Privacy-Preserving Location Services with Hashed Bloom Filters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing location-based services often compromise user privacy by allowing third parties to access sensitive location data, even when it is not necessary for the application's functionality, risking user privacy and security.

Innovation Solution

Utilizing probabilistic data structures like Bloom filters and one-way hash functions to store and query location data, ensuring that third parties cannot link location information to individual devices, while enabling privacy-preserving location services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If location data is made accessible to third-party applications, then location services functionality is improved, but user privacy is worsened

Engineering Contradiction:
Improvelocation services functionalityVSAvoiduser privacy risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a server as an intermediary between the mobile device and third-party applications. The server receives location data from the device, processes it, and returns only the necessary information to applications without exposing the full location history or identifying user patterns. This mediator architecture allows location services to function while preventing direct access to sensitive user location data by third parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts only the necessary location information from the complete location history and presents it to third-party applications. Instead of providing full access to location data, the system selectively extracts and shares only the specific location records needed for the current service request, thereby maintaining functionality while minimizing privacy exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

2Productivity

If complete location history is provided to applications, then location-based services are improved, but data security is worsened

Engineering Contradiction:
Improvelocation-based services capabilityVSAvoiddata security risk
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent applies partial action by providing only the necessary portion of location data to applications rather than the complete history. The system retrieves and shares only the specific location records relevant to the current service request, avoiding the security risks associated with exposing comprehensive location histories while maintaining sufficient functionality for the service.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent segments location data into individual records that can be selectively accessed and shared. Instead of providing a monolithic complete location history, the system divides the data into discrete, manageable records that can be retrieved and shared in controlled portions, reducing the security impact of any single data exposure event.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If location data is stored and processed on third-party servers, then application functionality is improved, but privacy protection is worsened

Engineering Contradiction:
Improveapplication functionalityVSAvoidprivacy protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent positions the server as a controlled intermediary that processes location data under the user's authorization. The server acts as a trusted mediator that performs necessary processing while maintaining privacy through controlled data access, distinguishing itself from unauthorized third-party servers that would directly expose user location information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action through the authorization mechanism, where users must explicitly grant permission before location data is processed by the server. This preliminary authorization step ensures that privacy protection is established before any data processing occurs, allowing application functionality to proceed only with user consent.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If location access is granted to applications, then service functionality is improved, but unnecessary data exposure is worsened

Engineering Contradiction:
Improveservice functionalityVSAvoidunnecessary location data exposure
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent extracts only the specific location records needed for the current service request from the complete location history. The system identifies and retrieves only the necessary portion of data, preventing unnecessary location information from being exposed to applications while maintaining full service functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by providing only the necessary portion of location data to applications rather than the complete history. The system retrieves and shares only the specific location records relevant to the current service request, avoiding the security risks associated with exposing comprehensive location histories while maintaining sufficient functionality for the service.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250227462A1Privacy preserving location services
Publication Date: 2025.07.10 AT&T INTELLECTUAL PROPERTY I L P
  • US20250227462A1 patent drawing
  • US20250227462A1 patent drawing
  • US20250227462A1 patent drawing

AI summary

Aspects of the subject disclosure may include, for example, accessing registration information that includes a criterion for allowing receiving notifications based on location information of a communication device, accessing a location request of equipment of a location requestor that includes a notification location, accessing encrypted information representative of identification information, the location information, and time information of the communication device that has been stored in a database where the time information corresponds to the location information, identifying a positive result for the location request, and causing a notification to be provided to the communication device responsive to the positive result, where the notification is associated with the location requestor, and wherein the notification is provided to the communication device without providing the identification information of the communication device to the equipment of the location requestor. Other embodiments are disclosed.