Location Privacy Cloaking via Footprint Anonymity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current location-based services lack effective privacy protection, as users' location information can be correlated with restricted spaces to reveal their identity, and existing techniques fail to provide robust location privacy, especially in continuous and frequent location updates, leading to potential misuse and privacy threats.
Innovation Solution
The proposed solution leverages historical location samples, or footprints, to cloak users' current locations, ensuring that each reported location or trajectory has been visited by at least K−1 other users, using algorithms for single location and trajectory cloaking, and employing a feeling-based privacy model to maintain anonymity by measuring the popularity of spatial regions using entropy, thus preventing identification of users' whereabouts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If users disclose their detailed location information for location-based services, then the quality and accuracy of service is improved, but their privacy and safety are compromised as adversaries can identify and locate them
Solution Approach 1:
The patent introduces an intermediary cloaking mechanism that mediates between the user's true location and the location-based service. Instead of directly disclosing the actual location, the system adds dummy location points (intermediaries) to create a cloaked location set, allowing the service to operate on approximate location data while protecting the user's true position from adversaries
Solution Approach 2:
The patent applies partial action by providing only sufficient location information needed for the service rather than complete accurate location data. By adding a controlled number of dummy points (excessive but manageable action), the system provides enough location data for LBS functionality while preventing precise identification, achieving a balance between service quality and privacy protection
2Reliability
If existing location anonymization techniques are used, then some privacy protection is provided, but they fail to provide robust protection in continuous location updates and frequent trajectory reports
Solution Approach 1:
The patent applies preliminary action by pre-generating multiple dummy location points and preparing cloaking strategies before continuous location updates occur. The system establishes a pool of dummy points in advance that can be dynamically assigned to trajectory points, ensuring robust privacy protection is already in place before adversaries can exploit continuous tracking
Solution Approach 2:
The patent ensures continuity of privacy protection by continuously applying the cloaking mechanism to each location update and trajectory point. The dummy points are dynamically assigned and updated with each location report, maintaining uninterrupted privacy protection throughout the entire duration of continuous location-based service usage
3Adaptability or versatility
If users specify a desired level of privacy protection, then personalized privacy control is achieved, but there is no convenient and effective way for users to specify their privacy requirements meaningfully
Solution Approach 1:
The patent applies parameter changes by transforming the abstract concept of privacy level into concrete, measurable parameters such as the number of dummy points added, the spatial extent of cloaking regions, and the temporal duration of protection. Users can specify privacy requirements by adjusting these parameters, making the privacy control both adaptable and operationally meaningful
Data Source
AI summary
A method for using a location-based service while preserving anonymity includes receiving a location associated with a mobile node, receiving an anonymity level associated with the mobile node, computing a region containing the location of the mobile node and a number of footprints based on the anonymity level, wherein each of the footprints from a different user, and providing the region to a location-based service to thereby preserve anonymity of the mobile node. A method also allow a mobile device or its user to specify the anonymity level by selecting a public region consistent with a user's feelings towards desired privacy.


