CONTACT TRACING An Overview of Technologies and Cyber Risks Franck Legendre, Mathias Humbert, Alain Mermoud, Vincent Lenders armasuisse, Science and Technology, Switzerland Corresponding author:
[email protected] Disclaimer: Opinions expressed in this report are solely our own and do not express the views or opinions of our employer, the Swiss government. EXECUTIVE SUMMARY 3 INTRODUCTION 4 How Manual Contact Tracing Works 4 How Can Technology Help Automate Contact Tracing 4 What Are The Risks of Digital Contact Tracing 5 TECHNOLOGY OVERVIEW 6 PRIVACY AND CYBERSECURITY RISKS 7 Threat Model 7 Privacy Risks 7 Cybersecurity Risks 8 INTERNATIONAL ADOPTION 9 Early Adopters 9 Switzerland’s Neighbors 10 MOBILE OPERATOR CONTACT TRACING 11 LOCATION-BASED CONTACT TRACING 13 PROXIMITY-BASED CONTACT TRACING 15 DETAILED RISK ANALYSIS OF PROXIMITY-BASED CONTACT TRACING 19 Risks on Health Status Privacy 19 Risks on Location Privacy 19 Example: Location Disclosure of Infected Users with Exposure Notification 20 Risks on Social Graph Privacy 21 Summary of Privacy Risks and Potential Improvements 21 Cybersecurity Risks 22 COMPARISON SUMMARY 24 CONCLUSION 25 2 EXECUTIVE SUMMARY The 2020 COVID-19 pandemic has led to a global lockdown with severe health and economical consequences. As a result, authorities around the globe have expressed their needs for better tools to monitor the spread of the virus and to support human labor. Researchers and technology companies such as Google and Apple have offered to develop such tools in the form of contact tracing applications running on smartphones. The goal of these applications is to continuously track people's proximity and to make the smartphone users aware if they have ever been in contact with positively diagnosed people, so that they could self-quarantine and possibly have an infection test.