Privacy Risk Quantification in Location Trajectories

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The aggregation of mobility traces data for location-based services poses a risk to user privacy, as it can be traced back to individual users, potentially harming their safety and security, and existing anonymization methods like splitting trajectories may not adequately protect against reconstruction attacks.

Innovation Solution

A method and apparatus for quantifying privacy risk in geographic data by receiving trajectory data, identifying sub-trajectories, defining a candidate list for reconstruction, calculating a reconstruction rate, and providing this rate as a privacy risk quantification to external devices, which includes a database, a sub-trajectory module, a candidate list calculator, and a provision module to assess and improve anonymization effectiveness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If trajectory data is aggregated for location-based services, then the usefulness and productivity of the data is improved, but user privacy security deteriorates

Engineering Contradiction:
Improveusefulness of trajectory dataVSAvoiduser privacy risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent divides trajectories into multiple sub-trajectories by introducing artificial gaps at random intervals, so that individual trajectory segments cannot be easily linked back to specific users, thereby protecting privacy while maintaining data utility for aggregation

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If trajectories are split into sub-trajectories for anonymization, then user privacy protection is improved, but the ability to reconstruct original trajectories deteriorates

Engineering Contradiction:
Improveprivacy protectionVSAvoidanonymization effectiveness
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent pre-calculates and stores metadata about sub-trajectories including start/end times, locations, and gap characteristics before any reconstruction attempt. This preliminary organization enables efficient verification of anonymization effectiveness and detection of potential reconstruction attacks

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism that quantifies privacy risk by analyzing the relationship between sub-trajectory gaps and potential reconstruction success rates, allowing the system to adjust anonymization parameters dynamically based on measured privacy protection effectiveness

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If anonymization parameters are adjusted to increase privacy protection, then user security is improved, but data utility for analysis deteriorates

Engineering Contradiction:
Improveuser securityVSAvoiddata utility
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent employs dynamic anonymization where gap intervals and sub-trajectory segmentation parameters are adjusted adaptively based on the specific characteristics of each trajectory and the required analysis type, optimizing the balance between privacy protection and data utility rather than applying fixed anonymization rules

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11042648B2Quantification of privacy risk in location trajectories
Publication Date: 2021.06.22 HERE GLOBAL BV
  • US11042648B2 patent drawing
  • US11042648B2 patent drawing
  • US11042648B2 patent drawing

AI summary

An apparatus for the quantification of privacy risk in geographic data for probe devices in a geographic region includes a database, a sub-trajectory module, a candidate list calculator, and a provision module. The database is configured to store trajectory data based on sequences of sensor measurements. The sub-trajectory module is configured to receive trajectory data points based on sequences of sensor measurements of the probe devices collected in the geographic region and determine sub-trajectories from changes in trajectory identifiers. The candidate list calculator is configured to concatenate at least two of the sub-trajectories based on at least one concatenation parameter. The provision module is configured to calculate a reconstruction rate in the trajectory data and provide the reconstruction rate for a quantification of privacy risk to an external device.