This paper introduces SPOT, a Secure and Privacy-preserving prOximity based protocol for e-healthcare systems. It relies on a distributed proxy-based approach to preserve users' privacy and a semi-trusted computing server to ensure data consistency and integrity. The proposed protocol ensures a balance between security, privacy and scalability. As far as we know, in terms of security, SPOT is the first one to prevent malicious users from colluding and generating false positives. In terms of privacy, SPOT supports both anonymity of users being in proximity of infected people and unlinkability of contact information issued by the same user. A concrete construction based on structure-preserving signatures and NIWI proofs is proposed and a detailed security and privacy analysis proves that SPOT is secure under standard assumptions. In terms of scalability, SPOT's procedures and algorithms are implemented to show its efficiency and practical usability with acceptable computation and communication overhead.
翻译:本文介绍了基于安全和隐私保护的电子保健系统协议SPOT, 即基于安全和隐私的基于电子保健系统的基于安全和隐私的一致的协议,它依靠分散的代用方法来保护用户隐私和半受托计算机服务器,以确保数据的一致性和完整性;拟议的协议确保安全、隐私和可扩缩性之间的平衡;就安全而言,SPOT是防止恶意用户串通和产生虚假阳性的首个协议;就隐私而言,SPOT支持用户的匿名性以及同一用户发布的接触信息的不可链接性;根据结构保护签名和NIWI证明进行的具体建设以及详细的安全和隐私分析证明SPOT在标准假设下是安全的;就可扩缩性而言,SPOT的程序和算法是用来显示其效率和实用性以及可接受的计算和通信间接费用。