SpreadMeNot : A Provably Secure and Privacy-Preserving Contact Tracing Protocol

被引:1
|
作者
Tedeschi, Pietro [1 ]
Bakiras, Spiridon [2 ]
Di Pietro, Roberto [3 ]
机构
[1] Technol Innovat Inst, Secure Syst Res Ctr, Abu Dhabi 2022, U Arab Emirates
[2] Singapore Inst Technol, Infocomm Technol Cluster, Singapore 138683, Singapore
[3] Hamad Bin Khalifa Univ HBKU, Coll Sci & Engn CSE, Div Informat & Comp Technol ICT, Doha 122104, Qatar
关键词
Bluetooth; Protocols; Elliptic curve cryptography; COVID-19; Global navigation satellite system; Elliptic curves; Standards; Contact tracing; cryptography; privacy; protocols; security;
D O I
10.1109/TDSC.2022.3186153
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
A plethora of contact tracing apps have been developed and deployed in several countries around the world in the battle against Covid-19. However, people are rightfully concerned about the security and privacy risks of such applications. To address these issues, in this paper we provide two main contributions. First, we present an in-depth analysis of the security and privacy characteristics of the most prominent contact tracing protocols, under both passive and active adversaries. The results of our study indicate that all protocols are vulnerable to a variety of attacks, mainly due to the deterministic nature of the underlying cryptographic protocols. Our second contribution is the design and implementation of SpreadMeNot, a novel contact tracing protocol that can defend against most passive and active attacks, thus providing strong (provable) security and privacy guarantees that are necessary for such a sensitive application. Our detailed analysis, both formal and experimental, shows that SpreadMeNot satisfies security, privacy, and performance requirements, hence being an ideal candidate for building a contact tracing solution that can be adopted by the majority of the general public, as well as to serve as an open-source reference for further developments in the field.
引用
收藏
页码:2500 / 2515
页数:16
相关论文
共 50 条
  • [21] Secure and Privacy-Preserving Matchmaking protocol for Mobile Social Networks
    Ansuura, John Bosco Aristotle Kanpogninge
    Qi, Xia
    Klugah-Brown, Benjamin
    Tei-Ahontu, Richmond Martei
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON LOGISTICS, ENGINEERING, MANAGEMENT AND COMPUTER SCIENCE (LEMCS 2015), 2015, 117 : 144 - 149
  • [22] A novel ECC-based provably secure and privacy-preserving multi-factor authentication protocol for cloud computing
    Shukla, Shivangi
    Patel, Sankita J.
    COMPUTING, 2022, 104 (05) : 1173 - 1202
  • [23] A novel ECC-based provably secure and privacy-preserving multi-factor authentication protocol for cloud computing
    Shivangi Shukla
    Sankita J. Patel
    Computing, 2022, 104 : 1173 - 1202
  • [24] Secure and Privacy-Preserving Consensus
    Ruan, Minghao
    Gao, Huan
    Wang, Yongqiang
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2019, 64 (10) : 4035 - 4049
  • [25] Non-interactive set intersection for privacy-preserving contact tracing
    Wu, Axin
    Yang, Yuer
    Wen, Jinghang
    Zhang, Yu
    Zhao, Qiuxia
    Journal of Systems Architecture, 2025, 158
  • [26] Review and Critical Analysis of Privacy-Preserving Infection Tracking and Contact Tracing
    Buchanan, William J. J.
    Imran, Muhammad Ali
    Ur-Rehman, Masood
    Zhang, Lei
    Abbasi, Qammer H. H.
    Chrysoulas, Christos
    Haynes, David
    Pitropakis, Nikolaos
    Papadopoulos, Pavlos
    FRONTIERS IN COMMUNICATIONS AND NETWORKS, 2020, 1
  • [27] Tracking the Invisible: Privacy-Preserving Contact Tracing to Control the Spread of a Virus
    Demirag, Didem
    Ayday, Erman
    DATA PRIVACY MANAGEMENT, CRYPTOCURRENCIES AND BLOCKCHAIN TECHNOLOGY, ESORICS 2020, DPM 2020, CBT 2020, 2020, 12484 : 240 - 249
  • [28] AEP-PPA: An anonymous, efficient and provably-secure privacy-preserving authentication protocol for mobile services in smart cities
    Li, JiLiang
    Zhang, WeiGuo
    Dabra, Vivek
    Choo, Kim-Kwang Raymond
    Kumari, Saru
    Hogrefe, Dieter
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 134 : 52 - 61
  • [29] A Secure and Privacy-Preserving Protocol for Smart Metering Operational Data Collection
    Mustafa, Mustafa A.
    Cleemput, Sara
    Aly, Abdelrahaman
    Abidin, Aysajan
    IEEE TRANSACTIONS ON SMART GRID, 2019, 10 (06) : 6481 - 6490
  • [30] An MPC-based Protocol for Secure and Privacy-Preserving Smart Metering
    Mustafa, A. Mustafa
    Cleemput, Sara
    Aly, Abdelrahaman
    Abidin, Aysajan
    2017 IEEE PES INNOVATIVE SMART GRID TECHNOLOGIES CONFERENCE EUROPE (ISGT-EUROPE), 2017,