|  | |
| Developed by | |
|---|---|
| Introduced | April 10, 2020 (2020-04-10) | 
| Industry | Digital contact tracing | 
| Compatible hardware | Android &iOS smartphones | 
| Physical range | ~10 m (33 ft)[1] | 
The(Google/Apple) Exposure Notification System (GAEN)[2][3][a] is a framework and protocol specification developed byApple Inc. andGoogle to facilitatedigital contact tracing during theCOVID-19 pandemic. When used by health authorities, it augments more traditionalcontact tracing techniques by automatically logging close approaches among notification system users usingAndroid oriOSsmartphones. Exposure Notification is a decentralized reporting protocol built on a combination ofBluetooth Low Energy technology and privacy-preservingcryptography. It is an opt-in feature withinCOVID-19 apps developed and published by authorized health authorities.[10][11] Unveiled on April 10, 2020, it was made available on iOS on May 20, 2020 as part of theiOS 13.5 update[12] and on December 14, 2020 as part of theiOS 12.5 update for older iPhones.[13] On Android, it was added to devices via aGoogle Play Services update, supporting all versions sinceAndroid Marshmallow.
The Apple/Google protocol is similar to theDecentralized Privacy-Preserving Proximity Tracing (DP-3T) protocol created by the European DP-3T consortium and theTemporary Contact Number (TCN) protocol byCovid Watch, but is implemented at theoperating system level, which allows for more efficient operation as a backgroundprocess.[14][15][16] Since May 2020, a variant of the DP-3T protocol is supported by the Exposure Notification Interface.[17] Other protocols are constrained in operation because they are not privileged over normalapps. This leads to issues, particularly on iOS devices where digital contact tracing apps running in the background experience significantly degraded performance.[18][19][20] The joint approach is also designed to maintain interoperability between Android and iOS devices, which constitute nearly all of the market.
TheACLU stated the approach "appears to mitigate the worst privacy and centralization risks, but there is still room for improvement".[21] In late April, Google and Apple shifted the emphasis of the naming of the system, describing it as an "exposure notification service", rather than "contact tracing" system.[22]
Digital contact tracing protocols typically have two major responsibilities: encounter logging and infection reporting.[19] Exposure Notification only involves encounter logging which is a decentralized architecture. The majority of infection reporting is centralized in individual app implementations.[23]
To handle encounter logging, the system usesBluetooth Low Energy to send tracking messages to nearby devices running the protocol to discover encounters with other people. The tracking messages contain unique identifiers that are encrypted with a secret daily key held by the sending device. These identifiers change every 15–20 minutes as well as BluetoothMAC address in order to prevent tracking of clients by malicious third parties through observing static identifiers over time.[citation needed]
The sender's daily encryption keys are generated using a random number generator.[24] Devices record received messages, retaining them locally for 14 days. If a user tests positive for infection, the last 14 days of their daily encryption keys can be uploaded to a central server, where it is then broadcast to all devices on the network. The method through which daily encryption keys are transmitted to the central server and broadcast is defined by individual app developers. The Google-developed reference implementation calls for a health official to request aone-time verification code (VC) from averification server, which the user enters into the encounter logging app. This causes the app to obtain a cryptographically signed certificate, which is used to authorize the submission of keys to the central reporting server.[25]
The received keys are then provided to the protocol, where each client individually searches for matches in their local encounter history. If a match meeting certain risk parameters is found, the app notifies the user of potential exposure to the infection.[26] Google and Apple intend to use the received signal strength (RSSI) of the beacon messages as a source to infer proximity.[27] RSSI and other signal metadata will also be encrypted to resist deanonymization attacks.[24]
To generate encounter identifiers, first a persistent 32-byte privateTracing Key () is generated by a client. From this a 16 byteDaily Tracing Key is derived using the algorithm, where is aHKDF function using SHA-256, and is theday number for the 24-hour window the broadcast is in starting from Unix Epoch Time. These generated keys are later sent to the central reporting server should a user become infected.[28]
From the daily tracing key a 16-byte temporaryRolling Proximity Identifier is generated every 10 minutes with the algorithm, where is aHMAC function using SHA-256, and is thetime interval number, representing a unique index for every 10 minute period in a 24-hour day. The Truncate function returns the first 16 bytes of the HMAC value. When two clients come within proximity of each other they exchange and locally store the current as the encounter identifier.[28]
Once a registered health authority has confirmed the infection of a user, the user's Daily Tracing Key for the past 14 days is uploaded to the central reporting server. Clients then download this report and individually recalculate every Rolling Proximity Identifier used in the report period, matching it against the user's local encounter log. If a matching entry is found, then contact has been established and the app presents a notification to the user warning them of potential infection.[28]
Unlike version 1.0 of the protocol, version 1.1 does not use a persistenttracing key, rather every day a new random 16-byteTemporary Exposure Key() is generated. This is analogous to thedaily tracing key from version 1.0. Here denotes the time is discretized in 10 minute intervals starting from Unix Epoch Time. From this two 128-bit keys are calculated, theRolling Proximity Identifier Key () and theAssociated Encrypted Metadata Key (). is calculated with the algorithm, and using the algorithm.[29]
From these values a temporaryRolling Proximity Identifier () is generated every time the BLEMAC address changes, roughly every 15–20 minutes. The following algorithm is used:, where is anAES cryptography function with a 128-bit key, the data is one 16-byte block, denotes the Unix Epoch Time at the moment the roll occurs, and is the corresponding 10-minute interval number. Next, additionalAssociated Encrypted Metadata is encrypted. What the metadata represents is not specified, likely to allow the later expansion of the protocol. The following algorithm is used:, where denotes AES encryption with a 128-bit key in CTR mode. The Rolling Proximity Identifier and the Associated Encrypted Metadata are then combined and broadcast using BLE. Clients exchange and log these payloads.[29]
Once a registered health authority has confirmed the infection of a user, the user's Temporary Exposure Keys and their respective interval numbers for the past 14 days are uploaded to the central reporting server. Clients then download this report and individually recalculate every Rolling Proximity Identifier starting from interval number, matching it against the user's local encounter log. If a matching entry is found, then contact has been established and the app presents a notification to the user warning them of potential infection.[29]
Version 1.2 of the protocol is identical to version 1.1, only introducing minor terminology changes.[29]
Preservation ofprivacy was referred to as a major component of the protocol; it isdesigned so that nopersonally identifiable information can be obtained about the user or their device.[30][11][31][32] Apps implementing Exposure Notification are only allowed to collect personal information from users on a voluntary basis.[33] Consent must be obtained by the user to enable the system or publicize a positive result through the system, and apps using the system are prohibited from collecting location data.[34] As an additional measure, the companies stated that it wouldsunset the protocol by-region once they determine that it is "no longer needed".[35]
TheElectronic Frontier Foundation showed concerns the protocol was vulnerable to "linkage attacks", where sufficiently capable third parties who had recorded beacon traffic may retroactively be able to turn this information into tracking information, for only areas in which they had already recorded beacons, for a limited time segment and for only users who have disclosed their COVID-19 status, once a device's set of daily encryption keys have been revealed.[36]
On April 16, theEuropean Union started the process of assessing the proposed system for compatibility with privacy and data protection laws, including theGeneral Data Protection Regulation (GDPR).[37] On April 17, 2020, the UK'sInformation Commissioner's Office, a supervisory authority for data protection, published an opinion analyzing both Exposure Notification and theDecentralized Privacy-Preserving Proximity Tracing protocol, stating that the systems are "aligned with the principles of data protection by design and by default" (as mandated by the GDPR).[38]
Exposure Notification is compatible with Android devices supportingBluetooth Low Energy and runningAndroid 6.0 "Marshmallow" and newer withGoogle Mobile Services. It is serviced via updates toGoogle Play Services, ensuring compatibility with the majority of Android devices released outside of Mainland China, and not requiring it to be integrated into Android firmware updates (which would hinder deployment by relying on individualOEMs). It is not compatible with devices that do not have GMS, such asHuawei devices released since May 2019.[39][40] On iOS, EN is serviced via operating system updates.[12] It was first introduced as part ofiOS 13.5 on May 20, 2020.[41][42] In December 2020, Apple released iOS 12.5, whichbackported EN support to iPhone models that cannot be upgraded to iOS 13, includingiPhone 6 and older.[42]
Exposure Notification apps may only be released by public health authorities. To discourage fragmentation, each country will typically be restricted to one app, although Apple and Google stated that they would accommodate regionalized approaches if a country elects to do so.[34] Apple and Google released reference implementations for apps utilizing the system, which can be used as a base.[34]
On September 1, 2020, the consortium announced "Exposure Notifications Express" (EN Express), a system designed to ease adoption of the protocol by health authorities by removing the need to develop an app themselves. Under this system, a health authority provides parameters specific to their implementation (such as thresholds, branding, messaging, and key servers), which is then processed to generate the required functionality. On Android, this data is used to generate an app, and a configuration profile that can also be deployed to users via Google Play Services without a dedicated app.[43] On iOS, the functionality is integrated directly at the system level on iOS 13.7 and newer without a dedicated app.[44]
The last information update on the "Exposure Notification Systems" partnership was a year end review issued by Google in December 2020:[45] "we plan to keep you updated here with new information again next year". Nothing has however been issued on the one year anniversary of the launch of the "Exposure Notification Interface" API in spite of important changes on the pandemic front such as vaccination,variants, digital health passports, app adoption challenges as well as growing interest for tracking QR codes (and notifying from that basis) on a mostly airborne transmitted virus.[original research?] The Frequently Asked Questions (FAQ) published document has not been revised since May 2020.[46] Basic support remains provided through the apps store released by authorized public health agencies, including enforcement of the personal privacy protection framework as demonstrated on the UK NHS challenge in support of their contact tracers.[47]
In June 2021, Google faced allegations that it had automatically downloaded Massachusetts' "MassNotify" app to Android devices without user consent. Google clarified that it had not actually downloaded the app to user devices, and that Google Play Services was being used to deploy an EN Express configuration profile that would allow it to be enabled via the Google Settings app without needing to download a separate app.[43]
As of May 21, at least 22 countries had received access to the protocol.[33] Switzerland and Austria were among the first to back the protocol.[48] On April 26, after initially backingPEPP-PT, Germany announced it would back Exposure Notification,[49] followed shortly after by Ireland[50] and Italy.[51] Despite already adopting the centralisedBlueTrace protocol,[52] Australia'sDepartment of Health andDigital Transformation Agency were investigating whether the protocol could be implemented to overcome limitations of itsCOVIDSafe app.[33] On May 25, Switzerland became the first country to launch an app leveraging the protocol,SwissCovid, beginning with a small pilot group.[53]
In England, theNational Health Service (NHS) trialed both anin-house app on a centralized platform developed by itsNHSX division, and a second app using Exposure Notification.[54] On June 18, the NHS announced that it would focus on using Exposure Notification to complement manual contact tracing, citing tests on theIsle of Wight showing that it had better cross-device compatibility (and would also be compatible with other European approaches), but that its distance calculations were not as reliable as the centralized version of the app,[55] an issue which was later rectified.[56][57] Later, it was stated that the app would be supplemented byQR codes at venues.[58] A study of the impact of Exposure Notification in England and Wales estimated that it averted 8,700 (95%confidence interval 4,700–13,500) deaths out of the 32,500 recorded from its introduction on 24 September 2020 to 31 December 2020.[59]
Canada launched its COVID Alert app, co-developed in partnership withBlackBerry Limited andShopify,[60] on July 31 in Ontario.[61] As of February 2022, only around 57,000 positive cases had been reported via the app, leading some critics to dismiss it as a failure.[62][63][64]
In May 2020,Covid Watch launched the first calibration and beta testing pilot of the GAEN APIs in the United States at the University of Arizona.[65][66] In Aug 2020, the app launched publicly for a phased roll-out in the state of Arizona.[67][68][69]
The U.S.Association of Public Health Laboratories (APHL) stated in July 2020 that it was working with Apple, Google, andMicrosoft on a national reporting server for use with the protocol, which it stated would ease adoption and interoperability between states.[70][44]
In August 2020, Google stated that at least 20 U.S. states had expressed interest in using the protocol. InAlabama, theAlabama Department of Public Health,University of Alabama at Birmingham, and theUniversity of Alabama System deployed the "GuideSafe" app for university students returning to campus, which includes Exposure Notification features.[71][72] On August 5, theVirginia Department of Health released its "COVIDWise" app — making it the first U.S. state to release an Exposure Notification-based app for the general public.[73][74][75] North Dakota and Wyoming released an EN app known as "Care19 Alert", developed by ProudCrowd and using the APHL server (the app is a spin-off from an existing location logging application it had developed, based on one it had developed primarily for use by students travelling to attend college football away games).[76][77]
Maryland, Nevada, Virginia, and Washington, D.C. have announced plans to use EN Express.[44] In September, Delaware, New Jersey, New York, and Pennsylvania all adopted "COVID Alert" apps developed by NearForm, which are based on itsCOVID Tracker Ireland app.[78][79] Later that month, theNorwegian Institute of Public Health announced that it would lead development of an Exposure Notification-based app for the country, which replaces a centralized app that had ceased operations in June 2020 after theNorwegian Data Protection Authority ruled that it violated privacy laws.[80][81]
In Nov 2020, Bermuda launched the Wehealth Bermuda app developed by Wehealth, a Public Benefit Corporation, which was based on the Covid Watch app released in Arizona.[82][83][84]
| Country | Region/State | Name | Announced/Released | Notes | 
|---|---|---|---|---|
|  Austria | Stopp Corona App | June 26, 2020 | [85] | |
|  Brazil | Coronavírus-SUS | July 31, 2020 | [86] | |
|  Bermuda | Wehealth Bermuda | Nov 24, 2020 | [82][83][84] | |
|  Belgium | Coronalert | October 1, 2020 (public) | September 2, 2020 (Pilot phase) [87] | |
|  Canada | COVID Alert | July 31, 2020 | Available in New Brunswick, Newfoundland and Labrador, Ontario, Manitoba, Saskatchewan, Quebec, Prince Edward Island, and Nova Scotia.[88][61][89] Alberta and British Columbia have declined its use.[89] | |
|  Czech Republic | eRouška (eMask) | September 17, 2020 | Since version 2.1[90][91] | |
|  Denmark | Smittestop | June 18, 2020 | [92] | |
|  Estonia | Hoia | August 20, 2020 | [93] | |
|  Finland | Koronavilkku | August 31, 2020 | [94] | |
|  Germany | Corona-Warn-App | June 16, 2020 | [95] | |
|  Gibraltar | BEAT Covid Gibraltar | June 18, 2020 | Based onCOVID Tracker Ireland and will interoperate with it.[96][97] | |
|  Iceland | Rakning C-19 | May 12, 2021 | GEAN implementation activated in May 2021, replaced previous version of app which used GPS tracking stored on-device launched in April 2020.[98][99] | |
|  Ireland | COVID Tracker Ireland | July 7, 2020 | [100][101] | |
|  Italy | Immuni | June 1, 2020 | [102] | |
|  Japan | COCOA | June 19, 2020 | [103] | |
|  Jersey | Jersey COVID Alert | September 21, 2020 | [104] | |
|  Latvia | Apturi Covid | May 29, 2020 | [105] | |
|  Lebanon | Ma3an | July 16, 2020 | [106] | |
|  Netherlands | CoronaMelder | October 10, 2020 (full release) | [107] | |
|  New Zealand | NZ COVID Tracer | December 10, 2020 (full release) | [108] | |
|  Norway | Smittestopp | December 21, 2020 | Replaced a version of the app that was suspended earlier in the year due to scrutiny from the localNorwegian Data Protection Authority.[80][81] | |
|  Philippines | StaySafe.ph | March 29, 2021 | GAEN implementation activated in April 2021[109] | |
|  Poland | ProteGO Safe | June 9, 2020 | Update to existing encounter logging app.[110] | |
|  Portugal | STAYAWAY COVID | August 28, 2020 | [111] | |
|  Russia | Gosuslugi. Covid Tracker | November 23, 2020 | https://play.google.com/store/apps/details?id=com.minsvyaz.gosuslugi.exposurenotificationdroid | |
|  South Africa | COVID Alert SA | September 1, 2020 | [112] | |
|  Spain | Radar COVID | June 30, 2020 (beta test) | [113] | |
|  Switzerland | SwissCovid | May 26, 2020 (pilot phase) | [53] | |
|  Taiwan | 臺灣社交距離 | May 3, 2021 | [114] | |
|  Thailand | Thai Covid Alert | April 26, 2022 | [115] | |
|  United Kingdom |  England  Wales | NHS COVID-19 | September 24, 2020 | [116] | 
|  Northern Ireland | StopCOVID NI | July 30, 2020 | Interoperates withCOVID Tracker Ireland.[101] | |
|  Scotland | Protect Scotland | September 11, 2020 | Based onCOVID Tracker Ireland and will interoperate with it.[96] | |
|  United States |  Alabama | GuideSafe | August 3, 2020 | TargetingUniversity of Alabama students as part of a larger program under the same name.[71] | 
|  Alaska | Alaska COVID ENX | January 20, 2022 | [117] | |
|  Arizona | Covid Watch | May 28, 2020 (attenuation and dynamic risk testing) August 19, 2020 (released) | TargetingUniversity of Arizona in a phased roll-out for the state of Arizona.[67][68][69] | |
|  California | CA Notify | December 10, 2020 | [118][119] | |
|  Colorado | CO Exposure Notifications | October 25, 2020 | [120] | |
|  Connecticut | COVID Alert CT | November 12, 2020 | [121] | |
|  Delaware | COVID Alert DE | September 15, 2020 | Based onCOVID Tracker Ireland.[79] | |
|  Guam | Guam Covid Alert | September 10, 2020 | Based on the PathCheck Foundation's GAEN Mobile project | |
|  Hawaii | Aloha Safe Alert | November 11, 2020 | Based on the PathCheck Foundation's GAEN Mobile project | |
|  Louisiana | COVID Defense | January 22, 2021 | Based on the PathCheck Foundation's GAEN Mobile project [122][123] | |
|  Maryland | MD COVID Alert | October 10, 2020 | [124] | |
|  Massachusetts | MassNotify | Uses EN Express.[125] | ||
|  Michigan | MI COVID Alert | October 15, 2020 (Michigan State University pilot) November 9, 2020 (statewide) | [126][127][128] | |
|  Minnesota | COVIDaware MN | November 23, 2020 | [129][130] | |
|  Missouri | MO/Notify | July 29, 2021 | TargetingWashington University in St. Louis in a phased roll-out for the state of Missouri.[131][132] | |
|  New Jersey | COVID Alert NJ | September 30, 2020 | Based onCOVID Tracker Ireland.[79] | |
|  New York | COVID Alert NY | September 30, 2020 | Based onCOVID Tracker Ireland.[79] | |
|  North Carolina | SlowCOVIDNC | September 22, 2020 | The app was shut down on or before August 19, 2022.[133] | |
|  North Dakota | Care19 Alert | August 13, 2020 | [134] | |
|  Pennsylvania | COVID Alert PA | September 24, 2020 | Based onCOVID Tracker Ireland.[79] | |
|  Utah | UT Exposure Notifications | February 16, 2021 | [135] | |
|  Virginia | COVIDWise | August 5, 2020 | [75] | |
|  Washington | WA Notify | November 30, 2020 | [136][137] | |
|  Wisconsin | WI Exposure Notification | December 23, 2020 | [138] | |
|  Wyoming | Care19 Alert | August 14, 2020 | [139] | |
|  Uruguay | Coronavirus UY | June 15, 2020 | [140] | |
Some countries, such as France, have pursued centralized approaches to digital contact tracing, in order to maintain records of personal information that can be used to assist in investigating cases.[31][141] The French government asked Apple in April 2020 to allow apps to perform Bluetooth operations in the background, which would allow the government to create its own system independent of Exposure Notification.[142]
On August 9, the Canadian province of Alberta announced plans to migrate to the EN-based COVID Alert from its BlueTrace-based ABTraceTogether app.[143][144] This did not occur, and on November 6Premier of AlbertaJason Kenney announced that the province would not do so, arguing that ABTraceTogether was "from our view, simply a better and more effective public health tool", and that they would be required to phase out ABTraceTogether if they did switch.[145] British Columbia has also declined to adopt COVID Alert, with provincial health officerBonnie Henry stating that COVID Alert was too "non-specific".[145]
Australia's officials have stated itsCOVIDSafe, which is based on Singapore'sBlueTrace, will not be shifting from manual intervention.[146][147]
In the United States, states such as California and Massachusetts declined to use the technology, opting for manual contact tracing.[148] California later reversed course and adopted the system in December 2020.[118][119]
Chinese vendorHuawei (which cannot include Google software on its current Android products due to U.S. sanctions) added a OS-level DP-3T API known as "Contact Shield" to its Huawei Mobile Services stack in June 2020, which the company states is intended to be interoperable with Exposure Notification.[149]
{{cite web}}:  CS1 maint: archived copy as title (link){{cite web}}:  CS1 maint: multiple names: authors list (link)