PriSC: Redefining Location Privacy in IoV via Decentralized Multi-Level Protection
16045_A Decentralized Location Privacy-Preserving Spatial Crowdsourcing for Internet of Vehicles.
This paper introduces PriSC, a decentralized location privacy-preserving framework for Spatial Crowdsourcing (SC) in the Internet of Vehicles (IoV). By leveraging blockchain, Additively Homomorphic Encryption (AHE), and Order-Preserving Encryption (OPE), it enables secure task assignment and verification without a trusted third party.
TL;DR
In the era of the Internet of Vehicles (IoV), Spatial Crowdsourcing (SC) is essential for real-time navigation and traffic monitoring. However, uploading precise GPS coordinates to a central server is a privacy nightmare. PriSC is a new decentralized framework that replaces the "trusted" central server with a blockchain and uses a suite of cryptographic tools (AHE, OPE, NIZK) to allow workers to choose their own privacy levels while still proving their location is authentic.
The Motivation: The "Semi-Honest" Server Trap
Current SC platforms like Waze or Google Maps operate on a centralized model. While effective, they present two major flaws:
- Privacy Leakage: The server learns the requester's sensitive locations (e.g., home address) and the workers' full driving trajectories.
- Inflexible Privacy: Existing privacy tools (like differential privacy) often apply a blanket level of noise, ignoring that different users have different privacy-utility trade-offs.
The authors' insight was to decouple the "matching" of tasks from a central authority and empower vehicles to verify their own eligibility locally using encrypted policies.
Methodology: The Cryptographic Trio
The PriSC framework relies on three pillars to maintain a balance between privacy and verifiability.
1. Decentralized Infrastructure
Instead of a single server, Road Side Units (RSUs) act as blockchain nodes. Task requests and worker responses are recorded as immutable transactions, removing a single point of failure or data harvesting.
2. Encrypted Task Policies (AHE)
Requesters hide their target area using Additively Homomorphic Encryption (AHE). The task area is defined by circles. Because AHE allows operations on ciphertexts, a worker can verify if they are within the required zone without either party revealing their actual coordinates to the public.

3. Multi-Level Location Proof (OPE & NIZK)
This is the paper's core innovation. Workers don't provide a point; they provide a Grid.
- Privacy Levels: A worker can choose a small grid (low privacy, high reward) or a large grid (high privacy, low reward).
- Verification: To prevent cheating (claiming to be in a grid when they aren't), workers use Order-Preserving Encryption (OPE) to show their coordinate falls between the grid boundaries and NIZK to prove the consistency of their claims without revealing the underlying data.

Experiments & Results
The authors evaluated PriSC using the Gowalla dataset (Beijing check-ins) and a private Ethereum network.
- Scalability: The computation cost for the requester scales linearly with the number of workers, but the worker's overhead remains constant (~1.7s), making it highly suitable for mobile vehicle units.
- Precision vs. Security: Using a 1024-bit Paillier key provides a robust security margin while keeping policy generation under 2 seconds.

Critical Analysis & Conclusion
Takeaway: PriSC successfully proves that decentralization isn't just for currency; it's a viable architecture for privacy-preserving geometric computations.
Limitations:
- Gas Costs: While Ethereum was a good testbed, real-world L1 gas prices would make these transactions expensive for a "micro-tasking" environment.
- Static Grids: The current model uses a quad-tree grid system which might be less efficient than hexagonal tiling or dynamic zones in highly irregular urban environments.
Future Outlook: The integration of Layer-2 scaling or specialized ZK-rollups could further reduce the latency observed in the Ethereum testing environment, potentially making PriSC the blueprint for future "Privacy-as-a-Service" in smart cities.
