Privacy-Preserving Location Service Provisioning via Secret Key Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing location-based services face challenges in preserving user privacy, as they often require access to the exact location of the user, leading to potential privacy concerns.
Innovation Solution
A system where the location information of a target device is encrypted and partitioned among multiple devices, using secret sub-keys to generate a secure key for decryption, allowing access to location-based service data without exposing the location information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If location-based services access the exact location of the user, then service customization and accuracy are improved, but user privacy is compromised
Solution Approach 1:
The patent segments the secret key into multiple secret sub-keys, each held by different devices. The complete location information remains encrypted and cannot be accessed by any single device, including the location-based service provider. This segmentation enables precise location-based services while protecting user privacy through distributed key management.
Solution Approach 2:
The patent introduces a first device as an intermediary that facilitates service provision without directly accessing the user's location information. The first device enables the location-based service to obtain service data without exposing the actual location, acting as a mediator that preserves privacy while enabling service functionality.
2Reliability
If encrypted location information is used to protect privacy, then privacy security is improved, but access to location-based service data becomes more complex
Solution Approach 1:
The encryption system is simplified through key segmentation rather than complex encryption protocols. By dividing the secret key into multiple sub-keys distributed across different devices, the system achieves strong security without requiring complex encryption algorithms, reducing overall system complexity while maintaining high privacy security.
Solution Approach 2:
The first device automatically manages the key generation, distribution, and coordination process without requiring direct user intervention for each service access. The system self-manages the cryptographic operations, reducing the operational complexity for users while maintaining strong privacy protections.
3Object-affected harmful factors
If secret keys are distributed among multiple devices, then privacy protection is improved, but key management and coordination become more difficult
Solution Approach 1:
The first device automatically performs key management functions including generation, distribution, and coordination of secret sub-keys across multiple devices. This self-service mechanism eliminates the need for manual key management by users, making the distributed key system easy to operate while maintaining strong privacy protection through automatic coordination.
Solution Approach 2:
The first device serves multiple functions: it acts as a key management server, a coordination intermediary, and an authentication authority. This multi-functional design consolidates complex key management operations into a single device that can handle multiple aspects of the distributed key system, simplifying overall key management while improving privacy protection.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Example embodiments of the present disclosure relate to privacy-preserving service provision. A first device receives, from a second device, a request for provisioning data of a location-based service from the second device to a third device, the request comprising first secret sub-key associated with the third device. The first device generates a first secret key for the third device based on the first secret sub-key and second secret sub-key associated with the third device, and decrypts encrypted location information of the third device using the first secure key. The first device accesses the data of the location-based service from the second device based on the decrypted location information of the third device and provides the data of the location-based service to the third device. Through this solution, privacy of location information of a target device can be preserved during provisioning of a service.