论文标题

接触示踪使得不可延期

Contact Tracing Made Un-relay-able

论文作者

Casagrande, Marco, Conti, Mauro, Losiouk, Eleonora

论文摘要

自动接触跟踪是控制空降可传播疾病传播的关键解决方案:它可以追溯个人之间的接触,以便提醒人们可能被感染的潜在风险。当前的SARS-COV-2大流行对许多国家的医疗保健系统产生了巨大的压力。政府选择了面对病毒传播的不同方法,并且接触式追踪应用被认为是最有效的应用程序。特别是,通过利用蓝牙低能技术,移动应用程序可以实现对公民的隐私联系跟踪。研究人员提出了几种接触追踪方法,但每个政府都开发了自己的国家联系跟踪应用程序。 在本文中,我们证明了许多流行的联系追踪应用程序(例如,意大利语,法国,瑞士政府推广的应用程序)很容易受到接力攻击的影响。通过这样的攻击,人们可能会被误导地被诊断为SARS-COV-2,因此被强制隔离并最终导致医疗保健系统破裂。为了解决这一脆弱性,我们提出了一种新颖且轻巧的解决方案,以防止继电器攻击,同时提供与当前方法相同的隐私功能。为了评估中继攻击和我们新颖的防御机制的可行性,我们为意大利触点跟踪应用程序(即免疫)制定了概念证明。我们的防御设计使其可以集成到任何接触跟踪应用程序中。

Automated contact tracing is a key solution to control the spread of airborne transmittable diseases: it traces contacts among individuals in order to alert people about their potential risk of being infected. The current SARS-CoV-2 pandemic put a heavy strain on the healthcare system of many countries. Governments chose different approaches to face the spread of the virus and the contact tracing apps were considered the most effective ones. In particular, by leveraging on the Bluetooth Low-Energy technology, mobile apps allow to achieve a privacy-preserving contact tracing of citizens. While researchers proposed several contact tracing approaches, each government developed its own national contact tracing app. In this paper, we demonstrate that many popular contact tracing apps (e.g., the ones promoted by the Italian, French, Swiss government) are vulnerable to relay attacks. Through such attacks people might get misleadingly diagnosed as positive to SARS-CoV-2, thus being enforced to quarantine and eventually leading to a breakdown of the healthcare system. To tackle this vulnerability, we propose a novel and lightweight solution that prevents relay attacks, while providing the same privacy-preserving features as the current approaches. To evaluate the feasibility of both the relay attack and our novel defence mechanism, we developed a proof of concept against the Italian contact tracing app (i.e., Immuni). The design of our defence allows it to be integrated into any contact tracing app.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源