SpreadMeNot : A Provably Secure and Privacy-Preserving Contact Tracing Protocol

被引:1
|
作者
Tedeschi, Pietro [1 ]
Bakiras, Spiridon [2 ]
Di Pietro, Roberto [3 ]
机构
[1] Technol Innovat Inst, Secure Syst Res Ctr, Abu Dhabi 2022, U Arab Emirates
[2] Singapore Inst Technol, Infocomm Technol Cluster, Singapore 138683, Singapore
[3] Hamad Bin Khalifa Univ HBKU, Coll Sci & Engn CSE, Div Informat & Comp Technol ICT, Doha 122104, Qatar
关键词
Bluetooth; Protocols; Elliptic curve cryptography; COVID-19; Global navigation satellite system; Elliptic curves; Standards; Contact tracing; cryptography; privacy; protocols; security;
D O I
10.1109/TDSC.2022.3186153
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
A plethora of contact tracing apps have been developed and deployed in several countries around the world in the battle against Covid-19. However, people are rightfully concerned about the security and privacy risks of such applications. To address these issues, in this paper we provide two main contributions. First, we present an in-depth analysis of the security and privacy characteristics of the most prominent contact tracing protocols, under both passive and active adversaries. The results of our study indicate that all protocols are vulnerable to a variety of attacks, mainly due to the deterministic nature of the underlying cryptographic protocols. Our second contribution is the design and implementation of SpreadMeNot, a novel contact tracing protocol that can defend against most passive and active attacks, thus providing strong (provable) security and privacy guarantees that are necessary for such a sensitive application. Our detailed analysis, both formal and experimental, shows that SpreadMeNot satisfies security, privacy, and performance requirements, hence being an ideal candidate for building a contact tracing solution that can be adopted by the majority of the general public, as well as to serve as an open-source reference for further developments in the field.
引用
收藏
页码:2500 / 2515
页数:16
相关论文
共 50 条
  • [31] WeTrace: A Privacy-preserving Tracing Approach
    Franco, Muriel
    Rodrigues, Bruno
    Killer, Christian
    Scheid, Eder John
    De Carli, Alessandro
    Gassmann, Andreas
    Schonbachler, David
    Stiller, Burkhard
    JOURNAL OF COMMUNICATIONS AND NETWORKS, 2021, 23 (05) : 374 - 389
  • [32] A Privacy-Preserving Secure Service Discovery Protocol for Ubiquitous Computing Environments
    Kim, Jangseong
    Baek, Joonsang
    Kim, Kwangjo
    Zhou, Jianying
    PUBLIC KEY INFRASTRUCTURES, SERVICES AND APPLICATIONS, 2011, 6711 : 45 - +
  • [33] A secure and privacy-preserving protocol for holding double auctions in smart grid
    Sarenche, Roozbeh
    Salmasizadeh, Mahmoud
    Ameri, Mohammad Hassan
    Aref, Mohammad Reza
    INFORMATION SCIENCES, 2021, 557 : 108 - 129
  • [34] A Lightweight Privacy-Preserving Protocol for VANETs Based on Secure Outsourcing Computing
    Wei, Zhijun
    Li, Jing
    Wang, Xianmin
    Gao, Chong-Zhi
    IEEE ACCESS, 2019, 7 : 62785 - 62793
  • [35] PTAP: A novel secure privacy-preserving & traceable authentication protocol in VANETs
    Liu, Xiaoxue
    Wang, Yichuan
    Li, Yanping
    Cao, Hao
    COMPUTER NETWORKS, 2023, 226
  • [36] A Privacy-Preserving Comparison Protocol
    Sutradhar, Kartick
    Om, Hari
    IEEE TRANSACTIONS ON COMPUTERS, 2023, 72 (06) : 1815 - 1821
  • [37] Privacy-preserving and incentivized contact tracing for COVID-19 using blockchain
    Naren
    Tahiliani A.
    Hassija V.
    Chamola V.
    Kanhere S.S.
    Guizani M.
    IEEE Internet of Things Magazine, 2021, 4 (03): : 72 - 79
  • [38] Peer-to-Peer Contact Tracing: Development of a Privacy-Preserving Smartphone App
    Yasaka, Tyler M.
    Lehrich, Brandon M.
    Sahyouni, Ronald
    JMIR MHEALTH AND UHEALTH, 2020, 8 (04):
  • [39] A Privacy-Preserving Contact Tracing System based on a Publish-Subscribe Model
    da Silva, Mikaella F.
    Santos, Bruno P.
    Rettore, Paulo H. L.
    Mota, Vinicius F. S.
    JOURNAL OF INTERNET SERVICES AND APPLICATIONS, 2024, 15 (01)
  • [40] Self-Sovereign Identity and User Control for Privacy-Preserving Contact Tracing
    Song, Wenting
    Zaeem, Razieh Nokhbeh
    Liau, David
    Chang, Kai Chih
    Lamison, Michael R.
    Khalil, Manah M.
    Barber, K. Suzanne
    2021 IEEE/WIC/ACM INTERNATIONAL CONFERENCE ON WEB INTELLIGENCE AND INTELLIGENT AGENT TECHNOLOGY (WI-IAT 2021), 2021, : 438 - 445