Position Data Anonymization via Multi-Dimensional L-Diversity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anonymization techniques for position data from mobile terminals often fail to effectively protect user privacy, especially when analyzing a plurality of position data points, as they may reveal sensitive information about a user's habits or locations, and current systems struggle to maintain anonymity when the data does not overlap sufficiently.
Innovation Solution
The proposed solution involves an information management apparatus that processes position data from multiple mobile terminals by generating nodes from user identification data and movement data, applying abstraction schemes to anonymize the data, and ensuring that the anonymized data sets meet predetermined diversity thresholds, such as l-diversity and multi-dimensional l-diversity, to prevent user identification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing anonymization techniques (k-anonymity, 1-diversity) are applied to position data, then user anonymity is improved, but the data utility for analyzing user habits and locations deteriorates
Solution Approach 1:
The patent segments position data into multiple dimensions (location, time, movement pattern, duration) and applies different anonymization strategies to each dimension. This allows maintaining utility in some dimensions while protecting privacy in others, resolving the contradiction between anonymity and data utility.
Solution Approach 2:
The patent introduces multi-dimensional l-diversity that operates across multiple data dimensions simultaneously. By extending anonymization from single-dimensional k-anonymity to multi-dimensional space, the system maintains data utility across dimensions while ensuring privacy protection, addressing the limitation of existing techniques.
2Reliability
If position data is anonymized using traditional methods, then individual user identification is prevented, but patterns of user behavior and location preferences can still be inferred
Solution Approach 1:
The patent applies anonymization processing before data release or analysis, preemptively removing identifying characteristics across multiple dimensions. This preliminary action prevents both direct identification and indirect inference of user habits, as the anonymization is performed upfront rather than attempting to protect against future inference attacks.
Solution Approach 2:
The patent creates a composite anonymization approach that combines multiple techniques (k-anonymity, l-diversity, multi-dimensional constraints) into a unified framework. This composite approach addresses both direct identification and pattern inference by layering multiple protection mechanisms.
3Productivity
If multiple position data points are analyzed together, then more insights about user behavior are obtained, but the risk of user identification and privacy violation increases
Solution Approach 1:
The patent extends anonymization from single data points to multi-dimensional datasets by implementing multi-dimensional l-diversity. This allows analyzing multiple position data points together for insights while maintaining privacy protection across the entire multi-dimensional space, preventing both identification and pattern inference even when data is analyzed collectively.
Solution Approach 2:
The patent introduces anonymized position data as an intermediary between raw position data and analysis results. This intermediary layer allows analytical processing to extract insights while the anonymization properties prevent privacy violations, enabling productive analysis without direct access to identifying information.
Data Source
AI summary
An information management apparatus receives position data from each terminal device. The position data contains position measurement data showing its positions at multiple clock times and its user identification data. The apparatus creates action history for every user based on the position data, and abstracts the position data in the action history. The apparatus includes an abstracting section and a testing section. The abstracting section abstracts arbitrary position data in the action history of a certain user. The testing section extracts another action history of another user. The other action history includes position data of the other user which shows a position same as or included in a position of the abstracted position data of the certain user, but excludes position data of the other user which shows positions same as remaining position of the certain user. The testing section outputs the abstracted position data as anonymity data.


