SpreadMeNot : A Provably Secure and Privacy-Preserving Contact Tracing Protocol

被引:1
|
作者
Tedeschi, Pietro [1 ]
Bakiras, Spiridon [2 ]
Di Pietro, Roberto [3 ]
机构
[1] Technol Innovat Inst, Secure Syst Res Ctr, Abu Dhabi 2022, U Arab Emirates
[2] Singapore Inst Technol, Infocomm Technol Cluster, Singapore 138683, Singapore
[3] Hamad Bin Khalifa Univ HBKU, Coll Sci & Engn CSE, Div Informat & Comp Technol ICT, Doha 122104, Qatar
关键词
Bluetooth; Protocols; Elliptic curve cryptography; COVID-19; Global navigation satellite system; Elliptic curves; Standards; Contact tracing; cryptography; privacy; protocols; security;
D O I
10.1109/TDSC.2022.3186153
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
A plethora of contact tracing apps have been developed and deployed in several countries around the world in the battle against Covid-19. However, people are rightfully concerned about the security and privacy risks of such applications. To address these issues, in this paper we provide two main contributions. First, we present an in-depth analysis of the security and privacy characteristics of the most prominent contact tracing protocols, under both passive and active adversaries. The results of our study indicate that all protocols are vulnerable to a variety of attacks, mainly due to the deterministic nature of the underlying cryptographic protocols. Our second contribution is the design and implementation of SpreadMeNot, a novel contact tracing protocol that can defend against most passive and active attacks, thus providing strong (provable) security and privacy guarantees that are necessary for such a sensitive application. Our detailed analysis, both formal and experimental, shows that SpreadMeNot satisfies security, privacy, and performance requirements, hence being an ideal candidate for building a contact tracing solution that can be adopted by the majority of the general public, as well as to serve as an open-source reference for further developments in the field.
引用
收藏
页码:2500 / 2515
页数:16
相关论文
共 50 条
  • [1] Towards Privacy-preserving Digital Contact Tracing
    Ahmed, Nadeem
    Michelin, Regio A.
    Xue, Wanli
    Putra, Guntur Dharma
    Song, Wei
    Ruj, Sushmita
    Kanhere, Salil S.
    Jha, Sanjay
    2021 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN AND CRYPTOCURRENCY (ICBC), 2021,
  • [2] Privacy-preserving contact tracing curbed COVID
    Salathe, Marcel
    NATURE, 2023, 619 (7968) : 31 - 33
  • [3] DIMY: Enabling privacy-preserving contact tracing
    Ahmed, Nadeem
    Michelin, Regio A.
    Xue, Wanli
    Putra, Guntur Dharma
    Ruj, Sushmita
    Kanhere, Salil S.
    Jha, Sanjay
    Journal of Network and Computer Applications, 2022, 202
  • [4] DIMY: Enabling privacy-preserving contact tracing
    Ahmed, Nadeem
    Michelin, Regio A.
    Xue, Wanli
    Putra, Guntur Dharma
    Ruj, Sushmita
    Kanhere, Salil S.
    Jha, Sanjay
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2022, 202
  • [5] Efficient provably-secure privacy-preserving signature-based key establishment protocol
    Abbasinezhad-Mood, Dariush
    Ostad-Sharif, Arezou
    Nikooghadam, Morteza
    AD HOC NETWORKS, 2020, 100
  • [6] An improved and provably secure privacy preserving authentication protocol for SIP
    Chaudhry, Shehzad Ashraf
    Naqvi, Husnain
    Sher, Muhammad
    Farash, Mohammad Sabzinejad
    ul Hassan, Mahmood
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2017, 10 (01) : 1 - 15
  • [7] An improved and provably secure privacy preserving authentication protocol for SIP
    Shehzad Ashraf Chaudhry
    Husnain Naqvi
    Muhammad Sher
    Mohammad Sabzinejad Farash
    Mahmood Ul Hassan
    Peer-to-Peer Networking and Applications, 2017, 10 : 1 - 15
  • [8] SPOT+: Secure and Privacy-Preserving Proximity-Tracing Protocol with Efficient Verification over Multiple Contact Information
    Masmoudi, Souha
    Laurent, Maryline
    Kaaniche, Nesrine
    Communications in Computer and Information Science, 2023, 1849 CCIS : 1 - 19
  • [9] Another Look at Privacy-Preserving Automated Contact Tracing
    Tang, Qiang
    ACM TRANSACTIONS ON SPATIAL ALGORITHMS AND SYSTEMS, 2022, 8 (02)
  • [10] Privacy-preserving Identity Broadcast for Contact Tracing Applications
    Dyo, Vladimir
    Ali, Jahangir
    12TH WIRELESS DAYS CONFERENCE (WD 2021), 2020,