DESIRE: A Third Way for a European Exposure Notification System Leveraging the best of centralized and decentralized systems

08/04/2020
by   Claude Castelluccia, et al.
0

This document presents an evolution of the ROBERT protocol that decentralizes most of its operations on the mobile devices. DESIRE is based on the same architecture than ROBERT but implements major privacy improvements. In particular, it introduces the concept of Private Encounter Tokens, that are secret and cryptographically generated, to encode encounters. In the DESIRE protocol, the temporary Identifiers that are broadcast on the Bluetooth interfaces are generated by the mobile devices providing more control to the users about which ones to disclose. The role of the server is merely to match PETs generated by diagnosed users with the PETs provided by requesting users. It stores minimal pseudonymous data. Finally, all data that are stored on the server are encrypted using keys that are stored on the mobile devices, protecting against data breach on the server. All these modifications improve the privacy of the scheme against malicious users and authority. However, as in the first version of ROBERT, risk scores and notifications are still managed and controlled by the server of the health authority, which provides high robustness, flexibility, and efficacy.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/10/2018

Tandem: Securing Keys by Using a Central Server While Preserving Privacy

Users' devices, e.g., smartphones or laptops, are typically incapable of...
research
01/30/2020

Towards Designing A Secure Plausibly Deniable System for Mobile Devices against Multi-snapshot Adversaries – A Preliminary Design

Mobile computing devices have been used broadly to store, manage and pro...
research
10/26/2022

Privacy Analysis of Samsung's Crowd-Sourced Bluetooth Location Tracking System

We present a detailed privacy analysis of Samsung's Offline Finding (OF)...
research
01/06/2022

Blizzard: a Distributed Consensus Protocol for Mobile Devices

We present Blizzard, a Byzantine Fault Tolerant (BFT) distributed ledger...
research
11/09/2020

SplitEasy: A Practical Approach for Training ML models on Mobile Devices in a split second

Modern mobile devices, although resourceful, cannot train state-of-the-a...
research
06/05/2019

Fusion of Mobile Device Signal Data Attributes Enables Multi-Protocol Entity Resolution and Enhanced Large-Scale Tracking

Use of persistent identifiers in wireless communication protocols is a k...
research
11/14/2021

Choriented Maps: Visualizing SDG Data on Mobile Devices

Choropleth maps and graduated symbol maps are often used to visualize qu...

Please sign up or login with your details

Forgot password? Click here to reset