM algorithm.
[0124] Figure 4 It shows that when the data set increases continuously, the running time of the three algorithms on the data set also increases accordingly. This is because when K is very large, the geographical space traversed by the algorithm increases, and thus the required time also increases. The execution times of the PR-Diff algorithm and the DPLRM algorithm are much longer than that of the CLM algorithm. This is because this method adds different levels of noise parameters and performs different intensities of interference based on the different sensitivities of the location points on the trajectory, providing higher data availability, so the execution time of the algorithm is longer. The PR-Diff algorithm uses the PageRank algorithm to calculate the privacy budget parameters of the location, and the DPLRM method not only considers the privacy impact of the current published location on the current moment, but also considers the privacy impact of the current published location on the previously published locations. There are more limiting factors in the algorithm, so the running time of the PR-Diff algorithm is shorter than that of the DPLRM method.
[0125] In the present invention, data availability can be measured by the mean absolute error (MAE). The smaller the MAE, the higher the data availability. Evaluate the MAE in the PR-Diff algorithm, the CLM algorithm and the DPLRM algorithm, as Figure 5 shown.
[0126] The experimental results show that the PR-Diff algorithm outperforms the other two algorithms in terms of data availability. This is because the CLM method adds noise information of the same intensity to all position points on the trajectory, interferes with the entire trajectory to the same extent, and causes a large amount of information loss. Although the DPLRM method also adds different noises, it not only considers the privacy impact of the current published location on the current moment but also the privacy impact of the current published location on the previously published locations. There are more limiting factors in the algorithm, while the PR-Diff algorithm uses the PageRank algorithm to allocate the privacy budget. Under the same privacy protection intensity ε, a smaller noise can achieve the same privacy protection intensity. Therefore, PR-Diff has higher data availability.
[0127] In the present invention, the location privacy security mainly refers to the probability that the published trajectory data can be recognized by an attacker. From the characteristics of the differential privacy protection method, it can be seen that the actual size of the differential privacy budget ε directly reflects the level of privacy protection achieved; the smaller the value of ε, the more noise is added, the higher the privacy protection level achieved, and the better the security of the vehicle trajectory data.
[0128] In differential privacy, ε is a key parameter used to determine the privacy strength. Research shows that when ε = 1 or less, the data availability can reach a relatively reasonable level. Therefore, the present invention evaluates the security of the three algorithms when ε is in the range of 0.1 to 1.
[0129] Figure 6 It shows that as the privacy protection budget value ε increases, the achieved privacy protection level decreases. It can be seen from the figure that the privacy levels of the three algorithms are similar, and the PR-Diff algorithm is slightly higher than the other two algorithms. Because when the three methods add noise, they consider the temporal correlation between the added noise sequence and the original trajectory sequence, which makes the original trajectory sequence and the added noise sequence become unrecognizable to a certain extent. However, the PR-Diff algorithm uses the PageRank algorithm to calculate the differential privacy budget parameter, which better reflects the objectivity of the privacy parameter allocation, so the achieved privacy protection effect is better.
[0130] Figure 7 The r distributions under different privacy protection degrees ε are compared. It can be seen from Equation 15 that the relationship between the distance r and the probability density D is that as r increases, the probability density first increases and then decreases. This is because within a certain radius range, the larger ε is, the smaller the added noise is, and the lower the privacy degree is. As the radius increases, the change of ε is not obvious, and it is necessary to supplement the explanation by comparing the cumulative probability distribution C ε (r).
[0131] From Figure 8It can be seen that the added noise is negatively correlated with the differential privacy budget ε value. The smaller ε is, the higher the privacy protection level of the PR-Diff algorithm, and the more noise needs to be added. Thus, it can be known that there is a restrictive relationship between the privacy protection level and the efficiency of the location service. To achieve a high privacy protection level, the accuracy of the location has to be sacrificed, and to ensure the availability of the location will result in the weakening of privacy protection.
[0132] In summary, the PR-Diff algorithm proposed by the present invention uses the background knowledge of sequence position points to predict the current position point, uses the PageRank algorithm to allocate differential privacy budgets for the position points of vehicle network users, and then adds Laplace noise of different degrees according to different differential privacy budgets. By protecting the position points, the PR-Diff algorithm achieves the purpose of ensuring data availability while protecting data privacy. The experimental results on the real trajectory dataset show that, compared with the existing trajectory data privacy protection methods, the method of the present invention improves data availability while protecting the privacy of trajectory data. In future research, consideration will be given to further optimizing the PR-Diff algorithm to improve the availability of location data and reduce the running time of the algorithm, and better extend it to real-time vehicle network location services.
[0133] In this specification, each embodiment is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the system disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0134] In this specification, specific examples are used to elaborate the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A method for protecting location privacy in the Internet of Vehicles, characterized in that, it includes: Predict all user location points in the Internet of Vehicles using the background knowledge of sequence location points to generate a location point directed graph; Based on the location point directed graph, use the PageRank algorithm to calculate the sensitive attribute value of each user location point, specifically including: Based on the position point digraph, use the formula to calculate the sensitive attribute value of each user position point; where PR(L i ) is the sensitive attribute value of the i-th user position point L i ; N is the number of all user position points; M(L i ) is the set of positions with out-links for L i ; PR(L j ) is the sensitive attribute value of the j-th user position point L j ; Out(L j ) is the number of out-links of L j ; d is the probability of aiming at the position of the privacy protection vehicle node, and 1 - d is the probability of randomly jumping to other positions; Divide all the user location points according to the sensitive attribute value to determine multiple regions; Obtain the inflow and outflow conditions of vehicles in each region, and calculate the structure coefficient of each region according to the inflow and outflow conditions of vehicles; the structure coefficient is the influence of the region on the importance of user location points; Calculate the sensitivity of each user location point according to the sensitive attribute value and the structure coefficient; Allocate differential privacy budgets for the sensitivities to determine the differential privacy budget of each region; Based on the differential privacy budget of each region, use the Laplace mechanism to add Laplace noise to the user location points, and use the user location points after adding Laplace noise to replace the original user location points.
2. The method for protecting location privacy in the Internet of Vehicles according to claim 1, characterized in that, The step of dividing all the user location points according to the sensitive attribute value to determine multiple regions specifically includes: Merge the user location points corresponding to the sensitive attribute values with a similarity less than the similarity threshold to determine multiple regions; each region has multiple user location points, and the similarity of the sensitive attribute values of the user location points in each region is less than the similarity threshold.
3. The method for protecting location privacy in the Internet of Vehicles according to claim 1, characterized in that, The step of obtaining the inflow and outflow conditions of vehicles in each region and calculating the structure coefficient of each region according to the inflow and outflow conditions of vehicles specifically includes: The structure coefficient is: Among them, is the sum of the internal degrees of any one of the said regions; is the sum of the external degrees of any one of the said regions; A nn is the total number of edges connecting region n and region n in the adjacency matrix, where n is the region serial number.
4. The method for protecting location privacy in the Internet of Vehicles according to claim 3, characterized in that, The step of calculating the sensitivity of each user location point according to the sensitive attribute value and the structure coefficient specifically includes: According to the structural coefficient, use the formula to determine the structural coefficient vector; where I (n) is the structural coefficient vector; According to the sensitive attribute value and the structure coefficient vector, use the formula to calculate the sensitivity of each user location point; where P x is the sensitivity of each user location point, and x is the user location point.
5. The method for protecting location privacy in the Internet of Vehicles according to claim 4, characterized in that, The step of using the Laplace mechanism to add Laplace noise to the user location points based on the differential privacy budget of each region and using the user location points after adding Laplace noise to replace the original user location points specifically includes: Obtain the differential privacy budget for each of the said regions, and use the Laplace mechanism to add Laplace noise with a radius of r and an angle of θ to the user location point to generate a user location point after adding Laplace noise; the Laplace noise with a radius of r and an angle of θ satisfies the formula where is the probability distribution function; ε is the differential privacy budget; x 0 is the actual user location point; π is 180°.
6. A system for protecting location privacy in the Internet of Vehicles, characterized in that, it includes: A location point directed graph generation module for predicting all user location points in the Internet of Vehicles using the background knowledge of sequence location points to generate a location point directed graph; A sensitive attribute value calculation module for calculating the sensitive attribute value of each user location point based on the location point directed graph using the PageRank algorithm; The sensitive attribute value calculation module specifically includes: A sensitive attribute value calculation unit, which is used to calculate the sensitive attribute value of each user location point based on the position point directed graph by using the formula ; where, PR(L i ) is the sensitive attribute value of the i-th user location point L i ; N is the number of all user location points; M(L i ) is the set of positions with out-links of L i ; PR(L j ) is the sensitive attribute value of the j-th user location point L j ; Out(L j ) is the number of out-links of L j ; d is the probability of aiming at the position of the privacy protection vehicle node, and 1 - d is the probability of randomly jumping to other positions; A region division module for dividing all the user location points according to the sensitive attribute value to determine multiple regions; A structure coefficient calculation module, configured to obtain the vehicle inflow and outflow conditions in each of the regions, and calculate the structure coefficient of each of the regions according to the vehicle inflow and outflow conditions; the structure coefficient is the influence of the region on the importance of the user location point; A sensitivity calculation module, configured to calculate the sensitivity of each of the user location points according to the sensitive attribute value and the structure coefficient; A differential privacy budget determination module, configured to perform differential privacy budget allocation on the sensitivity, and determine the differential privacy budget of each of the regions; A Laplace noise addition module, configured to add Laplace noise to the user location points by using the Laplace mechanism based on the differential privacy budget of each of the regions, and replace the original user location points with the user location points after adding Laplace noise.
7. The vehicle networking location privacy protection system according to claim 6, wherein, the region division module specifically includes: a region division unit, configured to merge the user location points corresponding to the sensitive attribute values with a similarity less than the similarity threshold, and determine a plurality of regions; each of the regions has a plurality of user location points, and the similarity of the sensitive attribute values of the user location points in each of the regions is less than the similarity threshold.
8. The vehicle networking location privacy protection system according to claim 7, wherein, the structure coefficient in the structure coefficient calculation module is: Among them, is the sum of the internal degrees of any one of the said regions; is the sum of the external degrees of any one of the said regions; A nn is the total number of edges connecting region n and region n in the adjacency matrix, where n is the region serial number.
Citation Information
Patent Citations
Differential privacy trajectory data protection method based on clustering
CN110727959A
Personalized position privacy protection method based on differential privacy
CN111556437A