[论文解读] Digital Surveillance Systems for Tracing COVID-19: Privacy and Security Challenges with Recommendations
本文分析了用于新冠疫情接触者追踪的数字监控系统,包括基于智能手机的应用程序和无人机监控,识别出关键的隐私与安全挑战。针对自动化接触者追踪和基于无人机的系统,提出了有针对性的建议,以减轻数据滥用和网络攻击的风险,同时保持公共卫生有效性。
Coronavirus disease 2019, i.e. COVID-19 has imposed the public health measure of keeping social distancing for preventing mass transmission of COVID-19. For monitoring the social distancing and keeping the trace of transmission, we are obligated to develop various types of digital surveillance systems, which include contact tracing systems and drone-based monitoring systems. Due to the inconvenience of manual labor, traditional contact tracing systems are gradually replaced by the efficient automated contact tracing applications that are developed for smartphones. However, the commencement of automated contact tracing applications introduces the inevitable privacy and security challenges. Nevertheless, unawareness and/or lack of smartphone usage among mass people lead to drone-based monitoring systems. These systems also invite unwelcomed privacy and security challenges. This paper discusses the recently designed and developed digital surveillance system applications with their protocols deployed in several countries around the world. Their privacy and security challenges are discussed as well as analyzed from the viewpoint of privacy acts. Several recommendations are suggested separately for automated contact tracing systems and drone-based monitoring systems, which could further be explored and implemented afterwards to prevent any possible privacy violation and protect an unsuspecting person from any potential cyber attack.
研究动机与目标
- 审查多个国家在新冠疫情接触者追踪中部署的数字监控系统的设计与实施。
- 识别并分析基于智能手机的自动化接触者追踪系统和基于无人机的监控系统中的隐私与安全挑战。
- 根据既定的隐私法律和法规评估这些系统。
- 为改善两类监控系统的隐私与安全性提供可操作的建议。
- 支持在疫情期间开发可信赖的数字公共卫生工具。
提出的方法
- 对多个国家部署的用于新冠疫情接触者追踪的数字监控系统进行系统性综述。
- 分析智能手机接触者追踪应用程序中使用的协议,包括去中心化和集中化模型。
- 评估基于无人机的监控系统在隐私标准合规性以及监控越权风险方面的表现。
- 评估隐私与安全威胁,如数据泄露、未授权访问和追踪持久性。
- 应用隐私优先设计原则,提出缓解策略。
- 制定适用于自动化接触者追踪和基于无人机的监控系统的、不依赖国家的建议。
实验结果
研究问题
- RQ1基于智能手机的数字接触者追踪系统主要存在哪些隐私与安全风险?
- RQ2基于无人机的监控系统在疫情监测中如何侵犯个人隐私?
- RQ3现有监控协议在哪些方面未能符合国际隐私法规?
- RQ4哪些技术和政策措施能有效减少数字接触者追踪系统中的隐私侵犯?
- RQ5如何设计基于无人机的监控,以在保持公共卫生效用的同时最小化监控越权?
主要发现
- 基于智能手机的接触者追踪系统由于采用集中式数据存储模式,面临严重的数据泄露和未授权追踪风险。
- 去中心化系统虽可降低隐私风险,但仍面临用户采纳率低和跨国互操作性差的挑战。
- 基于无人机的监控系统引入了高水平的监控,若未得到适当监管和审计,可能违反隐私法律。
- 两类系统均易受网络攻击,包括欺骗攻击和中间人攻击,尤其是在使用不安全通信通道时。
- 缺乏透明度和公众监督会增加疫情结束后长期监控滥用的风险。
- 本文建议强调隐私优先设计、数据最小化和强加密,以降低两类系统的风险。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。