Vetting Security and Privacy of Global COVID-19 Contact Tracing Applications

06/19/2020
by   Ruoxi Sun, et al.
0

The rapid spread of COVID-19 has made traditional manual contact tracing to identify potential persons in close physical proximity to an known infected person challenging. Hence, a number of public health authorities have experimented with automated contact tracing apps. While the global deployment of contact tracing apps aims to protect the health of citizens, these apps have raised security and privacy concerns. In this paper, we assess the security and privacy of 34 exemplar contact tracing apps using three methodologies: (i) evaluate the design paradigms and the privacy protections provided; (ii) static analysis to discover potential vulnerabilities and data flows to identify potential leaks of private data; and (iii) evaluate the robustness of privacy protection approaches. Based on the results, we propose a venue-access-based contact tracing solution, VenueTrace, which preserves user privacy while enabling proximity contact tracing. We hope that our systematic assessment results and concrete recommendations can contribute to the development and deployment of applications against COVID-19 and help governments and application development industry build secure and privacy-preserving contract tracing applications.

READ FULL TEXT

page 5

page 6

research
07/18/2022

A Security Privacy Analysis of US-based Contact Tracing Apps

With the onset of COVID-19, governments worldwide planned to develop and...
research
04/08/2020

TraceSecure: Towards Privacy Preserving Contact Tracing

Contact tracing is being widely employed to combat the spread of COVID-1...
research
05/25/2020

Decentralized Privacy-Preserving Proximity Tracing

This document describes and analyzes a system for secure and privacy-pre...
research
01/20/2022

CoAvoid: Secure, Privacy-Preserved Tracing of Contacts for Infectious Diseases

To fight against infectious diseases (e.g., SARS, COVID-19, Ebola, etc.)...
research
03/22/2021

Preliminary Analysis of Potential Harms in the Luca Tracing System

In this document, we analyse the potential harms a large-scale deploymen...
research
07/02/2020

Robust ambiguity for contact tracing

A known drawback of `decentralised' contact tracing architectures is tha...

Please sign up or login with your details

Forgot password? Click here to reset