Automated Security Analysis of Exposure Notification Systems
Kevin Morio, Ilkan Esiyok, Dennis Jackson, Robert Künnemann
摘要
We present the first formal analysis and comparison of the security of the two most widely deployed exposure notification systems, ROBERT and the Google and Apple Exposure Notification (GAEN) framework. ROBERT is the most popular instalment of the centralised approach to exposure notification, in which the risk score is computed by a central server. GAEN, in contrast, follows the decentralised approach, where the user's phone calculates the risk. The relative merits of centralised and decentralised systems have proven to be a controversial question. The majority of the previous analyses have focused on the privacy implications of these systems, ours is the first formal analysis to evaluate the security of the deployed systems -- the absence of false risk alerts. We model the French deployment of ROBERT and the most widely deployed GAEN variant, Germany's Corona-Warn-App. We isolate the precise conditions under which these systems prevent false alerts. We determine exactly how an adversary can subvert the system via network and Bluetooth sniffing, database leakage or the compromise of phones, back-end systems and health authorities. We also investigate the security of the original specification of the DP3T protocol, in order to identify gaps between the proposed scheme and its ultimate deployment. We find a total of 27 attack patterns, including many that distinguish the centralised from the decentralised approach, as well as attacks on the authorisation procedure that differentiate all three protocols. Our results suggest that ROBERT's centralised design is more vulnerable against both opportunistic and highly resourced attackers trying to perform mass-notification attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper3
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic 等CCS 2018 · 被引用 428 次
- Automated Analysis and Verification of TLS 1.3: 0-RTT, Resumption and Delayed AuthenticationCas Cremers, Marko Horvat, Sam Scott, Thyla van der MerweS&P 2016 · 被引用 128 次
- A Devil of a Time: How Vulnerable is NTP to Malicious Timeservers?Yarin Perry, Neta Rozen Schiff, Michael SchapiraNDSS 2021
相关 Paper
- Contact Tracing App Privacy: What Data Is Shared By Europe's GAEN Contact Tracing AppsDouglas J. Leith, Stephen FarrellINFOCOM 2021 · 被引用 42 次
- Users' Expectations, Experiences, and Concerns With COVID Alert, an Exposure-Notification AppYue Huang, Borke Obada-Obieh, Satya Lokam, Konstantin BeznosovCSCW 2022 · 被引用 4 次
- Protect Your Score: Contact-Tracing with Differential Privacy GuaranteesRob Romijnders, Christos Louizos, Yuki M. Asano, Max WellingAAAI 2024 · 被引用 5 次
- Provable Security Analyses of Google's and Apple's Bluetooth Fast Pair ProtocolsAlexandra Boldyreva, Olga Sanina, Roy StracovskyCRYPTO 2026
- Linking Bluetooth LE & Classic and Implications for Privacy-Preserving Bluetooth-Based ProtocolsNorbert Ludant, Tien Dang Vo-Huu, Sashank Narain, Guevara NoubirS&P 2021 · 被引用 11 次
