Location service method and device for smart city
By employing edge node verification, federated learning, and blockchain technologies, combined with differential privacy and homomorphic encryption, the security and privacy issues of smart city location service systems have been resolved, achieving high-precision and reliable positioning services to meet the construction needs of smart cities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-15
- Publication Date
- 2026-04-07
AI Technical Summary
Existing smart city location service systems suffer from single-point failure risks, data tampering risks, and privacy leaks, making it difficult to balance the accuracy and real-time nature of location data with user privacy.
Edge nodes are used for identity verification and base station reputation verification. A global positioning model is trained using federated learning. Differential privacy and homomorphic encryption technologies are used to control noise offsets to protect privacy. At the same time, blockchain and a zero-trust engine are used for dynamic risk assessment to ensure the security and accuracy of location services.
It achieves the provision of reliable and secure location services while ensuring high-precision positioning, resolves the core contradictions between security, privacy and efficiency, meets the construction needs of smart cities, and realizes a paradigm shift from "precise positioning" to "reliable services".
Smart Images

Figure CN121815402A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of core network technology, and in particular to a location service method and apparatus for smart cities. Background Technology
[0002] Against the backdrop of the rapid development of smart cities, the location service of the 5G core network has become a core infrastructure supporting key applications such as vehicle networking, emergency command, and intelligent transportation. These applications place extremely high demands on the accuracy, real-time performance, and security of location data.
[0003] In related technologies, location service methods based on centralized architectures often suffer from single point of failure risks, data tampering risks, and privacy leaks; at the same time, it is difficult to balance the need for accuracy and real-time location data with user privacy. Summary of the Invention
[0004] This disclosure is made in view of the above-mentioned problems. This disclosure provides a location service method and apparatus for smart cities.
[0005] According to one aspect of this disclosure, a location service method for smart cities is provided, applied to an edge node in a location service system, the location service system further including at least an application server, the method comprising: Receive the location request and real-time signal feature vector sent by the target terminal from the application server; If the identity verification of the target terminal based on the location request is successful and the reputation verification of the base station connected to the target terminal is successful, a global positioning model that has been pre-trained by federated learning by multiple terminals to build a global positioning model is obtained; wherein, in each iteration of the federated learning training, the noise amount of the noise offset of the global positioning model to be built on each terminal is controlled by the privacy budget of the application server. The location information of the target terminal is obtained by processing the real-time signal feature vector using the global positioning model.
[0006] According to another aspect of this disclosure, a location service device for smart cities is provided, applied to an edge node in a location service system, the location service system further including at least an application server, the device comprising: The communication module is used to receive the location request and real-time signal feature vector sent by the target terminal from the application server; The acquisition module is used to acquire a global positioning model that has been pre-trained by federated learning by multiple terminals to build a global positioning model, provided that the identity verification of the target terminal based on the positioning request is successful and the reputation verification of the base station connected to the target terminal is successful; wherein, in each iteration of the federated learning training, the noise amount of the noise offset of the global positioning model to be built on each terminal is controlled by the privacy budget of the application server. The processing module is used to process the real-time signal feature vector using the global positioning model to obtain the positioning information of the target terminal.
[0007] In another aspect of exemplary embodiments of this disclosure, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory, the processor executing the computer program to implement the methods described in exemplary embodiments of this disclosure.
[0008] In another aspect of exemplary embodiments of the present disclosure, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the methods described in exemplary embodiments of the present disclosure.
[0009] In another aspect of the exemplary embodiments of this disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the methods described in the exemplary embodiments of this disclosure.
[0010] As will be described in detail below, the location service method for smart cities according to embodiments of this disclosure involves receiving a location request and a real-time signal feature vector sent by an application server from a target terminal; after the target terminal's identity verification based on the location request is successful and the reputation verification of the base station connected to the target terminal is successful, a global positioning model is obtained, which has been pre-trained by federated learning by multiple terminals to construct a global positioning model; wherein, in each iteration of the federated learning training, the noise amount of the noise offset of the global positioning model to be constructed on each terminal is controlled by the privacy budget of the application server; and the location information of the target terminal is obtained by processing the real-time signal feature vector using the global positioning model. This method can resolve the core contradictions of smart city location services in terms of security, privacy, accuracy, and efficiency, meet the core needs of smart city construction, provide reliable and secure accurate location services, and realize a paradigm shift from "accurate positioning" to "reliable service".
[0011] It should be understood that both the foregoing general description and the following detailed description are exemplary and intended to provide further illustration of the claimed technology. Attached Figure Description
[0012] The above and other objects, features, and advantages of this disclosure will become more apparent from the more detailed description of the embodiments thereof in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of this disclosure and form part of the specification. They are used together with the embodiments of this disclosure to explain the disclosure and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.
[0013] Figure 1 This illustration shows a schematic diagram of the architecture of a location service system provided in an exemplary embodiment of this disclosure; Figure 2 A flowchart illustrating a location service method for smart cities provided by an exemplary embodiment of this disclosure is shown. Figure 3 A schematic diagram of the structure of a location service device for smart cities provided in an exemplary embodiment of this disclosure is shown. Figure 4 A schematic diagram of the structure of an electronic device provided in an exemplary embodiment of this disclosure is shown; Figure 5 A schematic diagram of the structure of a computer system provided in an exemplary embodiment of this disclosure is shown. Detailed Implementation
[0014] To make the objectives, technical solutions, and advantages of this disclosure more apparent, exemplary embodiments according to this disclosure will now be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this disclosure, and not all embodiments of this disclosure. It should be understood that this disclosure is not limited to the exemplary embodiments described herein.
[0015] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.
[0016] The term "comprising" and its variations as used herein are open-ended, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below. It should be noted that the concepts of "first", "second", etc., used in this disclosure are only used to distinguish different devices, modules, or units, and are not intended to limit the order of functions performed by these devices, modules, or units or their interdependencies.
[0017] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0018] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.
[0019] Traditional systems rely on centralized control by operators, which poses a single point of failure risk. Furthermore, the authenticity and integrity of location data are difficult to guarantee, making them vulnerable to attacks from fake base stations and data tampering. At the same time, because location data often contains sensitive information such as user movement trajectories, existing location service systems lack effective privacy protection mechanisms during data collection, transmission, and processing, making it difficult to meet stringent regulatory requirements.
[0020] To enhance the reliability of location data, related technologies have improved signal feature extraction algorithms. By optimizing the physical layer and using the enhanced technical standard of the 3GPP TS 38.305 positioning protocol, a signal acquisition method employing joint sampling of multi-base station Channel State Information (CSI) signals is used to obtain raw coordinate data. This achieves sub-meter accuracy in target positioning for smart cities, and deployment costs are low, requiring only software upgrades. However, this method still relies on the authenticity of base station signals, making it more vulnerable to fake base station attacks. Furthermore, the positioning results obtained through this technology are entirely controlled by the operator's system, making it difficult to distinguish between genuine and fake results. Additionally, the raw signal data output by this method contains sensitive information such as user movement trajectories, posing a risk of data leakage. It cannot fundamentally solve the problem of signal source spoofing and lacks dynamic privacy protection capabilities, making it difficult to balance high-precision positioning with user privacy.
[0021] Therefore, in order to solve the above problems, this disclosure provides a location service method for smart cities, which can achieve a new location service architecture with reliable signal source verification, data anti-tampering and privacy control while ensuring high-precision positioning. It proposes a "trustworthy enhanced location service method" that integrates blockchain, zero trust, federated learning and differential privacy, aiming to achieve a paradigm shift from "precise positioning" to "trustworthy service".
[0022] This disclosure provides a location service system for smart cities. Figure 1 A schematic diagram of the architecture of a location service system provided by an exemplary embodiment of this disclosure is shown. Figure 1 As shown, the location service system 100 includes at least an edge node 101 and an application server 102.
[0023] For example, the aforementioned edge node 101 may be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms. This exemplary embodiment does not limit the scope of the invention.
[0024] For example, the application server 102 may include, but is not limited to, application platforms such as vehicle networking, emergency command, and intelligent transportation, and the exemplary embodiments disclosed herein do not impose any limitations on this.
[0025] The location service method for smart cities provided in this disclosure is applied to the edge node 101 (Mobile Edge Computing, MEC) in the location service system 100 described above, and can be executed by the edge node 101. Figure 2 A flowchart illustrating a location service method for smart cities provided by an exemplary embodiment of this disclosure is shown. Figure 2 As shown, this location service method for smart cities includes: S201, Receive the location request and real-time signal feature vector sent by the target terminal from the application server; S202, if the authentication of the target terminal based on the location request is successful and the reputation verification of the base station connected to the target terminal is successful, obtain the global positioning model that has been pre-trained by multiple terminals through federated learning to build the global positioning model; wherein, in each iteration of the federated learning training, the noise amount of the noise offset of the global positioning model to be built on each terminal is controlled by the privacy budget of the application server. S203 uses a global positioning model to process the real-time signal feature vector to obtain the positioning information of the target terminal.
[0026] Specifically, the application server can provide corresponding services to the target terminal based on its location. When the application server needs to determine the location of the target terminal, the target terminal can send a location request from the application server to the edge node. Here, the location request is transmitted in an encrypted manner. For example, the data transmission of the location request adopts the encryption method of Shang Mi 4 (SM4) - Galois / Counter Mode (GCM).
[0027] Upon receiving a location request from the application server sent by the target terminal, the edge node can authenticate the target terminal based on the location request to prevent terminal spoofing and avoid privacy leaks. The edge node can also verify the reputation of the base station connected to the target terminal based on the location request to defend against fake base station attacks. This dual-chain collaborative verification mechanism ensures the dual trustworthiness of both the location service requester (target terminal) and the data source (base station), defending against malicious terminal access and fake base station attacks at the source and guaranteeing the security of location services.
[0028] Once the target terminal's authentication is successful and the base station connected to the target terminal has passed reputation verification, the edge node can pre-build a global positioning model. This global positioning model can be trained by federated learning from multiple terminals (UserEquipment, UE) to be built. Here, the target terminal can be one of the multiple terminals or another terminal outside of the multiple terminals; this disclosure does not specifically limit this.
[0029] During each iteration of the federated learning training, each terminal reports the noise offset of the global localization model to be built. This noise offset can be understood as the noise-added model parameters obtained by each terminal after each iteration of the model parameters to be built (which can be understood as the local localization model on each terminal). This noise offset is used for the aggregation and update of the global localization model to be built. Here, the local localization model on each terminal is trained locally using the original local data. Since the original local data does not leave the local area, during the federated learning training process, not only can the user location privacy of the target terminal be protected, but the data and computing power of multiple parties (multiple terminals and edge nodes) can also be used to complete the federated learning training of a high-precision global localization model, thereby ensuring the accuracy of the subsequent location calculation of the global localization model.
[0030] The noise offsets reported by each terminal for the global positioning model to be built are noise-added. The amount of noise in these offsets is controlled by the application server's privacy budget, ensuring that the final trained global positioning model provides high accuracy while maintaining privacy. Furthermore, the degree of privacy protection is adaptively adjusted by controlling the amount of noise through the application server's privacy budget. Based on this, the privacy of the location service can be guaranteed.
[0031] The aforementioned real-time signal feature vector can be the real-time signal feature vector of the base stations around the target terminal when the target terminal sends a location request to the application server. This real-time signal feature vector is merely a set of physical layer measurements and does not contain any location information itself. It may include, but is not limited to, the Reference Signal Received Power (RSRP), Reference Signal Received Quality (RSRQ), Timing Advance (TA) of the serving cell and neighboring cells, as well as the Time Difference of Arrival (TDOA), Reference Signal Time Difference (RSTD), and Angle of Arrival (AoA) information provided by the primary base station (following the 3GPP LPP / NRPPa protocol). This real-time signal feature vector can be represented as: [Base station 1 - RSRP: -85dBm, Base station 2 - RSRP: -78dBm, TDOA of base station 1-2: 310ns].
[0032] The real-time signal feature vector is input into a pre-constructed global positioning model. The global positioning model processes the real-time signal feature vector to obtain the positioning information of the target terminal. This positioning information can be location coordinates, location probability distribution, or other positioning representations used to characterize the location of the target terminal. This disclosure does not specifically limit the specific representation. For example, when the positioning information is location coordinates, the federated learning training of the global positioning model can be understood as: learning a "signal-location map," finding the location point that best matches the real-time signal feature vector, and outputting the coordinates of that location point to obtain the location coordinates of the target terminal.
[0033] According to the technical solution of the exemplary embodiments of this disclosure, by receiving a location request and a real-time signal feature vector sent by an application server from a target terminal; and after the identity verification of the target terminal based on the location request is passed and the reputation verification of the base station connected to the target terminal is passed, a global positioning model is obtained, which has been pre-trained by federated learning by multiple terminals to build a global positioning model; wherein, in each iteration of the federated learning training, the noise amount of the noise offset of the global positioning model to be built on each terminal is controlled by the privacy budget of the application server; and by processing the real-time signal feature vector using the global positioning model, the location information of the target terminal is obtained. This can solve the core contradictions of smart city location services in terms of security, privacy, accuracy and efficiency, meet the core needs of smart city construction, provide reliable and secure accurate location services, and realize a paradigm shift from "accurate positioning" to "reliable service".
[0034] In some embodiments, such as Figure 1 As shown, the location service system 100 may further include a zero-trust engine 103 (ZTEngine), where the target terminal is one of multiple terminals during federated learning training; the method may further include: In each iteration of federated learning training, if authentication and reputation verification are successful, the target location information of the application server is obtained from the zero-trust engine in response to the location request; the target location information includes at least the target location accuracy level and the privacy budget corresponding to the target location accuracy level. Send the target positioning accuracy level, privacy budget, and encryption gradient corresponding to the target positioning accuracy level to the target terminal; The target terminal receives a noise offset obtained by differential privacy processing of the locally computed offset of the global localization model to be constructed based on a privacy budget; wherein the locally computed offset is obtained by the target terminal through federated learning training based on encrypted gradients of the global localization model to be constructed. Based on the noise offset, the global localization model to be built is updated by aggregation until the global localization model converges, thus obtaining the global localization model.
[0035] Specifically, in each iteration of federated learning training, after executing step S201 above, the edge node needs to first authenticate the target terminal based on the location request and perform reputation verification on the base station connected to the target terminal. If the authentication of the target terminal and the reputation verification of the base station connected to the target terminal are successful, the edge node can respond to the location request and obtain the target location information from the zero-trust engine. This target location information includes at least the target location accuracy level and the privacy budget corresponding to that accuracy level.
[0036] As can be seen, the process of obtaining the target location information of the application server can be understood as: adaptively customizing the target location accuracy level for the application server and determining the privacy budget corresponding to the target location accuracy level.
[0037] Here, the target positioning accuracy level can be one of multiple preset positioning accuracy levels, each with a corresponding privacy budget. The number of preset positioning accuracy levels and the corresponding privacy budget can be set according to actual needs, and this embodiment does not specifically limit this. In the method of this embodiment, five preset positioning accuracy levels (L1 to L5) are set, where the privacy budget corresponding to L1 is 0.1 and the positioning accuracy is 1m; the privacy budget corresponding to L5 is 2.0 and the positioning accuracy is 50m. The smaller the privacy budget, the higher the required privacy protection strength, and therefore the greater the amount of noise that needs to be added, resulting in a corresponding decrease in the positioning accuracy of the final positioning result; conversely, the larger the privacy budget, the smaller the amount of noise, and the higher the positioning accuracy.
[0038] After receiving the target positioning accuracy level and privacy budget from the application server via the zero-trust engine, the edge node can prepare a gradient for positioning calculation based on the target positioning accuracy level. Then, it uses a homomorphic encryption algorithm (such as the Paillier algorithm) to encrypt this gradient, obtaining an encrypted gradient. This encryption ensures that even in encrypted form, the gradient corresponding to the target positioning accuracy level can be used for specific computational operations by the target terminal during transmission. This lays the foundation for subsequent secure collaborative computation, preventing the task content from being stolen or tampered with during transmission. This encrypted gradient can be a parameter used to guide the target terminal on how to perform local computations, rather than the original positioning data or the complete model.
[0039] Edge nodes send the target positioning accuracy level, privacy budget, and encryption gradient to the target terminal. Upon receiving the encryption gradient, the target terminal decrypts it locally (using a homomorphic encryption algorithm such as the Paillier algorithm's corresponding key) and performs federated learning computation. This computation process utilizes the target terminal's own local data (such as received base station signal strength and angle information) to perform federated learning training on the global positioning model to be built based on the encryption gradient, obtaining the locally calculated offset of the global positioning model. The target terminal does not directly return this locally calculated offset in plaintext; instead, it injects noise that meets differential privacy requirements into the locally calculated offset to obtain a noisy offset, thus protecting privacy. The entire local computation process (including decryption, computation, and noise addition) is controlled within 30ms to meet the requirements of 5G low-latency services.
[0040] Differential privacy can employ Laplace noise as its noise mechanism. The magnitude of this noise is controlled by a key parameter called the "privacy budget." The added noise offset effectively prevents attackers from deducing the target terminal's true location from the returned results. It also meets tiered requirements: by binding the privacy budget to the positioning accuracy level, users essentially choose between privacy protection strength and service accuracy when requesting services, satisfying the differentiated needs of different application scenarios (such as precise navigation vs. regional pedestrian flow statistics).
[0041] After receiving the noise offset returned by the target terminal, the edge node can aggregate and update the global localization model to be built based on the noise offset until the global localization model to be built converges, thus obtaining the global localization model.
[0042] The training process described above places the most data-intensive and privacy-sensitive computations locally on the terminal, while placing model aggregation and global coordination tasks at the edge. This collaborative model reduces network bandwidth pressure (saving 30% bandwidth) and separates data ownership from control. This training process is a meticulously designed distributed computing process with privacy protection as its primary consideration. It cleverly solves the privacy leakage problem in collaborative location computation in untrusted or semi-trusted environments through a combination of "homomorphic encrypted transmission of computation tasks" and "local differential privacy-enhanced noise-adding computation results." It quantifies the user's choice of privacy protection level (through L1-L5 levels) into executable noise-adding parameters, achieving a dynamic and controllable trade-off between privacy protection and service quality (accuracy). This is one of the key technical steps in this disclosure's embodiment from "precise positioning" to "trusted service."
[0043] In addition, multi-party collaborative training of the global localization model, with the original data not leaving the local machine, and the use of federated averaging algorithm combined with gradient clipping, can prevent privacy leaks from being amplified.
[0044] In some embodiments, obtaining target location information of the application server from the zero-trust engine in response to a location request may include: In response to the location request, a dynamic risk assessment request is sent to the zero-trust engine. The dynamic risk assessment request carries the target terminal's digital identity credentials, the base station's reputation score, the application server's location sensitivity, and the network status. The system receives target location information of the application server based on digital identity credentials, base station reputation scores, application server location sensitivity, and network status returned by the zero-trust engine.
[0045] Specifically, the digital identity credentials of the target terminal can be used to verify whether the terminal is legitimate, whether it has been revoked or forged; the reputation score of the base station can reflect the reliability of the base station's historical behavior and directly defend against fake base station attacks; the location sensitivity of the application server can be used to distinguish the location data sensitivity requirements of different application servers and achieve the principle of data minimization; the network status can take into account the security situation of the current network environment (such as whether it is in a peak attack period).
[0046] The zero-trust engine can combine the target terminal's digital identity credentials, the reputation score of the base station connected to the target terminal, the location sensitivity of the application server, and the network status to determine the target location information of the application server, including the target location accuracy level and privacy budget.
[0047] The process of determining the target location information can upgrade the authorization decision of the location service from the traditional static check based on roles or rules (such as RBAC) to a dynamic risk assessment based on multi-dimensional real-time context, so as to enhance the adaptive capability.
[0048] In some embodiments, the formula for calculating the noise offset can be:
[0049]
[0050]
[0051] in, This represents the noise offset of the global localization model to be built. This represents the locally calculated offset for the global localization model to be built. Indicates Gaussian noise. Represents variance. This represents the application server's privacy budget, which corresponds to the application server's target positioning accuracy level. This represents the Rényi divergence order, usually taken as... , The noise level represents the noise offset.
[0052] In some embodiments, the aggregation and update process of the global localization model to be constructed can be represented as follows:
[0053]
[0054] in, Indicates the first The model parameters of the global localization model are updated iteratively and aggregated. Indicates the first Iteration number The noise offset of the global localization model to be built updated for each terminal. Indicates the first Iteration number The noise offset of the global localization model to be built updated for each terminal. Indicates the first Local datasets for each terminal Indicates the first The amount of local data per terminal This represents a local dataset from multiple terminals. Indicates the learning rate. This represents the gradient of the loss function.
[0055] Here, the gradient of the loss function can be obtained by decrypting the encrypted gradient, and needs to be clipped to the threshold C.
[0056] In some embodiments, the target positioning information may further include the retention period corresponding to the target positioning accuracy level. During the retention period when the target terminal is undergoing federated learning training, the target positioning accuracy level and privacy budget remain unchanged.
[0057] Here, during the retention period for federated learning training on the target terminal, the target positioning accuracy level and privacy budget remain unchanged (e.g., the retention period for L1 level is 12 hours). This can reduce the number of communications between edge nodes and the target terminal and the zero-trust engine, enhance effective communication, and improve the efficiency of federated learning training.
[0058] In some embodiments, such as Figure 1 As shown, the location service system 100 may further include an identity chain 104, wherein the location request carries a digital identity credential issued by the identity chain for the target terminal, and the method may further include: In response to a location request, the target terminal's digital identity credentials are sent to the identity chain; Receive the current credential status returned by the identity chain based on the digital identity credential; If the current credentials are valid, the authentication of the target terminal is confirmed to be successful.
[0059] Specifically, in response to a location request, edge nodes first determine whether the target terminal is accessing the location service system for the first time. If it is, the Identity Chain issues a digital identity credential to the target terminal. Upon first access, the target terminal registers a decentralized identity (DID) with the Identity Chain. The Identity Chain generates an asymmetric key pair using PK / SK and submits a device fingerprint generated by hashing the International Mobile Equipment Identity (IMEI) and Media Access Control Address (MAC) to the Identity Chain. This avoids directly exposing sensitive device information. The Certificate Authority (CA) smart contract of the Identity Chain returns the issued digital identity credential to the target terminal. The algorithm signature uses Shangmi 2 (SM2), and the digital identity credential is updated every 24 hours. This step satisfies the "authenticate before service" security principle in 5G protocols.
[0060] Here, to ensure that only authorized entities (such as traffic police platforms) can decrypt specific data, this disclosure adopts CP-ABE (Attribute-Based Encryption, ABE) with attributes bound to smart city roles.
[0061] The key generation process can be represented as:
[0062] Data encryption can be represented as:
[0063] Where SK represents the user's private key, and g represents the generator. and Y represents the master key, and Y represents the set of user attributes. Here, r represents a random number generated individually for each user attribute, s represents the random exponent, and CT represents the ciphertext. M represents the hash function (such as SHA-256), and M represents the encrypted plaintext data. Indicates accessing a tree node Shared values.
[0064] If an edge node responds to a location request and determines that the target terminal is not accessing the location service system for the first time, it sends the target terminal's digital identity credential to the identity chain. This digital identity credential can be issued by the identity chain when the target terminal first accesses the location service system and is updated every 24 hours.
[0065] After receiving the digital identity credential from the target terminal, the identity link can determine the current credential status of the digital identity credential and return the current credential status to the edge node. Here, the current credential status can be one of several preset credential statuses, which can be valid, invalid, or revoked.
[0066] The edge node receives the current credential status returned by the identity chain based on the digital identity credential, and determines that the target terminal's authentication is successful if the current credential status is valid. If the current credential status of the digital identity credential is invalid or revoked, the target terminal's authentication is deemed unsuccessful.
[0067] While digital identity credentials are difficult to forge, simply checking the credential format cannot determine whether it has been revoked by the user or blacklisted by the system. By querying the identity chain to obtain the current credential status, it is possible to know in real time whether the digital identity credential is "valid," "invalid," or "revoked." This ensures that only the latest and most authoritative status is recognized, preventing the continued misuse of stolen, lost, or expired credentials.
[0068] The trust foundation for the aforementioned identity verification has shifted from a single operator or Certificate Authority (CA) to an identity chain jointly maintained by multiple parties. This chain offers tamper-proof and highly available characteristics, avoiding the risks of single points of failure, internal tampering, or external attacks that could paralyze the entire authentication system, a problem inherent in traditional centralized authentication servers. Therefore, this method of authenticating target terminals through an identity chain eliminates the need to expose the terminal's true identity information during the verification process, preventing terminal spoofing attacks and reducing the risk of privacy breaches.
[0069] In some embodiments, such as Figure 1 As shown, the location service system 100 may further include a data link 105, wherein the location request carries a query identifier of the base station; the method may further include: In response to a location request, a query identifier of the base station is sent to the data link; The receiving data chain returns the current reputation score based on the query identifier; If the current reputation score is greater than the preset reputation score, the base station's reputation verification is deemed successful.
[0070] Specifically, the aforementioned query identifier can be the identity identifier of the base station, such as the base station ID. In response to a location request, the edge node can send the base station's query identifier to the data link. Upon receiving the base station's query identifier, the data link can query the reputation score (current reputation score) based on the base station's recent behavior and return this current reputation score to the edge node. The edge node receives the current reputation score returned by the data link, and if the current reputation score is greater than a preset reputation score, it determines that the base station's reputation verification has passed.
[0071] Here, the preset reputation score can be set according to actual needs, and this embodiment does not impose specific limitations on it. In the method of this embodiment, the preset reputation score can be set to 80 points. If the current reputation score is greater than 80 points, it is determined that the reputation verification of the base station has passed; if the current reputation score is less than or equal to 80 points, it is determined that the reputation verification of the base station has failed. At this time, the base station can be marginalized or even disabled.
[0072] Here, the response time for target terminal authentication and base station reputation verification is less than 500ms.
[0073] Compared to traditional methods that verify the legitimacy of base stations through operator-issued certificates, which cannot determine the current legitimacy of a base station, the aforementioned reputation verification transforms base station security from static authentication to dynamic behavioral reputation assessment. By querying the current reputation score of a base station on the data chain, it dynamically reflects the legitimacy of the base station's recent behavior, improving the real-time identification capability of malicious base stations. Furthermore, the current reputation score of a base station on the data chain is not unilaterally determined by a single operator, but rather generated through multi-party consensus and recorded on the blockchain. This ensures transparency and immutability, effectively suppressing attacks from fake base stations.
[0074] In some embodiments, the data chain is also used to record the request hash of the location request, the request hash including at least the timestamp of the location request, the query identifier, the location of the base station, and relevant information of the application server.
[0075] Specifically, key information related to the location request, such as the timestamp of the location request, query identifier, base station location, and application server information, is permanently stored in the data chain as a hash, representing the request hash. Since hash-based notation is not full-text storage, it balances data integrity and storage efficiency.
[0076] The aforementioned data chain evidence storage and verification behavior ensures that the operation is auditable, while recording the base station's historical behavior score for subsequent dynamic evaluation by the zero-trust engine. This allows the zero-trust engine to query not only the current reputation score but also the high-reputation score when conducting dynamic risk assessment, thus expanding the traceability dimensions.
[0077] In some embodiments, the method may further include: Based on the location information of the target terminal, the evidence-based location result is sent to the data chain; the evidence-based location result includes the timestamp of the location request, the query identifier, and the location information.
[0078] Specifically, the location information of the target terminal is inherently fragile and easily forged, tampered with, or denied. Therefore, embodiments of this disclosure can generate a notarized location result from key information such as the timestamp of the location request, the query identifier, and the location information, and write this notarized location result into the data chain. This notarized location result can be uploaded to the chain in the form of a Merkle tree hash, and can be accompanied by multiple digital signatures. Through the immutability and traceability of the blockchain, the problem of difficulty in tracing data tampering and abuse in centralized systems can be solved.
[0079] In some embodiments, the method may further include: Based on the target terminal's location information, a trusted location credential is returned to the application server. The trusted location credential includes the target terminal's location information, the credibility score of the location information, and the target location accuracy level corresponding to the privacy budget.
[0080] Specifically, the application server can transform the judgment of the target terminal's location information from a location to a trusted location by using the trusted location credentials returned by the edge node based on the target terminal's location information, thus solving the problems of difficulty in distinguishing the authenticity of data and the inability to assess its quality in traditional services.
[0081] Here, trusted location credentials can be represented in the form of Merkle tree hashes, etc., and can be accompanied by multi-party digital signatures, solving the problem of difficulty in tracing data tampering and abuse in centralized systems.
[0082] The credibility scoring mechanism for the aforementioned location information can be determined according to actual needs, and this disclosure does not impose specific limitations on it. In the method of this disclosure, the credibility scoring mechanism can dynamically score the location information by comprehensively considering factors such as signal, behavior, and environment, with a credibility score greater than or equal to 0 and less than or equal to 100. Based on this, this disclosure can add a quality assessment dimension to the location service of the target terminal, providing support for establishing a reliable service system for location signals.
[0083] The specific process of the location service method for smart cities provided in this disclosure can be summarized as follows: 1. Target terminal → Identity chain: Register a decentralized identity and obtain digital identity credentials (including device fingerprint); 2. Identity Chain → Target Terminal: Returns digital identity credentials; 3. Target terminal → Edge node: Request location service (carrying digital identity credentials + target location accuracy level); 4. Edge node → Identity chain: Verify terminal identity / base station reputation; 5. Identity Chain → Edge Node: Returns verification results; 6. Edge node → Data chain: Records request hash (time / location / requester); 7. Edge Node → Zero Trust Engine: Dynamic Risk Assessment (Device Reputation / Environmental Parameters); 8. Zero Trust Engine → Edge Node: Returns permission policy (e.g., allows L3 precision); 9. Edge node → Target terminal: Federated learning location request (encrypted gradient data); 10. Target terminal → Edge node: Return local computation results (with privacy budget noise added); 11. Edge Node → Data Chain: Evidence Location Result (Multi-Party Signature); 12. Edge node → Application server: Returns trusted location credentials (including trust score); 13. Application Server → Data Chain: Audit data usage records.
[0084] The location service system for smart cities provided in this disclosure adopts a dual-chain, three-domain model system architecture, including: Identity Chain: using a consortium blockchain to manage base station / terminal DID identities and optimizing PBFT consensus to achieve a block time of <1s; Data Chain: storing Merkle hashes of location operation logs and supporting fast verification by light nodes; Zero Trust Control Domain (i.e., Zero Trust Engine): dynamically evaluating the context of access requests, including device reputation and environmental risks; Edge Computing Domain (i.e., Edge Nodes): deploying federated learning nodes to achieve privacy-preserving location computing; Service Domain (i.e., Application Server): providing standardized location APIs, graded according to accuracy, divided into 5 levels from L1 to L5.
[0085] This disclosure aims to construct a trusted service system, realizing a paradigm shift in smart city positioning services from "precise positioning" to "trusted services." It employs trusted-enhanced blockchain technology to verify signal authenticity, thus solving the fundamental security problem of signal source spoofing. Simultaneously, it utilizes a three-tiered protection approach of federated learning, differential privacy, and ABE (Adaptive Behavior-Based Optimization) to ensure that smart city positioning services meet both meter-level positioning accuracy and stringent regulations. Furthermore, it eliminates single-point trust risks and prevents the emergence of false positioning data through blockchain multi-party consensus and zero-trust dynamic verification. The technical advantages of this solution lie in its 99.1% fake base station identification rate, support for location data tampering detection, and the ability to achieve "usable but invisible" data, thereby achieving the goal of constructing a trusted system.
[0086] Based on this, the beneficial effects of the embodiments disclosed herein are as follows: 1. A dual-chain collaborative trust architecture was constructed: the identity chain (digital identity credentials for management terminals) and the data chain (reputation assessment of base stations and log storage of evidence operation) are designed separately; cross-chain verification (such as base station certificate status synchronization) is realized through smart contracts, which solves the problems of single-chain performance bottleneck and functional coupling in traditional solutions.
[0087] 2. Dynamic Privacy-Accuracy Adjustment: User-selectable privacy levels (L1-L5) are linked to the amount of differential privacy noise (controlled by privacy budget); real-time noise injection (Laplace mechanism) in edge node federated learning solves the problem that existing technologies cannot achieve both high-precision positioning and strong privacy protection.
[0088] 3. Zero Trust Engine Dynamic Access Control: Real-time policy generation based on base station reputation score + environmental risk index (updated every 5 seconds); Attribute-Based Encryption (ABE) enables service precision hierarchical authorization, solving the problem that static RBAC policies are difficult to cope with complex threats in smart cities.
[0089] 4. Auditable evidence storage by multiple parties: Merkle hash of location operation logs on the blockchain + digital signatures from three parties (operators / users / government); smart contracts automatically execute data lifecycle management, solving the problem of difficulty in tracing data tampering and abuse in centralized systems.
[0090] Compared with the prior art, the technical advantages of this application are as follows: I. Advantages in Credibility: 1. Fake base station identification rate: Based on blockchain certificate chain verification, it can identify 99.1% of fake base stations, making location data go from "undefendable" to "nearly immune" to fake base stations.
[0091] 2. Data tampering detection: The traditional technical solution relies on database logs, while the solution uses blockchain evidence storage and multi-party signatures to achieve 100% traceability and solve the risk of tampering in centralized systems.
[0092] 3. The credibility score provides a dynamic score (0-100 points, combining signal / behavior / environment), adding a quality assessment dimension to support the establishment of a reliable positioning signal service system.
[0093] II. Advantages in privacy protection capabilities: 1. Employs three-tiered protection: Transmission encryption (SM4) + Storage encryption (ABE) + Computational privacy (ε-DP); 2. Users can choose their privacy level (L1-L5) to achieve the "data autonomy" requirement of Role-Based Access Control (GDPR); 3. Differential noise disrupts the continuity of the trajectory (P<0.05 significance level), making it impossible to identify users through trajectory reconstruction, thus failing to defend against advanced inference attacks.
[0094] III. System Performance Advantages: 1. Employs edge-terminal collaborative computing (saving 30% bandwidth), making it more suitable for scenarios with massive numbers of IoT devices; 2. Adopts native built-in privacy compliance design, reducing GDPR compliance audit workload by 80%.
[0095] Based on this, the location service method for smart cities provided in this disclosure can meet the core needs of smart city construction and provide reliable and secure accurate location services: smart cities rely on high-precision, low-latency location data (such as traffic management, emergency response, and unmanned delivery), and this location service system can become a key component of the infrastructure; the enhanced "trust" characteristics (such as anti-tampering and privacy protection) meet the requirements of regulations such as GDPR and increase the willingness of governments and enterprises to purchase.
[0096] The foregoing mainly describes the solutions provided by the embodiments of this disclosure. It is understood that, in order to achieve the above functions, the electronic device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein, this disclosure can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.
[0097] This disclosure embodiment can divide the electronic device into functional units according to the above method example. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this disclosure embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0098] By dividing each functional module according to its corresponding function, an exemplary embodiment of this disclosure provides a location service device for smart cities, which is applied to the edge node of a location service system, the location service system including at least an application server. Figure 3 A schematic diagram of the structure of a location service device for smart cities provided by an exemplary embodiment of this disclosure is shown. Figure 3 As shown, the device 300 includes: The device includes: Communication module 301 is used to receive the location request and real-time signal feature vector sent by the target terminal from the application server; The acquisition module 302 is used to acquire a global positioning model that has been pre-trained by federated learning by multiple terminals to build a global positioning model, provided that the identity verification of the target terminal based on the positioning request is successful and the reputation verification of the base station connected to the target terminal is successful; wherein, in each iteration of the federated learning training, the noise amount of the noise offset of the global positioning model to be built on each terminal is controlled by the privacy budget of the application server. The processing module 303 is used to process the real-time signal feature vector using the global positioning model to obtain the positioning information of the target terminal.
[0099] In some embodiments, the location service system further includes a zero-trust engine, and the target terminal is one of the plurality of terminals; the communication module 301 is further configured to, in each iteration of the federated learning training, if the authentication is successful and the reputation verification is successful, in response to the location request, obtain the target location information of the application server from the zero-trust engine; wherein, the target location information includes at least the target location accuracy level and the privacy budget corresponding to the target location accuracy level; The communication module 301 is also used to send the target positioning accuracy level, the privacy budget, and the encryption gradient corresponding to the target positioning accuracy level to the target terminal; The communication module 301 is further configured to receive the noise offset obtained by the target terminal performing differential privacy processing on the locally computed offset of the global localization model to be constructed based on the privacy budget; wherein the locally computed offset is obtained by the target terminal performing federated learning training on the global localization model to be constructed based on the encryption gradient; The processing module 303 is further configured to aggregate and update the global localization model to be constructed based on the noise offset until the global localization model to be constructed converges, thereby obtaining the global localization model.
[0100] In some embodiments, the communication module 301 is further configured to send a dynamic risk assessment request to the zero-trust engine in response to the location request. The dynamic risk assessment request carries the digital identity credentials of the target terminal, the reputation score of the base station, the location sensitivity of the application server, and the network status. The communication module 301 is also used to receive the target location information of the application server returned by the zero-trust engine based on the digital identity credential, the reputation score of the base station, the location sensitivity of the application server, and the network status.
[0101] In some embodiments, the formula for calculating the noise offset is:
[0102]
[0103]
[0104] in, This represents the noise offset of the global localization model to be constructed. This represents the locally calculated offset of the global positioning model to be constructed. Indicates Gaussian noise. Represents variance. This represents the privacy budget of the application server, which corresponds to the target positioning accuracy level of the application server. This represents the Rényi divergence order, usually taken as... , The noise amount represents the noise offset.
[0105] In some embodiments, the aggregation and update process of the global localization model to be constructed is represented as follows:
[0106]
[0107] in, Indicates the first The model parameters of the global localization model are updated iteratively and aggregated. Indicates the first Iteration number The noise offset of the global localization model to be built is updated by each terminal. Indicates the first Iteration number The noise offset of the global localization model to be built is updated by each terminal. Indicates the first Local datasets for each terminal Indicates the first The amount of local data per terminal This represents the local dataset of the multiple terminals. Indicates the learning rate. This represents the gradient of the loss function.
[0108] In some embodiments, the target positioning information further includes a retention period corresponding to the target positioning accuracy level, during which the target positioning accuracy level and the privacy budget remain unchanged during the retention period when the target terminal performs federated learning training.
[0109] In some embodiments, the location service system further includes an identity chain, wherein the location request carries a digital identity credential issued by the identity chain for the target terminal; The communication module 301 is also configured to send the target terminal's digital identity credential to the identity chain in response to the location request; The communication module 301 is also used to receive the current credential status returned by the identity chain based on the digital identity credential; The processing module 303 is further configured to determine that the authentication of the target terminal is successful if the current credential status meets the validity requirements.
[0110] In some embodiments, if the target terminal accesses the location service system for the first time, the identity chain is also used to issue the digital identity credential to the target terminal.
[0111] In some embodiments, the location service system further includes a data link, wherein the location request carries a query identifier of the base station; The communication module 301 is also configured to send the query identifier of the base station to the data link in response to the positioning request; The communication module 301 is also used to receive the current reputation score returned by the data chain based on the query identifier; The processing module 303 is further configured to determine that the reputation verification of the base station has passed when the current reputation score is greater than the preset reputation score.
[0112] In some embodiments, the data chain is further used to record the request hash of the location request, the request hash including at least the timestamp of the location request, the query identifier, the location of the base station, and relevant information of the application server.
[0113] In some embodiments, the communication module 301 is further configured to send a stored location result to the data link based on the location information of the target terminal; wherein the stored location result includes the timestamp of the location request, the query identifier, and the location information.
[0114] In some embodiments, the location request is transmitted in an encrypted manner, and the encryption gradient is obtained by the target terminal using a homomorphic encryption algorithm to encrypt the gradient corresponding to the target location accuracy level.
[0115] In some embodiments, the communication module 301 is further configured to return a trusted location credential to the application server based on the location information of the target terminal; wherein the trusted location credential includes the location information of the target terminal, a trust score of the location information, and a target location accuracy level corresponding to the privacy budget.
[0116] This disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the methods disclosed in this disclosure.
[0117] Figure 4 A schematic diagram of the structure of an electronic device provided in an exemplary embodiment of this disclosure is shown. For example... Figure 4 As shown, the electronic device 400 includes at least one processor 401 and a memory 402 coupled to the processor 401, which can perform the corresponding steps in the methods disclosed in the embodiments of this disclosure.
[0118] The processor 401 described above can also be called a Central Processing Unit (CPU), which can be an integrated circuit chip with signal processing capabilities. Each step in the method disclosed in this embodiment can be implemented by the integrated logic circuitry in the hardware of the processor 401 or by instructions in software form. The processor 401 can be a general-purpose processor, a digital signal processor (DSP), an ASIC, a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this embodiment can be directly implemented by a hardware decoding processor, or implemented by a combination of hardware and software modules in the decoding processor. The software modules can be located in the memory 402, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The processor 401 reads information from the memory 402 and, in conjunction with its hardware, completes the steps of the method described above.
[0119] Furthermore, various operations / processes according to this disclosure, implemented via software and / or firmware, can be transmitted from a storage medium or network to a computer system with a dedicated hardware architecture, for example, Figure 5 The computer system 500 shown is equipped with the programs that constitute the software. When various programs are installed, the computer system is able to perform various functions, including functions such as those described above. Figure 5 A schematic diagram of the structure of a computer system provided in an exemplary embodiment of this disclosure is shown.
[0120] Computer system 500 is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. Electronic devices may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of this disclosure described and / or claimed herein.
[0121] like Figure 5 As shown, the computer system 500 includes a computing unit 501, which can perform various appropriate actions and processes based on a computer program stored in a read-only memory (ROM) 502 or a computer program loaded from a storage unit 508 into a random access memory (RAM) 503. The RAM 503 may also store various programs and data required for the operation of the computer system 500. The computing unit 501, ROM 502, and RAM 503 are interconnected via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.
[0122] Multiple components in the computer system 500 are connected to the I / O interface 505, including: an input unit 506, an output unit 507, a storage unit 508, and a communication unit 509. The input unit 506 can be any type of device capable of inputting information into the computer system 500. The input unit 506 can receive input digital or character information and generate key signal inputs related to user settings and / or function control of the electronic device. The output unit 507 can be any type of device capable of presenting information and may include, but is not limited to, a monitor, speaker, video / audio output terminal, vibrator, and / or printer. The storage unit 508 may include, but is not limited to, a hard disk and an optical disk. The communication unit 509 allows the computer system 500 to exchange information / data with other devices via a network such as the Internet, and may include, but is not limited to, a modem, network card, infrared communication device, wireless communication transceiver, and / or chipset, such as Bluetooth™ devices, WiFi devices, WiMax devices, cellular communication devices, and / or the like.
[0123] The computing unit 501 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 501 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 501 performs the various methods and processes described above. For example, in some embodiments, the methods disclosed in this disclosure can be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 508. In some embodiments, part or all of the computer program can be loaded and / or installed on an electronic device via ROM 502 and / or communication unit 509. In some embodiments, the computing unit 501 can be configured to perform the methods disclosed in this disclosure by any other suitable means (e.g., by means of firmware).
[0124] This disclosure also provides a computer-readable storage medium, wherein when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is able to perform the methods disclosed in this disclosure.
[0125] The computer-readable storage medium in this disclosure can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. The aforementioned computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specifically, the aforementioned computer-readable storage medium may include electrical connections based on one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0126] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.
[0127] This disclosure also provides a computer program product, including a computer program, wherein when the computer program is executed by a processor, it implements the methods disclosed in the embodiments of this disclosure.
[0128] In embodiments of this disclosure, computer program code for performing the operations of this disclosure can be written in one or more programming languages or a combination thereof. These programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network (including a local area network (LAN) or a wide area network (WAN)), or it can be connected to an external computer.
[0129] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0130] The modules, components, or units described in the embodiments of this disclosure can be implemented in software or hardware. The names of the modules, components, or units do not necessarily constitute a limitation on the module, component, or unit itself.
[0131] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary hardware logic components that can be used include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.
[0132] The above description is merely an illustration of some embodiments of this disclosure and the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.
[0133] While specific embodiments of this disclosure have been described in detail by way of example, those skilled in the art should understand that the examples are for illustrative purposes only and not intended to limit the scope of this disclosure. Those skilled in the art should understand that modifications can be made to the above embodiments without departing from the scope and spirit of this disclosure. The scope of this disclosure is defined by the appended claims.
Claims
1. A location service method for smart cities, characterized in that, The method, applied to edge nodes in a location service system, which at least includes an application server, comprises: Receive the location request and real-time signal feature vector sent by the target terminal from the application server; If the identity verification of the target terminal based on the location request is successful and the reputation verification of the base station connected to the target terminal is successful, a global positioning model that has been pre-trained by federated learning by multiple terminals to build a global positioning model is obtained; wherein, in each iteration of the federated learning training, the noise amount of the noise offset of the global positioning model to be built on each terminal is controlled by the privacy budget of the application server. The location information of the target terminal is obtained by processing the real-time signal feature vector using the global positioning model.
2. The method as described in claim 1, characterized in that, The location service system further includes a zero-trust engine, and the target terminal is one of the plurality of terminals; the method further includes: In each iteration of the federated learning training, if the authentication and reputation verification are successful, then in response to the location request, the target location information of the application server is obtained from the zero-trust engine; wherein, the target location information includes at least the target location accuracy level and the privacy budget corresponding to the target location accuracy level; Send the target positioning accuracy level, the privacy budget, and the encryption gradient corresponding to the target positioning accuracy level to the target terminal; The target terminal receives the noise offset obtained by performing differential privacy processing on the locally computed offset of the global localization model to be constructed based on the privacy budget; wherein the locally computed offset is obtained by the target terminal through federated learning training on the global localization model to be constructed based on the encrypted gradient; Based on the noise offset, the global localization model to be built is updated by aggregation until the global localization model to be built converges, thus obtaining the global localization model.
3. The method as described in claim 2, characterized in that, The step of obtaining the target location information of the application server from the zero-trust engine in response to the location request includes: In response to the location request, a dynamic risk assessment request is sent to the zero-trust engine. The dynamic risk assessment request carries the target terminal's digital identity credentials, the base station's reputation score, the application server's location sensitivity, and the network status. The system receives the target location information of the application server returned by the zero-trust engine based on the digital identity credential, the reputation score of the base station, the location sensitivity of the application server, and the network status.
4. The method as described in claim 2, characterized in that, The formula for calculating the noise offset is: in, This represents the noise offset of the global localization model to be constructed. This represents the locally calculated offset of the global positioning model to be constructed. Indicates Gaussian noise. Represents variance. This represents the privacy budget of the application server, which corresponds to the target positioning accuracy level of the application server. This represents the Rényi divergence order, usually taken as... , The noise amount represents the noise offset.
5. The method as described in claim 2, characterized in that, The aggregation and update process of the global localization model to be constructed is represented as follows: in, Indicates the first The model parameters of the global localization model are updated iteratively and aggregated. Indicates the first Iteration number The noise offset of the global localization model to be built is updated by each terminal. Indicates the first Iteration number The noise offset of the global localization model to be built is updated by each terminal. Indicates the first Local datasets for each terminal Indicates the first The amount of local data per terminal This represents the local dataset of the multiple terminals. Indicates the learning rate. This represents the gradient of the loss function.
6. The method as described in claim 2, characterized in that, The target positioning information also includes the retention period corresponding to the target positioning accuracy level. During the retention period when the target terminal is subjected to federated learning training, the target positioning accuracy level and the privacy budget remain unchanged.
7. The method as described in claim 1, characterized in that, The location service system further includes an identity chain, wherein the location request carries a digital identity credential issued by the identity chain for the target terminal, and the method further includes: In response to the location request, the digital identity credential of the target terminal is sent to the identity chain; Receive the current credential status returned by the identity chain based on the digital identity credential; If the current credential status meets the validity requirement, the authentication of the target terminal is determined to be successful.
8. The method as described in claim 7, characterized in that, If the target terminal accesses the location service system for the first time, the identity chain is also used to issue the digital identity credential to the target terminal.
9. The method as described in claim 1, characterized in that, The location service system further includes a data link, and the location request carries a query identifier of the base station; the method further includes: In response to the location request, the query identifier of the base station is sent to the data link; Receive the current reputation score returned by the data chain based on the query identifier; If the current reputation score is greater than the preset reputation score, the reputation verification of the base station is determined to be successful.
10. The method as described in claim 9, characterized in that, The data chain is also used to record the request hash of the location request, which includes at least the timestamp of the location request, the query identifier, the location of the base station, and relevant information of the application server.
11. The method as described in claim 9, characterized in that, The method further includes: Based on the location information of the target terminal, the evidence-based location result is sent to the data chain; wherein, the evidence-based location result includes the timestamp of the location request, the query identifier, and the location information.
12. The method as described in claim 2, characterized in that, The location request is transmitted in encrypted form, and the encryption gradient is obtained by the target terminal using a homomorphic encryption algorithm to encrypt the gradient corresponding to the target location accuracy level.
13. The method according to any one of claims 1 to 12, characterized in that, The method further includes: Based on the location information of the target terminal, a trusted location credential is returned to the application server; wherein the trusted location credential includes the location information of the target terminal, a trust score of the location information, and the target location accuracy level corresponding to the privacy budget.
14. A location service device for smart cities, characterized in that, An edge node used in a location service system, the location service system further including at least an application server, the device comprising: The communication module is used to receive the location request and real-time signal feature vector sent by the target terminal from the application server; The acquisition module is used to acquire a global positioning model that has been pre-trained by federated learning by multiple terminals to build a global positioning model, provided that the identity verification of the target terminal based on the positioning request is successful and the reputation verification of the base station connected to the target terminal is successful; wherein, in each iteration of the federated learning training, the noise amount of the noise offset of the global positioning model to be built on each terminal is controlled by the privacy budget of the application server. The processing module is used to process the real-time signal feature vector using the global positioning model to obtain the positioning information of the target terminal.
15. The apparatus as claimed in claim 14, characterized in that, The location service system also includes a zero-trust engine, and the target terminal is one of the plurality of terminals; The communication module is further configured to, in each iteration of the federated learning training, if the authentication and reputation verification are successful, respond to the location request and obtain the target location information of the application server from the zero-trust engine; wherein the target location information includes at least the target location accuracy level and the privacy budget corresponding to the target location accuracy level; The communication module is also used to send the target positioning accuracy level, the privacy budget, and the encryption gradient corresponding to the target positioning accuracy level to the target terminal; The communication module is further configured to receive the noise offset obtained by the target terminal performing differential privacy processing on the locally computed offset of the global localization model to be constructed based on the privacy budget; wherein the locally computed offset is obtained by the target terminal performing federated learning training on the global localization model to be constructed based on the cryptographic gradient; The processing module is further configured to aggregate and update the global localization model to be constructed based on the noise offset until the global localization model to be constructed converges, thereby obtaining the global localization model.
16. The apparatus as claimed in claim 15, characterized in that, The communication module is also used to send a dynamic risk assessment request to the zero-trust engine in response to the location request. The dynamic risk assessment request carries the digital identity credential of the target terminal, the reputation score of the base station, the location sensitivity of the application server, and the network status. The communication module is also used to receive the target location information of the application server returned by the zero-trust engine based on the digital identity credential, the reputation score of the base station, the location sensitivity of the application server, and the network status.
17. The apparatus as claimed in claim 15, characterized in that, The formula for calculating the noise offset is: in, This represents the noise offset of the global localization model to be constructed. This represents the locally calculated offset of the global positioning model to be constructed. Indicates Gaussian noise. Represents variance. This represents the privacy budget of the application server, which corresponds to the target positioning accuracy level of the application server. This represents the Rényi divergence order, usually taken as... , The noise amount represents the noise offset.
18. The apparatus as claimed in claim 15, characterized in that, The aggregation and update process of the global localization model to be constructed is represented as follows: in, Indicates the first The model parameters of the global localization model are updated iteratively and aggregated. Indicates the first Iteration number The noise offset of the global localization model to be built is updated by each terminal. Indicates the first Iteration number The noise offset of the global localization model to be built is updated by each terminal. Indicates the first Local datasets for each terminal Indicates the first The amount of local data per terminal This represents the local dataset of the multiple terminals. Indicates the learning rate. This represents the gradient of the loss function.
19. The apparatus as claimed in claim 15, characterized in that, The target positioning information also includes the retention period corresponding to the target positioning accuracy level. During the retention period when the target terminal is subjected to federated learning training, the target positioning accuracy level and the privacy budget remain unchanged.
20. The apparatus as claimed in claim 14, characterized in that, The location service system also includes an identity chain, and the location request carries a digital identity credential issued by the identity chain for the target terminal. The communication module is also configured to send the target terminal's digital identity credential to the identity chain in response to the location request; The communication module is also used to receive the current credential status returned by the identity chain based on the digital identity credential; The processing module is also used to determine that the target terminal's authentication is successful if the current credential status meets the validity requirements.
21. The apparatus as claimed in claim 20, characterized in that, If the target terminal accesses the location service system for the first time, the identity chain is also used to issue the digital identity credential to the target terminal.
22. The apparatus as claimed in claim 14, characterized in that, The location service system also includes a data link, and the location request carries the query identifier of the base station; The communication module is also configured to send the query identifier of the base station to the data link in response to the positioning request; The communication module is also used to receive the current reputation score returned by the data chain based on the query identifier; The processing module is also used to determine that the reputation verification of the base station has passed if the current reputation score is greater than the preset reputation score.
23. The apparatus as claimed in claim 22, characterized in that, The data chain is also used to record the request hash of the location request, which includes at least the timestamp of the location request, the query identifier, the location of the base station, and relevant information of the application server.
24. The apparatus as claimed in claim 22, characterized in that, The communication module is also used to send the evidence-based location result to the data chain based on the location information of the target terminal; wherein the evidence-based location result includes the timestamp of the location request, the query identifier, and the location information.
25. The apparatus as claimed in claim 15, characterized in that, The location request is transmitted in encrypted form, and the encryption gradient is obtained by the target terminal using a homomorphic encryption algorithm to encrypt the gradient corresponding to the target location accuracy level.
26. The apparatus as described in any one of claims 14 to 25, characterized in that, The communication module is further configured to return a trusted location credential to the application server based on the location information of the target terminal; wherein the trusted location credential includes the location information of the target terminal, a trust score of the location information, and a target location accuracy level corresponding to the privacy budget.
27. An electronic device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 12.
28. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the steps of the method described in any one of claims 1 to 12.
29. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program implements the steps of the method described in any one of claims 1 to 12.