论文标题
PAAR:隐私意识访问调节系统
PAARS: Privacy Aware Access Regulation System
论文作者
论文摘要
在大流行期间,卫生官员通常建议在主要活动中心的地方使用访问监控和监管协议/系统。作为组织遵守这些建议,他们通常无法执行适当的隐私要求,以防止这些协议或系统用户的隐私损失。这是一个非常及时的问题,因为世界各地的卫生当局越来越多地提出这些法规,以减轻当前大流行的传播。已经提出了许多解决方案,以减轻当前联系跟踪或访问法规系统模型中存在的这些隐私问题。但是,这些解决方案中的普遍模式主要是专注于保护用户从服务器端保护隐私,并涉及用户之间的基于蓝牙的临时标识符交换。另一种模式是当前的所有解决方案都试图解决全市或全国范围内的问题。在本文中,我们提出了一个系统,即PAAR,该系统从微观层面处理访问监控/调节系统中的隐私问题。我们在访问监视/监管系统中解决了隐私问题,而无需交换用户之间的任何短暂标识符。此外,我们提出的系统通过使用安全的哈希和差异隐私机制在服务器端和用户端提供隐私。
During pandemics, health officials usually recommend access monitoring and regulation protocols/systems in places that are major activity centres. As organizations adhere to those recommendations, they often fail to implement proper privacy requirements to prevent privacy loss of the users of those protocols or systems. This is a very timely issue as health authorities across the world are increasingly putting these regulations in place to mitigate the spread of the current pandemic. A number of solutions have been proposed to mitigate these privacy issues existing in current models of contact tracing or access regulations systems. However, a prevalent pattern among these solutions are they mainly focus on protecting users privacy from server side and involve Bluetooth based ephemeral identifier exchange between users. Another pattern is all the current solutions try to solve the problem in city-wide or nation-wide level. In this paper, we propose a system, PAARS, which approaches the privacy issues in access monitoring/regulation systems from a micro level. We solve the privacy issues in access monitoring/regulation systems without any exchange of any ephemeral identifiers between users. Moreover, our proposed system provides privacy on both server side and the user side by using secure hashing and differential privacy mechanism.