Privacy-Preserving Contact Tracing via Dynamic Beacon Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional contact tracing systems raise privacy concerns and suffer from accuracy issues in determining close proximity, as they can reveal user identities and miss detections due to infrequent updates or broadcasts of Rolling Proximity Identifiers (RPIs) and Daily Tracking Keys (DTKs.
Innovation Solution
A system that includes beacon devices and user devices, which anonymously register and transmit encrypted beacon data using a public key, allowing the server to decrypt and verify proximity, while authorities request time-limited tokens to alert users of close contacts without revealing identities, using IEEE 802.11 and Bluetooth standards for data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If Rolling Proximity Identifiers (RPIs) are updated frequently to improve tracking accuracy, then detection accuracy is improved, but privacy protection deteriorates because constant RPIs can be used to track users by observers in close proximity
Solution Approach 1:
The patent applies dynamics by making RPIs time-varying rather than constant. Each RPI is generated as a function of the Daily Tracking Key and a time value, and is updated at specified time intervals. This dynamic update mechanism ensures that even if observers capture RPIs at different times, they cannot correlate them to track the same user across different time periods, thus maintaining privacy while improving detection accuracy through frequent updates.
Solution Approach 2:
The patent implements periodic action by updating RPIs at predetermined time intervals (e.g., every 10-15 minutes). This periodic regeneration of RPIs from the DTK ensures that tracking information changes over time, preventing continuous tracking by observers while maintaining sufficient update frequency for accurate contact tracing. The periodic nature balances privacy protection with detection effectiveness.
2Object-affected harmful factors
If Daily Tracking Keys (DTKs) are updated frequently to improve privacy protection, then privacy protection is improved, but data transmission volume increases causing high inquiry data volume
Solution Approach 1:
The patent applies segmentation by dividing the tracking system into hierarchical components: a long-lived Daily Tracking Key (DTK) that changes infrequently, and multiple short-lived Rolling Proximity Identifiers (RPIs) generated from each DTK. This segmentation allows the system to maintain privacy through frequent RPI changes without requiring frequent DTK updates, thereby reducing data transmission volume while preserving privacy protection.
Solution Approach 2:
The patent implements preliminary action by generating multiple RPIs in advance from a single DTK before the DTK needs to be updated. User devices can pre-generate a batch of RPIs using the current DTK, reducing the frequency of DTK updates and associated data transmissions. This approach maintains privacy through frequent RPI rotation while minimizing the data transmission burden of frequent key updates.
3Measurement precision
If RPI broadcast frequency is increased to improve detection accuracy, then detection accuracy is improved, but energy consumption increases due to more frequent transmissions
Solution Approach 1:
The patent applies dynamics by implementing adaptive broadcast frequency based on operational conditions. The system can dynamically adjust the RPI broadcast interval depending on factors such as detected proximity to other devices, current infection risk levels, or battery status. This allows the system to maintain high detection accuracy when needed while conserving energy during periods of lower risk or when devices are stationary, resolving the contradiction between detection accuracy and energy consumption.
Data Source
AI summary
A method can include, by operation of a user device, receiving beacon data via a wireless signal. Beacon data can include unencrypted data that includes a key identification (ID) corresponding to a private key/public key pair, a time value, and a location value. Beacon data can also include encrypted data that includes at least a beacon ID, a beacon time value, and a beacon location value. If the unencrypted time value is within a predetermined range of a current time value of the user device, the beacon data can be stored in a user record with a user ID. Periodically, the user record can be uploaded to a tracking system. Corresponding devices and systems are also disclosed.


