SpreadMeNot : A Provably Secure and Privacy-Preserving Contact Tracing Protocol

被引:1
作者
Tedeschi, Pietro [1 ]
Bakiras, Spiridon [2 ]
Di Pietro, Roberto [3 ]
机构
[1] Technol Innovat Inst, Secure Syst Res Ctr, Abu Dhabi 2022, U Arab Emirates
[2] Singapore Inst Technol, Infocomm Technol Cluster, Singapore 138683, Singapore
[3] Hamad Bin Khalifa Univ HBKU, Coll Sci & Engn CSE, Div Informat & Comp Technol ICT, Doha 122104, Qatar
关键词
Bluetooth; Protocols; Elliptic curve cryptography; COVID-19; Global navigation satellite system; Elliptic curves; Standards; Contact tracing; cryptography; privacy; protocols; security;
D O I
10.1109/TDSC.2022.3186153
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
A plethora of contact tracing apps have been developed and deployed in several countries around the world in the battle against Covid-19. However, people are rightfully concerned about the security and privacy risks of such applications. To address these issues, in this paper we provide two main contributions. First, we present an in-depth analysis of the security and privacy characteristics of the most prominent contact tracing protocols, under both passive and active adversaries. The results of our study indicate that all protocols are vulnerable to a variety of attacks, mainly due to the deterministic nature of the underlying cryptographic protocols. Our second contribution is the design and implementation of SpreadMeNot, a novel contact tracing protocol that can defend against most passive and active attacks, thus providing strong (provable) security and privacy guarantees that are necessary for such a sensitive application. Our detailed analysis, both formal and experimental, shows that SpreadMeNot satisfies security, privacy, and performance requirements, hence being an ideal candidate for building a contact tracing solution that can be adopted by the majority of the general public, as well as to serve as an open-source reference for further developments in the field.
引用
收藏
页码:2500 / 2515
页数:16
相关论文
共 50 条
  • [41] Privacy-preserving COVID-19 contact tracing solution based on blockchain
    Liu, Momeng
    Zhang, Zeyu
    Chai, Wenqiang
    Wang, Baocang
    COMPUTER STANDARDS & INTERFACES, 2023, 83
  • [42] Secure and Privacy-Preserving Matchmaking protocol for Mobile Social Networks
    Ansuura, John Bosco Aristotle Kanpogninge
    Qi, Xia
    Klugah-Brown, Benjamin
    Tei-Ahontu, Richmond Martei
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON LOGISTICS, ENGINEERING, MANAGEMENT AND COMPUTER SCIENCE (LEMCS 2015), 2015, 117 : 144 - 149
  • [43] A novel ECC-based provably secure and privacy-preserving multi-factor authentication protocol for cloud computing
    Shivangi Shukla
    Sankita J. Patel
    Computing, 2022, 104 : 1173 - 1202
  • [44] A secure enhanced privacy-preserving key agreement protocol for wireless mobile networks
    Vanga Odelu
    Sherali Zeadally
    Ashok Kumar Das
    Mohammad Wazid
    Debiao He
    Telecommunication Systems, 2018, 69 : 431 - 445
  • [45] Environmental Adaptive Privacy Preserving Contact Tracing System: A Construction From Public Key Rerandomizable BLS Signatures
    Wang, Pengfei
    Su, Xiangyu
    Jourenko, Maxim
    Jiang, Zixian
    Larangeira, Mario
    Tanaka, Keisuke
    IEEE ACCESS, 2022, 10 : 37181 - 37199
  • [46] Secure and Privacy-Preserving Consensus
    Ruan, Minghao
    Gao, Huan
    Wang, Yongqiang
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2019, 64 (10) : 4035 - 4049
  • [47] A secure enhanced privacy-preserving key agreement protocol for wireless mobile networks
    Odelu, Vanga
    Zeadally, Sherali
    Das, Ashok Kumar
    Wazid, Mohammad
    He, Debiao
    TELECOMMUNICATION SYSTEMS, 2018, 69 (04) : 431 - 445
  • [48] Secure and privacy-preserving, timed vehicular communications
    Burmester, Mike
    Magkos, Emmanouil
    Chrissikopoulos, Vassilis
    INTERNATIONAL JOURNAL OF AD HOC AND UBIQUITOUS COMPUTING, 2012, 10 (04) : 219 - 229
  • [49] Conditional Privacy-Preserving Authentication Protocol With Dynamic Membership Updating for VANETs
    Xiong, Hu
    Chen, Jinhao
    Mei, Qian
    Zhao, Yanan
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2022, 19 (03) : 2089 - 2104
  • [50] A Privacy-Preserving Protocol for Network-Neutral Caching in ISP Networks
    Andreoletti, Davide
    Ayoub, Omran
    Rottondi, Cristina
    Giordano, Silvia
    Verticale, Giacomo
    Tornatore, Massimo
    IEEE ACCESS, 2019, 7 : 160227 - 160240