Privacy-Preserving Proof-of-Location With Security Against Geo-Tampering

Md. Mamunur Rashid Akand, Reihaneh Safavi–Naini, Marc Kneppers, Matthieu Giraud, Pascal Lafourcade · IEEE Transactions on Dependable and Secure Computing · 2021

A Proof-of-Location (POL) system is used to issue a proof-of-location token ($pol$) to a user who has been present at a location$\ell oc$, such that it can be later presented to a verifier to assure the presence of the user at$\ell oc$. Basic POL security requirements areunforgeabilityof$pol$, and itsnon-transferability(a$pol$issued to user$u_1$cannot be used by$u_2$). An additional important property of POL systems isuser privacyagainst the issuers and verifiers. We make two contributions. First, we formalize the POL security and privacy properties, and construct the first system providing provable security and privacy against the issuer and the verifier, both. Second, we introduce ageo-tampering attackthat completely breaks POL system security, by simply changing the location of a$pol$issuing node. The attack applies to portable infrastructure nodes that are not continually monitored. We propose an algorithm that is used by a$pol$issuer to provide a location integrity “proof”, that will be embedded in a$pol$to protect against this attack. The proof relies on a novel application of euclidean Distance Matrices. We implemented our POL on an off-the-shelf Android smartphone to show the practicality of the proposed algorithms.

Read the paper · More papers on PaperTik