华东师范大学学报(自然科学版) ›› 2016, Vol. 2016 ›› Issue (2): 62-72.doi: 10.3969/j.issn.1000-5641.2016.02.009

• 计算机科学 • 上一篇    下一篇

基于位置社交网络的高效定位算法

王荣荣,薛旻辉,李祥学,钱海峰   

  1. 华东师范大学 计算机科学技术系,上海200241
  • 收稿日期:2015-02-13 出版日期:2016-03-25 发布日期:2016-07-25
  • 通讯作者: 钱海峰,男,研究员,博士生导师,研究方向为密码学、信息安全 E-mail:hfqian@cs.ecnu.edu.cn.
  • 作者简介:王荣荣,女,硕士研究生,研究方向为信息安全. E-mail: ghghgh8032@126.com.
  • 基金资助:

    国家自然科学基金(61172085)

An effective localization attack in locationbased social network

 WANG  Rong-Rong, XUE  Min-Hui, LI  Xiang-Xue, QIAN  Hai-Feng   

  • Received:2015-02-13 Online:2016-03-25 Published:2016-07-25

摘要: 基于位置社交网络(LocationBased Social Network,LBSN)服务使得用户能够利用位置服务发现附近的人.原始的LBSN服务为用户提供确切的相对距离,而这种做法已被证实易于遭受三角定位攻击.为防御此类攻击,当今LBSN服务普遍采用以带宽的方式来报告距离.本文利用数论,通过技巧性地摆放虚拟探针,伪装地理位置,提出了一种不受地理位置限制、高精度、易于实现的定位目标算法.作为概念验证,本文使用微信进行实验最终验证了该攻击算法在实际部署中的有效性.本文的研究旨在呼吁LBSN服务提供商改进位置隐私保护技术,唤醒公众充分认识LBSN软件所带来的潜在隐私泄露.

关键词: 基于位置社交网络, 定位攻击, 微信

Abstract: Locationbased social network (LBSN) services enable users to discover nearby people. Original LBSN services provide the exact distances for nearby users. Existing studies have shown that it is easy to localize target users by using trilateration methodology. To defend against the trilateration attack, current LBSN services adopt the concentric bandbased approach when reporting distances. In this paper, by using number theory, we analytically show that by strategically placing multiple virtual probes as fake GPS, one can accurately pinpoint user locations with either accurate or coarse bandbased distances. As a proof of this concept, WeChat is examplified to validate that our attack methodology is effective in a realworld deployment. Our study is expected to draw more public attention to this serious privacy issue and hopefully motivate better privacypreserving LBSN designs.

Key words: locationbased social network, localization attack, WeChat

中图分类号: