top of page

Privacy Considerations

The key schedule is fixed and defined by operating system components, preventing applications from including static or predictable information that could be used for tracking.


A Temporary Exposure Key is required to correlate between a user’s Rolling Proximity Identifiers. This reduces the risk of privacy loss from broadcasting the identifiers.


Without the release of the Temporary Exposure Keys, it’s computationally infeasible for an attacker to find a collision on a Rolling Proximity Identifier. This prevents a wide range of replay and impersonation attacks.


When reporting Diagnosis Keys, the correlation of Rolling Proximity Identifiers by others is limited to 24 hour periods due to the use of Temporary Exposure Keys that change daily. The server must not retain metadata from clients uploading Diagnosis Keys after including those key in the aggregated list of Diagnosis Keys per day.


ree


Test Vectors‌


Test vectors for interoperability testing between implementations of this specification are available upon request in a machine-readable format.


 
 
 

Comments


  • Manny Berrios LinkedIn Icon
  • Manny Berrios Twitter Icon
  • Manny Berrios Instagram Icon
  • Manny Berrios Facebook Icon
  • YouTube - White Circle

© 1974 by J. Manny Berrios

bottom of page