The infection rate of COVID-19 and lack of an approved vaccine has forced governments and health authorities to adopt lockdowns, increased testing, and contact tracing to reduce the spread of the virus. Digital contact tracing has become a supplement to the traditional manual contact tracing process. However, although there have been a number of digital contact tracing apps proposed and deployed, these have not been widely adopted owing to apprehensions surrounding privacy and security. In this paper, we propose a blockchain-based privacy-preserving contact tracing protocol, "Did I Meet You" (DIMY), that provides full-lifecycle data privacy protection on the devices themselves as well as on the back-end servers, to address most of the privacy concerns associated with existing protocols. We have employed Bloom filters to provide efficient privacy-preserving storage, and have used the Diffie-Hellman key exchange for secret sharing among the participants. We show that DIMY provides resilience against many well known attacks while introducing negligible overheads. DIMY's footprint on the storage space of clients' devices and back-end servers is also significantly lower than other similar state of the art apps.
翻译:由于COVID-19的感染率和缺乏经批准的疫苗,迫使政府和卫生当局采用封闭式监控、增加检测和接触追踪,以减少病毒的传播。数字联系追踪已成为传统人工接触追踪过程的一种补充。然而,尽管已经提出并部署了一些数字联系追踪应用程序,但由于对隐私和安全的担忧,这些应用程序尚未被广泛采用。在本文件中,我们提议采用基于链式隐私保护接触追踪协议“我是否遇见你”(DIMY),为设备本身和后端服务器提供全寿命周期数据隐私保护,以解决与现有协议有关的大部分隐私问题。我们利用Bloom过滤器提供高效的隐私保存存储,并使用Diffie-Hellman关键交换器在参与者之间进行秘密共享。我们表明DIMY提供抵御许多已知袭击的复原力,同时引入了微不足道的间接费用。DIMY在客户设备和后端服务器的存储空间上的足迹也大大低于其他类似的艺术应用程序状态。