论文标题
斑点:电子保健系统的安全和隐私的接近协议
SPOT: Secure and Privacy-preserving prOximiTy protocol for e-healthcare systems
论文作者
论文摘要
本文介绍了Spot,这是针对电子保健系统的基于安全且具有隐私的邻近协议。它依靠基于分布式代理的方法来保护用户的隐私和半信任的计算服务器,以确保数据的一致性和完整性。提出的协议确保了安全性,隐私和可扩展性之间的平衡。据我们所知,就安全性而言,斑点是第一个防止恶意用户勾结和产生假阳性的斑点。在隐私方面,Spot支持用户邻近受感染者的匿名性,又支持同一用户发出的联系信息的不链接性。提出了基于结构性签名和NIWI证明的具体构造,并提出了详细的安全性和隐私分析证明,在标准假设下,斑点是安全的。就可伸缩性而言,实施了SPOT的过程和算法,以通过可接受的计算和通信开销来显示其效率和实际可用性。
This paper introduces SPOT, a Secure and Privacy-preserving prOximity based protocol for e-healthcare systems. It relies on a distributed proxy-based approach to preserve users' privacy and a semi-trusted computing server to ensure data consistency and integrity. The proposed protocol ensures a balance between security, privacy and scalability. As far as we know, in terms of security, SPOT is the first one to prevent malicious users from colluding and generating false positives. In terms of privacy, SPOT supports both anonymity of users being in proximity of infected people and unlinkability of contact information issued by the same user. A concrete construction based on structure-preserving signatures and NIWI proofs is proposed and a detailed security and privacy analysis proves that SPOT is secure under standard assumptions. In terms of scalability, SPOT's procedures and algorithms are implemented to show its efficiency and practical usability with acceptable computation and communication overhead.