Position information hiding method based on active opacity of random discrete event system
By modeling the location information concealment system as a random discrete event system, and constructing a k-step active opaque verifier and a Markov chain, the problem of difficulty in guaranteeing opacity under multiple secret states is solved, and effective concealment and reliability protection of location information are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUANGDONG UNIV OF TECH
- Filing Date
- 2024-11-22
- Publication Date
- 2026-05-08
AI Technical Summary
Existing technologies struggle to guarantee opacity in random discrete event systems with multiple secret states, and the applicability of active opacity is limited. In particular, existing methods are insufficient to effectively protect user location privacy in location-hidden systems.
The location information concealment system is modeled as a random discrete event system. Multiple location information concealment schemes are introduced. By constructing a k-step active opaque validator and a Markov chain, the exposure probability of each location information concealment scheme is calculated to ensure that it is less than a preset threshold in order to achieve reliable concealment of location information.
It significantly improves the control capability of opacity, broadens the scope of application of active opacity, ensures the effective concealment and reliability of location information, and is applicable to complex systems with multiple secret states.
Smart Images

Figure CN119622802B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of location information concealment technology, and more specifically, to a location information concealment method based on the active opacity of a random discrete event system. Background Technology
[0002] Discrete Event Systems (DESs) are a class of dynamic systems in which discrete events interact according to certain rules, leading to state evolution. Due to their significant advantages in optimal control, fault diagnosis and prediction, and information security verification, DESs have been widely applied in various fields such as industrial manufacturing, software engineering, traffic control, computer-integrated manufacturing systems, electronic communication networks, and robotics.
[0003] In recent years, the study of opacity of discrete event systems has attracted widespread attention from many scholars at home and abroad. In the literature [5], Lin first proposed the concept of opacity in the DESs framework and studied the application of opacity in observability, anonymity, and diagnosability. Intuitively, a system with opacity satisfies the following: for any path to the secret state of the system, there exists at least one other path to the non-secret state, such that the two paths have the same observation value. Therefore, a system with opacity can effectively resist attacks from intruders and protect privacy, because the intruder cannot determine whether the state reached by the system is a secret state or a non-secret state based solely on its observation results. For this reason, it has achieved important applications in information security mechanisms such as digital signatures, secure communication, information authentication, intrusion detection, and data encryption.
[0004] To address the difficulty in guaranteeing opacity in complex systems with multiple secret states, the paper "TAN JX, LIU F, ZBIGNIEW D. Active opacity of discrete-event systems[J]. International Journal of Control, 2023, 96(8): 2090-2099" introduces controllable events, proposes the concept of active opacity, and constructs a validator for active opacity, providing a necessary and sufficient condition for verifying the active opacity of a system. However, this paper is based on the Deterministic Automaton (DESs) framework and only studies the active opacity of the current state of DESs, lacking the ability for dynamic analysis, and thus has a narrow scope of application for active opacity.
[0005] Traditional research on opacity primarily relies on binary representations, classifying the opacity of all systems into two forms: complete transparency and complete opacity. However, in real-world applications, unforeseen factors (such as sensor malfunctions) often make it difficult to ensure absolute opacity. In such cases, the system may exhibit a small probability of violating opacity. Furthermore, some applications may not necessarily require complete opacity, but only need to ensure that the probability of violating opacity remains below an acceptable threshold.
[0006] With the widespread adoption of mobile devices and online transactions, more and more applications are requiring users to provide real-time location information to offer personalized and timely updates. This type of service is known as Location Based Services (LBS), such as food delivery and navigation services. While LBS provides users with better services, it also increases the risk of privacy breaches. Intruders can use this information to learn a user's home address, workplace, and even health status. To protect user location privacy, the most commonly used technology in LBS is location anonymizers. These anonymizers transform a user's accurate location information into a larger area containing multiple fake location data points before providing it to the LBS server. The workflow is as follows: Figure 1 As shown;
[0007] When a user is in motion, the provided LBS data may only show location areas, leading to inconsistent or unclear user trajectories. Therefore, in addition to setting fake locations, fake paths also need to be set, which involves arranging the same trajectory path as the user between fake locations. This is especially important for sensitive locations, where users may further request that their presence at sensitive locations not be revealed for a period of time (or even forever) after passing through them to better protect their privacy.
[0008] Based on the above considerations, many researchers have begun to use Stochastic Discrete Event Systems (SDESs) to evaluate and quantify the opacity of systems. For example, in the paper "YIN X, LI Z, WANG W, LI S, Infinite-step opacity and K-step opacity of stochastic discrete event systems[J]. Automatica, 2019, 99: 266-274", Yin et al. explored near-k-step opacity and near-infinite-step opacity within the SDESs framework and proposed an efficient algorithm to verify these opacities. However, this paper did not consider active opacity based on event controllability and is not applicable to the aforementioned positioning system. Within the SDESs framework, which uses stochastic automata as a model, opacity is still difficult to guarantee when the system has multiple secret states. Summary of the Invention
[0009] To overcome the shortcomings of existing technologies, such as the difficulty in guaranteeing opacity when multiple secret states exist in SDESs (e.g., location-hidden systems), and the narrow applicability of active opacity, this invention provides a location information concealment method based on active opacity of stochastic discrete event systems. This method models the location information concealment system as a stochastic discrete event system, pre-sets multiple location information concealment schemes, introduces active control into the opacity study, and verifies... k Active opacity significantly improves the control capability of opacity and broadens the scope of application of active opacity, effectively achieving reliable concealment of location information.
[0010] To solve the above-mentioned technical problems, the technical solution of the present invention is as follows:
[0011] A method for concealing location information based on the active opacity of a random discrete event system includes the following steps:
[0012] S1: Obtain the map, determine several real locations and real paths of the user on the map based on LBS, and designate at least one real location as a secret location that needs to be hidden.
[0013] S2: Within a preset range around each real location, several false locations are randomly generated, and each real location is converted into a corresponding location region;
[0014] S3: Randomly generate several false paths between each of the location regions, and save each false path that can reach the secret location as a location information concealment scheme;
[0015] S4: Construct a mathematical model for the random discrete event system, and build upon the mathematical model... k Step-by-step active opaque validator ,in, k Preset to a non-negative integer;
[0016] S5: According to the above k Step-by-step active opaque validator Construct the corresponding Markov chain Calculate the probability that the secret location will be exposed after each location information concealment scheme is forcibly implemented;
[0017] S6: Determine whether there exists at least one location information concealment scheme with a probability less than a preset threshold. If so, the mathematical model of the random discrete event system has randomness. k If the location information is not actively concealed, all false paths are saved to complete the concealment of location information; otherwise, step S3 is executed again to generate a new location information concealment scheme.
[0018] Preferably, in step S4, the random discrete event system includes: a set of states, a set of events, a partial state transition probability function, and an initial state, wherein the set of events includes observable events and unobservable events.
[0019] Preferably, the unobservable events also include controllable events, and each controllable event corresponds to one of the location information concealment schemes.
[0020] Preferably, in step S4, the mathematical model of the random discrete event system is:
[0021]
[0022] in, Represents a system of random discrete events. This represents a set of states, where each state corresponds to a real or false location. This represents a set of events, where each event corresponds to a state transition process. Specifically, moving a user from one location area to another is considered an observable event, while moving a user within the same location area is considered an unobservable event. Among the unobservable events, moving a user from their initial location to the virtual location closest to the secret location is considered a controllable event. This represents a partial state transition probability function; Representing a system of random discrete events The initial state.
[0023] Preferably, in step S4, k Step-by-step active opaque validator Specifically:
[0024]
[0025] in, A set of states that have undergone controllable events, satisfying , Represents an ordered set of controllable events; Let be the state transition function, satisfying ; for k Step-by-step active opaque validator The initial state satisfies , Representing state A set of states that can be reached through unobservable events;
[0026] For any and ,have:
[0027]
[0028]
[0029]
[0030] in, The state after a controllable event; For random discrete event systems The current state; The controllable sequence of events that the process takes to reach the current state; For path Estimation of the current state corresponding to unobservable events after they occur; For path Estimation of the current state corresponding to the observable event after it occurs; For the unobservable event corresponding to the first i Pre-step state estimation ; The first observable event i State estimation before step; A set of unobservable events; It is the set of observable events; Representing state A set of states that can be reached through observable events; Indicates that an event can be executed. Status and events A set of state pairs formed by the states reached; Preset operators;
[0031] For any ,have , Representing a system of random discrete events No. i Step-delay state estimation.
[0032] Preferably, the random discrete event system have k The necessary and sufficient condition for proactive opacity is:
[0033] If and only if k Step-by-step active opaque validator Any state that has undergone a controllable event ,Right now and Simultaneously satisfying:
[0034] and
[0035] in, A set of secret locations.
[0036] Preferably, in step S5, according to the k Step-by-step active opaque validator Construct the corresponding Markov chain include:
[0037] For all locations that can be reached from the secret location path By performing controlled projection, it becomes possible to reach a secret state. Controllable event set , is represented as:
[0038]
[0039] in, Indicates to To create a controllable projection;
[0040] If the system exists n A secret location, then a secret controllable event sequence Represented as: ;
[0041] Define the set of states :
[0042]
[0043] Eliminating random discrete event systems From the set of states After the part that can be transferred is obtained, the resulting state space is used This indicates that the Markov chain is constructed. ,in, Let be the initial state probability vector, satisfying ; Let the state transition function of a Markov chain be defined as: for any , ,have:
[0044]
[0045] Calculate the probability that the secret location will be exposed after each location information concealment scheme is forcibly implemented. Specifically:
[0046]
[0047] in, Indicates starting from the initial state Migration to state The probability of; Indicates from state The probability of migrating to the exposed state. Find the smallest nonnegative solution to the following equation:
[0048] .
[0049] Preferably, the random discrete event system With randomness k The necessary and sufficient condition for proactive opacity is:
[0050] Given a preset threshold , if and only if: for any There is at least one controllable event sequence in each. ,satisfy .
[0051] The present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the above-described method.
[0052] The present invention also provides an electronic device, including a processor and a memory, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps in the above method are performed.
[0053] Compared with the prior art, the beneficial effects of the technical solution of the present invention are:
[0054] This invention provides a location information concealment method based on the active opacity of a random discrete event system. First, a map is acquired, and several real locations and real paths of the user are determined on the map using Location-Based Services (LBS). At least one real location is designated as a secret location to be concealed. Next, several false locations are randomly generated within a preset range around each real location, converting each real location into a corresponding location region. Several false paths are randomly generated between each location region, and each false path leading to the secret location is saved as a location information concealment scheme. Then, a mathematical model of the random discrete event system is constructed, and based on the mathematical model, a method for... k Step-by-step active opaque validator ,in, k The preset non-negative integer; according to the above k Step-by-step active opaque validator Construct the corresponding Markov chain Calculate the probability of exposing the secret location after the forced execution of each location information concealment scheme; finally, determine whether there exists at least one location information concealment scheme whose probability is less than a preset threshold. If so, the mathematical model of the random discrete event system possesses randomness. k If the location information is not actively concealed, all false paths will be saved to complete the concealment of location information; otherwise, a new location information concealment scheme will be generated.
[0055] This invention uses random k By introducing controllable events into active opacity, this invention solves the problem of difficulty in guaranteeing opacity in complex systems with multiple secret states. Applied to positioning systems, it actively introduces multiple location concealment schemes, ensuring the effectiveness and reliability of location information concealment. Furthermore, this invention extends active opacity from discrete event systems to random discrete event systems, and also extends active opacity from current state opacity to… k Step-by-step opacity significantly expands the scope of application of proactive opacity. Attached Figure Description
[0056] Figure 1 This is a schematic diagram of the LBS workflow provided in the background technology.
[0057] Figure 2 This is a flowchart of a location information concealment method based on the active opacity of a random discrete event system provided in Example 1.
[0058] Figure 3 This is a schematic map of a certain region provided in Example 2.
[0059] Figure 4 This is a schematic diagram of the generated location region provided in Example 2.
[0060] Figure 5 This is a schematic diagram of the two location information concealment schemes provided in Example 2.
[0061] Figure 6 This is a schematic diagram of the random discrete event system G provided in Example 2.
[0062] Figure 7 As provided in Example 2 k Step-by-step active opaque validator Schematic diagram.
[0063] Figure 8 The Markov chain provided in Example 2 Schematic diagram.
[0064] Figure 9 This is a schematic diagram of the random discrete event system G in the verification experiment provided in Example 3.
[0065] Figure 10 The verification experiment provided in Example 3 k Step-by-step active opaque validator Schematic diagram.
[0066] Figure 11 The Markov chain in the verification experiment provided in Example 3 Schematic diagram. Detailed Implementation
[0067] The accompanying drawings are for illustrative purposes only and should not be construed as limiting the scope of this patent.
[0068] To better illustrate this embodiment, some parts in the accompanying drawings may be omitted, enlarged, or reduced, and do not represent the actual product dimensions;
[0069] It will be understood by those skilled in the art that certain well-known structures and their descriptions may be omitted in the accompanying drawings.
[0070] The technical solution of the present invention will be further described below with reference to the accompanying drawings and embodiments.
[0071] Example 1
[0072] like Figure 2 As shown, this embodiment provides a method for concealing location information based on the active opacity of a random discrete event system, including the following steps:
[0073] S1: Obtain the map, determine several real locations and real paths of the user on the map based on LBS, and designate at least one real location as a secret location that needs to be hidden.
[0074] S2: Within a preset range around each real location, several false locations are randomly generated, and each real location is converted into a corresponding location region;
[0075] S3: Randomly generate several false paths between each of the location regions, and save each false path that can reach the secret location as a location information concealment scheme;
[0076] S4: Construct a mathematical model for the random discrete event system, and build upon the mathematical model... k Step-by-step active opaque validator ,in, k Preset to a non-negative integer;
[0077] S5: According to the above k Step-by-step active opaque validator Construct the corresponding Markov chain Calculate the probability that the secret location will be exposed after each location information concealment scheme is forcibly implemented;
[0078] S6: Determine whether there exists at least one location information concealment scheme with a probability less than a preset threshold. If so, the mathematical model of the random discrete event system has randomness. k If the location information is not actively concealed, all false paths are saved to complete the concealment of location information; otherwise, step S3 is executed again to generate a new location information concealment scheme.
[0079] In the specific implementation process, the map is first obtained, and several real locations and real paths of the user are determined on the map based on LBS. At least one real location is designated as a secret location that needs to be hidden.
[0080] Next, within a preset range around each real location, several fake locations are randomly generated, converting each real location into a corresponding location region;
[0081] Several false paths are randomly generated between each location area, and each false path that can reach the secret location is saved as a location information concealment scheme;
[0082] Next, a mathematical model of the random discrete event system is constructed. In this embodiment, the random discrete event system includes: a set of states, a set of events, a partial state transition probability function, and an initial state. The set of events includes observable events and unobservable events. Unobservable events also include controllable events, and each controllable event corresponds to a location information concealment scheme.
[0083] The mathematical model of a system of random discrete events is:
[0084]
[0085] in, Represents a system of random discrete events. This represents a set of states, where each state corresponds to a real or false location. This represents a set of events, where each event corresponds to a state transition process. Specifically, moving a user from one location area to another is considered an observable event, while moving a user within the same location area is considered an unobservable event. Among the unobservable events, moving a user from their initial location to the virtual location closest to the secret location is considered a controllable event. Let represent a partial state transition probability function. For example, state A may have three events a, b, and c, with probabilities of 0.3, 0.3, and 0.4 respectively. ; Representing a system of random discrete events The initial state;
[0086] In this embodiment, random k The definition of active opacity is: given a system of random discrete events For any secret state A non-negative integer k≥0 and a threshold There exists a controllable event sequence in each. The following conditions must be met:
[0087] 1)
[0088] 2)
[0089] Then the system G of random discrete events is said to have randomness. k Step-by-step opacity;
[0090] Intuitively, random k The requirement for proactive opacity in the system For each secret state, there exists at least one controllable event sequence. u Forced execution u Post-system Path taken s satisfy k The probability of step opacity Greater than a given threshold ; has randomness k Step-by-step opacity system It is only required that for each secret state there exists a condition that satisfies... k A path that is not transparent (without requiring every path passing through the secret state to satisfy the condition). k (Opacity) allows intruders to bypass the secret state after... kThe system cannot be determined within a step. Has it ever been in a state of secrecy?
[0091] for" k "Opacity" k This refers to the number of steps; the specific number is determined by the user based on their needs. In short... k A step refers to the period after an event occurs. k Within a short time, the intruder is unaware whether the event has occurred, i.e., provides k Information protection within a specific step; for example, if a user goes to the hospital first, then the post office, and finally home today, taking the hospital trip as an example... k =0 indicates that the user wants the intruder to be unaware that the user has been to the hospital when they arrive at the hospital. k =1 means that the user wants the intruder not to know that the user has been to the hospital when they arrive at the post office, but the user has already completed step 2 when they return home, so the intruder may know that the user has been to the hospital, which means providing information protection within 1 step;
[0092] Constructed based on mathematical model k Step-by-step active opaque validator ,in, k Preset to a non-negative integer; Specifically:
[0093]
[0094] in, A set of states that have undergone controllable events, satisfying , Represents a set of controllable events. This represents the ordered set of controllable events. For example, if there are controllable events c1, c2, and c3 in the system, then... This represents the possible ordering of all controllable events, such as c1c2c3, empty set, c1c3c2, etc. Let be the state transition function, satisfying ; for k Step-by-step active opaque validator The initial state satisfies ;
[0095] For the state set and events , Defined as:
[0096]
[0097] in, Representing state A set of states that can be reached through unobservable events; therefore, Representing state A set of states that can be reached through unobservable events;
[0098] For any and ,have:
[0099]
[0100]
[0101]
[0102]
[0103]
[0104] in, A state that has undergone a controllable event; state In x It tracks the current state of system G; The controllable sequence of events that the process takes to reach the current state; For path Estimating the current state after it occurs, if To migrate to The path, then for Post-occurrence state estimation, i.e. ; For the first i Pre-step state estimation ; A set of unobservable events; It is the set of observable events; Representing state A set of states that can be reached through observable events. Defined as:
[0105]
[0106] For observable event sequences , operator Defined as:
[0107]
[0108] Indicates that an event string can be executed. status and can be achieved through event strings State of arrival The set of state pairs;
[0109] For a set of state pairs , operator Defined as:
[0110]
[0111] For the state set , operator Defined as:
[0112]
[0113] and The difference is Includes arrival A state that can be reached after a middle state through an unobservable event, for example, There are two states, 1 and 2. State 2 may experience an invisible event 'a', after which it will transition to state 3. It has three states: 1, 2, and 3. Similarly;
[0114] In order to use k Step-by-step active opaque validator Verification system G k To establish active opacity, we first define that for any... ,have , Representing a system of random discrete events No. i Step-delay state estimation;
[0115] Lemma 1:
[0116] For any If we can start from the initial state via string s Migration arrival ,Right now Then we have:
[0117] 1)
[0118] 2)
[0119] 3) For strings ,like Then there is ;
[0120] Among them, 1) can be achieved by analyzing the event string. s Perform controlled mapping 1) Obtain; 2) Can be constructed 3) It can be proven by induction;
[0121] Intuitively, Lemma 1 states that for any condition satisfying ... event chain , It is the delayed state estimation of the previous i-step, i.e., the transition to x Before the state k The possible states that a step can pass through;
[0122] Therefore, if the string s Not belonging to Only one of the following conditions needs to be met: 1) ;2) Therefore, define a set of states. :
[0123]
[0124] State set The meaning is: all that satisfy (That is, the current state estimate set is a subset of the secret state set) or The set of states (where the estimated state set before a certain step is a subset of the secret state);
[0125] Lemma 2:
[0126] For any ,have:
[0127]
[0128] Proof of Lemma 2: By using Lemma 1, we can obtain:
[0129]
[0130] Furthermore, we can obtain:
[0131]
[0132] Therefore, Lemma 2 is proved;
[0133] Then we obtain Theorem 1: Random Discrete Event Systems have k The necessary and sufficient condition for proactive opacity is:
[0134] If and only if k Step-by-step active opaque validator Any state that has undergone a controllable event ,Right now and Simultaneously satisfying:
[0135] 1)
[0136] 2)
[0137] in, A set of secret locations;
[0138] Theorem 1 can be proved by contradiction:
[0139] Suppose that according to having Step-by-step opacity of random discrete event systems Corresponding construction There is a state in the step-by-step active opaque validator. And there are That is, violating condition 1 in Theorem 1); let ,because If we assume that all possible states currently in a state are secret states, then we have: There is no non-secret state. and path satisfy Therefore, the system It lacks proactive opacity; while proactive opacity is Active opacity in step A special case when =0, that is, it also does not have Step-by-step opacity, 1) proof obtained;
[0140] Alternatively, based on having Step-by-step opacity of random discrete event systems Corresponding construction There is a state in the step-by-step active opaque validator. ,satisfy and for , have That is, violating condition 2 in Theorem 1); let , prefix And there are , This indicates that the system has arrived. The state is the state estimate of the system at the i-th step before the current state, i.e. Then there is ; This describes the language. Passed through a secret state and does not exist in the system. and prefix At the same time satisfy , and ,language It is a violation The language of opacity, that is, language and Therefore, the system Not available Step-by-step opacity, 2) Proof obtained;
[0141] This method constructs and k Step-by-step active opaque validator Related Markov chains To calculate what will be reached Violation path in the middle state s probability of occurrence ;
[0142] First, for all locations that can be reached from the secret location... path By performing controlled projection, it becomes possible to reach a secret state. Controllable event set , represented as:
[0143]
[0144] in, Indicates to To create a controllable projection;
[0145] If the system exists n A secret location, then a secret controllable event sequence Represented as: ;
[0146] To put it simply, It is a set of controllable events that can lead to the secret state;
[0147] Because the system is running to Once a system enters a state, it cannot escape and will remain in that state indefinitely, thus creating an infinite loop. Therefore, random discrete event systems should be excluded. From the set of states The part that can be transferred from the middle, and then the resulting state space is used This indicates that a new validator is being constructed simultaneously. And further construct Markov chains , and The state spaces are the same, where, Let be the initial state probability vector, satisfying ; Let the state transition function of a Markov chain be defined as: for any , ,have:
[0148]
[0149] Because the part to which the system can transition from is removed. Therefore, if the system reaches any state in , then the subsequent reached states will be merged, that is, the system will always stay in ; In this embodiment, is used to represent the probability that the system stays in a u state after passing through a controllable event string , and it can be calculated by the following formula:
[0150]
[0151] where, represents the probability of transitioning from the initial state to the state ; represents the probability of transitioning from the state to the exposed state, and is the smallest non - negative solution of the following equation:
[0152] ;
[0153] Because is obtained by tracking the transition probability of the initial system and there is , we can get , so, we can get the following theorem:
[0154] Theorem 2: The necessary and sufficient condition for the stochastic discrete - event system to have stochastic k step active opacity is:
[0155] Given a preset threshold , if and only if: for any , there exists at least one controllable event string such that ;
[0156] Specific to the location information hiding in the positioning system, this method constructs the corresponding Markov chain k step active opacity verifier , calculates the probability of exposing the secret location after each location information hiding scheme is enforced; finally, determines whether there is at least one probability corresponding to the location information hiding scheme less than the preset threshold. If so, the mathematical model of the stochastic discrete - event system has stochastic k step active opacity, saves all false paths, and completes the hiding of location information; otherwise, regenerates a new location information hiding scheme;
[0157] This embodiment uses random... k By introducing controllable events into proactive opacity, this embodiment solves the problem of difficulty in guaranteeing opacity in complex systems with multiple secret states. Applying this to a positioning system, it proactively introduces multiple location concealment schemes, ensuring the effectiveness and reliability of location information concealment. Furthermore, this embodiment extends proactive opacity from discrete event systems to random discrete event systems, and also extends proactive opacity from current state opacity to… k Step-by-step opacity significantly expands the scope of application of proactive opacity.
[0158] Example 2
[0159] This embodiment provides a method for concealing location information based on the active opacity of a random discrete event system, including the following steps:
[0160] S1: Obtain the map, determine several real locations and real paths of the user on the map based on LBS, and designate at least one real location as a secret location that needs to be hidden.
[0161] S2: Within a preset range around each real location, several false locations are randomly generated, and each real location is converted into a corresponding location region;
[0162] S3: Randomly generate several false paths between each of the location regions, and save each false path that can reach the secret location as a location information concealment scheme;
[0163] S4: Construct a mathematical model for the random discrete event system, and build upon the mathematical model... k Step-by-step active opaque validator ,in, k Preset to a non-negative integer;
[0164] S5: According to the above k Step-by-step active opaque validator Construct the corresponding Markov chain Calculate the probability that the secret location will be exposed after each location information concealment scheme is forcibly implemented;
[0165] S6: Determine whether there exists at least one location information concealment scheme with a probability less than a preset threshold. If so, the mathematical model of the random discrete event system has randomness. k If the location information is not actively concealed, all false paths are saved to complete the concealment of location information; otherwise, step S3 is executed again to generate a new location information concealment scheme.
[0166] In the specific implementation process, this embodiment takes a map of a certain region as an example, such as... Figure 3 As shown, the user's movement trajectory is: starting from state 0, passing through state 1 to state 2, as follows... Figure 3 As shown, the three states represent three real locations, and the connecting lines represent the real path. Assume that state 1 is a sensitive location, and the user wants to keep the information about "whether state 1 has been reached" confidential until state 2 (that is, before reaching state 2, the outside world does not know whether the user has reached state 1).
[0167] In LBS (Location-Based Services), when a user's specific location (real location) is uploaded to a location anonymization server, several fake locations are randomly generated, and the specific location is converted into a location region. Let's say that state 0, state 1, and state 2 are converted into region 0, region 1, and region 2, respectively. Figure 4 As shown; Figure 4 Positions 5-7 in zone 0, positions 3 and 8 in zone 1, and position 4 in zone 2 are all randomly generated spurious positions. Next, spurious paths are generated between states 0, 1, 2 and the spurious positions 3, 4, 5, 6, 7, 8. The spurious paths are as follows: Figure 4 The black line path is shown in the image; to keep the "whether state 1 has been reached" confidential, assume the location anonymity system contains two location anonymity schemes, such as... Figure 5 The two paths shown in the diagram;
[0168] Model the location anonymity system as follows Figure 6 The system G shown is a random discrete event system, where the set of events is... Each event corresponds to a state transition process;
[0169] The meanings of each event are shown in Table 1, where , , These are observable events, representing moves to zones 0, 1, and 2 respectively. , , It is an unobservable event, among which , As a controllable event, and Let these represent anonymity scheme 1 and anonymity scheme 2, respectively, with the state set as follows: The controllable event set that can reach secret state 1 is ;
[0170] Table 1 Event Description Table for Location Anonymity Systems
[0171]
[0172] To effectively conceal location information, the following conditions must be met: Of the two location anonymization schemes, at least one scheme can ensure that the probability of "the system exposing that the user has passed through state 1 before reaching state 2" does not exceed 0.2.
[0173] according to Figure 6 Construction of a random discrete event system G k Step-by-step active opaque validator ,like Figure 7 As shown; by formula It can be seen that, Figure 7 The states marked in the square boxes all belong to State set;
[0174] Then according to Construct the corresponding Markov chain Calculate controllable event sets The probability that the system exposes its secret state after each controllable event sequence is forcibly executed, such as... Figure 8 As shown, it can be calculated The violation rates of the two schemes are respectively , ,and That is, in Of the two plans, The probability that the user has been to state 1 before reaching state 2 is no more than 0.2.
[0175] Therefore, when k =1, threshold When ω = 0.2, the random discrete event system G exhibits random one-step active opacity, indicating that the scheme in this location anonymity system... It can ensure that the probability of "the system revealing that the user has been through state 1 before reaching state 2" does not exceed 0.2;
[0176] This embodiment uses random... k By introducing controllable events into proactive opacity, this embodiment solves the problem of difficulty in guaranteeing opacity in complex systems with multiple secret states. Applying this to a positioning system, it proactively introduces multiple location concealment schemes, ensuring the effectiveness and reliability of location information concealment. Furthermore, this embodiment extends proactive opacity from discrete event systems to random discrete event systems, and also extends proactive opacity from current state opacity to… k Step-by-step opacity significantly expands the scope of application of proactive opacity.
[0177] Example 3
[0178] This embodiment provides a verification experiment to verify whether the determination process of random k-step active opacity of the random discrete event system provided in Embodiment 1 is correct and effective.
[0179] like Figure 9 As shown, given a system of random discrete events State set The secret state set is event set ,in, A considerable set of events, A set of unobservable events It is a set of controllable events.
[0180] In the specific implementation process, 1) Verification system Does it possess proactive opacity: based on the system Taking secret state 5 as an example, we can see that ,like , , It can be known that ,and ,Right now This violates the definition of proactive opacity. ,Right now It lacks proactive opacity;
[0181] 2) Verification System Does it have Step opacity: Let =1, take , prefix ,have ,satisfy ,and State 4 is a secret state, satisfying the condition that... , and the system There is no path in it. and prefix At the same time satisfy , and Therefore when When =1, the system Not having Step opacity;
[0182] 3) Verification System Does it have randomness? Active Opacity: Let =1, When in secret state hour, .when At that time, the system All controllable projections in the middle are equal to All paths will pass through secret state 4, satisfying... There exists a line belonging to path , The execution probability can be obtained from equation (14). Then enforce control The path taken by the subsequent system belongs to The probability is Therefore, when the secret state , At the same time, satisfy and Two conditions;
[0183] When in secret state Similarly, it can be concluded that... ,when At that time, there exists a line belonging to path The execution probability is Therefore, when the secret state , At the same time, satisfy and Two conditions;
[0184] Therefore, for random discrete event systems Each secret state in the sequence has a controllable event chain. Forced execution The path taken by the subsequent system satisfy The probability of step opacity Therefore, when When = 1, the random discrete event system Both have randomness Step-by-step opacity;
[0185] The random discrete event system was then determined using the method provided in Example 1. Does it have randomness? Step-by-step opacity;
[0186] when When =1, G of Step-by-step active opaque validator like Figure 10 As shown, where initial state ;
[0187] When the event string After it occurs, the system will migrate to a new state, using It means that, among them, ;here This represents the sequence of controllable events that occurred before reaching this state. ; Indicates the observation of a sequence of observable events. After this occurs, the system's current possible state is state 4, state 5, or state 7. This represents the delayed state estimate from the previous step, such as... In This indicates that the previous state in state 4 was estimated to be state 0.
[0188] pass Figure 9 The system in and Figure 10 In Constructing Markov chains ,like Figure 11 As shown; System If a sequence of events contains two secret states, 4 and 5, then the controllable event sequences that can reach states 4 and 5 are respectively... and ,So Secret Controllable Event Series ; Figure 11 The square box marks what belongs to The state, such as state ;
[0189] For convenience, Each state in the process starts from... arrive The numbering requires calculation of the secret controllable event sequence. The probability that each controllable event sequence exposes the secret state; such as a controllable event sequence set. Controllable event string in ,go through The states are , , , and Add the initial state The following equation is used to calculate the result after... The probability that the secret state will eventually be revealed:
[0190]
[0191] The above system of equations has infinite solutions. To obtain the minimum result, we take the free variables... You can get , respectively representing from arrive State is achieved through a controllable event chain The probability of transitioning to the marked state; therefore, we can obtain , i.e., enforcement The probability that the secret state will eventually be exposed is: ;
[0192] Similarly, execution can be achieved. The probability of exposing the secret state is , implement The probability of exposing the secret state is ,implement The probability of exposing the secret state is ;
[0193] Therefore, in Selected after controllable projection The path is forced to execute, in Selected after controllable projection If the path is forced to execute, then when When =1, for all thresholds , With randomness Step-by-step opacity;
[0194] This embodiment utilizes the method proposed in Embodiment 1, and the final verification result obtained is correct and error-free, through the construction of a random discrete event system. of Step-by-step active opaque validator We introduce controllable events and further construct Markov chains. Finally, the probability of the secret state being exposed after the controllable event is forcibly executed can be calculated. It can be seen that the judgment method proposed in Example 1 (i.e., Theorems 1 and 2) is effective and can solve the problem of the difficulty in ensuring opacity in complex systems with multiple secret states. At the same time, it expands the scope of application of active opacity. By applying it to the positioning system and actively introducing multiple location concealment schemes, the effectiveness and reliability of location information concealment can be guaranteed.
[0195] The same or similar labels correspond to the same or similar parts;
[0196] The terms used to describe positional relationships in the accompanying drawings are for illustrative purposes only and should not be construed as limiting this patent.
[0197] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the present invention, and are not intended to limit the implementation of the present invention. Those skilled in the art will recognize that other variations or modifications can be made based on the above description. It is neither necessary nor possible to exhaustively describe all embodiments here. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the claims of the present invention.
Claims
1. A method for concealing location information based on the active opacity of a random discrete event system, characterized in that, Includes the following steps: S1: Obtain the map, determine several real locations and real paths of the user on the map based on LBS, and designate at least one real location as a secret location that needs to be hidden. S2: Within a preset range around each real location, several false locations are randomly generated, and each real location is converted into a corresponding location region; S3: Randomly generate several false paths between each of the location regions, and save each false path that can reach the secret location as a location information concealment scheme; S4: Construct a mathematical model for the random discrete event system, and build upon the mathematical model... k Step-by-step active opaque validator ,in, k Preset to a non-negative integer; S5: According to the above k Step-by-step active opaque validator Construct the corresponding Markov chain Calculate the probability that the secret location will be exposed after each location information concealment scheme is forcibly implemented; S6: Determine whether there exists at least one location information concealment scheme with a probability less than a preset threshold. If so, the mathematical model of the random discrete event system has randomness. k By actively maintaining opacity, all false paths are saved, thus concealing location information. Otherwise, repeat step S3 to generate a new location information concealment scheme.
2. The location information concealment method based on the active opacity of a random discrete event system according to claim 1, characterized in that, In step S4, the random discrete event system includes: a set of states, a set of events, a partial state transition probability function, and an initial state, wherein the set of events includes observable events and unobservable events.
3. The location information concealment method based on the active opacity of a random discrete event system according to claim 2, characterized in that, The unobservable events also include controllable events, and each controllable event corresponds to one of the location information concealment schemes.
4. The location information concealment method based on the active opacity of a random discrete event system according to claim 3, characterized in that, In step S4, the mathematical model of the random discrete event system is: in, Represents a system of random discrete events. This represents a set of states, where each state corresponds to a real or false location. This represents a set of events, where each event corresponds to a state transition process. Specifically, moving a user from one location area to another is considered an observable event, while moving a user within the same location area is considered an unobservable event. Among the unobservable events, moving a user from their initial location to the virtual location closest to the secret location is considered a controllable event. This represents a partial state transition probability function; Representing a system of random discrete events The initial state.
5. A method for concealing location information based on the active opacity of a random discrete event system according to claim 4, characterized in that, In step S4 k Step-by-step active opaque validator Specifically: in, A set of states that have undergone controllable events, satisfying , Represents an ordered set of controllable events; Let be the state transition function, satisfying ; for k Step-by-step active opaque validator The initial state satisfies , Representing state A set of states that can be reached through unobservable events; For any and ,have: in, The state after a controllable event; For random discrete event systems The current state; The controllable sequence of events that the process takes to reach the current state; For path Estimation of the current state corresponding to unobservable events after they occur; For path Estimation of the current state corresponding to the observable event after it occurs; For the unobservable event corresponding to the first i Pre-step state estimation ; The first observable event i State estimation before step; A set of unobservable events; It is the set of observable events; Representing state A set of states that can be reached through observable events; Indicates that an event can be executed. Status and events A set of state pairs consisting of the states that have been reached; Preset operators; For any ,have , Representing a system of random discrete events No. i Step-delay state estimation.
6. A method for concealing location information based on the active opacity of a random discrete event system according to claim 5, characterized in that, The random discrete event system have k The necessary and sufficient condition for proactive opacity is: If and only if k Step-by-step active opaque validator Any state that has undergone a controllable event ,Right now and Simultaneously satisfying: and in, A set of secret locations.
7. A method for concealing location information based on the active opacity of a random discrete event system according to claim 6, characterized in that, In step S5, according to the k Step-by-step active opaque validator Construct the corresponding Markov chain include: For all locations that can be reached from the secret location path By performing controlled projection, it becomes possible to reach a secret state. Controllable event set , is represented as: in, Indicates to To create a controllable projection; If the system exists n A secret location, then a secret controllable event sequence Represented as: ; Define the set of states : Eliminating random discrete event systems From the set of states After the part that can be transferred is obtained, the resulting state space is used This indicates that the Markov chain is constructed. ,in, Let be the initial state probability vector, satisfying ; Let the state transition function of a Markov chain be defined as: for any , ,have: Calculate the probability that the secret location will be exposed after each location information concealment scheme is forcibly implemented. Specifically: in, Indicates starting from the initial state Migration to state The probability of; Indicates from state The probability of migrating to the exposed state. Find the smallest nonnegative solution to the following equation: 。 8. A method for concealing location information based on the active opacity of a random discrete event system according to claim 7, characterized in that, The random discrete event system With randomness k The necessary and sufficient condition for proactive opacity is: Given a preset threshold , if and only if: for any There is at least one controllable event sequence in each. ,satisfy .
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 8.
10. An electronic device, characterized in that, It includes a processor and a memory, the memory storing computer-readable instructions, which, when executed by the processor, perform the steps of the method as described in any one of claims 1 to 8.