Trajectory Anonymization by Map Tile Removal for Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing location-based services face challenges in maintaining user anonymity while providing accurate and timely information, as current anonymization strategies are often tailored to specific use cases and can lead to reduced data utility or increased privacy risks when applied across different use cases.
Innovation Solution
A second-level anonymization strategy is employed to identify and remove subsets of mobility data that fail to meet predefined anonymity parameters, applying a re-anonymization level to ensure high utility and enhanced privacy, particularly in areas of low data density or trajectory reconstruction risk.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a first level of anonymization is applied to mobility data, then data utility is maintained for location-based services, but trajectory reconstruction and re-identification risks remain
Solution Approach 1:
The geographic area is divided into multiple map tiles, and the anonymization process is applied independently to each tile. This segmentation allows the system to identify and remove problematic data in specific regions without affecting the entire dataset, thereby reducing trajectory reconstruction risks while maintaining overall data utility for location-based services.
Solution Approach 2:
Before publishing mobility data, the system performs a preliminary analysis to identify map tiles where the first level of anonymization is insufficient. This preliminary action enables the system to apply a second level of anonymization or remove data from specific tiles proactively, preventing trajectory reconstruction attacks before they can occur.
2Reliability
If mobility data is removed from map tiles with low data density, then anonymity is improved, but data utility for location-based services is reduced
Solution Approach 1:
The system applies different anonymization strategies to different map tiles based on their local characteristics. In map tiles with low data density where anonymity is compromised, the system either applies enhanced anonymization or removes data selectively. In map tiles with sufficient data density, the first level of anonymization is maintained to preserve data utility. This localized approach ensures that anonymity is improved where necessary without unnecessarily reducing overall data utility.
3Reliability
If a second level of anonymization is applied to all mobility data, then privacy is enhanced, but data utility and processing efficiency are reduced
Solution Approach 1:
The system performs a preliminary analysis of mobility data to identify specific map tiles where the first level of anonymization is insufficient. By targeting only these specific tiles for a second level of anonymization rather than applying it universally, the system enhances privacy where needed while avoiding unnecessary processing of data that already meets anonymity requirements, thereby maintaining data processing efficiency.
Solution Approach 2:
The mobility data is segmented by geographic location into map tiles, allowing the system to apply the second level of anonymization only to specific segments (tiles with insufficient anonymity) rather than the entire dataset. This segmented approach enhances privacy in problematic areas while preserving processing efficiency by avoiding redundant anonymization operations on already-sufficient data.
Data Source
AI summary
A method, apparatus, and computer program product are provided for establishing and applying a second level of anonymization of trajectories to improve privacy. Methods may include: receiving anonymized mobility data for a geographic region subdivided into a plurality of map tiles, where the mobility data includes a plurality of probe data points anonymized with a first anonymization level, where sequences of probe data points define trajectories; determining, based on the anonymized mobility data, one or more map tiles of the plurality of map tiles where anonymization of trajectories using the first anonymization level fails to satisfy a predefined anonymity parameter value; removing a subset of the anonymized mobility data corresponding to the one or more map tiles; and publishing the anonymized mobility data without the subset of the mobility data corresponding to the one or more map tiles for use with one or more location-based services.


