Location privacy protection method and device, computer equipment, storage medium and product
By collaborating with requesting and cooperating nodes, anonymous regions are filtered and dynamically optimized, solving the problem of vulnerability of anonymous regions to attacks in existing technologies. This improves the security and reliability of location privacy protection and reduces latency and overhead.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-01
- Publication Date
- 2026-03-27
AI Technical Summary
The existing distributed K-anonymity mechanism's anonymous region is difficult to resist inference attacks by attacking nodes with rich background knowledge, and the scope of the anonymous region is limited, which increases the risk of exposing the real location and results in poor location privacy protection.
Through collaboration between requesting nodes and collaborating nodes, anonymous region construction requests are broadcast and reputation-related information is verified. The target location set is filtered, the initial anonymous region is dynamically optimized, and the final anonymous region is generated. Diversity indicators are used to reduce the distinguishability of attacking nodes, and the speculative behavior of attacking nodes is simulated for dynamic optimization.
It improves the security and reliability of location privacy protection, reduces the latency and performance overhead of location privacy protection, and ensures the continuity and reliability of communication.
Smart Images

Figure CN121751149A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the technical field of information security, and in particular to a location privacy protection method and device, computer equipment, storage medium and product. BACKGROUND
[0002] With the deep application of location-based services in the fields of intelligent transportation, social networks and Internet of Things, the privacy protection of user location data has become a key issue that directly affects personal information security. At present, the distributed K-anonymity mechanism is widely used in location privacy protection schemes because it does not need to involve a trusted third party.
[0003] However, the anonymous region constructed by the existing scheme is difficult to resist the reasoning attack of an attack node with rich background knowledge, and the range of the anonymous region is limited, which increases the risk of real location exposure, making the construction effect of the anonymous region poor, the protection effect of location privacy poor, and the security low. SUMMARY
[0004] Embodiments of the present application provide a location privacy protection method, device, computer equipment, storage medium and product, which can determine the location privacy protection mode according to the network state, to determine the location privacy protection mode most suitable for the current network environment, realize intelligent switching of the network, thereby reducing the location privacy protection delay and the performance overhead during switching, reducing the delay and interruption of data transmission, and protecting the continuity and reliability of communication. The technical scheme is as follows.
[0005] In one aspect, a location privacy protection method is provided, which is executed by a request node, and the method comprises: broadcasting an anonymous region construction request, wherein the anonymous region construction request contains a node identifier of the request node and reputation-related information; receiving response information sent by a plurality of cooperative nodes corresponding to the anonymous region construction request, wherein the response information is sent by the cooperative nodes after verifying that the reputation-related information is real information, and the response information contains location information of the cooperative nodes; in a case where the number of received response information is greater than a response number threshold, filtering the location information contained in a plurality of response information based on a predefined diversity index to obtain a target location set; the diversity index is used to reduce the distinguishability of each location in the target location set by an attack node; The initial anonymous area is dynamically optimized to obtain a final anonymous area, and a location service is acquired based on the final anonymous area; the dynamic optimization guides adjustment of the initial anonymous area by simulating a behavior of the attack node performing location speculation based on the initial anonymous area, and the initial anonymous area is generated based on the target location set and location information of the request node.
[0006] In another aspect, a location privacy protection method is provided, the method is performed by a cooperative node, and the method comprises: receiving an anonymous area construction request broadcast by a request node, the anonymous area construction request containing a node identifier of the request node and reputation-related information; performing authenticity verification on the reputation-related information in the anonymous area construction request to obtain a verification result; in a case where the verification result indicates that the reputation-related information is authentic information, feeding back response information to the request node, so that the request node performs screening on location information contained in multiple pieces of the response information based on a predefined diversity index to obtain a target location set in a case where a quantity of the response information received from multiple nodes is greater than a response quantity threshold; and performing dynamic optimization on an initial anonymous area generated based on the target location set and location information of the request node to obtain a final anonymous area, and acquiring a location service based on the final anonymous area; the diversity index is used to reduce distinguishability of each location in the target location set by an attack node; and the dynamic optimization guides adjustment of the initial anonymous area by simulating a behavior of the attack node performing location speculation based on the initial anonymous area.
[0007] In another aspect, a location privacy protection device is provided, the device is applied in a request node, and the device comprises: a request broadcast module configured to broadcast an anonymous area construction request, the anonymous area construction request containing a node identifier of the request node and reputation-related information; an information receiving module configured to receive response information sent by multiple cooperative nodes corresponding to the anonymous area construction request, the response information being sent by the cooperative nodes after verifying that the reputation-related information is authentic information, and the response information containing location information of the cooperative nodes; an information screening module configured to perform screening on location information contained in multiple pieces of the response information based on a predefined diversity index to obtain a target location set in a case where a quantity of the response information received is greater than a response quantity threshold; and the diversity index is used to reduce distinguishability of each location in the target location set by an attack node. An optimization module is used to dynamically optimize an initial anonymous region to obtain a final anonymous region, so as to obtain location services based on the final anonymous region. The dynamic optimization guides the adjustment of the initial anonymous region by simulating the behavior of the attacking node inferring the location based on the initial anonymous region. The initial anonymous region is generated based on the target location set and the location information of the requesting node.
[0008] In one possible implementation, the diversity metrics include at least two of the following: location query probability, physical distance between locations, and location semantic attributes; The information filtering module includes: The problem construction submodule is used to construct a multi-objective optimization problem based on the diversity indicators; the optimization objectives of the multi-objective optimization problem include at least two of the following: maximizing the minimum physical distance between any two locations in the location set, maximizing the minimum semantic distance between any two locations in the location set, and minimizing the difference between the location query probability of each location in the location set and the query probability of the request node; the location set is a subset constructed based on the location information contained in multiple response information. The problem-solving submodule is used to solve the multi-objective optimization problem to obtain the set of target locations.
[0009] In one possible implementation, the semantic distance is based on the path length between the classification nodes corresponding to two locations in the location semantic tree, which is constructed based on the location semantic attributes of each location.
[0010] In one possible implementation, the optimization module includes: The calculation submodule is used to calculate the posterior probability distribution of the attacking node's inference of the true location of the requesting node based on the initial anonymous region. The location estimation submodule is used to determine the optimal estimated location of the attacking node relative to the true location of the requesting node based on the posterior probability distribution. The adjustment submodule is used to dynamically adjust the composition of the initial anonymized region with the optimization objective of maximizing the expected distance between the optimal predicted position and the actual position, so as to obtain the final anonymized region.
[0011] In one possible implementation, the device further includes: An update module is used to dynamically update the reputation-related information based on the historical collaboration behavior records of the requesting node; the historical collaboration behavior records include the authenticity verification records of the reputation-related information, and the successful records of the requesting node as a collaboration node in constructing an anonymous region.
[0012] On the other hand, a location privacy protection device is provided, which is applied in a collaborative node, the device comprising: The request receiving module is used to receive anonymous region construction requests broadcast by requesting nodes. The anonymous region construction requests include the node identifier and reputation-related information of the requesting node. The verification module is used to verify the authenticity of the reputation-related information in the anonymous region construction request and obtain the verification result. The information feedback module is used to provide response information to the requesting node when the verification result indicates that the reputation-related information is genuine. This allows the requesting node to filter the location information contained in the multiple response messages based on a predefined diversity index, obtaining a target location set, when the number of response messages received from multiple nodes exceeds a response quantity threshold. The module then dynamically optimizes an initial anonymous region generated based on the target location set and the requesting node's location information to obtain a final anonymous region, which is used to obtain location services. The diversity index is used to reduce the distinguishability of each location in the target location set by the attacking node. The dynamic optimization guides the adjustment of the initial anonymous region by simulating the attacking node's location inference behavior based on the initial anonymous region.
[0013] In one possible implementation, the reputation-related information includes a reputation value and the number of times a region has been constructed as a collaborating node; The verification module includes: The reference information acquisition submodule is used to obtain the reference reputation value and reference area construction count of the requesting node from the blockchain; The first determining submodule is used to determine that the verification result indicates that the reputation-related information is false information when the reputation value is less than the reference reputation value, or when the number of times the region is constructed is less than the number of times the reference region is constructed. The second determining submodule is used to determine that the verification result indicates that the reputation-related information is true information when the reputation value is greater than or equal to the reference reputation value and the number of times the region is constructed is greater than or equal to the number of times the reference region is constructed.
[0014] In one possible implementation, the device further includes: The penalty module is used to broadcast a penalty bill and store it in the blockchain when the verification result indicates that the reputation-related information is false. The penalty bill is used to instruct the requesting node to enter a request-restricted state. In the request-restricted state, the anonymous region construction request sent by the requesting node is invalid before the requesting node completes m anonymous region constructions as a cooperating node, where m is a positive integer.
[0015] In one possible implementation, the information feedback module is configured to provide the response information to the requesting node when the verification result indicates that the reputation-related information is genuine, and the requesting node is determined not to be in the request-restricted state based on the penalty bill queried from the blockchain.
[0016] On the other hand, a computer device is provided, the computer device including a processor and a memory, the memory storing at least one computer program, the at least one computer program being loaded and executed by the processor to implement the above-described location privacy protection method.
[0017] On the other hand, a computer-readable storage medium is provided, wherein at least one computer program is stored in the computer-readable storage medium, the computer program being loaded and executed by a processor to implement the above-described location privacy protection method.
[0018] On the other hand, a computer program product is provided, the computer program product including a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions that, when executed by a computer, cause the computer to perform to implement the location privacy protection method provided in the various optional implementations described above.
[0019] The technical solution provided in this application may include the following beneficial effects: The location privacy protection method provided in this application involves: a requesting node broadcasting an anonymous region construction request containing node identifiers and reputation-related information; receiving response information containing location information sent by collaborating nodes after verifying the authenticity of the reputation-related information; when the number of response information exceeds a threshold, filtering the location information based on a predefined diversity index to obtain a target location set; and dynamically optimizing the initial anonymous region generated based on the target location set and the requesting node's location information to obtain the final anonymous region. By filtering the target location set using a diversity index, the distinguishability of each location within the anonymous region is reduced by an attacker. Furthermore, by dynamically optimizing the anonymous region by simulating attacker speculation behavior, the generated final anonymous region maximizes the attacker's speculation error, thereby improving the security and reliability of location privacy protection.
[0020] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0021] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0022] Figure 1 This invention illustrates a schematic diagram of the architecture of a location privacy protection system provided in an exemplary embodiment of this application. Figure 2 A flowchart of a location privacy protection method provided in an exemplary embodiment of this application is shown; Figure 3 A schematic diagram of a location semantic tree provided in an exemplary embodiment of this application is shown; Figure 4 A flowchart of a location privacy protection method provided by another exemplary embodiment of this application is shown; Figure 5 A block diagram of a location privacy protection device provided in an exemplary embodiment of this application is shown; Figure 6 A block diagram of a location privacy protection device provided in another exemplary embodiment of this application is shown; Figure 7 A structural block diagram of a computer device illustrated in an exemplary embodiment of this application is shown; Figure 8 A structural block diagram of a computer device illustrated in an exemplary embodiment of this application is shown. Detailed Implementation
[0023] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0024] This application provides a location privacy protection method that can be applied to a location privacy protection system. Figure 1 This application illustrates a schematic diagram of the architecture of a location privacy protection system provided in an exemplary embodiment, as shown below. Figure 1 As shown, the location privacy protection system is a distributed system, including a request node 110, a cooperating node 120, and an LSP (Location-Based Services) server 130. In this embodiment, the request node is a user device that needs to obtain location services but has a real location hiding requirement. It has functions such as broadcasting anonymous region construction requests, maintaining reputation-related information, filtering location information based on diversity indicators, constructing and dynamically optimizing anonymous regions, and interacting with the LSP server based on anonymous regions to obtain location services.
[0025] The cooperating node is a user device used to assist in the construction of anonymous regions in this application embodiment. There can be multiple cooperating nodes. After receiving the anonymous region construction request broadcast by the requesting node, the node can request the reputation information of the requesting node for authenticity verification. After the verification is passed, the node can provide its own real location information to assist the requesting node in constructing anonymous regions.
[0026] The LSP server acts as a location service provider in the system. After receiving a location service request from a requesting node, it can perform a location service query based on a provided anonymous area and return the query results to provide a location server to the requesting node. For example, when performing a service query, the LSP server can obtain a list of all POIs (Points of Interest) within the anonymous area and send this list to the requesting node so that the requesting node can filter out the desired location service from the list based on its actual location.
[0027] Based on such Figure 1 The location privacy protection system shown in this application provides a location privacy protection method that can improve the construction effect of anonymous regions, thereby improving the protection effect of location privacy and enhancing security. Figure 2 This application illustrates a flowchart of a location privacy protection method provided in an exemplary embodiment. This method can be implemented by, for example... Figure 1 The request node in the location privacy protection system shown is executed; this request node can be implemented as a terminal device, such as... Figure 2 As shown, the location privacy protection method may include the following steps.
[0028] Step 210: Broadcast an anonymous region construction request, which includes the node identifier of the requesting node and reputation-related information.
[0029] In this embodiment of the application, each device node in the system can act as a requesting node or a cooperating node, and the reputation-related information of each device node can be related to the cooperative behavior of each device node in the system.
[0030] Indicatively, the reputation-related information may include a reputation value and the number of times a device node has built a region as a collaborating node. The reputation value indicates the trustworthiness of the device node in the system. When a device node first connects to the system, the system can assign an initial reputation value to the device node. The value of the initial reputation value can be set based on actual needs, for example, it can be set to 60. Furthermore, the system can assign a new device tag to the device node to indicate that the device node has not yet broadcast an anonymous region building request. This new device tag becomes invalid after the device node broadcasts an anonymous region building request as a requesting node.
[0031] In this embodiment, the reputation value of the requesting node is dynamically changing. In one possible implementation, the requesting node can dynamically update its reputation-related information based on its historical collaborative behavior records. These historical collaborative behavior records include verification records of the authenticity of reputation-related information and successful records of the requesting node's participation in anonymous zone construction as a collaborative node. These historical collaborative records can be recorded in a blockchain to ensure the immutability and traceability of the data. For example, if the requesting node participates in anonymous zone construction as a collaborative node and the anonymous zone construction is successful, a reputation value incentive can be applied based on its current reputation value, i.e., an increase in reward value. The reward value can be a pre-set fixed value based on actual needs, or it can be dynamically determined based on the current reputation value; for example, it could be n percent of the current reputation value, such as 5%. , This represents the current reputation score. If the user's location information is leaked, or if false location information is provided during collaboration, a reputation penalty can be applied based on the current reputation score. This penalty can be a pre-set fixed value based on actual needs, or it can be dynamically determined based on the current reputation score. Indicatively, it can be randomly reduced by a certain value within the penalty range determined by the current reputation score, for example, randomly reduced by 0.05. Up to 0.1 .
[0032] In one possible implementation, the request node The anonymous region construction request sent can be represented as ,in, For the timestamp information when sending the anonymous region build request, A unique identifier for the requesting node. For the reputation value of the requesting node, Indicates the request node The number of times a region is built as a collaborative node. This indicates that the requesting node uses its private key to sign the timestamp and reputation value.
[0033] Step 220: Receive response information from multiple collaborating nodes corresponding to the anonymous region construction request. The response information is sent by the collaborating nodes after verifying that the reputation-related information is genuine. The response information includes the location information of the collaborating nodes.
[0034] In one possible implementation, the reputation-related information of each node can be maintained in the blockchain. In this case, after receiving an anonymous zone construction request, a collaborating node can retrieve the reference reputation-related information of the requesting node from the blockchain based on the node identifier in the anonymous zone construction request. The authenticity of the reputation-related information is determined by comparing the reference reputation-related information in the blockchain with the reputation-related information broadcast by the requesting node. If the reputation-related information is determined to be authentic, a response information is sent to the requesting node.
[0035] When reputation-related information includes reputation value and the number of times a collaborating node has built a region, the process of a collaborating node verifying the authenticity of reputation-related information in anonymous region building requests can be implemented as follows: Query the requesting node's reference reputation value and the number of reference regions constructed from the blockchain; If the reputation value is less than the reference reputation value, or the number of times a region is constructed is less than the number of times a region is constructed, the verification result indicates that the reputation-related information is false. If the reputation value is greater than or equal to the reference reputation value, and the number of region constructions is greater than or equal to the reference number of region constructions, the verification result indicates that the reputation-related information is true.
[0036] In one possible implementation, the blockchain can store historical transaction records for each node. In this case, after receiving the anonymous zone construction request Q, the collaborating node, according to... The blockchain is queried to retrieve the historical transaction records of the requesting node and its reference reputation information is calculated, including the reference reputation value and the number of reference area constructions, which are denoted as follows: and .
[0037] In another possible implementation, the blockchain can store reference reputation information for each node, maintained and updated via smart contracts deployed on the chain. In this case, upon receiving the anonymous zone construction request Q, the collaborating node, according to... Query the blockchain for the reference reputation information of the requesting node.
[0038] After obtaining the reference reputation value and the reference region construction count, the collaborating node can compare the reputation value broadcast by the requesting node with the reference reputation value, and compare the region construction count broadcast by the requesting node with the reference region construction count; when and When this occurs, it indicates that the reputation-related information sent by the requesting node is genuine. Under this premise, the collaborating node can respond to the requesting node's anonymous zone construction request, i.e., send a response message to the requesting node. In one possible implementation, the collaborating node can send this response message to the requesting node in the form of a participation collaboration request, which can be represented as... ,in, The collaborating nodes use the requesting node's public key to encrypt the location and timestamp information. The actual location of the collaborating nodes. This is the timestamp information when the collaboration request was sent.
[0039] Conversely, when or If the requested node broadcasts a value that is inconsistent with the actual statistics and is greater than the actual value, indicating that there is a case of false reporting, the collaborating node can mark the requested node as having an abnormal value, determine that the reputation-related information is false information, and not respond to the region construction request.
[0040] Furthermore, if the collaborating node determines that reputation-related information is false, it can broadcast a penalty bill and store it in the blockchain to deduct the requesting node's reputation value and instruct the requesting node to enter a request-restricted state, making the requesting node's state traceable. In the request-restricted state, anonymous region construction requests sent by the requesting node are invalid until it completes m anonymous region constructions as a collaborating node. Here, m is a positive integer; that is, from the moment it enters the request-restricted state, the requesting node needs to complete m anonymous region constructions as a collaborating node to lift the request-restricted state. While in the request-restricted state, its anonymous region construction requests cannot receive responses from collaborating nodes. The value of m can be set based on actual needs, and this embodiment does not impose any restrictions on it.
[0041] Schematic, the penalty bill broadcast by the cooperating node can be represented as ,in, and These are the timestamps and identity identifiers of the collaborating nodes, respectively. The identification number for the penalty bill. Sign the penalty bill number and timestamp using the private key of the collaborating node.
[0042] In other words, after receiving an anonymous region construction request from a requesting node, the collaborating node, in addition to verifying the authenticity of reputation-related information, can also determine the requesting node's current state. If it determines that the requesting node is not in a restricted state and verifies that the requesting node's reputation-related information is genuine, it sends a response to the requesting node; if it determines that the requesting node is in a restricted state, it does not respond to the anonymous region construction request. (Illustratively, the collaborating node determines...) and Then, further determine the requesting device. Is it within the system's specified penalty period? In the middle, this involves querying the blockchain for the last time the requesting node was penalized, and counting the number of times the requesting node has participated in assisting in the construction of anonymous zones so far. ,like If so, the collaborating node sends a request to the requesting node to participate in the collaboration.
[0043] In one possible implementation, different reputation value response thresholds can be set for different device nodes. In this case, after receiving an anonymous region construction request from a requesting node, each collaborating node can first compare its own reputation value response threshold with the reputation value broadcast by the requesting node. If the reputation value is less than the reputation value response threshold, the collaborating node determines not to respond to the anonymous region construction request and does not proceed with the subsequent judgment process. If the reputation value is greater than or equal to the reputation value response threshold, the subsequent judgment process is performed. That is to say, the higher the reputation value of a device node, the higher the probability that its anonymous region construction request sent as a requesting node will be responded to, and the higher the probability that it will successfully construct an anonymous region.
[0044] In another possible implementation, when the same requesting node initiates a request within a short period of time, for requesting nodes with high reputation values, the collaborative nodes from the previous request can be directly queried from the blockchain and their location information can be used to construct the anonymous region without further communication. In other words, when a requesting node initiates an anonymous region construction request again within a preset time interval, if its reputation value is higher than a preset threshold, the location information of the collaborative nodes stored in the node's historical interaction records can be directly obtained from the blockchain, and the anonymous region of the current request can be directly constructed based on the location information, thereby avoiding repeated communication interactions and effectively reducing the system's communication overhead. The value of the preset time interval and the value of the preset threshold can be set based on actual needs.
[0045] Step 230: If the number of received response messages is greater than the response quantity threshold, the location information contained in multiple response messages is filtered based on a predefined diversity index to obtain a target location set; this diversity index is used to reduce the distinguishability of each location in the target location set by the attacking node.
[0046] After receiving response information from multiple cooperating nodes, the requesting node can count the number of received response information and compare it with a response quantity threshold. This response quantity threshold is determined based on the privacy and anonymity requirements of the requesting node, specifically based on the number of location information k in the final anonymized region. In a random selection scenario, the attacking node has a probability of identifying the requesting node's true location from k locations that is 1 / k. The larger the value of k, the lower the probability of identifying the true location, the better the privacy protection effect, and the greater the communication overhead for the attacking node. The value of the number of location information in the final anonymized region can be set based on actual needs, and this embodiment does not impose any restrictions on this.
[0047] The threshold value for the number of responses is greater than the number of location information k in the anonymous region, so as to provide a basis for subsequent information filtering; illustratively, if the threshold value for the number of responses is 4k, when the number of received response information... If the number of response messages from the collaborating nodes is insufficient to meet subsequent requirements, the anonymous region construction is deemed to have failed, and the requesting node will resend the anonymous region construction request after a preset interval. If the response information from the collaborating node meets the requirements, the anonymous zone construction process can proceed. Furthermore, if the number of response messages received by the requesting node exceeds a threshold, the requesting node can broadcast the transaction invoice generated during the transaction to the network. Each device node in the network verifies the authenticity of this transaction invoice. If verification passes, the transaction invoice is recorded in the blockchain; if verification fails, a corresponding penalty invoice is broadcast. This penalty invoice is similar to the penalty invoice broadcast by the collaborating node and will not be elaborated here. The verification success rate can be determined based on the proportion of device nodes that confirm the authenticity of the transaction invoice. If the number of device nodes confirming the transaction invoice as authentic exceeds a node count threshold, the verification is considered successful; otherwise, the verification fails.
[0048] After determining that the number of response information is greater than the response number threshold, in order to make the query probability and location semantic information of each node's location the same or similar, and to maximize the location dispersion in the anonymous region, i.e., maximize the Euclidean distance between each node in the anonymous region, this application embodiment can filter the location information contained in multiple response information based on a predefined diversity index. In one possible implementation, the diversity index includes at least two of the following: location query probability, physical distance between locations, and location semantic attributes. Taking the selection of k-1 location information based on the above diversity index as an example to form an initial anonymous region together with the location information of the requesting node, and illustratively taking the diversity index including location query probability, physical distance between locations, and location semantic attributes as an example, each location information in the initial anonymous region must simultaneously meet the following conditions:
[0049] in, This represents the set of locations within the anonymous region, including the actual location of the requested node. This represents the semantic distance between any two points in the location set. This represents the physical distance between any two points in the location set. Indicates other locations in the set. The relationship between the query probability of a single location and the query probability of the actual location.
[0050] The semantic distance is based on the path length between the classification nodes corresponding to two locations in the location semantic tree, which is constructed based on the location semantic attributes of each location. In other words, the semantic distance essentially represents the semantic difference between different locations. For example, some locations are schools and restaurants, and schools can be further divided into universities, middle schools, and primary schools. In one possible implementation, the requesting node can obtain the semantic information of each location through reverse geospatial analysis, and then perform layer-by-layer semantic division based on point-of-interest (POI) classification rules. A location semantic tree is constructed based on the semantic information of each location, where nodes can represent different categories, and the number of hops between nodes is the semantic distance. The POI classification rules can be custom-defined or general classification rules; this embodiment does not impose any limitations on this. Figure 3 A schematic diagram of a location semantic tree provided in an exemplary embodiment of this application is shown, such as... Figure 3 As shown, this location semantic tree is a three-layer location semantic tree. When the semantic distance, i.e., the number of hops of the semantic tree node corresponding to the semantic information of the location, is greater than or equal to the hop count threshold, it is confirmed that the two locations satisfy semantic differences. For example, if the hop count threshold is 4, then... Figure 3 The number of hops between the primary school node and the credit union node is 4, and the two satisfy semantic differences.
[0051] Because it's necessary to satisfy the semantic differences between locations, maximize the physical distance between locations, and maximize the location entropy in the anonymous region (so that the query probability of each location in the anonymous region is close to the real location of the requesting node), this can be transformed into a multi-objective optimization problem. The process of filtering location information can be transformed into solving a multi-objective optimization problem, and the solution to this multi-objective optimization problem is the location information in the initial anonymous region. In this case, based on a predefined diversity index, the location information contained in multiple response messages is filtered to obtain the target location set, including: A multi-objective optimization problem is constructed based on diverse indicators; the optimization objectives of the multi-objective optimization problem include at least two of the following: maximizing the minimum physical distance between any two locations within the location set, maximizing the minimum semantic distance between any two locations within the location set, and minimizing the difference between the location query probability of each location within the location set and the query probability of the requesting node; the location set is a subset constructed based on the location information contained in multiple response messages; Solve the multi-objective optimization problem to obtain the set of target locations.
[0052] This multi-objective optimization problem can be expressed as:
[0053] During the calculation process, since the location distance is usually large, such as tens to thousands of meters, while the semantic distance is usually small, such as no more than 8, a balance factor is set when constructing the multi-objective optimization problem to reduce the impact of the large numerical difference between the two. =0 . 01 is used to balance semantic distance and physical distance.
[0054] In one possible implementation, the location set is the location information contained in all the response information received by the requesting node. The requesting node directly constructs a multi-objective optimization problem based on this location set, and selects the final k-1 locations to form the target location set by solving the problem.
[0055] In another possible implementation, since there are many locations in the grid area during the location selection process, it is difficult to filter them all. Therefore, in the solution provided in this application embodiment, selection can be made first based on the query probability, and then further filtered based on other limiting conditions. That is, a two-stage filtering strategy can be adopted to optimize computational efficiency while ensuring the quality of the anonymized area. In this case, the multi-objective optimization problem can be simplified to:
[0056] Taking a response count threshold of 4k as an example, when filtering: First, an initial selection is performed based on the location query probability. This involves calculating the absolute difference between the historical query probability of each location and the query probability of the requesting node itself. Then, 2k+1 locations with the smallest absolute difference are selected from all locations to form a set of locations that are closest to the requesting node in terms of query behavior characteristics. This maximizes the location entropy of the set. Location entropy is an indicator used in information theory to measure the uncertainty of probability distribution. The larger the entropy value, the closer the query probabilities of each location in the set are, making it more difficult for attacking nodes to infer based on query popularity. This reduces the possibility of attacking nodes inferring the true location of the requesting node based on popularity.
[0057] After obtaining a location set containing 2k+1 locations, an optimized selection process is performed based on distance and semantics: from 2 Select the actual location from the request node from the +1 location. The most recent position is used as the offset position, denoted as . .
[0058] Except for the offset position The remaining 2 besides For each location, a cyclical comparison is performed based on both physical and semantic distance. In each iteration, the location that best represents the combined distance metric is selected. The position with the largest value is selected as the position in the anonymous region. This process is repeated until a position is found from the set of positions. Given a set of locations, we obtain the target location set.
[0059] Step 240: Dynamically optimize the initial anonymous region to obtain the final anonymous region, and obtain location services based on the final anonymous region; the dynamic optimization guides the adjustment of the initial anonymous region by simulating the behavior of attack nodes inferring location based on the initial anonymous region, which is generated based on the target location set and the location information of the requesting node.
[0060] To prevent attacking nodes from inferring the location of requesting nodes, this embodiment of the application optimizes the composition of anonymous regions by constructing a Stackelberg game. In this game, the requesting node acts as the leader, and its strategy is to select anonymous regions; the attacking node acts as the follower, and its strategy is to infer the true location based on the regions it sees. In this case, the initial anonymous regions are dynamically optimized to obtain the final anonymous regions, including: Based on the initial anonymous region, calculate the posterior probability distribution of the attacking node's inference of the true location of the requesting node; Based on the posterior probability distribution, determine the optimal predicted position of the attacking node for the true position of the requesting node; With the goal of maximizing the expected distance between the optimal predicted location and the actual location, the composition of the initial anonymized region is dynamically adjusted to obtain the final anonymized region.
[0061] In other words, during the game, the requesting node can treat the privacy-preserving model and the attacking node model as two players, and through this game, output the optimal location information. The attacking node model can learn background knowledge related to the requesting node through pre-training, and can also use existing information and details of anonymity mechanisms to infer and filter the location of the requesting node, thereby obtaining the probability distribution of the requesting node querying at a certain location. Due to the uneven probability distribution, the attacking node can reasonably infer that the true location of the requesting node is likely located in a region with a higher query probability. The anonymity mechanism controlled by the attacking node can be represented as follows: .
[0062] Therefore, the attacking node can use Bayesian inference to infer the true location of the requesting node based on the information it has, that is, the attacking node bases its analysis on the observed anonymous region. The posterior probability distribution of the true location L of the requested node is inferred as follows:
[0063] in, Indicates the actual location as Anonymous regions are generated in time. The probability, This represents the prior probability distribution of the attacking node relative to its real location.
[0064] After obtaining the posterior probability distribution, the attacking node aims to minimize the inference error and find an optimal inference position. To make it consistent with the actual location The expected distance is minimized, and this expected distance can be expressed as: ,in, The predicted location of the attacking node With real location The physical distance between them. Therefore, the optimal predicted location of the attacking node can be expressed as:
[0065] In the Stackelberg game, the requesting node in the privacy-preserving model is treated as the leader, and the attacking node as the follower. This game requires the leader to make the first decision, and the followers then make their decisions based on the leader's outcome; that is, a set of positions needs to be generated first. The attacking node then makes a decision based on the information in the location set.
[0066] The payoff in leader-based games is determined by the position of the attacking node. With real location To measure this, the larger the error, the higher the reward; conversely, the smaller the error, the lower the reward. Therefore, in the game process, the requesting node needs to find an optimal... This allows the attacker to maximize their own gains even when the attacker adopts the optimal response strategy, thus achieving a strong Nash equilibrium in the Stackelberg game.
[0067] Therefore, using probability Indicates the request node generates a set of locations. The probability of the attack node prediction model, after optimization. The expected return can be expressed as:
[0068]
[0069] Therefore, the search for the optimal The process can be represented as To facilitate calculation, the expected return is... This transforms into a linear constraint form, meaning that for any attacker's strategy... It must meet the following requirements: , By solving this optimization problem, the optimal set of anonymous locations can be obtained. This set contains the actual position L and the offset position. Including The final anonymous area is formed by the locations.
[0070] After obtaining the final anonymous region, the requesting node can send the final anonymous region to the LSP server. The service provider returns all query results related to that region. The requesting node then filters the required information from the query results based on its known real location and refines the query results returned by the service provider to obtain the necessary information.
[0071] In summary, the location privacy protection method provided in this application involves: requesting nodes broadcasting an anonymous region construction request containing node identifiers and reputation-related information; receiving response information containing location information sent by collaborating nodes after verifying the authenticity of the reputation-related information; when the number of response information exceeds a threshold, filtering the location information based on a predefined diversity index to obtain a target location set; and dynamically optimizing the initial anonymous region generated based on the target location set and the requesting node's location information to obtain the final anonymous region. Through this method, filtering the target location set using a diversity index reduces the distinguishability of each location within the anonymous region for attackers. Dynamically optimizing the anonymous region by simulating attacker speculation maximizes the attacker's speculation error in the final anonymous region, thereby improving the security and reliability of location privacy protection.
[0072] Based on such Figure 2 The location privacy protection method shown corresponds to the one used on the collaborating node side. Figure 4 A flowchart of a location privacy protection method provided in another exemplary embodiment of this application is shown, which is executed by a collaborating node, such as... Figure 4 As shown, the method may include the following steps.
[0073] Step 410: Receive the anonymous region construction request broadcast by the requesting node. The anonymous region construction request contains the node identifier and reputation-related information of the requesting node.
[0074] Step 420: Verify the authenticity of the reputation-related information in the anonymous region construction request and obtain the verification result.
[0075] In one possible implementation, reputation-related information includes reputation value and the number of times a region has been built as a collaborating node.
[0076] In this case, the authenticity of reputation-related information in the anonymous region construction request is verified, and the verification results are obtained, including: Obtain the reference reputation value and reference area construction count of the requesting node from the blockchain; If the reputation value is less than the reference reputation value, or the number of times a region is constructed is less than the number of times a region is constructed, the verification result indicates that the reputation-related information is false. If the reputation value is greater than or equal to the reference reputation value, and the number of region constructions is greater than or equal to the number of reference region constructions, the verification result indicates that the reputation-related information is true information.
[0077] Step 430: If the verification result indicates that the reputation-related information is genuine, a response is sent back to the requesting node. This ensures that if the number of response messages received from multiple nodes exceeds a response quantity threshold, the requesting node filters the location information contained in the multiple response messages based on a predefined diversity index to obtain a target location set. The initial anonymous region generated based on the target location set and the location information of the requesting node is dynamically optimized to obtain a final anonymous region, which is then used to obtain location services. This diversity index is used to reduce the distinguishability of each location in the target location set by the attacking node. The dynamic optimization guides the adjustment of the initial anonymous region by simulating the behavior of the attacking node inferring location based on the initial anonymous region.
[0078] If the verification result indicates that the reputation-related information is true, and the penalty bill queried from the blockchain confirms that the requesting node is not in a request-restricted state, then a response message is sent back to the requesting node.
[0079] If the verification result indicates that the reputation-related information is false, a penalty bill is broadcast and stored in the blockchain. This penalty bill is used to instruct the requesting node to enter a request-restricted state. In the request-restricted state, the anonymous region construction requests sent by the requesting node are invalid until the requesting node completes m anonymous region constructions as a cooperating node, where m is a positive integer.
[0080] For details regarding the steps mentioned above, please refer to the following: Figure 2 The relevant descriptions of the cooperative nodes in the illustrated embodiments will not be repeated here.
[0081] In summary, the location privacy protection method provided in this application involves a requesting node broadcasting an anonymous region construction request containing node identifiers and reputation-related information; a collaborating node sending response information containing location information after verifying the authenticity of the reputation-related information; and when the number of response messages exceeds a threshold, the requesting node filters the location information based on a predefined diversity index to obtain a target location set. The initial anonymous region generated based on the target location set and the requesting node's location information is then dynamically optimized to obtain the final anonymous region. By filtering the target location set using a diversity index, the distinguishability of each location within the anonymous region is reduced by an attacker. Furthermore, by dynamically optimizing the anonymous region by simulating attacker speculation behavior, the generated final anonymous region maximizes the attacker's speculation error, thereby improving the security and reliability of location privacy protection.
[0082] Figure 5 This invention illustrates a block diagram of a location privacy protection device provided in an exemplary embodiment of this application, the method of which can perform the following... Figure 2 or Figure 4In the illustrated embodiments, all or part of the steps performed by the requesting node, such as Figure 5 As shown, the location privacy protection device may include the following modules.
[0083] The request broadcast module 510 is used to broadcast an anonymous region construction request, wherein the anonymous region construction request includes the node identifier of the request node and reputation-related information. The information receiving module 520 is used to receive response information sent by multiple collaborative nodes corresponding to the anonymous region construction request. The response information is sent by the collaborative nodes after verifying that the reputation-related information is real information. The response information includes the location information of the collaborative nodes. The information filtering module 530 is used to filter the location information contained in multiple response messages based on a predefined diversity index when the number of received response messages is greater than a response quantity threshold, thereby obtaining a target location set; the diversity index is used to reduce the distinguishability of each location in the target location set by the attacking node. The optimization module 540 is used to dynamically optimize the initial anonymous region to obtain a final anonymous region, so as to obtain location services based on the final anonymous region; the dynamic optimization guides the adjustment of the initial anonymous region by simulating the behavior of the attacking node inferring the location based on the initial anonymous region, and the initial anonymous region is generated based on the target location set and the location information of the requesting node.
[0084] In one possible implementation, the diversity metrics include at least two of the following: location query probability, physical distance between locations, and location semantic attributes; The information filtering module 530 includes: The problem construction submodule is used to construct a multi-objective optimization problem based on the diversity indicators; the optimization objectives of the multi-objective optimization problem include at least two of the following: maximizing the minimum physical distance between any two locations in the location set, maximizing the minimum semantic distance between any two locations in the location set, and minimizing the difference between the location query probability of each location in the location set and the query probability of the request node; the location set is a subset constructed based on the location information contained in multiple response information. The problem-solving submodule is used to solve the multi-objective optimization problem to obtain the set of target locations.
[0085] In one possible implementation, the semantic distance is based on the path length between the classification nodes corresponding to two locations in the location semantic tree, which is constructed based on the location semantic attributes of each location.
[0086] In one possible implementation, the optimization module 540 includes: The calculation submodule is used to calculate the posterior probability distribution of the attacking node's inference of the true location of the requesting node based on the initial anonymous region. The location estimation submodule is used to determine the optimal estimated location of the attacking node relative to the true location of the requesting node based on the posterior probability distribution. The adjustment submodule is used to dynamically adjust the composition of the initial anonymized region with the optimization objective of maximizing the expected distance between the optimal predicted position and the actual position, so as to obtain the final anonymized region.
[0087] In one possible implementation, the device further includes: An update module is used to dynamically update the reputation-related information based on the historical collaboration behavior records of the requesting node; the historical collaboration behavior records include the authenticity verification records of the reputation-related information, and the successful records of the requesting node as a collaboration node in constructing an anonymous region.
[0088] In summary, the location privacy protection device provided in this application is applied in a requesting node to broadcast an anonymous region construction request containing node identifier and reputation-related information; receive response information containing location information sent by cooperating nodes after verifying the authenticity of the reputation-related information; when the number of response information exceeds a threshold, filter the location information based on a predefined diversity index to obtain a target location set; and dynamically optimize the initial anonymous region generated based on the target location set and the requesting node's location information to obtain the final anonymous region. Through this method, filtering the target location set using a diversity index reduces the distinguishability of each location within the anonymous region for attackers. Dynamically optimizing the anonymous region by simulating attacker speculation maximizes the attacker's speculation error in the final anonymous region, thereby improving the security and reliability of location privacy protection.
[0089] Figure 6 A block diagram of a location privacy protection device provided in another exemplary embodiment of this application is shown, the method of which can perform as follows: Figure 2 or Figure 4 In the illustrated embodiments, all or part of the steps performed by the collaborating nodes, such as Figure 6 As shown, the location privacy protection device may include the following modules.
[0090] The request receiving module 610 is used to receive an anonymous region construction request broadcast by a requesting node, wherein the anonymous region construction request includes the node identifier and reputation-related information of the requesting node. Verification module 620 is used to verify the authenticity of the reputation-related information in the anonymous region construction request and obtain the verification result; The information feedback module 630 is used to provide response information to the requesting node when the verification result indicates that the reputation-related information is genuine. This allows the requesting node to filter the location information contained in the multiple response messages based on a predefined diversity index to obtain a target location set when the number of received response messages from multiple nodes exceeds a response quantity threshold. The module then dynamically optimizes an initial anonymous region generated based on the target location set and the location information of the requesting node to obtain a final anonymous region, which is used to obtain location services. The diversity index is used to reduce the distinguishability of each location in the target location set by the attacking node. The dynamic optimization guides the adjustment of the initial anonymous region by simulating the attacking node's location inference behavior based on the initial anonymous region.
[0091] In one possible implementation, the reputation-related information includes a reputation value and the number of times a region has been constructed as a collaborating node; The verification module 620 includes: The reference information acquisition submodule is used to obtain the reference reputation value and reference area construction count of the requesting node from the blockchain; The first determining submodule is used to determine that the verification result indicates that the reputation-related information is false information when the reputation value is less than the reference reputation value, or when the number of times the region is constructed is less than the number of times the reference region is constructed. The second determining submodule is used to determine that the verification result indicates that the reputation-related information is true information when the reputation value is greater than or equal to the reference reputation value and the number of times the region is constructed is greater than or equal to the number of times the reference region is constructed.
[0092] In one possible implementation, the device further includes: The penalty module is used to broadcast a penalty bill and store it in the blockchain when the verification result indicates that the reputation-related information is false. The penalty bill is used to instruct the requesting node to enter a request-restricted state. In the request-restricted state, the anonymous region construction request sent by the requesting node is invalid before the requesting node completes m anonymous region constructions as a cooperating node, where m is a positive integer.
[0093] In one possible implementation, the information feedback module 630 is used to provide the response information to the requesting node when the verification result indicates that the reputation-related information is true, and the requesting node is determined not to be in the request-restricted state based on the penalty bill queried from the blockchain.
[0094] In summary, the location privacy protection device provided in this application, when applied to a collaborative node, enables the collaborative node to send a response containing location information to the requesting node after receiving a request from a requesting node to construct an anonymous region containing node identifier and reputation-related information. This response verifies the authenticity of the reputation-related information. When the number of response messages exceeds a threshold, the requesting node filters the location information based on a predefined diversity index to obtain a target location set. The initial anonymous region generated based on the target location set and the requesting node's location information is then dynamically optimized to obtain the final anonymous region. By filtering the target location set using a diversity index, the distinguishability of each location within the anonymous region is reduced by an attacker. Furthermore, by dynamically optimizing the anonymous region by simulating attacker speculation behavior, the final anonymous region maximizes the attacker's speculation error, thereby improving the security and reliability of location privacy protection.
[0095] Figure 7 A structural block diagram of a computer device 700 illustrated in an exemplary embodiment of this application is shown. This computer device can be implemented as a server as described above in this application. The computer device 700 includes a Central Processing Unit (CPU) 701, a system memory 704 including Random Access Memory (RAM) 702 and Read-Only Memory (ROM) 703, and a system bus 705 connecting the system memory 704 and the CPU 701. The computer device 700 also includes a mass storage device 706 for storing an operating system 709, application programs 710, and other program modules 711.
[0096] Without loss of generality, the computer-readable medium may include computer storage media and communication media. Computer storage media include volatile and non-volatile, removable and non-removable media implemented using any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer storage media include RAM, ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other solid-state storage technologies, CD-ROM, digital versatile disc (DVD) or other optical storage, magnetic tape cassettes, magnetic tape, disk storage, or other magnetic storage devices. Of course, those skilled in the art will recognize that the computer storage media are not limited to the above-mentioned types. The system memory 704 and mass storage device 706 described above can be collectively referred to as memory.
[0097] According to various embodiments of this disclosure, the computer device 700 can also be connected to a remote computer on a network, such as the Internet. That is, the computer device 700 can be connected to a network 708 via a network interface unit 707 connected to the system bus 705, or it can use the network interface unit 707 to connect to other types of networks or remote computer systems (not shown).
[0098] The memory also includes at least one instruction, at least one program, code set, or instruction set, which are stored in the memory. The central processing unit 701 executes the at least one instruction, at least one program, code set, or instruction set to implement all or part of the steps in the location privacy protection method shown in the above embodiments.
[0099] Figure 8 A structural block diagram of a computer device 800 illustrating an exemplary embodiment of this application is shown. The computer device 800 can be implemented as a device node as described above, such as a request node or a collaborative node, such as a smartphone, tablet computer, laptop computer, or desktop computer. The computer device 800 may also be referred to as a user device, portable terminal, laptop terminal, desktop terminal, or other names.
[0100] Typically, computer device 800 includes a processor 801 and a memory 802.
[0101] In some embodiments, the computer device 800 may also optionally include a peripheral device interface 803 and at least one peripheral device. The processor 801, memory 802, and peripheral device interface 803 can be connected via a bus or signal line. Each peripheral device can be connected to the peripheral device interface 803 via a bus, signal line, or circuit board. Specifically, the peripheral device includes at least one of the following: a radio frequency circuit 804, a display screen 805, a camera assembly 806, an audio circuit 807, and a power supply 808.
[0102] In some embodiments, the computer device 800 further includes one or more sensors 809. The one or more sensors 809 include, but are not limited to, an accelerometer 810, a gyroscope 811, a pressure sensor 812, an optical sensor 813, and a proximity sensor 814.
[0103] Those skilled in the art will understand that Figure 8 The structure shown does not constitute a limitation on the computer device 800, and may include more or fewer components than shown, or combine certain components, or use different component arrangements.
[0104] In one exemplary embodiment, a computer-readable storage medium is also provided, which stores at least one computer program that is loaded and executed by a processor to implement all or part of the steps in the location privacy protection method described above. For example, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, or optical data storage device, etc.
[0105] In one exemplary embodiment, a computer program product is also provided, comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions that, when executed by a computer, cause the computer to perform the above-described actions. Figure 2 or Figure 4 All or part of the steps of the location privacy protection method shown in the embodiments.
[0106] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the claims.
[0107] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for protecting location privacy, characterized in that, The method is executed by the requesting node, and the method includes: Broadcast an anonymous region construction request, wherein the anonymous region construction request contains the node identifier and reputation-related information of the requesting node; Receive response information from multiple collaborating nodes corresponding to the anonymous region construction request. The response information is sent by the collaborating nodes after verifying that the reputation-related information is genuine. The response information includes the location information of the collaborating nodes. If the number of received response messages exceeds a response quantity threshold, the location information contained in multiple response messages is filtered based on a predefined diversity index to obtain a target location set; the diversity index is used to reduce the distinguishability of each location in the target location set by the attacking node. The initial anonymous region is dynamically optimized to obtain the final anonymous region, and location services are obtained based on the final anonymous region. The dynamic optimization guides the adjustment of the initial anonymous region by simulating the location inference behavior of the attacking node based on the initial anonymous region. The initial anonymous region is generated based on the target location set and the location information of the requesting node.
2. The method according to claim 1, characterized in that, The diversity metrics include at least two of the following: location query probability, physical distance between locations, and location semantic attributes; The step of filtering the location information contained in multiple response messages based on predefined diversity indicators to obtain a target location set includes: A multi-objective optimization problem is constructed based on the aforementioned diversity indicators; the optimization objectives of the multi-objective optimization problem include at least two of the following: maximizing the minimum physical distance between any two locations within the location set, maximizing the minimum semantic distance between any two locations within the location set, and minimizing the difference between the location query probability of each location within the location set and the query probability of the request node; the location set is a subset constructed based on the location information contained in multiple response information; Solve the multi-objective optimization problem to obtain the set of target locations.
3. The method according to claim 2, characterized in that, The semantic distance is based on the path length between the classification nodes corresponding to two locations in the location semantic tree, which is constructed based on the location semantic attributes of each location.
4. The method according to claim 1, characterized in that, The process of dynamically optimizing the initial anonymized region to obtain the final anonymized region includes: Based on the initial anonymous region, the posterior probability distribution of the attacking node's inference of the true location of the requesting node is calculated; Based on the posterior probability distribution, the optimal predicted position of the attacking node relative to the true position of the requesting node is determined; With the goal of maximizing the expected distance between the optimal predicted position and the actual position, the composition of the initial anonymized region is dynamically adjusted to obtain the final anonymized region.
5. A method for protecting location privacy, characterized in that, The method is executed by the collaborating node, and the method includes: Receive an anonymous region construction request broadcast by a requesting node, wherein the anonymous region construction request contains the node identifier and reputation-related information of the requesting node; The authenticity of the reputation-related information in the anonymous region construction request is verified to obtain the verification result; If the verification result indicates that the reputation-related information is genuine, response information is fed back to the requesting node. This allows the requesting node to filter the location information contained in the multiple response messages based on a predefined diversity index, obtaining a target location set, when the number of response messages received from multiple nodes exceeds a response quantity threshold. The initial anonymous region generated based on the target location set and the location information of the requesting node is then dynamically optimized to obtain a final anonymous region, which is used to obtain location services. The diversity index is used to reduce the distinguishability of each location in the target location set by the attacking node. The dynamic optimization guides the adjustment of the initial anonymous region by simulating the location inference behavior of the attacking node based on the initial anonymous region.
6. The method according to claim 5, characterized in that, The reputation-related information includes the reputation value and the number of times the region was constructed as a collaborative node; The verification of the authenticity of the reputation-related information in the anonymous region construction request, and the resulting verification results, include: Obtain the reference reputation value and reference region construction count of the requesting node from the blockchain; If the reputation value is less than the reference reputation value, or if the number of times the region is constructed is less than the number of times the reference region is constructed, the verification result indicates that the reputation-related information is false information. If the reputation value is greater than or equal to the reference reputation value, and the number of times the region is constructed is greater than or equal to the number of times the reference region is constructed, the verification result indicates that the reputation-related information is true information.
7. A location privacy protection device, characterized in that, The device is used in the request node, and the device includes: The request broadcast module is used to broadcast anonymous region construction requests, wherein the anonymous region construction requests include the node identifier of the request node and reputation-related information; The information receiving module is used to receive response information sent by multiple collaborative nodes corresponding to the anonymous region construction request. The response information is sent by the collaborative nodes after verifying that the reputation-related information is genuine. The response information includes the location information of the collaborative nodes. The information filtering module is used to filter the location information contained in multiple response messages based on a predefined diversity index when the number of received response messages exceeds a response quantity threshold, thereby obtaining a target location set; the diversity index is used to reduce the distinguishability of each location in the target location set by the attacking node. An optimization module is used to dynamically optimize an initial anonymous region to obtain a final anonymous region, so as to obtain location services based on the final anonymous region. The dynamic optimization guides the adjustment of the initial anonymous region by simulating the behavior of the attacking node inferring the location based on the initial anonymous region. The initial anonymous region is generated based on the target location set and the location information of the requesting node.
8. A computer device, characterized in that, The computer device includes a processor and a memory, the memory storing at least one computer program, which is loaded and executed by the processor to implement the location privacy protection method as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one computer program, which is loaded and executed by a processor to implement the location privacy protection method as described in any one of claims 1 to 6.
10. A computer program product, characterized in that, The computer program product includes a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions that, when executed by a computer device, cause the computer device to perform the location privacy protection method as described in any one of claims 1 to 6.