Ilmu Komputer & AI editorial
CrossLink: Breaking Location Privacy by Linking Device Identifiers Across Protocols
The core problem
Innovation
Why it matters
The findings of this paper have significant implications for location privacy. They show that per-protocol privacy defenses do not compose; an adversary can link identifiers across protocols to reconstruct full device traces. This is particularly concerning because the adversary is fully passive—they only observe the wireless medium and do not inject any signals. The unsynchronized nature of identifier rotations, which is inherent to independent protocol implementations, creates a side channel that CrossLink exploits. The authors argue that location privacy must be analyzed jointly across protocols, and defenses should be designed with cross-protocol linking in mind. Potential countermeasures include synchronizing identifier rotations across protocols, adding artificial noise to observations, or using mix networks. However, each has trade-offs in terms of performance and complexity. The paper also demonstrates that partial coverage is sufficient for effective linking, meaning that even limited deployment of sniffers can compromise privacy. This raises questions about the feasibility of achieving strong location privacy in practice.
To illustrate the cross-protocol linking process, consider the following Mermaid diagram:
This diagram shows how identifiers from different protocols observed at different times can be linked to reconstruct a device's path.
Who should read this
Opening member content…