5G Positioning: Security and Privacy Aspects 303
13.10.3 Cryptographic Techniques for Privacy‐Preserving
Location‐based Services
Privacy is a major concern in location‐based services. Current services set a lot of trust
on the LBSP, because they typically require full disclosure of the end‐user’s location.
Cryptography also has potential to improve the privacy of location‐based services. Fully
Homomorphic Encryption (FHE) [22], the greatest triumph of recent theoretical cryptography, offers a promise of privacy‐preserving cloud computing and, consequently,
also privacy‐preserving LBSP. Traditional encryption requires data to be decrypted
before it can be processed, but FHE allows computing arbitrary functions with encrypted
data so that results are correct after decryption. If the end‐user uses FHE to encrypt its
location, then the LBSP (and LISP) can do computations with this data so that the result
can be decrypted only by the end‐user, as shown in Figure 13.8.
Unfortunately, FHE is computationally too demanding for practical purposes. In
practice, the capability to perform arbitrary computations can be traded for better
performance. Certain cryptosystems are partially homomorphic so that they allow,
for  example, only additions with encrypted data (e.g. the Paillier cryptosystem [92]).
Other (more expensive) alternatives are somewhat homomorphic encryptions, which
allow both additions and multiplications (similarly to FHE), but so that the number of
consecutive operations (multiplications) is limited, thus limiting the complexity of possible computations. Other related concepts, such as multiparty computation (e.g. [94]),
which allows two (or more) parties to jointly evaluate a function without revealing their
own inputs to each other, or functional encryption [29], which allows setting keys that
allow decrypting a certain predefined function of the encrypted data but not the data
itself, may also have a role in solving the privacy aspects of location‐based services.
Differential privacy techniques ([21]) that protect individual records in statistical datasets can also improve privacy of certain location‐based services.
Because large‐scale use of the aforementioned general privacy‐preserving cryptographic schemes (and FHE in particular) can be too heavy for most practical applications, privacy must be ensured by other means. Typically, this means that schemes are
carefully tailored for a specific use case. Examples of such can be found in the academic
literature. For example, [51] presented techniques for privacy‐preserving electronic
toll  pricing combining multiple cryptographic techniques (digital signatures,
Encrypted position π
Encrypted result σ
LBSP
Decrypting σ gives
the result f (p)
Computes σ = f (π)
without learning p
Position p
Figure 13.8 A privacy‐preserving LBSP based on FHE, which computes a position‐related function f(p)
on fully homomorphically encrypted data without learning the end‐user’s position p.
Précédent

- 345/483

Suivant