IP Library Granted Patent US 11,645,730
Granted Patent B2
US 11,645,730 · App. 17/099,144 · Granted May 9, 2023

Method, apparatus, and computer program product for identifying privacy risks in datasets

Inventor: Stefano Bennati (Zurich, CH)
Assignee: HERE GLOBAL B.V.
G06Q50/265G06F16/24556G06F21/6254G06Q10/0635H04W4/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,645,730
App. No.
17/099,144
Granted
May 9, 2023
Kind
B2
Abstract

Embodiments described herein relate to establishing a privacy risk score between two datasets based on features common to the datasets. Methods may include: receiving a first dataset of probe data points defining a trajectory; receiving a second dataset of the probe data points defining the trajectory; identifying a plurality of features common to the first dataset and the second dataset; computing a privacy risk value for the identified features common to the first dataset and the second dataset; and computing an aggregate privacy risk score between the first dataset and the second dataset.

Claims (42)

1. An apparatus comprising at least one processor and at least one memory including computer program code, the at least one memory and computer program code configured to, with the processor, cause the apparatus to at least:

receive a first dataset of probe data points defining a trajectory;

receive a second dataset of the probe data points defining the trajectory;

identify a plurality of features common to the first dataset and the second dataset, wherein the features common to the first dataset and the second dataset comprise equivalence areas, wherein equivalence areas comprise spatio-temporal regions for an origin and a destination of the first dataset and the second dataset;

compute a privacy risk value for the identified features common to the first dataset and the second dataset;

aggregate the privacy risk values for the identified features common to the first dataset and the second dataset;

compute an aggregate privacy risk score between the first dataset and the second dataset; and

in response to the aggregate privacy risk score between the first data set and the second data set satisfying a predetermined value, release the second dataset to a third-party entity to provide location-based services using the second dataset.

2. The apparatus of claim 1 , wherein the second dataset of the probe data points defining the trajectory is an anonymized dataset anonymized using a first anonymization algorithm, wherein the apparatus is further caused to:

in response to the aggregate privacy risk score failing to satisfy the predetermined value, provide for anonymization of the first dataset of probe data points using a second anonymization algorithm to generate an anonymized third dataset.

3. The apparatus of claim 1 , wherein the apparatus is further caused to:

receive location-based services in response to release of the second dataset.

4. The apparatus of claim 1 , wherein the plurality of features comprise the equivalence areas and trajectories.

5. The apparatus of claim 1 , wherein causing the apparatus to compute a privacy risk value for the features common to the first dataset and the second dataset comprises causing the apparatus to:

conduct a pair-wise comparison of privacy risk values between the first dataset and the second dataset inside the identified equivalency areas; and

wherein causing the apparatus to aggregate the privacy risk values for the identified features common to the first dataset and the second dataset comprises causing the apparatus to aggregate a result of the pair-wise comparison of privacy risk values between the first dataset and the second dataset.

6. A computer program product comprising at least one non-transitory computer-readable storage medium having computer-executable program code portions stored therein, the computer-executable program code portions comprising program code instructions configured to:

receive a first dataset of probe data points defining a trajectory;

receive a second dataset of the probe data points defining the trajectory;

identify a plurality of features common to the first dataset and the second dataset, wherein the features common to the first dataset and the second dataset comprise equivalence areas, wherein equivalence areas comprise spatio-temporal regions for an origin and a destination of the first dataset and the second dataset;

compute a privacy risk value for the identified features common to the first dataset and the second dataset;

aggregate the privacy risk values for the identified features common to the first dataset and the second dataset;

compute an aggregate privacy risk score between the first dataset and the second dataset; and

in response to the aggregate privacy risk score between the first data set and the second data set satisfying a predetermined value, release the second dataset to a third-party entity to provide location-based services using the second dataset.

7. The computer program product of claim 6 , wherein the second dataset of the probe data points defining the trajectory is an anonymized dataset anonymized using a first anonymization algorithm, wherein computer program product further comprises program code instructions configured to:

in response to the aggregate privacy risk score failing to satisfy the predetermined value, provide for anonymization of the first dataset of probe data points using a second anonymization algorithm to generate an anonymized third dataset.

8. The computer program product of claim 6 , further comprising program code instructions configured to:

receive location-based services in response to release of the second dataset.

9. The computer program product of claim 6 , wherein the plurality of features comprise the equivalence areas and trajectories.

10. The computer program product of claim 6 , wherein the program code instructions to compute a privacy risk value for the features common to the first dataset and the second dataset comprise program code instructions to:

conduct a pair-wise comparison of privacy risk values between the first dataset and the second dataset inside the identified equivalency areas; and

wherein the program code instructions to aggregate the privacy risk values for the identified features common to the first dataset and the second dataset comprise program code instructions to aggregate a result of the pair-wise comparison of privacy risk values between the first dataset and the second dataset.

11. A method comprising:

receiving a first dataset of probe data points defining a trajectory;

receiving a second dataset of the probe data points defining the trajectory;

identifying a plurality of features common to the first dataset and the second dataset, wherein the features common to the first dataset and the second dataset comprise equivalence areas, wherein equivalence areas comprise spatio-temporal regions for an origin and a destination of the first dataset and the second dataset;

computing a privacy risk value for the identified features common to the first dataset and the second dataset;

aggregating the privacy risk values for the identified features common to the first dataset and the second dataset;

computing an aggregate privacy risk score between the first dataset and the second dataset; and

in response to the aggregate privacy risk score between the first data set and the second data set satisfying a predetermined value, releasing the second dataset to a third-party entity to provide location-based services using the second dataset.

12. The method of claim 11 , wherein the second dataset of the probe data points defining the trajectory is an anonymized dataset anonymized using a first anonymization algorithm, wherein the method further comprises:

in response to the aggregate privacy risk score failing to satisfy the predetermined value, providing for anonymization of the first dataset of probe data points using a second anonymization algorithm to generate an anonymized third dataset.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2020
From: BENNATI, STEFANO
To: HERE GLOBAL B.V.
Reel/Frame 054768/0094 →
Continuity (1)
Related Publication 20220156869A1 · May 19, 2022
Cited By (1)
US 12,711,271