Trajectory Anonymization by Cropping Origin and Destination Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anonymization strategies for location-based services are tailored to specific use cases, leading to increased privacy risks or reduced data utility when applied to different use cases, and there is a lack of strategies that provide high utility for both traffic congestion estimation and commuting pattern analysis.

Innovation Solution

A method that anonymizes trajectories by cropping the initial and final sections of the trajectory to introduce uncertainty about the origin and destination, using generalized timestamps and areas based on population density, geographical boundaries, and map features to maintain privacy while preserving data utility for multiple use cases.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If existing anonymization strategies are applied to trajectories, then privacy risks are reduced for specific use cases, but data utility is reduced when applied to different use cases

Engineering Contradiction:
Improveprivacy risksVSAvoiddata utility for different use cases
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent applies a universal anonymization strategy that simultaneously protects privacy across multiple use cases including traffic congestion estimation and commuting pattern analysis. The method crops initial and final trajectory sections and generalizes timestamps in a way that provides high utility for both use cases, making the anonymization approach multi-functional rather than tailored to a single application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes key parameters of the trajectory data by cropping spatial sections (removing initial and final points) and temporal information (generalyzing timestamps). These parameter modifications reduce privacy risks while preserving sufficient data utility for multiple analytical purposes, demonstrating how parameter transformation can resolve the contradiction between privacy protection and data usefulness.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If trajectory data is anonymized by removing identifying information, then privacy is protected, but data utility for analysis is reduced

Engineering Contradiction:
Improveprivacy exposureVSAvoidtrajectory utility
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent extracts and removes only the critical identifying portions of trajectory data - specifically the initial and final sections that reveal origin and destination, as well as precise timestamps. By taking out only these essential privacy-sensitive elements rather than the entire trajectory, the method protects privacy while retaining sufficient information for traffic and commuting analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial anonymization by cropping only the initial and final sections of trajectories rather than removing all identifying information. This partial action is sufficient to protect privacy (the most critical portions containing origin/destination) while preserving enough trajectory data to maintain high utility for both traffic congestion estimation and commuting pattern analysis.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4421450B1Method, apparatus, and computer program product for anonymizing trajectories
Publication Date: 2025.12.31 HERE GLOBAL BV
  • EP4421450B1 patent drawingFigure 1
  • EP4421450B1 patent drawingFigure 2
  • EP4421450B1 patent drawingFigure 3

AI summary

A method, apparatus, and computer program product are provided for anonymizing a trajectory. Methods may include: receiving a sequence of probe data points defining a trajectory having an origin location and a destination location; determining, from the origin location, an origin area that includes the origin location; determining, from the destination location, a destination location that includes the destination location; determining an origin timestamp based on a first probe data point of the trajectory outside of the origin area; determining a destination timestamp based on a last probe data point of the trajectory outside of the destination area; generating a shared trajectory beginning with the first probe data point of the trajectory outside of the origin area and ending with the last probe data point of the trajectory outside of the destination area; and publishing the shared trajectory including the origin timestamp and the destination timestamp to a service provider.