VPriv: protecting privacy in location-based vehicular services
Raluca Ada Popa, Hari Balakrishnan, Andrew J. Blumberg · 2009
A variety of location-based vehicular services are currently being woven into the national transportation infrastructure in many countries. These include usageor congestion-based road pricing, traffic law enforcement, traffic monitoring, “pay-as-you-go ” insurance, and vehicle safety systems. Although such applications promise clear benefits, there are significant potential violations of the locational privacy of drivers under standard implementations (i.e., GPS monitoring of cars as they drive, surveillance cameras, and toll transponders). In this paper, we develop and evaluate VPriv, a system that can be used by several such applications without violating the locational privacy of drivers. The starting point is the observation that in many applications, some centralized server needs to compute a function of a car’s or user’s path—a list of timeposition tuples. VPriv provides two components: 1) a protocol to compute path functions in a way that does not reveal anything more than the result of the function to the server, and 2) an out-of-band enforcement mechanism using random spot checks that allows the server and application to handle misbehaving cars or users. Our implementation of VPriv is efficient enough to be run on inexpensive stock devices. Using analysis and simulation based on real vehicular data collected over two months from the CarTel project testbed of 27 taxis running in an urban area, we demonstrate that our protocol is resistant to a range of possible attacks. 1.