Low-energy Bluetooth devices have become ubiquitous and widely used for different applications. Among these, Bluetooth trackers are becoming popular as they allow users to track the location of their physical objects. To do so, Bluetooth trackers are often built-in within other commercial products connected to a larger crowdsourced tracking system. Such a system, however, can pose a threat to the security and privacy of the users, for instance, by revealing the location of a user's valuable object. In this paper, we introduce a set of security properties and investigate the state of commercial crowdsourced tracking systems, which present common design flaws that make them insecure. Leveraging the results of our investigation, we propose a new design for a secure crowdsourced tracking system (SECrow), which allows devices to leverage the benefits of the crowdsourced model without sacrificing security and privacy. Our preliminary evaluation shows that SECrow is a practical, secure, and effective crowdsourced tracking solution
翻译:低能蓝牙装置已变得无处不在,广泛用于不同应用,其中,蓝牙追踪器正在变得受欢迎,因为蓝牙追踪器允许用户跟踪其物理物体的位置。为此,蓝牙追踪器往往在其他商业产品中嵌入与更大的众源跟踪系统连接的蓝牙追踪器。然而,这样的系统可能会对用户的安全和隐私构成威胁,例如,通过披露用户贵重物品的位置。在本文中,我们引入了一套安全特性,并调查商业众源跟踪系统的状况,这些系统存在共同的设计缺陷,使其变得不安全。我们利用我们的调查结果,提出了安全众源跟踪系统的新设计,允许在不牺牲安全和隐私的情况下利用众源模型的好处。我们的初步评估表明,SECrow是一种实用、安全和有效的众源跟踪解决方案。