论文标题
联系跟踪:技术和网络风险的概述
Contact Tracing: An Overview of Technologies and Cyber Risks
论文作者
论文摘要
2020年的Covid-19大流行导致了全球封锁,并带来了严重的健康和经济后果。结果,全球当局表示需要更好的工具来监测病毒的传播和支持人类劳动。 Google和Apple等研究人员和技术公司已提出,以联系跟踪应用程序的形式开发此类工具。这些应用程序的目的是不断跟踪人们的接近性,并使智能手机用户知道是否曾经与正面诊断的人保持联系,以便他们可以自我验证并可能进行感染测试。这些基于智能手机的联系跟踪技术的基本挑战是确保用户的安全性和隐私。从手动到基于智能手机的接触跟踪会产生新的网络风险,可能会突然影响整个人群。主要风险包括例如,公司和/或当局滥用人民的私人数据,或恶意用户散布错误的警报以迫使个人隔离。 2020年4月,宣布了泛欧隐私的接近追踪(PEPP-PT)的目标,目的是开发和评估欧洲国家的安全解决方案。但是,过了一会儿,几个团队成员离开了这个财团,创建了DP-3T,这导致了专家之间的国际辩论。目前,非专家遵循这场辩论令人困惑。该报告旨在通过对网络安全和隐私风险进行客观评估来阐明各种提议的技术。我们首先回顾了数字接触跟踪技术的最新技术,然后探索为Covid-19提出的技术的风险耐用权衡。我们专门关注某些国家已经采用的技术。
The 2020 COVID-19 pandemic has led to a global lockdown with severe health and economical consequences. As a result, authorities around the globe have expressed their needs for better tools to monitor the spread of the virus and to support human labor. Researchers and technology companies such as Google and Apple have offered to develop such tools in the form of contact tracing applications. The goal of these applications is to continuously track people's proximity and to make the smartphone users aware if they have ever been in contact with positively diagnosed people, so that they could self-quarantine and possibly have an infection test. A fundamental challenge with these smartphone-based contact tracing technologies is to ensure the security and privacy of their users. Moving from manual to smartphone-based contact tracing creates new cyber risks that could suddenly affect the entire population. Major risks include for example the abuse of the people's private data by companies and/or authorities, or the spreading of wrong alerts by malicious users in order to force individuals to go into quarantine. In April 2020, the Pan-European Privacy-Preserving Proximity Tracing (PEPP-PT) was announced with the goal to develop and evaluate secure solutions for European countries. However, after a while, several team members left this consortium and created DP-3T which has led to an international debate among the experts. At this time, it is confusing for the non-expert to follow this debate; this report aims to shed light on the various proposed technologies by providing an objective assessment of the cybersecurity and privacy risks. We first review the state-of-the-art in digital contact tracing technologies and then explore the risk-utility trade-offs of the techniques proposed for COVID-19. We focus specifically on the technologies that are already adopted by certain countries.