论文标题
对Google Apple曝光通知(GAEN)框架的批评
A Critique of the Google Apple Exposure Notification (GAEN) Framework
论文作者
论文摘要
为了对COVID-19大流行数字接触追踪的回应,已提出作为一种工具,以支持卫生当局寻求确定谁与冠状病毒感染的人保持紧密和持续的联系。 2020年4月,Google和Apple发布了Google Apple曝光通知(GAEN)框架,作为一个分散且更加隐私友好的平台,用于接触跟踪。 Gaen框架主要在操作系统层上实现曝光通知,而不是完全在应用程序层(LICATION)层。在本文中,我们研究了这种方法的后果。我们认为,这为操作系统层的质量监视创造了休眠功能。我们展示了它如何从技术上阻止卫生当局实施纯粹的集中式接触跟踪形式(即使这是既定的目的)。我们强调说,Gaen允许Google和Apple决定卫生当局在实践中(或更确切地说不是)实施联系方式,以及它如何引入功能蠕变的风险。
As a response to the COVID-19 pandemic digital contact tracing has been proposed as a tool to support the health authorities in their quest to determine who has been in close and sustained contact with a person infected by the coronavirus. In April 2020 Google and Apple released the Google Apple Exposure Notification (GAEN) framework, as a decentralised and more privacy friendly platform for contact tracing. The GAEN framework implements exposure notification mostly at the operating system layer, instead of fully at the app(lication) layer. In this paper we study the consequences of this approach. We argue that this creates a dormant functionality for mass surveillance at the operating system layer. We show how it does not technically prevent the health authorities from implementing a purely centralised form of contact tracing (even though that is the stated aim). We highlight that GAEN allows Google and Apple to dictate how contact tracing is (or rather isn't) implemented in practice by health authorities, and how it introduces the risk of function creep.