论文标题

Prilok:保护公民分布式流行示威

PriLok: Citizen-protecting distributed epidemic tracing

论文作者

Esteves-Verissimo, Paulo, Decouchant, Jérémie, Völp, Marcus, Esfahani, Alireza, Graczyk, Rafal

论文摘要

接触跟踪是国家卫生服务与流行病的重要工具。作为COVID-19情况的一部分,已经提出了许多建议,以借助智能手机应用程序来扩大合同追踪能力,这是由于此类解决方案所涉及的隐私风险,这是一项重要但高度关键的努力。在本文中,我们清楚地表达了我们先前表示关注的关注点,即任何解决方案在努力服务时都必须满足的功能和非功能性要求,而不是仅仅是个人的集合,而是整个国家,而这是面对这种潜在危险的流行病的所要求的。我们提出了一个关键的信息基础架构Prilock,这是一个全面开放的初步架构建议,并设计了隐私触点跟踪的隐私范围,我们认为可以以满足以前的要求的方式进行构建。我们的架构利用现有的受监管的移动通信基础架构,并基于“制衡和余额”的概念,要求大多数独立玩家同意对其进行任何操作,从而防止滥用必须收集和处理的高度敏感信息,以有效接触式接触。这是通过在很大程度上分散的布局和高度弹性的最先进技术来实现的,我们在本文中对此进行了解释,并通过提供安全性,可靠性和弹性分析来完成,即使基础架构受到攻击,它也表明了它如何满足确定的要求。

Contact tracing is an important instrument for national health services to fight epidemics. As part of the COVID-19 situation, many proposals have been made for scaling up contract tracing capacities with the help of smartphone applications, an important but highly critical endeavor due to the privacy risks involved in such solutions. Extending our previously expressed concern, we clearly articulate in this article, the functional and non-functional requirements that any solution has to meet, when striving to serve, not mere collections of individuals, but the whole of a nation, as required in face of such potentially dangerous epidemics. We present a critical information infrastructure, PriLock, a fully-open preliminary architecture proposal and design draft for privacy preserving contact tracing, which we believe can be constructed in a way to fulfill the former requirements. Our architecture leverages the existing regulated mobile communication infrastructure and builds upon the concept of "checks and balances", requiring a majority of independent players to agree to effect any operation on it, thus preventing abuse of the highly sensitive information that must be collected and processed for efficient contact tracing. This is enforced with a largely decentralised layout and highly resilient state-of-the-art technology, which we explain in the paper, finishing by giving a security, dependability and resilience analysis, showing how it meets the defined requirements, even while the infrastructure is under attack.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源