Privacy Risk Quantification in Location Trajectories
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The aggregation of mobility traces data for location-based services poses a risk to user privacy, as it can be traced back to individual users, potentially harming their safety and security, and existing anonymization methods like splitting trajectories may not adequately protect against reconstruction attacks.
Innovation Solution
A method and apparatus for quantifying privacy risk in geographic data by receiving trajectory data, identifying sub-trajectories, defining a candidate list for reconstruction, calculating a reconstruction rate, and providing this rate as a privacy risk quantification to external devices, which includes a database, a sub-trajectory module, a candidate list calculator, and a provision module to assess and improve anonymization effectiveness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If trajectory data is aggregated for location-based services, then the usefulness and productivity of the data is improved, but user privacy security deteriorates
Solution Approach 1:
The patent divides trajectories into multiple sub-trajectories by introducing artificial gaps at random intervals, so that individual trajectory segments cannot be easily linked back to specific users, thereby protecting privacy while maintaining data utility for aggregation
2Object-affected harmful factors
If trajectories are split into sub-trajectories for anonymization, then user privacy protection is improved, but the ability to reconstruct original trajectories deteriorates
Solution Approach 1:
The patent pre-calculates and stores metadata about sub-trajectories including start/end times, locations, and gap characteristics before any reconstruction attempt. This preliminary organization enables efficient verification of anonymization effectiveness and detection of potential reconstruction attacks
Solution Approach 2:
The patent implements a feedback mechanism that quantifies privacy risk by analyzing the relationship between sub-trajectory gaps and potential reconstruction success rates, allowing the system to adjust anonymization parameters dynamically based on measured privacy protection effectiveness
3Object-affected harmful factors
If anonymization parameters are adjusted to increase privacy protection, then user security is improved, but data utility for analysis deteriorates
Solution Approach 1:
The patent employs dynamic anonymization where gap intervals and sub-trajectory segmentation parameters are adjusted adaptively based on the specific characteristics of each trajectory and the required analysis type, optimizing the balance between privacy protection and data utility rather than applying fixed anonymization rules
Data Source
AI summary
An apparatus for the quantification of privacy risk in geographic data for probe devices in a geographic region includes a database, a sub-trajectory module, a candidate list calculator, and a provision module. The database is configured to store trajectory data based on sequences of sensor measurements. The sub-trajectory module is configured to receive trajectory data points based on sequences of sensor measurements of the probe devices collected in the geographic region and determine sub-trajectories from changes in trajectory identifiers. The candidate list calculator is configured to concatenate at least two of the sub-trajectories based on at least one concatenation parameter. The provision module is configured to calculate a reconstruction rate in the trajectory data and provide the reconstruction rate for a quantification of privacy risk to an external device.


