作者: Seyit Camtepe , Gareth Tyson , Damith Ranasinghe , Minhui Xue , Wei Wang
DOI:
关键词:
摘要: The rapid spread of COVID-19 has made traditional manual contact tracing to identify potential persons in close physical proximity an known infected person challenging. Hence, a number public health authorities have experimented with automated apps. While the global deployment apps aims protect citizens, these raised security and privacy concerns. In this paper, we assess 34 exemplar using three methodologies: (i) evaluate design paradigms protections provided; (ii) static analysis discover vulnerabilities data flows leaks private data; (iii) robustness protection approaches. Based on results, propose venue-access-based solution, VenueTrace, which preserves user while enabling tracing. We hope that our systematic assessment results concrete recommendations can contribute development applications against help governments application industry build secure privacy-preserving contract applications.