Map-Matched Sensor Data Anonymization for Location Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of maintaining user anonymity while providing accurate location-based services using sensor data, as the data can reveal sensitive information such as home addresses and travel patterns, is not adequately addressed by existing technologies, which often compromise privacy for data accuracy.
Innovation Solution
Anonymization of sensor data is achieved through the use of map data by determining specific amounts (N and K) of sensor data to be removed from the beginning and end of a trajectory based on functional road classes, ensuring privacy while retaining valuable location information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If sensor data is retained in full detail for location-based services, then service accuracy is improved, but user privacy is compromised
Solution Approach 1:
The patent extracts and removes specific portions of sensor data (N elements from start, K elements from end) that contain sensitive location information such as home addresses and frequent destinations, while retaining the intermediate data that is less sensitive but still useful for location-based services. This selective extraction resolves the contradiction by removing harmful privacy-revealing data while preserving service-accurate data.
Solution Approach 2:
The patent applies different anonymization treatments to different parts of the trajectory data. The start and end portions (which contain sensitive static location information) are heavily redacted, while the intermediate portions (which contain dynamic travel pattern information) are retained with less redaction. This local differentiation resolves the contradiction by applying varying degrees of privacy protection based on the sensitivity of each data segment.
2Object-affected harmful factors
If sensor data is redacted to protect privacy, then user anonymity is improved, but data utility is reduced
Solution Approach 1:
The patent applies partial redaction rather than complete anonymization. By removing only N and K elements from the trajectory rather than all identifying information, the patent achieves sufficient anonymity protection while preserving enough data utility for location-based services to function effectively. This partial action resolves the contradiction by finding the optimal balance between privacy protection and data usefulness.
Solution Approach 2:
The patent changes the parameter of data completeness by selectively removing specific portions of the trajectory. Instead of maintaining full data integrity or complete anonymization, the system adjusts the data parameter to retain only the necessary intermediate elements that provide service utility without revealing sensitive start/end location information, thus resolving the contradiction between anonymity and utility.
3Object-affected harmful factors
If trajectory data is anonymized by removing elements, then privacy is improved, but temporal accuracy is degraded
Solution Approach 1:
The patent performs preliminary map-matching of the sensor data to road network elements before redacting portions of the trajectory. This preliminary action establishes the temporal and spatial context of the data, allowing the system to remove N and K elements while maintaining accurate timestamp information and road segment associations for the remaining data, thus preserving temporal accuracy despite redaction.
Solution Approach 2:
The patent creates a map-matched copy of the original sensor data that preserves the temporal structure and road network relationships. Even when portions are redacted for privacy, the remaining elements maintain their original timestamps and spatial relationships in the map-matched representation, resolving the contradiction by preserving temporal accuracy in the anonymized output.
Data Source
AI summary
Embodiments described herein relate to anonymizing sensor data through the use of map data. Methods include: receiving sensor data defining a trajectory; map-matching the sensor data using a map-matching algorithm to a plurality of road segments of a map database to generate a sequence of map-matched sensor data elements; determining a first value representing anonymization associated with a start of the trajectory; determining a second value representing anonymization associated with an end of the trajectory; determining first map-matched sensor data elements at the start of the trajectory to be redacted based on the first value; determining second map-matched sensor data elements at the end of the trajectory to be redacted based on the second value; and transmitting sensor data associated with elements in the sequence of map-matched sensor data elements between the first map-matched sensor data elements and the second map-matched sensor data elements.


