[论文解读] SwissCovid: a critical analysis of risk assessment by Swiss authorities
本文對瑞士Covid接觸追蹤應用程式進行了批判性分析,揭示Google與Apple的暴露通知(GAEN)架構中存在密碼學缺陷,導致重新識別攻擊與偽陽性信標操控。作者證明,即使未實際抵達瑞士的攻擊者,亦可利用這些弱點推斷使用者身分並操控風險評估,直接與官方聲稱的低風險說法相矛盾。
Ahead of the rollout of the SwissCovid contact tracing app, an official public security test was performed. During this audit, Prof. Serge Vaudenay and Dr. Martin Vuagnoux described a large set of problems with the app, including a new variation of a known false-positive attack, leveraging a cryptographic weakness in the Google and Apple Exposure Notification framework to tamper with the emitted Bluetooth beacons. Separately, the first author described a re-identification attack leveraging rogue apps or SDKs. The response from the Swiss cybersecurity agency and the Swiss public health authority was to claim these various attacks were unlikely as they required physical proximity of the attacker with the target (although it was admitted the attacker could be further than two meters). The physical presence of the attacker in Switzerland was deemed significant as it would imply such attackers would fall under the Swiss Criminal Code. We show through one example that a much larger variety of adversaries must be considered in the scenarios originally described and that these attacks can be done by adversaries without any physical presence in Switzerland. This goes directly against official findings of Swiss public authorities evaluating the risks associated with SwissCovid. To move the discussion further along, we briefly discuss the growth of the attack surface and harms with COVID-19 and SwissCovid prevalence in the population. While the focus of this article is on Switzerland, we emphasize the core technical findings and cybersecurity concerns are of relevance to many contact tracing efforts.
研究动机与目标
- 在公開發布前揭露SwissCovid接觸追蹤應用程式中關鍵的密碼學與隱私弱點。
- 挑戰瑞士官方當局所聲稱的「攻擊者需具備實體接近條件」之說法,認為威脅可能性極低。
- 證明遠端攻擊者——即使未實際抵達瑞士——亦可利用系統弱點對使用者進行重新識別與操控風險通知。
- 強調此類弱點對依賴GAEN架構之數位接觸追蹤系統所帶來的廣泛影響。
- 呼籲瑞士當局與科技平台重新評估隱私風險,並提升公共衛生監控系統的透明度與安全性。
提出的方法
- 針對兩種主要攻擊向量(重新識別與偽陽性信標操控)進行威脅模型分析。
- 透過篡改AES-CTR加密載具中的元資料,操縱藍牙訊號強度數值,進而導致偽造接近檢測。
- 展示利用歷史藍牙信標資料與外部資料庫(如監視攝影機、支付系統)關聯,進行重新識別攻擊。
- 建模攻擊者相較於SwissCovid與公共衛生當局的知識獲取程度,比較覆蓋率與準確率指標($\alpha_{SC}^2$ 對 $\alpha_{CD}$)。
- 分析第三方應用程式與SDK在監視中的角色,特別是過度的藍牙權限所帶來的風險。
- 評估在瑞士法律體系下,將持續發射的滾動接近識別碼(RPIs)視為個人資料的法律與倫理影響。
实验结果
研究问题
- RQ1攻擊者僅憑歷史藍牙信標資料與外部側信道,能在多大程度上重新識別SwissCovid使用者?
- RQ2GAEN架構中的密碼學弱點如何使遠端攻擊者在無實體接觸的情況下,操控接觸追蹤訊號?
- RQ3當遠端攻擊者可利用相同弱點時,為何官方聲稱攻擊需具備實體接近條件的說法不成立?
- RQ4若攻擊者對感染事件與接觸網絡的知識優於公共衛生當局,其所帶來的量化與質性風險為何?
- RQ5第三方應用程式與SDK如何擴大依賴GAEN架構系統的攻擊面?缺少哪些防護機制?
主要发现
- 發現偽陽性攻擊的新變種,利用未經認證的AES-CTR加密技術篡改藍牙訊號強度元資料,實現遠端操控接觸事件。
- 即使在應用程式發布後,重新識別攻擊仍具可行性,因RPIs可從上傳的暫時暴露金鑰(TEKs)重構,進而與外部資料來源關聯。
- 即使未實際抵達瑞士的攻擊者,仍可執行有效攻擊,從而推翻瑞士當局所聲稱的『實體接近為威脅必要條件』之說法。
- 攻擊者對高風險接觸者的知識掌握程度($\alpha_{SC}^2$)可能超過官方系統($\alpha_{CD}$),特別是在感染盛行率上升時。
- 具備過度藍牙權限的第三方應用程式與SDK顯著擴大攻擊面,使隱蔽監視與資料外洩成為可能。
- 瑞士資料保護專員應重新評估,將持續發射的RPIs依瑞士法律視為個人資料,因其具備可識別性與連結攻擊潛力。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。