Abuse-Resistant Location Tracking: Balancing Privacy and Safety in the Offline Finding Ecosystem

Authors: 

Harry Eldridge, Gabrielle Beck, and Matthew Green, Johns Hopkins University; Nadia Heninger, University of California, San Diego; Abhishek Jain, Johns Hopkins University

Abstract: 

Location tracking accessories (or "tracking tags") such as those sold by Apple, Samsung, and Tile, allow owners to track the location of their property via offline finding networks. The tracking protocols were designed to ensure that no entity (including the vendor) can use a tag's broadcasts to surveil its owner. These privacy guarantees, however, seem to be at odds with the phenomenon of tracker-based stalking, where attackers use these very tags to monitor a target's movements. Numerous such criminal incidents have been reported, and in response, manufacturers have chosen to substantially weaken privacy guarantees in order to allow users to detect stalker tags. This compromise has been adopted in a recent IETF draft jointly proposed by Apple and Google.

We put forth the notion of abuse-resistant offline finding protocols that aim to achieve a better balance between user privacy and stalker detection. We present an efficient protocol that achieves stalker detection under realistic conditions without sacrificing honest user privacy. At the heart of our result, and of independent interest, is a new notion of multi-dealer secret sharing which strengthens standard secret sharing with novel privacy and correctness guarantees. We show that this primitive can be instantiated efficiently on edge devices using variants of Interleaved Reed-Solomon codes combined with new lattice-based decoding algorithms.

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {299830,
author = {Harry Eldridge and Gabrielle Beck and Matthew Green and Nadia Heninger and Abhishek Jain},
title = {{Abuse-Resistant} Location Tracking: Balancing Privacy and Safety in the Offline Finding Ecosystem},
booktitle = {33rd USENIX Security Symposium (USENIX Security 24)},
year = {2024},
isbn = {978-1-939133-44-1},
address = {Philadelphia, PA},
pages = {5431--5448},
url = {https://www.usenix.org/conference/usenixsecurity24/presentation/eldridge},
publisher = {USENIX Association},
month = aug
}