SUPL Privacy Checking Entity for Location Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SUPL networks lack effective privacy management and authorization services, particularly in managing location-based privacy rules and conditional reporting of user locations, leading to inadequate control over the sharing of location information.

Innovation Solution

A user privacy management method and apparatus that allows users to selectively grant or deny location information sharing based on predefined privacy rules associated with specific locations, using a SUPL network structure with a SUPL Location Platform (SLP) and SUPL Positioning Center (SPC) to calculate and manage location information, and an external Privacy Checking Entity (PCE) for authorization checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If location information is transferred between mobile terminal and location server to provide location services, then positioning capability is improved, but user privacy control is worsened

Engineering Contradiction:
Improvepositioning capabilityVSAvoiduser privacy control
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The SUPL Location Platform is divided into multiple functional entities: SUPL Positioning Center (SPC) for location calculation, SUPL Location Center (SLC) for service management, and Privacy Checking Entity (PCE) for authorization. This segmentation allows location services to be provided while privacy control is maintained through dedicated authorization checks between entities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Privacy Checking Entity (PCE) acts as an intermediary between the location server and external clients. It receives positioning requests, checks authorization based on user privacy settings, and selectively grants or denies location information disclosure, thereby maintaining user privacy control while enabling legitimate positioning services.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If location information is shared with third parties, then positioning service availability is improved, but user authorization control is worsened

Engineering Contradiction:
Improvepositioning service availabilityVSAvoiduser authorization control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

User privacy settings and authorization rules are established in advance before any positioning service requests. The PCE stores and retrieves these pre-configured privacy policies to automatically determine whether to grant authorization, eliminating the need for real-time user intervention while maintaining control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides feedback mechanisms where users can define privacy rules that specify which applications or entities are authorized to access location information under certain conditions. The PCE continuously checks these rules and provides authorization decisions based on feedback from user-defined policies, enabling versatile service availability with maintained control.

Inventive Principle:
Principle #23Feedback

3Reliability

If privacy checking is performed for each positioning request, then user privacy protection is improved, but signaling overhead is worsened

Engineering Contradiction:
Improveuser privacy protectionVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The privacy checking function is merged with the existing SUPL positioning protocol flow. The PCE performs authorization checks as an integrated part of the positioning request processing, using the same user plane data bearer for communication. This merging reduces additional signaling overhead while maintaining comprehensive privacy protection.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9723087B2User privacy management apparatus and method in mobile communications system
Publication Date: 2017.08.01 LG ELECTRONICS INC
  • US9723087B2 patent drawing
  • US9723087B2 patent drawing
  • US9723087B2 patent drawing

AI summary

Provided is a user privacy management apparatus and method on a Secure User Plane Location (SUPL) network including a SUPL Location Platform (SLP) and a SUPL Enabled Terminal (SET) and performing privacy authorization according to location of the SET, wherein when the location of the SET is calculated, the SLP (or SUPL Positioning Center (SPC) within the SLP) checks a privacy setup according to the calculated location, thereafter queries to a SET user whether to execute the privacy setup using a SUPL INIT message or a SUPL NOTIFICATION message, and then executes the privacy setup according to queries and responses transmitted through a SUPL START message or a SUPL NOTIFICATION RESPONSE message, whereby a user privacy can be managed more stably by notifying a user of the privacy setup according to the location of the user for reconfirmation.