Epione: Lightweight Contact Tracing with Strong Privacy
Ni Trieu, Kareem Shehata, Prateek Saxena, Reza Shokri, and Dawn Song

TL;DR
Epione is a privacy-preserving contact tracing system that uses a novel cryptographic protocol to securely determine contact intersections without revealing user identities or contact details, enhancing privacy and false report protection.
Contribution
The paper introduces Epione, a lightweight contact tracing system with strong privacy guarantees and a new cryptographic tool for secure set intersection cardinality tailored for large-scale contact tracing.
Findings
Provides end-to-end privacy protection for contact tracing.
Achieves efficient intersection size computation with small client sets.
Protects against false reporting and linkage attacks.
Abstract
Contact tracing is an essential tool in containing infectious diseases such as COVID-19. Many countries and research groups have launched or announced mobile apps to facilitate contact tracing by recording contacts between users with some privacy considerations. Most of the focus has been on using random tokens, which are exchanged during encounters and stored locally on users' phones. Prior systems allow users to search over released tokens in order to learn if they have recently been in the proximity of a user that has since been diagnosed with the disease. However, prior approaches do not provide end-to-end privacy in the collection and querying of tokens. In particular, these approaches are vulnerable to either linkage attacks by users using token metadata, linkage attacks by the server, or false reporting by users. In this work, we introduce Epione, a lightweight system for…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPrivacy-Preserving Technologies in Data · Privacy, Security, and Data Protection · Internet Traffic Analysis and Secure E-voting
