SUPL Privacy Checking Entity for Location Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current SUPL networks lack effective privacy management and authorization services, particularly in managing location-based privacy rules and conditional reporting of user locations, leading to inadequate control over the sharing of location information.
Innovation Solution
A user privacy management method and apparatus that allows users to selectively grant or deny location information sharing based on predefined privacy rules associated with specific locations, using a SUPL network structure with a SUPL Location Platform (SLP) and SUPL Positioning Center (SPC) to calculate and manage location information, and an external Privacy Checking Entity (PCE) for authorization checks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If location information is transferred between mobile terminal and location server to provide location services, then positioning capability is improved, but user privacy control is worsened
Solution Approach 1:
The SUPL Location Platform is divided into multiple functional entities: SUPL Positioning Center (SPC) for location calculation, SUPL Location Center (SLC) for service management, and Privacy Checking Entity (PCE) for authorization. This segmentation allows location services to be provided while privacy control is maintained through dedicated authorization checks between entities.
Solution Approach 2:
The Privacy Checking Entity (PCE) acts as an intermediary between the location server and external clients. It receives positioning requests, checks authorization based on user privacy settings, and selectively grants or denies location information disclosure, thereby maintaining user privacy control while enabling legitimate positioning services.
2Adaptability or versatility
If location information is shared with third parties, then positioning service availability is improved, but user authorization control is worsened
Solution Approach 1:
User privacy settings and authorization rules are established in advance before any positioning service requests. The PCE stores and retrieves these pre-configured privacy policies to automatically determine whether to grant authorization, eliminating the need for real-time user intervention while maintaining control.
Solution Approach 2:
The system provides feedback mechanisms where users can define privacy rules that specify which applications or entities are authorized to access location information under certain conditions. The PCE continuously checks these rules and provides authorization decisions based on feedback from user-defined policies, enabling versatile service availability with maintained control.
3Reliability
If privacy checking is performed for each positioning request, then user privacy protection is improved, but signaling overhead is worsened
Solution Approach 1:
The privacy checking function is merged with the existing SUPL positioning protocol flow. The PCE performs authorization checks as an integrated part of the positioning request processing, using the same user plane data bearer for communication. This merging reduces additional signaling overhead while maintaining comprehensive privacy protection.
Data Source
AI summary
Provided is a user privacy management apparatus and method on a Secure User Plane Location (SUPL) network including a SUPL Location Platform (SLP) and a SUPL Enabled Terminal (SET) and performing privacy authorization according to location of the SET, wherein when the location of the SET is calculated, the SLP (or SUPL Positioning Center (SPC) within the SLP) checks a privacy setup according to the calculated location, thereafter queries to a SET user whether to execute the privacy setup using a SUPL INIT message or a SUPL NOTIFICATION message, and then executes the privacy setup according to queries and responses transmitted through a SUPL START message or a SUPL NOTIFICATION RESPONSE message, whereby a user privacy can be managed more stably by notifying a user of the privacy setup according to the location of the user for reconfirmation.


