English

Cross Hashing: Anonymizing encounters in Decentralised Contact Tracing Protocols

Cryptography and Security 2025-03-21 v4 Computers and Society

Abstract

During the COVID-19 (SARS-CoV-2) epidemic, Contact Tracing emerged as an essential tool for managing the epidemic. App-based solutions have emerged for Contact Tracing, including a protocol designed by Apple and Google (influenced by an open-source protocol known as DP3T). This protocol contains two well-documented de-anonymisation attacks. Firstly that when someone is marked as having tested positive and their keys are made public, they can be tracked over a large geographic area for 24 hours at a time. Secondly, whilst the app requires a minimum exposure duration to register a contact, there is no cryptographic guarantee for this property. This means an adversary can scan Bluetooth networks and retrospectively find who is infected. We propose a novel "cross hashing" approach to cryptographically guarantee minimum exposure durations. We further mitigate the 24-hour data exposure of infected individuals and reduce computational time for identifying if a user has been exposed using kk-Anonymous buckets of hashes and Private Set Intersection. We empirically demonstrate that this modified protocol can offer like-for-like efficacy to the existing protocol.

Keywords

Cite

@article{arxiv.2005.12884,
  title  = {Cross Hashing: Anonymizing encounters in Decentralised Contact Tracing Protocols},
  author = {Junade Ali and Vladimir Dyo},
  journal= {arXiv preprint arXiv:2005.12884},
  year   = {2025}
}

Comments

Accepted at the 35th International Conference on Information Networking (ICOIN 2021). To be presented between 13-16 January 2021

R2 v1 2026-06-23T15:49:44.687Z