论文标题
欲望:欧洲曝光通知系统的第三种方式利用了集中和分散系统的最佳
DESIRE: A Third Way for a European Exposure Notification System Leveraging the best of centralized and decentralized systems
论文作者
论文摘要
本文档提出了Robert协议的演变,该协议分散了其在移动设备上的大多数操作。欲望基于与罗伯特相同的架构,但实现了重大的隐私改善。特别是,它介绍了秘密和密码生成的私人遭遇令牌的概念,以编码相遇。在Desire协议中,移动设备为用户提供了更多的控制,以在蓝牙接口上广播的临时标识符为披露哪些提供。服务器的作用仅是将诊断用户生成的宠物与请求用户提供的宠物匹配。它存储最小的假名数据。最后,使用存储在移动设备上的密钥对服务器上存储的所有数据进行加密,以防止服务器上的数据泄露。所有这些修改都改善了针对恶意用户和权威的计划的隐私。但是,就像罗伯特(Robert)的第一版一样,风险评分和通知仍由卫生管理局的服务器管理和控制,卫生管理局提供了很高的鲁棒性,灵活性和功效。
This document presents an evolution of the ROBERT protocol that decentralizes most of its operations on the mobile devices. DESIRE is based on the same architecture than ROBERT but implements major privacy improvements. In particular, it introduces the concept of Private Encounter Tokens, that are secret and cryptographically generated, to encode encounters. In the DESIRE protocol, the temporary Identifiers that are broadcast on the Bluetooth interfaces are generated by the mobile devices providing more control to the users about which ones to disclose. The role of the server is merely to match PETs generated by diagnosed users with the PETs provided by requesting users. It stores minimal pseudonymous data. Finally, all data that are stored on the server are encrypted using keys that are stored on the mobile devices, protecting against data breach on the server. All these modifications improve the privacy of the scheme against malicious users and authority. However, as in the first version of ROBERT, risk scores and notifications are still managed and controlled by the server of the health authority, which provides high robustness, flexibility, and efficacy.