论文标题
另一个查看保护隐私的自动联系人跟踪
Another Look at Privacy-Preserving Automated Contact Tracing
论文作者
论文摘要
在当前的COVID-19大流行中,事实证明,手动接触跟踪非常有帮助,可以与受感染的用户的密切接触并减慢病毒扩散。为了提高其可扩展性,已经提出了许多自动接触跟踪(ACT)解决方案,其中一些已被部署。尽管付出了敬业的努力,但这些解决方案的安全和隐私问题仍然是开放的,并且在强烈的辩论中。在本文中,我们从更广泛的角度研究了ACT概念,不仅关注安全性和隐私问题,还要关注诸如接口,可用性和覆盖范围之类的功能问题。我们首先详细介绍了这些问题,尤其是指出现有基于BLE的ACT解决方案中不可避免的隐私泄漏。然后,我们提出了一个基于场地的ACT概念,该概念只能监视用户在传播病毒传播的场地中的联系历史,并能够合并其他位置跟踪技术,例如BLE和WiFi。最后,我们实例化了基于场地的行为概念,并表明我们的实例化可以减轻我们在分析中发现的大多数问题。
In the current COVID-19 pandemic, manual contact tracing has been proven very helpful to reach close contacts of infected users and slow down virus spreading. To improve its scalability, a number of automated contact tracing (ACT) solutions have proposed and some of them have been deployed. Despite the dedicated efforts, security and privacy issues of these solutions are still open and under intensive debate. In this paper, we examine the ACT concept from a broader perspective, by focusing on not only security and privacy issues but also functional issues such as interface, usability and coverage. We first elaborate on these issues and particularly point out the inevitable privacy leakages in existing BLE-based ACT solutions. Then, we propose a venue-based ACT concept, which only monitors users' contacting history in virus-spreading-prone venues and is able to incorporate different location tracking technologies such as BLE and WIFI. Finally, we instantiate the venue-based ACT concept and show that our instantiation can mitigate most of the issues we have identified in our analysis.