[Paper Review] Target Privacy Threat Modeling for COVID-19 Exposure Notification Systems
This paper proposes a targeted privacy threat modeling (TPTM) framework specifically for COVID-19 exposure notification systems (ENS), addressing privacy threats beyond traditional software-centric models by integrating hardware, human behavior, regulations, and system architecture. The framework identifies attacker capabilities, maps privacy threats to specific identifiers, and provides actionable mitigation strategies, resulting in a comprehensive, consistent, and privacy-by-design threat model for ENS deployments.
The adoption of digital contact tracing (DCT) technology during the COVID-19pandemic has shown multiple benefits, including helping to slow the spread of infectious disease and to improve the dissemination of accurate information. However, to support both ethical technology deployment and user adoption, privacy must be at the forefront. With the loss of privacy being a critical threat, thorough threat modeling will help us to strategize and protect privacy as digital contact tracing technologies advance. Various threat modeling frameworks exist today, such as LINDDUN, STRIDE, PASTA, and NIST, which focus on software system privacy, system security, application security, and data-centric risk, respectively. When applied to the exposure notification system (ENS) context, these models provide a thorough view of the software side but fall short in addressing the integrated nature of hardware, humans, regulations, and software involved in such systems. Our approach addresses ENSsas a whole and provides a model that addresses the privacy complexities of a multi-faceted solution. We define privacy principles, privacy threats, attacker capabilities, and a comprehensive threat model. Finally, we outline threat mitigation strategies that address the various threats defined in our model
Motivation & Objective
- To address the limitations of existing threat modeling frameworks like STRIDE, LINDDUN, PASTA, and NIST in capturing the full scope of privacy threats in exposure notification systems (ENS).
- To develop a unified, attacker-centric privacy threat modeling framework that accounts for the integrated nature of hardware, software, human behavior, and regulatory compliance in ENS ecosystems.
- To ensure consistent, exhaustive, and minimally redundant threat modeling outcomes through a target state-driven approach that reduces false positives and overlooked threats.
- To define a comprehensive set of privacy threats based on attacker capabilities and map them to specific privacy identifiers and attack vectors in ENS.
- To provide actionable, standardized mitigation strategies for each identified threat, aligned with privacy principles and regulatory standards such as GDPR and ePrivacy directives.
Proposed method
- The TPTM framework is built around a target state model that defines the desired privacy-preserving system state, ensuring consistency and completeness in threat modeling.
- It uses an attacker-centric approach, classifying threats based on attacker capabilities (e.g., coercion, data inference, device compromise) rather than just technical vulnerabilities.
- The framework maps privacy threats to specific privacy identifiers (e.g., location, device ID, exposure logs) and defines attack scenarios for each, using information flow diagrams (IFDs) and data flow diagrams (DFDs).
- It introduces standardized terminology and simplifies complex many-to-many relationships between threat categories and capabilities to improve clarity and usability.
- Mitigation strategies are mapped to each threat, including technical controls (e.g., end-to-end encryption, differential privacy, secure enclaves), policy controls (e.g., data minimization, user consent), and architectural patterns (e.g., reference architectures, separation of duties).
- The framework is applied to build a concrete Target Privacy Threat Model for ENS, covering both case management and proximity tracing components, with detailed threat-mitigation mappings.
Experimental results
Research questions
- RQ1How can existing threat modeling frameworks be enhanced to address the unique privacy challenges of exposure notification systems that integrate software, hardware, human behavior, and regulatory constraints?
- RQ2What are the key privacy threats in ENS that go beyond traditional software security, such as coercion, data re-identification, and regulatory non-compliance?
- RQ3How can a consistent, repeatable, and comprehensive threat modeling process be established for ENS that minimizes false positives and overlooked threats?
- RQ4What specific privacy identifiers are most at risk in ENS, and how can attacker capabilities be systematically categorized and mapped to these identifiers?
- RQ5What technical, organizational, and policy-based mitigation strategies are most effective in addressing the full spectrum of privacy threats in ENS?
Key findings
- The TPTM framework successfully identifies and categorizes privacy threats in ENS that are missed by conventional software-centric models, including coercion attacks and regulatory compliance risks.
- The framework enables consistent threat modeling outcomes regardless of who performs the analysis, due to its reliance on a well-defined target state and standardized terminology.
- Specific threats such as data linkage via Bluetooth identifiers, device fingerprinting, and unauthorized data access through compromised servers are formally mapped and mitigated with technical controls like differential privacy and secure enclaves.
- Mitigation strategies such as end-to-end encryption, HMAC for replay protection, and separation of verification from exposure notification significantly reduce attack surface and data exposure.
- The framework supports compliance with key privacy regulations like GDPR and ePrivacy directives by embedding principles like data minimization, user control, and transparency into the threat modeling process.
- The application of the TPTM framework to ENS results in a comprehensive, actionable, and auditable privacy threat model that supports ethical deployment and user trust in digital contact tracing systems.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.