论文标题

通过权力下放对基于位置的服务的弹性隐私保护

Resilient Privacy Protection for Location-Based Services through Decentralization

论文作者

Jin, Hongyu, Papadimitratos, Panos

论文摘要

基于位置的服务(LBSS)提供有价值的服务,并为移动用户提供便利的功能。但是,通过每个查询向LBS披露的位置和其他信息侵蚀了用户隐私。这是一个问题,尤其是因为LBS提供商可能会很诚实但很有趣,收集查询并跟踪用户的下落和推断敏感用户数据。这促使集中化和分散的位置保护计划用于LBSS:匿名和混淆LBS查询以不披露确切信息,同时仍获得有用的响应。分散的计划克服了集中计划的缺点,消除匿名者并增强用户对敏感信息的控制。但是,不安全的分散系统可能会在私人信息泄漏之外造成严重的风险。更重要的是,攻击不当设计的分散LBS隐私保护计划可能是违反用户隐私的有效且低成本的一步。我们通过提出有关移动数据共享系统的安全性增强功能来确切解决此问题。我们在保留用户活动的责任感的同时保护用户隐私,并利用主流密码学来利用化名身份验证。我们表明,根据对静态汽车测试台中实现的实验评估,可以使用现成的设备部署我们的计划。

Location-Based Services (LBSs) provide valuable services, with convenient features for mobile users. However, the location and other information disclosed through each query to the LBS erodes user privacy. This is a concern especially because LBS providers can be honest-but-curious, collecting queries and tracking users' whereabouts and infer sensitive user data. This motivated both centralized and decentralized location privacy protection schemes for LBSs: anonymizing and obfuscating LBS queries to not disclose exact information, while still getting useful responses. Decentralized schemes overcome disadvantages of centralized schemes, eliminating anonymizers, and enhancing users' control over sensitive information. However, an insecure decentralized system could create serious risks beyond private information leakage. More so, attacking an improperly designed decentralized LBS privacy protection scheme could be an effective and low-cost step to breach user privacy. We address exactly this problem, by proposing security enhancements for mobile data sharing systems. We protect user privacy while preserving accountability of user activities, leveraging pseudonymous authentication with mainstream cryptography. We show our scheme can be deployed with off-the-shelf devices based on an experimental evaluation of an implementation in a static automotive testbed.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源