Free GAEN alternative

Free GAEN alternative

LibreCHovid - Alternative to GAEN for contact tracing applications

Apple and Google developed the Google-Apple Exposure Notification system in order to provide a uniform API for contact-tracing apps while preserving user privacy. On Android, GAEN is integrated in the Google Play services, which is proprietary. As a consequence, users wanting to keep a free system, as well as phone manufacturers such as Huawei who don't have Google Play services cannot use these applications. This project aims to offer an alternative framework, based on open-source code, which requires only minimal changes to the apps.

BluetoothMobile AppProtocol
Key facts
Maturity
PrototypeIntermediateMature
Support
C4DT
Retired
Lab
Active
  • C4DT work
  • Technical
  • Presentation
  • App
Status: Retired
Timeline: 2021/Q1 worked on improving and integrating with microG and published app

HexHive Group

HexHive Group
Mathias Payer

Prof. Mathias Payer

Our research focuses on software and systems security. Despite efforts and improvements in bug discovery techniques, some exploitable vulnerabilities will remain. We target techniques that both enable developers to discover and remove bugs and make programs resilient against the exploitation of unknown or unpatched vulnerabilities.
  • To discover bugs we propose (i) sanitization techniques that enforce a security property such as memory or type safety; given concrete program input, our sanitizers then flag any property violations (ii) fuzzing techniques that leverage static and dynamic analysis to create program inputs to explore program areas that are not yet covered through existing test cases.
  • To protect against exploitable vulnerabilities, we focus on control-flow integrity using specific language semantics, enforcing type integrity, and protecting selective data. Under this premise, we focus on compiler-based, runtime-based, and language-based protection mechanisms and security policies that increase the resilience of applications against attacks (in the presence of software vulnerabilities).

All prototypes are released as open-source.

This page was last edited on 2024-04-12.