Apple and Google Announce Exposure Notification Technology
Published:
Apple and Google announced the Exposure Notification API on April 10, 2020, seventeen days after the World Health Organization declared COVID-19 a pandemic, in an unprecedented collaboration between the two companies whose competing mobile operating systems controlled over 99 percent of the global smartphone market. The announcement came as governments worldwide were evaluating contact-tracing applications that varied widely in their privacy properties — Singapore’s TraceTogether (March 20, 2020) used a centralized Bluetooth proximity log architecture where the health ministry held contact graphs, raising concerns about government surveillance. Several European countries were building centralized systems as well. The Apple-Google design deliberately chose a decentralized architecture: each phone generated a daily Temporary Exposure Key (TEK) using a cryptographically secure random source, then derived short-lived Rolling Proximity Identifiers (RPIs) from the TEK every 10-20 minutes using HMAC-SHA256. Phones broadcast their current RPI over Bluetooth Low Energy advertising packets while simultaneously logging the RPIs they observed from nearby devices, along with signal strength (RSSI) as a proxy for distance. No names, phone numbers, GPS locations, or account identifiers were broadcast or logged — only the cryptographic identifiers, which were unlinkable to individuals without knowledge of the originating TEK.
If a user tested positive for COVID-19 and chose to participate, an authorized public health app would upload only the user’s TEKs for the preceding 14 days to a public server — the minimum information needed for exposure matching. All other devices periodically downloaded the published diagnosis keys (the uploaded TEKs), computed all the RPIs those keys would have generated, and checked locally whether any observed RPI from their own log matched a diagnosis key RPI under conditions indicating sufficient proximity and duration to constitute a meaningful exposure. The matching computation happened entirely on-device: the server distributed diagnosis keys to millions of phones without knowing which phones had encountered which infected individuals. This decentralized design meant that Apple and Google themselves could not determine who had been in contact with whom, and no central authority accumulated a social graph of proximity relationships. The system was deployed in two phases: Phase 1 (released iOS 13.5 on May 20, 2020, and Android via Google Play Services on the same day) provided an API for public health apps; Phase 2 (iOS 13.7, September 1, 2020) embedded exposure notification directly into the operating system so US states could enable it without requiring users to install a separate app.
Adoption varied dramatically by country. Germany’s Corona-Warn-App, built by SAP and Deutsche Telekom for the Robert Koch Institute using the Apple-Google API, launched June 16, 2020 and was downloaded 28 million times in its first three weeks — one of the highest adoption rates globally. The United Kingdom’s NHS COVID-19 app (September 24, 2020) used the API after abandoning an earlier centralized architecture developed by NHSX. Ireland’s COVID Tracker App adopted the decentralized design from the start. In the United States, adoption was fragmented: the API was voluntary for states, and implementation required public health infrastructure to issue test results with verification codes that the app could upload. Epidemiological studies estimating exposure notification effectiveness were contested; a study in England estimated the NHS app may have prevented between 284,000 and 594,000 COVID-19 cases between September and December 2020, while critics noted that Bluetooth proximity is a poor proxy for actual infection risk (transmission through walls, at different ventilation rates, or outdoors over different distances than indoor settings). For privacy engineering, the Exposure Notification system was a significant demonstration that privacy-preserving design and epidemiological utility are not necessarily in opposition — and that cryptographic techniques (key derivation, rolling identifiers, on-device matching) could provide privacy guarantees that centralized database approaches structurally cannot.
