论文标题
数字接触跟踪解决方案:承诺,陷阱和挑战
Digital Contact Tracing Solutions: Promises, Pitfalls and Challenges
论文作者
论文摘要
COVID-19大流行使许多国家部署新型的数字接触跟踪(DCT)系统,以提高感染链的手动追踪效率。在本文中,我们根据其设计方法和体系结构系统地分析了DCT解决方案并将其分类。我们分析了他们的有效性,安全性,隐私和道德方面,并比较有关这些要求的突出解决方案。特别是,我们讨论了目前在世界范围内广泛采用的Google和Apple曝光通知API(GAEN)的缺点。我们发现,盖恩的安全性和隐私性存在相当大的缺陷,因为严重的大规模攻击可能会损害它。我们还讨论了其他提议的接触跟踪方法,包括我们的提案Tracecorona,这些方法基于Diffie-Hellman(DH)的密钥交换,并旨在解决现有解决方案的缺点。我们的广泛分析表明,与部署的最新方法相比,Tracecorona可以更好地满足上述安全要求。我们已经实施了tracecorona,并且其Beta测试版已被2000多个没有任何重大功能问题的用户使用,这表明没有技术原因需要就DCTAppRacees的要求做出妥协。
The COVID-19 pandemic has caused many countries to deploy novel digital contact tracing (DCT) systems to boost the efficiency of manual tracing of infection chains. In this paper, we systematically analyze DCT solutions and categorize them based on their design approaches and architectures. We analyze them with regard to effectiveness, security, privacy, and ethical aspects and compare prominent solutions with regard to these requirements. In particular, we discuss the shortcomings of the Google and Apple Exposure Notification API (GAEN) that is currently widely adopted all over the world. We find that the security and privacy of GAEN have considerable deficiencies as it can be compromised by severe, large-scale attacks. We also discuss other proposed approaches for contact tracing, including our proposal TRACECORONA, that are based on Diffie-Hellman (DH) key exchange and aim at tackling shortcomings of existing solutions. Our extensive analysis shows thatTRACECORONA fulfills the above security requirements better than deployed state-of-the-art approaches. We have implementedTRACECORONA, and its beta test version has been used by more than 2000 users without any major functional problems, demonstrating that there are no technical reasons requiring to make compromises with regard to the requirements of DCTapproaches.