Privacy-preserving contact tracing via zero-knowledge proofs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current contact tracing methods face challenges in balancing the need to control pathogen spread with individual privacy concerns, and they are often labor-intensive and ineffective in identifying broader exposure risks beyond direct contacts.

Innovation Solution

A system utilizing zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARKs) for generating and verifying cryptographic proofs of proximity, allowing for privacy-preserving contact tracing that includes first- and nth-order contact tracing without revealing personal information, using decentralized approaches like Bluetooth and public registries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If contact tracing data is collected and stored centrally to identify exposure risks, then the ability to trace and notify contacts is improved, but individual privacy is compromised and reliance on trusted third parties increases

Engineering Contradiction:
Improvecontact tracing effectivenessVSAvoidindividual privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system segments contact tracing data into decentralized proximity tokens stored locally on individual user devices rather than centralizing all data in a single database. Each user device independently stores and processes its own proximity tokens, eliminating the need for a trusted third party to hold sensitive personal information while maintaining the ability to perform contact tracing through cryptographic verification of these distributed tokens.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces cryptographic proofs as an intermediary mechanism that enables verification of exposure status without revealing underlying personal information. These cryptographic proofs act as mediators between the need for reliable contact tracing and the need to protect privacy, allowing the system to verify contacts while preventing direct access to sensitive user data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If manual contact tracing methods are used to identify contacts, then implementation is simpler, but the process is labor-intensive and ineffective in identifying broader exposure risks

Engineering Contradiction:
Improvetracing system simplicityVSAvoidcontact tracing efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The system enables user devices to autonomously perform contact tracing operations by automatically generating, storing, and verifying proximity tokens without requiring manual intervention. The devices independently compute cryptographic proofs and identify exposure risks, eliminating labor-intensive manual processes while scaling efficiently to identify both direct and indirect contacts across large populations.

Inventive Principle:
Principle #25Self-service

3Reliability

If centralized databases are used to store contact information, then contact tracing can be performed comprehensively, but the system becomes vulnerable to privacy breaches and requires trusted third parties

Engineering Contradiction:
Improveexposure identification accuracyVSAvoidprivacy breach risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system divides the centralized contact tracing database into distributed proximity tokens stored across multiple user devices. Instead of one central repository vulnerable to breaches, each user device holds its own tokens locally, and the collective network of devices provides comprehensive exposure identification without creating a single point of failure or privacy vulnerability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses cryptographic copies (proximity tokens) of contact information that can be verified without revealing the original sensitive data. These cryptographic representations allow comprehensive contact tracing to be performed while preventing direct access to personal information, as the tokens are mathematical transformations that preserve verification capability but obscure underlying identities.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12001584B2Privacy-preserving contact tracing
Publication Date: 2024.06.04 RTX BBN TECH INC
  • US12001584B2 patent drawing
  • US12001584B2 patent drawing
  • US12001584B2 patent drawing

AI summary

Techniques for privacy-preserving contact tracing are disclosed, including: generating, by a first user device, a first proximity token for contact tracing; receiving, by the first user device, a second proximity token from a second user device; generating, by the first user device, a hash based on the first proximity token and the second proximity token; generating, by the first user device using a prover function of a preprocessing zero knowledge succinct non-interactive argument of knowledge (pp-zk-SNARK), a cryptographic proof attesting that an individual associated with the first user device tested positive for a pathogen; and transmitting, by the first user device, publicly verifiable exposure data including at least the cryptographic proof and the hash to a public registry.