论文标题
将位置和全局上下文添加到Google/Apple曝光通知蓝牙API
Adding Location and Global Context to the Google/Apple Exposure Notification Bluetooth API
论文作者
论文摘要
接触跟踪需要对用户的上下文有深入的了解,并且具有其他感官数据的位置可以为任何感染遭遇提供背景。尽管蓝牙技术很好地了解了相遇的接近性方面,但它没有提供与之相关的任何位置上下文,从而有助于做出更好的决策。使用本文提出的想法,应该能够获得这些有价值的信息,这些信息可以在一定程度上解决假阳性和假阴性问题。在保留完整的用户隐私的同时,在Google/Apple曝光通知(GAEN)规范的权限范围内所有这些。在任何两个用户之间都有四种传播上下文的方法。两种这样的方法允许私有位置记录,而无需揭示应用程序中的位置历史记录。另外两种是基于加密的方法。第一个加密方法是Apple Findmy协议的一种变体,它允许附近的Apple设备捕获丢失的Apple设备的GPS位置。第二个加密是对现有GAEN协议的次要修改,因此只有在暴露的情况下,只有在健康手机中才能使用全局上下文 - 相对是更好的选择。决定如何使用位置时间上下文,建立成熟的联系跟踪和公共卫生解决方案,这仍然是公共卫生智能手机应用程序的角色。最后,我们强调了此处提出的这些上下文传播方法的每个上下文传播方法所面临的好处和潜在隐私问题。
Contact tracing requires a strong understanding of the context of a user, and location with other sensory data could provide a context for any infection encounter. Although Bluetooth technology gives a good insight into the proximity aspect of an encounter, it does not provide any location context related to it which helps to make better decisions. Using the ideas presented in this paper, one shall be able to obtain this valuable information that could address the problem of false-positive and false-negative to a certain extent. All of this within the purview of Google/Apple Exposure Notification (GAEN) specification, while preserving complete user privacy. There are four ways of propagating context between any two users. Two such methods allow private location logging, without revealing the location history within an app. The other two are encryption-based methods. The first encryption method is a variant of Apple's FindMy protocol, that allows nearby Apple devices to capture the GPS location of a lost Apple device. The second encryption is a minor modification of the existing GAEN protocol so that global context is available to a healthy phone only when it is exposed - this is a better option comparatively. It will still be the role of Public Health smartphone app to decide, on how to use the location-time context, to build a full-fledged contact tracing and public health solution. Lastly, we highlight the benefits and potential privacy issues with each of these context propagation methods proposed here.