BlindSignedID: Mitigating Denial-of-Service Attacks on Digital Contact Tracing

08/21/2020
by   Bo-Rong Chen, et al.
0

Due to the recent outbreak of COVID-19, many governments suspended outdoor activities and imposed social distancing policies to prevent the transmission of SARS-CoV-2. These measures have had severe impact on the economy and peoples' daily lives. An alternative to widespread lockdowns is effective contact tracing during an outbreak's early stage. However, mathematical models suggest that epidemic control for SARS-CoV-2 transmission with manual contact tracing is implausible. To reduce the effort of contact tracing, many digital contact tracing projects (e.g., PEPP-PT, DP-3T, TCN, BlueTrace, Google/Apple Exposure Notification, and East/West Coast PACT) are being developed to supplement manual contact tracing. However, digital contact tracing has drawn scrutiny from privacy advocates, since governments or other parties may attempt to use contact tracing protocols for mass surveillance. As a result, many digital contact tracing projects build privacy-preserving mechanisms to limit the amount of privacy-sensitive information leaked by the protocol. In this paper, we examine how these architectures resist certain classes of attacks, specifically DoS attacks, and present BlindSignedIDs, a privacy-preserving digital contact tracing mechanism, which are verifiable ephemeral identifiers to limit the effectiveness of MAC-compliant DoS attacks. In our evaluations, we showed BlindSignedID can effectively deny bogus EphIDs, mitigating DoS attacks on the local storage beyond 90 showed that using 4 attackers can cause the gigabyte level DoS attacks within normal working hours and days.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/25/2020

Confidential Computing for Privacy-Preserving Contact Tracing

Contact tracing is paramount to fighting the pandemic but it comes with ...
research
03/10/2021

DIMY: Enabling Privacy-preserving Contact Tracing

The infection rate of COVID-19 and lack of an approved vaccine has force...
research
07/26/2020

Digital Surveillance Systems for Tracing COVID-19: Privacy and Security Challenges with Recommendations

Coronavirus disease 2019, i.e. COVID-19 has imposed the public health me...
research
01/08/2021

Hansel and Gretel and the Virus: Privacy Conscious Contact Tracing

Digital contact tracing has been proposed to support the health authorit...
research
11/08/2020

Privacy-accuracy trade-offs in noisy digital exposure notifications

Since the global spread of Covid-19 began to overwhelm the attempts of g...
research
05/26/2020

Cross Hashing: Anonymizing encounters in Decentralised Contact Tracing Protocols

During the COVID-19 (SARS-CoV-2) epidemic, Contact Tracing emerged as an...
research
12/06/2020

On the Privacy and Integrity Risks of Contact-Tracing Applications

Smartphone-based contact-tracing applications are at the epicenter of th...

Please sign up or login with your details

Forgot password? Click here to reset