MHLPP: Strengthening Location Privacy in Mobile Social Networks via Multi-Hop Trust
Protecting location privacy in opportunistic mobile social networks
This paper introduces the Multi-Hop Location-Privacy Protection (MHLPP) protocol for Opportunistic Mobile Social Networks (OMSNs). By leveraging social ties and asymmetric encryption, MHLPP obfuscates a requester's identity and location through a chain of trusted friends before submitting queries to Location-Based Service (LBS) providers, achieving a significant boost in delivery success rates.
TL;DR
Location-Based Services (LBS) are essential but come at a high privacy cost. In the context of Opportunistic Mobile Social Networks (OMSNs), where connectivity is intermittent, protecting a user's location is notoriously difficult. The Multi-Hop Location-Privacy Protection (MHLPP) protocol solves this by using social relationships to route queries through a "chain of friends." Unlike previous methods, it doesn't break when friends are scarce, as it utilizes encrypted multi-hop paths to maintain a high query success rate.
Problem: The Fragility of Current Obfuscation
Most existing OMSN privacy protocols rely on k-anonymity. The logic is simple: pass your query to friends before it reaches the LBS server. However, this "chain of trust" has two fatal flaws:
- Connectivity Gaps: In sparse networks (DTNs), encountering friends sequentially can take so long that the query eventually times out.
- Trust Leaks: Most protocols assume intermediate nodes are either fully trusted or that "strangers" won't look at the data. In reality, any node forwarding a plaintext query can compromise the requester's location.
Methodology: Distance-Based Obfuscation & Encrypted Chains
The core insight of MHLPP is to shift from a hop-count requirement to a distance-based requirement. Instead of saying "find 3 friends," MHLPP says "move this query to a location meters away from me using only friends as decision-makers."
1. Two-Phase Architecture
- Obfuscation Phase: The query travels through friends until it reaches a "ring" area defined by an inner radius and external radius .
- Free Phase: Once in the target area, the last friend () replaces the original requester's ID with its own information and sends it to the LBS. The LBS only "sees" the last friend.
2. Secure Social Forwarding
MHLPP leverages asymmetric encryption. When a requester () finds a friend (), they encrypt the query using the friend's public key. Even if the query is physically carried by un-trusted "strangers" (via multi-hop routing like OLSR), those strangers cannot see the endpoint or the identity of the requester.
Fig 1. The selection of the next friend within an elliptical constraint to ensure the query isn't routed in an unacceptably long path.
Experiments: Performance under Pressure
The researchers simulated MHLPP using a real-world map of Helsinki. They compared it against HSLPO, a state-of-the-art predecessor.
Higher Success, Lower Sensitivity
The most striking result is the Query Success Ratio. As the privacy threshold () increases—meaning you only trust your closest friends—HSLPO's performance collapses because it cannot find enough direct contacts. MHLPP, because it can "hop" through strangers to reach a distant friend, maintains a steady success rate.
Fig 2. Query success ratio comparison: MHLPP (Red) remains robust where HSLPO (Blue) fails significantly as k-anonymity requirements increase.
The Cost of Security
Does this encryption slow things down? The study found that even with high privacy settings, the number of required encryptions/decryptions averaged less than 3 per query. This is a negligible computational overhead for modern mobile devices compared to the gains in privacy.
Critical Insight: Why it Works
MHLPP succeeds because it separates the physical path from the trust path. By allowing the query to be physically moved by anyone (via encryption) but logically handled only by friends, it breaks the "social bottleneck" that plagues earlier DTN privacy protocols.
Conclusion
The MHLPP protocol demonstrates that location privacy in mobile networks doesn't have to be a trade-off for reliability. By moving toward a distance-based obfuscation model and utilizing multi-hop social links, we can hide the origin of data without losing the data itself.
Future Outlook: While MHLPP protects against semi-trusted LBS servers, future work could explore Differential Privacy to protect against attackers who might observe the distribution of queries over very long periods across the entire city.
