Location Privacy Aggregation Testing via Fictitious Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems that use aggregated location data for location-based services may inadvertently disclose user location history by processing data from locations that do not meet the threshold minimum number of reports, violating privacy protocols.

Innovation Solution

A method and system for determining compliance with location data protocols by generating fictitious user data with locations that do not meet the threshold minimum number of reports, processing this data through a location data processing system, and identifying any inclusion of these locations in output lists to determine protocol compliance, with notifications and potential shutdown of non-compliant systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If location data from all locations is processed without threshold filtering, then the quantity of location data available for analysis increases, but user privacy protection deteriorates due to disclosure of location history from under-reported locations

Engineering Contradiction:
Improvequantity of location dataVSAvoidprivacy violation
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and removes location data from under-reported locations (locations below the threshold) from the aggregation process. By separating and excluding this problematic data subset, the system maintains privacy protection while preserving useful location data from well-reported locations for service provision.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary filtering action before location data aggregation by pre-establishing and applying minimum report thresholds. This preliminary action identifies and excludes under-reported locations in advance, preventing privacy violations before they occur during the aggregation process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a testing protocol with fictitious user data is implemented, then location privacy compliance can be verified, but device complexity increases due to additional testing infrastructure

Engineering Contradiction:
Improveprivacy complianceVSAvoidtesting infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates copies of user location data in the form of fictitious user records that replicate real user behavior patterns. These synthetic copies are used for testing and validation purposes, allowing verification of privacy compliance without handling actual sensitive user data, thus reducing the complexity of secure data management.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces fictitious user data as an intermediary between the testing system and actual user location data. This intermediary allows compliance testing to be performed without direct access to real user data, simplifying the testing infrastructure while maintaining reliable privacy verification through statistical equivalence.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10432498B1Location privacy aggregation testing
Publication Date: 2019.10.01 GOOGLE LLC
  • US10432498B1 patent drawing
  • US10432498B1 patent drawing
  • US10432498B1 patent drawing

AI summary

Aspects provide methods, systems, and recording mediums for determining compliance with a location data protocol including a threshold minimum number of location data reports by users. As an example, fictitious user data including a set of locations may be generated. The set of locations may include at least one location that does not meet the threshold minimum number of location data reports by users of the location data protocol. The fictitious user data may be provided to a location data processing system that processes user location data and outputs output data including a list of locations. The output data is received and used to determine whether the at least one location is included in the list of locations. When the at least one location is included in the list of locations, it may be determined that the location data processing system has not complied with the location data protocol.