Privacy-preserving COVID-19 contact tracing using blockchain

Shahzaib Tahir, Hasan Tahir, Ali Sajjad, Muttukrishnan Rajarajan, Fawad Khan

Research output: Contribution to journalArticlepeer-review

25 Citations (Scopus)
31 Downloads (Pure)

Abstract

The outbreak of the COVID-19 virus has caused widespread panic and global initiatives are geared towards treatment and limiting its spread. With technological advancements, several mechanisms and mobile applications have been developed that attempt to trace the physical contact made by a person with someone who has been tested COVID-19 positive. While designing these apps, user's privacy has been an afterthought and has resulted in mass violations of privacy of the public and the patients. A total of 32 countries have designed apps and rely on them as a strategy to flatten the pandemic curve. Along with lack of privacy, these methodologies are centralized, where they are fully controlled by the government and the healthcare providers. Owing to these and many other concerns, people are hesitant in the adoption of these technologies. This paper presents a detailed analysis of user tracking apps belonging to 32 countries, thus demonstrating that they collect personal data and are a gross violation of user privacy. This paper presents a novel architecture for the efficient, effective and privacy-preserving contact tracing of COVID-19 patients using blockchain. The proposed architecture preserves the privacy of individuals and their contact history by encrypting all the data specific to an individual using a privacy-preserving Homomorphic encryption scheme and storing it on a permissioned blockchain network. The contacts made with a COVID-19 positive patient are identified by performing search queries directly over the Homomorphic encrypted data stored in the blocks. Therefore, only those contacts that are suspected to be COVID-19 positive may be decrypted by the healthcare professional or government for further contact tracing/diagnosis and COVID-19 testing; thereby leading to enhanced privacy.

Original languageEnglish
Pages (from-to)360-373
Number of pages14
JournalJournal of Communications and Networks
Volume23
Issue number5
Early online date21 Sept 2021
DOIs
Publication statusPublished - Oct 2021

Bibliographical note

Creative Commons Attribution-NonCommercial (CC BY-NC).
This is an Open Access article distributed under the terms of Creative Commons Attribution Non-Commercial License (http://creativecommons.org/licenses/by-nc/3.0) which permits unrestricted non-commercial use, distribution, and reproduction in any medium, provided that the original work is properly cited.

Funder

This work was done collaboratively by the Information Security and Privacy Lab, NUST supported by the National Centre for Cyber Security, Pakistan, under the project titled “Privacy Preserving Search over Sensitive Data Stored in the Cloud” and the City, University of London, UK.

Funding

This work was done collaboratively by the Information Security and Privacy Lab, NUST supported by the National Centre for Cyber Security, Pakistan, under the project titled “Privacy Preserving Search over Sensitive Data Stored in the Cloud” and the City, University of London, UK.

FundersFunder number
National Centre for Cyber Security
National University of Sciences & Technology
City, University of London

    Keywords

    • Coronavirus
    • Hyperledger Fabric
    • pandemic
    • searchable encryption

    ASJC Scopus subject areas

    • Information Systems
    • Computer Networks and Communications

    Fingerprint

    Dive into the research topics of 'Privacy-preserving COVID-19 contact tracing using blockchain'. Together they form a unique fingerprint.

    Cite this