Digital Contact Tracing Solutions: Promises, Pitfalls and Challenges

被引:0
作者
Nguyen, Thien Duc [1 ]
Miettinen, Markus [1 ]
Dmitrienko, Alexandra [2 ]
Sadeghi, Ahmad-Reza [1 ]
Visconti, Ivan [3 ]
机构
[1] Tech Univ Darmstadt, D-64289 Darmstadt, Germany
[2] JMU Wurzburg, D-97070 Wurzburg, Germany
[3] Univ Salerno, I-84084 Fisciano, Italy
关键词
Privacy; Security; Smart phones; COVID-19; Object recognition; Internet; Ethics; Digital contact tracing; privacy; security;
D O I
10.1109/TETC.2022.3216473
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The COVID-19 pandemic has caused many countries to deploy novel digital contact tracing (DCT) systems to boost the efficiency of manual tracing of infection chains. In this paper, we systematically analyze DCT solutions and categorize them based on their design approaches and architectures. We analyze them with regard to effectiveness, security, privacy and ethical aspects and compare prominent solutions based on these requirements. In particular, we discuss shortcomings of the Google and Apple Exposure Notification API (GAEN) that is currently widely adopted all over the world. We find that the security and privacy of GAEN has considerable deficiencies as it can be compromised by severe large-scale attacks. We also discuss other proposed approaches for contact tracing, including our proposal TraceCORONA, that are based on Diffie-Hellman (DH) key exchange and aim at tackling shortcomings of existing solutions. Our extensive analysis shows that TraceCORONA fulfills the above security requirements better than deployed state-of-the-art approaches. We have implemented TraceCORONA and its beta test version has been used by more than 2000 users without any major functional problems,(1) demonstrating that there are no technical reasons requiring to make compromises with regard to the requirements of DCT approaches.
引用
收藏
页码:483 / 495
页数:13
相关论文
共 29 条
[1]   A Survey of COVID-19 Contact Tracing Apps [J].
Ahmed, Nadeem ;
Michelin, Regio A. ;
Xue, Wanli ;
Ruj, Sushmita ;
Malaney, Robert ;
Kanhere, Salil S. ;
Seneviratne, Aruna ;
Hu, Wen ;
Janicke, Helge ;
Jha, Sanjay K. .
IEEE ACCESS, 2020, 8 :134577-134601
[2]  
Ahmed S., 2021, arXiv
[3]  
[Anonymous], 2020, TraceTogether contact tracing app
[4]  
Apple and Google, 2020, Exposure notification apis
[5]  
Avitabile G., 2021, Towards defeating mass surveillance and SARS-CoV-2: The pronto-C2 fully decentralized automatic contact tracing system
[6]   Terrorist Attacks for Fake Exposure Notifications in Contact Tracing Systems [J].
Avitabile, Gennaro ;
Friolo, Daniele ;
Visconti, Ivan .
APPLIED CRYPTOGRAPHY AND NETWORK SECURITY (ACNS 2021), PT I, 2021, 12726 :220-247
[7]   Mind the GAP: Security & Privacy Risks of Contact Tracing Apps [J].
Baumgaertner, Lars ;
Dmitrienko, Alexandra ;
Freisleben, Bernd ;
Gruler, Alexander ;
Hoechst, Jonas ;
Kuehlberg, Joshua ;
Mezini, Mira ;
Mitev, Richard ;
Miettinen, Markus ;
Muhamedagic, Anel ;
Thien Duc Nguyen ;
Penning, Alvar ;
Pustelnik, Dermot ;
Roos, Filipp ;
Sadeghi, Ahmad-Reza ;
Schwarz, Michael ;
Uhl, Christian .
2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, :458-467
[8]   Function Secret Sharing [J].
Boyle, Elette ;
Gilboa, Niv ;
Ishai, Yuval .
ADVANCES IN CRYPTOLOGY - EUROCRYPT 2015, PT II, 2015, 9057 :337-367
[9]  
Brighton-Knight Z., Linkability of rolling proximity identifiers in googles implementation of the exposure notification system
[10]  
Canetti R., 2020, Privacy-preserving automated exposure notification