Privacy-Preserving Contact Tracing Protocol for Mobile Devices: A Zero-Knowledge Proof Approach

Joseph K. Liu*, Man Ho Au, Tsz Hon Yuen, Cong Zuo, Jiawei Wang, Amin Sakzad, Xiapu Luo, Li Li, Kim Kwang Raymond Choo

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Citations (Scopus)


In this paper, we propose a privacy-preserving contact tracing protocol for smart phones, and more specifically Android and iOS phones. The protocol allows users to be notified, if they have been a close contact of a confirmed patient. The protocol is designed to strike a balance between privacy, security, and scalability. Specifically, the app allows all users to hide their past location(s) and contact history from the Government, without affecting their ability to determine whether they have close contact with a confirmed patient whose identity will not be revealed. A zero-knowledge protocol is used to achieve such a user privacy functionality. In terms of security, no user can send fake messages to the system to launch a false positive attack. We present a security model and formally prove the security of the protocol. To demonstrate scalability, we evaluate an Android and an iOS implementation of our protocol. A comparative summary shows that our protocol is the most comprehensive and balanced privacy-preserving contact tracing solution to-date.

Original languageEnglish
Title of host publicationInformation Security Practice and Experience - 16th International Conference, ISPEC 2021, Proceedings
EditorsRobert Deng, Feng Bao, Guilin Wang, Jian Shen, Mark Ryan, Weizhi Meng, Ding Wang
PublisherSpringer Science and Business Media Deutschland GmbH
Number of pages18
ISBN (Print)9783030932053
Publication statusPublished - 2021
Externally publishedYes
Event16th International Conference on Information Security Practice and Experience, ISPEC 2021 - Nanjing, China
Duration: 17 Dec 202119 Dec 2021

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume13107 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349


Conference16th International Conference on Information Security Practice and Experience, ISPEC 2021


Dive into the research topics of 'Privacy-Preserving Contact Tracing Protocol for Mobile Devices: A Zero-Knowledge Proof Approach'. Together they form a unique fingerprint.

Cite this

Liu, J. K., Au, M. H., Yuen, T. H., Zuo, C., Wang, J., Sakzad, A., Luo, X., Li, L., & Choo, K. K. R. (2021). Privacy-Preserving Contact Tracing Protocol for Mobile Devices: A Zero-Knowledge Proof Approach. In R. Deng, F. Bao, G. Wang, J. Shen, M. Ryan, W. Meng, & D. Wang (Eds.), Information Security Practice and Experience - 16th International Conference, ISPEC 2021, Proceedings (pp. 327-344). (Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics); Vol. 13107 LNCS). Springer Science and Business Media Deutschland GmbH.