• DocumentCode
    77694
  • Title

    Privacy-Preserving and Content-Protecting Location Based Queries

  • Author

    Paulet, Russell ; Kaosar, Md Golam ; Xun Yi ; Bertino, Elisa

  • Author_Institution
    Sch. of Eng. & Sci., Victoria Univ., Melbourne, VIC, Australia
  • Volume
    26
  • Issue
    5
  • fYear
    2014
  • fDate
    May-14
  • Firstpage
    1200
  • Lastpage
    1210
  • Abstract
    In this paper we present a solution to one of the location-based query problems. This problem is defined as follows: (i) a user wants to query a database of location data, known as Points Of Interest (POIs), and does not want to reveal his/her location to the server due to privacy concerns; (ii) the owner of the location data, that is, the location server, does not want to simply distribute its data to all users. The location server desires to have some control over its data, since the data is its asset. We propose a major enhancement upon previous solutions by introducing a two stage approach, where the first step is based on Oblivious Transfer and the second step is based on Private Information Retrieval, to achieve a secure solution for both parties. The solution we present is efficient and practical in many scenarios. We implement our solution on a desktop machine and a mobile device to assess the efficiency of our protocol. We also introduce a security model and analyse the security in the context of our protocol. Finally, we highlight a security weakness of our previous work and present a solution to overcome it.
  • Keywords
    data protection; mobile computing; query processing; POIs; content-protecting location based query; desktop machine; location data; location server; mobile device; oblivious transfer; point of interest; privacy-preserving; private information retrieval; protocol; security model; two stage approach; Databases; Mobile communication; Mobile handsets; Privacy; Protocols; Security; Servers; Location based query; Oblivious transfer; Private information retrieval; Private query; oblivious transfer; private information retrieval; private query;
  • fLanguage
    English
  • Journal_Title
    Knowledge and Data Engineering, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1041-4347
  • Type

    jour

  • DOI
    10.1109/TKDE.2013.87
  • Filename
    6520849