MobiShare: Decoupling Identity and Geography in Mobile Social Networks

MobiShare: Flexible privacy-preserving location sharing in mobile online social networks

2012-03-01
Wei Wei, Fengyuan Xu, Qun Li
Summary
Problem
Method
Results
Takeaways
Abstract

MobiShare is a flexible privacy-preserving location sharing system for mobile online social networks (mOSNs) that supports both trusted friends and untrusted strangers. It achieves privacy by decoupling user identities from anonymized location data across two distinct entities: a Social Network Server and a third-party Location Server.

TL;DR

MobiShare is a privacy-preserving framework for mobile social networks that allows users to share their locations with friends and discover strangers within a certain range without revealing their identity to any single centralized server. By splitting data between a social network server and a location server, and utilizing cellular towers for anonymization, it achieves a balance between social utility and absolute privacy.

Problem & Motivation: The "All-Seeing" Social Server

Traditional Mobile Online Social Networks (mOSNs) like Foursquare or Facebook operate on a centralized model. This creates a single point of failure: if a server is hacked or if the service provider is malicious, a user's entire history of physical movements is tied directly to their real-world profile.

The authors identify two critical gaps in existing research:

  1. Sharing Rigidity: Previous privacy models often only allowed sharing with "Known Friends." This breaks "Serendipity" features—the ability to find interesting strangers nearby.
  2. Trust Over-Reliance: Most systems assume the platform itself is honest, which is a dangerous assumption in the modern era of data breaches and internal leaks.

Methodology: The Power of Separation

The core insight of MobiShare is the Multi-Entity Separation of Knowledge. No single entity knows both "Who you are" and "Where you are."

1. Dual-Server Architecture

  • Social Network Server (SNS): Stores identities, friend lists, and public keys. It knows who is friends with whom, but not their coordinates.
  • Location Server (LS): Stores anonymized coordinates and fake IDs. It knows where someone is, but not their real name.

2. The Cellular Tower as an Anonymizer

The system leverages the trusted status of cellular carriers. When a user updates their location, the cellular tower:

  • Replaces the real User ID with a Fake ID.
  • Generates dummy location updates to hide the real data point among "noise."
  • Sends these updates to the Location Server in random intervals to prevent timing attacks.

System Architecture Figure 1: The three-tier architecture ensuring privacy via cellular intermediaries.

3. Querying with Privacy

  • Friends Query: Uses symmetric session keys. Even if the Location Server returns a friend's coordinate, only the authorized friend can decrypt the specific location.
  • Strangers Query: Relies on k-anonymity. The LS returns a mix of real locations and dummy locations. The Social Server then acts as a filter, using its record of fake IDs to provide valid mapping entries without actually being able to see the coordinates itself.

Query Workflow - Friends Figure 2: Workflow for querying friends' locations, showing the interaction between the SNS and LS.

Experiments & Results: Real-World Viability

The authors didn't just stop at theory; they built a full implementation using Android devices and cloud instances (Linode and JoyentCloud).

  • Battery Efficiency: One of the biggest hurdles for location apps is power drain. MobiShare’s optimized encryption and background updates resulted in only 1.5% battery consumption per hour, making it practical for daily use.
  • Scalability: The cellular tower component (the bottleneck in theory) proved robust. In tests with 1,000 simultaneous users, CPU utilization remained under 5%, indicating that existing carrier infrastructure could easily handle the load.

Critical Insight: Why This Matters

MobiShare moves the needle by proving that "Privacy" doesn't have to mean "Isolation." By using a dummy-injection strategy at the tower level, the system provides a mathematical guarantee of anonymity (-anonymity) while still allowing for the "range queries" that make social apps useful.

Limitations & Future Work

The primary limitation is the reliance on the Cellular Tower's trustworthiness. While cellular carriers are generally more regulated than social media apps, they still represent a central point of trust. Future iterations could explore using Secure Multi-Party Computation (SMPC) or Differential Privacy to further reduce the reliance on any intermediary.

Conclusion

MobiShare offers a blueprint for the next generation of social apps. It respects user autonomy through user-defined access control (threshold distances) and ensures that our physical footprints remain our own, even in a hyper-connected world.

Find Similar Papers

Try Our Examples

  • Search for recent papers that utilize Trusted Execution Environments (TEEs) like Intel SGX to replace the dual-server architecture for privacy-preserving location sharing.
  • Which original paper proposed the 'Dummy Location' generation method used by MobiShare, and how has dummy-based k-anonymity evolved in the age of Differential Privacy?
  • Examine how current 5G/6G network standards have integrated location privacy features similar to the cellular tower proxying suggested in MobiShare.
Contents
MobiShare: Decoupling Identity and Geography in Mobile Social Networks
1. TL;DR
2. Problem & Motivation: The "All-Seeing" Social Server
3. Methodology: The Power of Separation
3.1. 1. Dual-Server Architecture
3.2. 2. The Cellular Tower as an Anonymizer
3.3. 3. Querying with Privacy
4. Experiments & Results: Real-World Viability
5. Critical Insight: Why This Matters
5.1. Limitations & Future Work
6. Conclusion