论文标题

三星众包蓝牙位置跟踪系统的隐私分析

Privacy Analysis of Samsung's Crowd-Sourced Bluetooth Location Tracking System

论文作者

Yu, Tingfeng, Henderson, James, Tiu, Alwen, Haines, Thomas

论文摘要

我们提供了三星离线查找(OF)协议的详细隐私分析,该协议是三星查找我的手机(FMM)位置跟踪系统的一部分,用于定位三星移动设备,例如三星智能手机和蓝牙跟踪器(Galaxy Smarttags)。协议使用蓝牙低能(BLE)来广播丢失设备的独特信标。然后,附近的三星手机或平板电脑({\ em Finder}设备)将此信标接收到,然后将其转发到独特的信标以及检测到的位置到三星托管服务器。然后,丢失的设备的所有者可以查询服务器以找到其设备。我们从所有者,发现者和供应商的角度研究了协议及其实施的几个安全和隐私属性。这些包括检查:通过从设备获得的蓝牙数据识别设备所有者的可能性,恶意演员通过利用网络来对某人进行不必要的跟踪的可能性,供应商可以将匿名报告降低位置报告的可能性,以确定损失的设备的位置或攻击攻击的位置的位置,并确定攻击性的位置。我们的发现表明,所有账户都有隐私风险,这是由于设计和实施协议的问题而引起的。

We present a detailed privacy analysis of Samsung's Offline Finding (OF) protocol, which is part of Samsung's Find My Mobile (FMM) location tracking system for locating Samsung mobile devices, such as Samsung smartphones and Bluetooth trackers (Galaxy SmartTags). The OF protocol uses Bluetooth Low Energy (BLE) to broadcast a unique beacon for a lost device. This beacon is then picked up by nearby Samsung phones or tablets (the {\em finder} devices), which then forward the unique beacon, along with the location it was detected at, to a Samsung managed server. The owner of a lost device can then query the server to locate their device. We examine several security and privacy related properties of the OF protocol and its implementation, from the perspectives of the owner, the finder and the vendor. These include examining: the possibility of identifying the owner of a device through the Bluetooth data obtained from the device, the possibility for a malicious actor to perform unwanted tracking against a person by exploiting the OF network, the possibility for the vendor to de-anonymise location reports to determine the locations of the owners or the finders of lost devices, and the possibility for an attacker to compromise the integrity of the location reports. Our findings suggest that there are privacy risks on all accounts, arising from issues in the design and the implementation of the OF protocol.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源