PPLS: Decoupling Social Identity from Location with Fine-Grained Privacy
PPLS: a privacy-preserving location-sharing scheme in mobile online social networks
The paper proposes PPLS (Privacy-Preserving Location-Sharing), a scheme for mobile online social networks (mOSNs). It introduces a secure distance comparison protocol using Paillier homomorphic encryption to allow multi-threshold access control without revealing sensitive location or relationship data to service providers.
TL;DR
PPLS (Privacy-Preserving Location-Sharing) is a novel protocol designed for mobile social networks that allows users to set individualized visibility distances for different friends. By leveraging Paillier homomorphic encryption and a non-colluding two-server architecture, it ensures that your exact location and your personal social preferences remain invisible even to the servers providing the service.
Contextual Background
In the era of Mobile Online Social Networks (mOSNs), location-based services (LBS) are ubiquitous. However, they present a classic privacy paradox: to find a nearby friend, you must tell a server where you are and who your friends are. Current SOTA methods like MobiShare or N-MobiShare fail in two major ways:
- Public Thresholds: They treat your "radius of visibility" as public, which can be used as a fingerprint to track you.
- Rigid Policies: They assume one distance fits all, ignoring that you might want a "Close Friend" to see you within 500m but a "Stranger" only within 50m.
Methodology: The Core Architecture
PPLS employs a dual-entity system to ensure no single point of failure for privacy:
- Mobile Social Network Server (MS): Knows who you are and your friend list, but never your location.
- Location Server (LS): Knows where various "pseudo-identities" are, but doesn't know who they belong to or their social ties.
Secure Distance Comparison Protocol
The "secret sauce" of PPLS is Protocol 1, which performs comparisons inside the encrypted domain. Using Paillier Encryption, the MS can encrypt a threshold distance (). The LS, possessing the user's location, can mathematicaly manipulate this ciphertext to include the actual distance () without ever decrypting it.

The logic follows a homomorphic subtraction: if the result of is positive, the proximity condition is met. Because of Paillier’s additive homomorphic properties, this comparison is "blind" to the LS.
Experimental Insights
The research team implemented PPLS using Python and tested it on an Intel Xeon environment. The primary metric was latency, as cryptographic operations are historically expensive for real-time mobile apps.
- Linear Scaling: The time cost increases linearly at a rate of 0.07s per user comparison.
- Bottleneck Identification: The majority of the processing time is spent on the secure comparison protocol rather than network overhead.

Critical Analysis & Conclusion
PPLS succeeds in providing a more "human" approach to privacy—acknowledging that social circles are not monolithic.
Takeaway: The transition from broadcast encryption to targeted, homomorphic-based comparison allows for much tighter access control.
Limitations: While the security is robust, a 10-second wait for 150 friends might be slow for a high-speed "People Nearby" feature. Future work should look into Edge Computing or Elliptic Curve Cryptography (ECC) to reduce the computational heavy-lifting required by traditional Paillier/RSA methods.
Ultimately, PPLS shifts the paradigm from "Do I trust the app?" to "The app's architecture makes trust unnecessary."
