Baseline Developers Propose DTL-Based Coronavirus Contact Tracing

Published at: April 17, 2020

Developers working on Baseline, an enterprise smart contract and tokenization platform developed by Microsoft, Ernst & Young, and ConsenSys, are working to solve several flaws identified with Apple and Google’s proposal for coronavirus tracking initiatives.

Google and Apple propose a contact tracing solution that would add cross-platform APIs that allow health authorities to monitor users. Both brands have discussed rolling out related software updates next month.

The plan suggests using a phone’s Bluetooth Low Energy to detect other devices within 30 feet of each other. This would allow infected individuals to be identified through proximity detection. For people who come in contact with a confirmed viral carrier, direct notification could help prompt access to testing facilities.

A second phase of this initiative is proposed for later in the year as well. In this update, tech firms would build their own contact tracing platforms into the operating system of devices — removing the need for health authorities to conduct monitoring.

Security flaws identified in Apple/Google proposal

John Wolpert, Group executive at ConsenSys, identifies two significant opportunities for a malicious actor to exploit Google and Apple’s proposal: 

“You could put someone’s Bluetooth key into your list nefariously and cause mayhem; you could find a way to set your state to ‘infectious’ and cause mayhem… or set yourself to 'safe' when you aren’t.”

To solve these issues, Wolpert suggests a system in which the “Bluetooth key and other attributes [are] traded via Bluetooth with devices nearby, but then baselined so that we have a proof that all parties indeed confirmed they were near each other… no more repudiation risk.”

Similarly, he suggests verifying test results against blockchain-based cryptographic proofs, with individuals caught attempting broadcast status information contrary to the baseline proof receiving punishment.

Baseline to decentralize contact tracing

Wolpert also emphasizes fundamental centralization issues with the plan, despite assurances of anonymous identification, stating: “the scheme still means the ‘anonymous’ ids get pooled with entity… govt or other.” 

He asserts that Baseline can be used to deliver a contact monitoring system with greater privacy and security than the plan articulated by Google and Facebook. Walport proposes:

“If you test positive, your hash [...] gets associated with a new value: "infectious", Anyone with one of your hashes in their list will be listening for that hash popping on the Mainnet [...], so when you test positive and the positive result is dropped [—] anyone who has you in their list gets an alert that they were exposed and to ‘hit this button to report the contact to the CDC.” 

Wolpert argues that the system prevents the collection of "a group of ‘anonymous' IDs [...] that would permit, say, a government with some friends that are really good at AI to generate 'interesting' classifiers on populations.” 

Instead, “the positive test result is ‘dead dropped’ on the Mainnet for the exposed parties to pick up as unobservable listeners and then opt-in,” he asserts.

Tags
Related Posts
Coin Center Calls on Crypto Developers to Protect Freedoms in COVID-19 Era
Nonprofit cryptocurrency advocacy group Coin Center has appealed to the community to develop tech-based responses to the COVID-19 pandemic that protect civil liberties and privacy. In a post published on April 8, the center’s director of research, Peter Van Valkenburgh, surveyed recent proposals from the Zcash Foundation for Private Contact Tracing Protocols, as well as progress with Decentralized Identifiers by Microsoft Research. “It's our duty as a community of technologists to be vigilant against the imposition of tracing and identity technologies that could, long term, jeopardize our autonomy and privacy,” Van Valkenburgh wrote. Resisting state overreach Coin Center warns against …
Technology / April 9, 2020
Why secure data tokenization should scare the hell out of Big Data
Data is becoming one of society’s most valuable resources. And yet, our existing approaches fail to unleash its massive intrinsic value. Why is this the case? The issue is that our data — who we are, and what is relevant about us — is defined and collected by corporations and governments. Consumers were alarmed to find their phones were being tracked by the government , for example. These organizations, whether private or governmental, seem interested primarily in using your personal identity and your data streams to enhance their power. If you are an average user, this means you are missing …
Technology / Jan. 21, 2021
Iota blockchain used to track COVID-19 test results at Frankfurt Airport
Early on in the coronavirus pandemic, the heightened need for various biosurveillance measures sparked interest in the relevance of privacy-enhancing technologies such as blockchain that could protect public health data amid the crisis. A Twitter user claimed last week that Frankfurt Airport's coronavirus testing center appeared to be using Iota blockchain technology to manage passengers' health stats, and this fact has now been confirmed to Cointelegraph by the technology provider. Ubirch, a blockchain-based cybersecurity technology provider based in Cologne and several other locations, has developed the IT infrastructure for a solution it calls the "Digital Corona Test Certificate." The solution …
Technology / Jan. 11, 2021
Noncustodial Technology and Security Is the Inevitable Future
In an increasingly digital world, security is a high-stakes game. The identities of customers along with their privacy and financial information are all in the hands of centralized security systems. We are reliant on these systems, and even though security plays a critical role in our lives, we rarely stop to think about the consequences of these systems failing us. Yet those who trade financial assets like cryptocurrencies think about these consequences all the time. Why? The risk of violations of our financial sovereignty coupled with the potential of theft without an option to recover are two big reasons why …
Decentralization / July 31, 2020
The ethics of the metaverse: Privacy, ownership and control
The metaverse, a virtual environment that simulates reality, offers complex moral dilemmas regarding privacy, ownership and control. These consist of: Privacy: Who has access to and how is personal information used within the metaverse? Ownership: Who owns the digital assets and real estate in the metaverse, and what rights do they have over it? Control: Who oversee activities in the metaverse, and what rules and regulations will be implemented to guarantee fair use and equal treatment for all participants? These are crucial issues to think about as the metaverse expands and is utilized more frequently, and they will probably have …
Adoption / Feb. 14, 2023