The UK Contact Tracing App: Version 2?

--

I am confused with the UK Contract Tracing App.

The UK have released a new contact tracing application within the Isle of Wright and with an expected large scale role out across the whole country. The method is almost completely different to the version that Google and Apple are using, and focuses on the use of public key encryption and a central server in the public Cloud. But why go our own way with an imcompatiable system that goes against many other countries? But, now to add a bit more doubt, the Financial Times has discovered that NHSX has awarded a six-month £3.8 million contract to a company in order to investigate a system using the Google/Apple API.

While the Apple/Google method uses the privacy enhancing method of generating a unique ID on the user’s device and an embedded Bluetooth integration, the UK system uses a centralised approach and with a weak use of public key encryption method. Bascially it uses public key encryption to regenerate a symmetric key. It should be noted that in TLS 1.3 the usage of a public key to protect the symmetric key was removed, as a long term leak of a private key would reveal all of the keys involved.

--

--

Prof Bill Buchanan OBE FRSE
ASecuritySite: When Bob Met Alice

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.