论文标题
私人访问的联系跟踪
Private-Yet-Verifiable Contact Tracing
论文作者
论文摘要
我们提出了PryVect,这是一种可以私人验证的接触跟踪系统。 PryVect也作为授权框架的工作,允许定义细粒度的策略,某个设施可以定义并适用于更好地建模其自己的访问规则。仅当用户展示符合政策的联系跟踪时,才可以访问该设施。政策评估过程是在不透露用户个人数据的情况下进行的。同时,每个用户可以向她获得一定授权的第三方(例如公共当局)证明。 PryVect利用遗忘的自动机评估来实施保存隐私的政策执法机制。
We propose PrYVeCT, a private-yet-verifiable contact tracing system. PrYVeCT works also as an authorization framework allowing for the definition of fine-grained policies, which a certain facility can define and apply to better model its own access rules. Users are authorized to access the facility only when they exhibit a contact trace that complies with the policy. The policy evaluation process is carried out without disclosing the personal data of the user. At the same time, each user can prove to a third party (e.g., a public authority) that she received a certain authorization. PrYVeCT takes advantage of oblivious automata evaluation to implement a privacy-preserving policy enforcement mechanism.