Contact Tracing: Ensuring Privacy and Security



van Leeuwen, Daan Storm, Ahmed, Ali ORCID: 0000-0002-7370-3044, Watterson, Craig and Baghaei, Nilufar
(2021) Contact Tracing: Ensuring Privacy and Security. APPLIED SCIENCES-BASEL, 11 (21). p. 9977.

Access the full-text of this item by clicking on the Open Access link.

Abstract

<jats:p>Faced with the biggest virus outbreak in a century, world governments at the start of 2020 took unprecedented measures to protect their healthcare systems from being overwhelmed in the light of the COVID-19 pandemic. International travel was halted and lockdowns were imposed. Many nations adopted measures to stop the transmission of the virus, such as imposing the wearing of face masks, social distancing, and limits on social gatherings. Technology was quickly developed for mobile phones, allowing governments to track people’s movements concerning locations of the virus (both people and places). These are called contact tracing applications. Contact tracing applications raise serious privacy and security concerns. Within Europe, two systems evolved: a centralised system, which calculates risk on a central server, and a decentralised system, which calculates risk on the users’ handset. This study examined both systems from a threat perspective to design a framework that enables privacy and security for contact tracing applications. Such a framework is helpful for App developers. The study found that even though both systems comply with the General Data Protection Regulation (GDPR), Europe’s privacy legislation, the centralised system suffers from severe risks against the threats identified. Experiments, research, and reviews tested the decentralised system in various settings but found that it performs better but still suffers from inherent shortcomings. User tracking and re-identification are possible, especially when users report themselves as infected. Based on these data, the study identified and validated a framework that enables privacy and security. The study also found that the current implementations using the decentralised Google/Apple API do not comply with the framework.</jats:p>

Item Type: Article
Uncontrolled Keywords: contact tracing, COVID-19 pandemic, security, privacy, mobile application
Divisions: Faculty of Science and Engineering > School of Electrical Engineering, Electronics and Computer Science
Depositing User: Symplectic Admin
Date Deposited: 23 Dec 2021 15:29
Last Modified: 18 Jan 2023 21:18
DOI: 10.3390/app11219977
Open Access URL: https://www.mdpi.com/2076-3417/11/21/9977
Related URLs:
URI: https://livrepository.liverpool.ac.uk/id/eprint/3145976