Trajectory Anonymization by Cropping Origin and Destination Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anonymization strategies for location-based services are tailored to specific use cases, leading to increased privacy risks or reduced data utility when applied to different use cases, and there is a lack of strategies that provide high utility for both traffic congestion estimation and commuting pattern analysis.
Innovation Solution
A method that anonymizes trajectories by cropping the initial and final sections of the trajectory to introduce uncertainty about the origin and destination, using generalized timestamps and areas based on population density, geographical boundaries, and map features to maintain privacy while preserving data utility for multiple use cases.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If existing anonymization strategies are applied to trajectories, then privacy risks are reduced for specific use cases, but data utility is reduced when applied to different use cases
Solution Approach 1:
The patent applies a universal anonymization strategy that simultaneously protects privacy across multiple use cases including traffic congestion estimation and commuting pattern analysis. The method crops initial and final trajectory sections and generalizes timestamps in a way that provides high utility for both use cases, making the anonymization approach multi-functional rather than tailored to a single application.
Solution Approach 2:
The patent changes key parameters of the trajectory data by cropping spatial sections (removing initial and final points) and temporal information (generalyzing timestamps). These parameter modifications reduce privacy risks while preserving sufficient data utility for multiple analytical purposes, demonstrating how parameter transformation can resolve the contradiction between privacy protection and data usefulness.
2Object-affected harmful factors
If trajectory data is anonymized by removing identifying information, then privacy is protected, but data utility for analysis is reduced
Solution Approach 1:
The patent extracts and removes only the critical identifying portions of trajectory data - specifically the initial and final sections that reveal origin and destination, as well as precise timestamps. By taking out only these essential privacy-sensitive elements rather than the entire trajectory, the method protects privacy while retaining sufficient information for traffic and commuting analysis.
Solution Approach 2:
The patent applies partial anonymization by cropping only the initial and final sections of trajectories rather than removing all identifying information. This partial action is sufficient to protect privacy (the most critical portions containing origin/destination) while preserving enough trajectory data to maintain high utility for both traffic congestion estimation and commuting pattern analysis.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method, apparatus, and computer program product are provided for anonymizing a trajectory. Methods may include: receiving a sequence of probe data points defining a trajectory having an origin location and a destination location; determining, from the origin location, an origin area that includes the origin location; determining, from the destination location, a destination location that includes the destination location; determining an origin timestamp based on a first probe data point of the trajectory outside of the origin area; determining a destination timestamp based on a last probe data point of the trajectory outside of the destination area; generating a shared trajectory beginning with the first probe data point of the trajectory outside of the origin area and ending with the last probe data point of the trajectory outside of the destination area; and publishing the shared trajectory including the origin timestamp and the destination timestamp to a service provider.