Towards Privacy-preserving Mobile Location Analytics

Marius Gassen, Technische Universität Darmstadt, Hervais Simo Fhom · 2016

Mobile Location Analytics (MLA) is enjoying increased at-tention. Typical businesses eager to exploit the opportuni-ties offered by this emerging form of location-based services are venues of various types and size including retail stores, shopping malls, airports, hotels, and theme parks. MLA relies on applying statistical inference methods to sensory data constantly generated by mobile devices of (potential) customers/visitors or data collected by a variety of in-door sensors in order to generate useful insights into people’s be-havior and interests. While providing venue operators and (potential) customers with many benefits, MLA also raises significant privacy concerns, given the sensitive nature of the data being collected and transferred to remote entities for further processing. In this paper, we offer a vision for building privacy and data protection into MLA. We argue for a holistic and user-centered approach, i.e., one enabling individuals whose data are collected and processed by MLA services to be aware of and understand the associated data flows, the resulting privacy risks, and appropriated options to restrict the access to and (downstream) usage of their data. The building blocks of our approach are highlighted. Our proposal rests on a comprehensive set of privacy and data protection requirements which in turn is a result of a thorough analysis of attack surfaces available in the context of MLA, the associated threat model and the privacy risks they might entail. The compiled set of privacy and data protection requirements is tailored to the specific needs of embedded systems which are key enablers of MLA.

Read the paper · More papers on PaperTik