Issue No. 05 - May (2014 vol. 26)
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/TKDE.2013.87
Russell Paulet , Sch. of Eng. & Sci., Victoria Univ., Melbourne, VIC, Australia
Md Golam Kaosar , Sch. of Eng. & Sci., Victoria Univ., Melbourne, VIC, Australia
Xun Yi , Sch. of Eng. & Sci., Victoria Univ., Melbourne, VIC, Australia
Elisa Bertino , Dept. of Comput. Sci., Purdue Univ., West Lafayette, IN, USA
In this paper we present a solution to one of the location-based query problems. This problem is defined as follows: (i) a user wants to query a database of location data, known as Points Of Interest (POIs), and does not want to reveal his/her location to the server due to privacy concerns; (ii) the owner of the location data, that is, the location server, does not want to simply distribute its data to all users. The location server desires to have some control over its data, since the data is its asset. We propose a major enhancement upon previous solutions by introducing a two stage approach, where the first step is based on Oblivious Transfer and the second step is based on Private Information Retrieval, to achieve a secure solution for both parties. The solution we present is efficient and practical in many scenarios. We implement our solution on a desktop machine and a mobile device to assess the efficiency of our protocol. We also introduce a security model and analyse the security in the context of our protocol. Finally, we highlight a security weakness of our previous work and present a solution to overcome it.
query processing, data protection, mobile computing
R. Paulet, M. G. Kaosar, Xun Yi and E. Bertino, "Privacy-Preserving and Content-Protecting Location Based Queries," in IEEE Transactions on Knowledge & Data Engineering, vol. 26, no. 5, pp. 1200-1210, 2014.