, Volume 15, Issue 4, pp 699–726 | Cite as

Approximate and exact hybrid algorithms for private nearest-neighbor queries with database protection

  • Gabriel GhinitaEmail author
  • Panos Kalnis
  • Murat Kantarcioglu
  • Elisa Bertino


Mobile devices with global positioning capabilities allow users to retrieve points of interest (POI) in their proximity. To protect user privacy, it is important not to disclose exact user coordinates to un-trusted entities that provide location-based services. Currently, there are two main approaches to protect the location privacy of users: (i) hiding locations inside cloaking regions (CRs) and (ii) encrypting location data using private information retrieval (PIR) protocols. Previous work focused on finding good trade-offs between privacy and performance of user protection techniques, but disregarded the important issue of protecting the POI dataset D. For instance, location cloaking requires large-sized CRs, leading to excessive disclosure of POIs (O(|D|) in the worst case). PIR, on the other hand, reduces this bound to \(O(\sqrt{|D|})\), but at the expense of high processing and communication overhead. We propose hybrid, two-step approaches for private location-based queries which provide protection for both the users and the database. In the first step, user locations are generalized to coarse-grained CRs which provide strong privacy. Next, a PIR protocol is applied with respect to the obtained query CR. To protect against excessive disclosure of POI locations, we devise two cryptographic protocols that privately evaluate whether a point is enclosed inside a rectangular region or a convex polygon. We also introduce algorithms to efficiently support PIR on dynamic POI sub-sets. We provide solutions for both approximate and exact NN queries. In the approximate case, our method discloses O(1) POI, orders of magnitude fewer than CR- or PIR-based techniques. For the exact case, we obtain optimal disclosure of a single POI, although with slightly higher computational overhead. Experimental results show that the hybrid approaches are scalable in practice, and outperform the pure-PIR approach in terms of computational and communication overhead.


Location privacy Private information retrieval Homomorphic encryption 


  1. 1.
    Gruteser M, Grunwald D (2003) Anonymous usage of location-based services through spatial and temporal cloaking. In: Proc. of USENIX MobiSysGoogle Scholar
  2. 2.
    Gedik B, Liu L (2005) Location privacy in mobile systems: a personalized anonymization model. In: Proc. of ICDCS, pp 620–629Google Scholar
  3. 3.
    Mokbel MF, Chow CY, Aref WG (2006) The new Casper: query processing for location services without compromising privacy. In: Proc. of VLDB, pp 763–774Google Scholar
  4. 4.
    Kalnis P, Ghinita G, Mouratidis K, Papadias D (2007) Preserving location-based identity inference in anonymous spatial queries. IEEE TKDE 19(12):1719–1733Google Scholar
  5. 5.
    Ghinita G, Kalnis P, Khoshgozaran A, Shahabi C, Tan KL (2008) Private queries in location based services: anonymizers are not necessary. In: SIGMOD, pp 121–132Google Scholar
  6. 6.
    Kido H, Yanagisawa Y, Satoh T (2005) An anonymous communication technique using dummies for location-based services. In: International conference on pervasive services (ICPS), pp 88–97Google Scholar
  7. 7.
    Yiu ML, Jensen C, Huang X, Lu H (2008) SpaceTwist: managing the trade-offs among location privacy, query performance, and query accuracy in mobile services. In: International conference on data engineering (ICDE), pp 366–375Google Scholar
  8. 8.
    Cheng R, Zhang Y, Bertino E, Prahbakar S (2006) Preserving user location privacy in mobile data management infrastructures. In: Privacy enhancing technologies (PET), pp 393–412Google Scholar
  9. 9.
    Chow CY, Mokbel MF (2007) Enabling private continuous queries for revealed user locations. In: SSTD, pp 258–275Google Scholar
  10. 10.
    Gruteser M, Liu X (2004) Protecting privacy in continuous location-tracking applications. IEEE Secur Priv 2:28–34CrossRefGoogle Scholar
  11. 11.
    Damiani M, Bertino E, Silvestri C (2008) PROBE: an obfuscation system for the protection of sensitive location information in LBS. Technical report 2001-145, CERIASGoogle Scholar
  12. 12.
    Khoshgozaran A, Shahabi C (2007) Blind evaluation of nearest neighbor queries using space transformation to preserve location privacy. In: SSTD, pp 239–257Google Scholar
  13. 13.
    Chor B, Goldreich O, Kushilevitz E, Sudan M (1995) Private information retrieval. In: IEEE symposium on foundations of computer science, pp 41–50Google Scholar
  14. 14.
    Kushilevitz E, Ostrovsky R (1997) Replication is NOT needed: SINGLE database, computationally-private information retrieval. In: FOCS, pp 364–373Google Scholar
  15. 15.
    Flath DE (1998) Introduction to number theory. Wiley, New YorkGoogle Scholar
  16. 16.
    Atallah MJ, Du W (2001) Secure multi-party computational geometry. In: WADS ’01: Proceedings of the 7th international workshop on algorithms and data structures, pp 165–179Google Scholar
  17. 17.
    Luo Y, Huang L, Zhong H (2007) Secure two-party point-circle inclusion problem. J Comput Sci Technol 22(1):88–91CrossRefGoogle Scholar
  18. 18.
    Goldreich O, Micali S, Wigderson A (1987) How to play any mental game. In: Proceedings of ACM symposium on theory of computing (STOC), pp 218–229Google Scholar
  19. 19.
    Fischlin M (2001) A cost-effective pay-per-multiplication comparison method for millionaires. In: CT-RSA 2001: Proceedings of the 2001 conference on topics in cryptology, pp 457–472Google Scholar
  20. 20.
    Blake IF, Kolesnikov V (2004) Strong conditional oblivious transfer and computing on intervals. In: Advances in cryptology—ASIACRYPT 2004, pp 515–529Google Scholar
  21. 21.
    Lin HY, Tzeng WG (2005) An efficient solution to the millionaires’ problem based on homomorphic encryption. In: Intl. conference on applied cryptography and network security, pp 456–466Google Scholar
  22. 22.
    Yao AC (1982) Protocols for secure computations. In: SFCS ’82: Proceedings of the 23rd annual symposium on foundations of computer science, pp 160–164Google Scholar
  23. 23.
    Chow CY, Mokbel MF, Liu X (2006) A peer-to-peer spatial cloaking algorithm for anonymous location-based service. In: GIS, pp 171–178Google Scholar
  24. 24.
    Ghinita G, Kalnis P, Skiadopoulos S (2007) PRIVE: anonymous location-based queries in distributed mobile systems. In: WWW, pp 371–380Google Scholar
  25. 25.
    Ghinita G, Kalnis P, Skiadopoulos S (2007) MobiHide: a mobile peer-to-peer system for anonymous location-based queries. In: SSTD, pp 221–238Google Scholar
  26. 26.
    Paillier P (1999) Public-key cryptosystems based on composite degree residuosity classes. In: EUROCRYPT, pp 223–238Google Scholar
  27. 27.
    Atallah MJ (1998) Algorithms and theory of computation handbook. CRC Press, Boca RatonCrossRefGoogle Scholar
  28. 28.
    de Berg M, van Kreveld M, Overmars M, Schwarzkopf O (2000) Computational geometry: algorithms and applications, 2nd edn. Springer, BerlinGoogle Scholar

Copyright information

© Springer Science+Business Media, LLC 2010

Authors and Affiliations

  • Gabriel Ghinita
    • 1
    Email author
  • Panos Kalnis
    • 2
  • Murat Kantarcioglu
    • 3
  • Elisa Bertino
    • 1
  1. 1.Purdue UniversityWest LafayetteUSA
  2. 2.King Abdullah University of Science and TechnologyJeddahSaudi Arabia
  3. 3.University of Texas at DallasRichardsonUSA

Personalised recommendations