论文标题
联系跟踪申请的隐私指南
Privacy Guidelines for Contact Tracing Applications
论文作者
论文摘要
接触跟踪是一种非常有力的方法,可以实施和执行社会距离,以避免传播传染病。接触追踪的传统方法是由于疲劳或缺乏技巧而耗时,人力密集型,危险和容易出错。因此,出现了基于移动的应用程序以进行接触跟踪。这些应用程序主要利用基于GPS的绝对位置和基于蓝牙的相对位置的组合,这些位置从用户的智能手机中汇出来推断各种见解。这些应用程序减轻了接触跟踪的任务;但是,它们也对用户的隐私有严重影响,例如,大规模监视,个人信息泄漏以及另外揭示用户的行为模式。对用户隐私的这种影响会导致这些应用程序的信任赤字,从而破坏了他们的目的。 在这项工作中,我们讨论了触点跟踪应用程序应该能够处理的各种情况。我们强调了一些突出的接触跟踪应用程序的隐私处理。此外,我们描述了可以破坏其工作或滥用最终用户数据或妨碍其大规模采用的各种威胁行为者。最后,我们从不同的利益相关者的角度提出了有关联系跟踪申请的隐私指南。据我们所知,这是第一项通用工作,它为联系跟踪应用程序提供了隐私指南。
Contact tracing is a very powerful method to implement and enforce social distancing to avoid spreading of infectious diseases. The traditional approach of contact tracing is time consuming, manpower intensive, dangerous and prone to error due to fatigue or lack of skill. Due to this there is an emergence of mobile based applications for contact tracing. These applications primarily utilize a combination of GPS based absolute location and Bluetooth based relative location remitted from user's smartphone to infer various insights. These applications have eased the task of contact tracing; however, they also have severe implication on user's privacy, for example, mass surveillance, personal information leakage and additionally revealing the behavioral patterns of the user. This impact on user's privacy leads to trust deficit in these applications, and hence defeats their purpose. In this work we discuss the various scenarios which a contact tracing application should be able to handle. We highlight the privacy handling of some of the prominent contact tracing applications. Additionally, we describe the various threat actors who can disrupt its working, or misuse end user's data, or hamper its mass adoption. Finally, we present privacy guidelines for contact tracing applications from different stakeholder's perspective. To best of our knowledge, this is the first generic work which provides privacy guidelines for contact tracing applications.