Skip to main content
QUICK REVIEW

[Paper Review] A Critique of the Google Apple Exposure Notification (GAEN) Framework

Jaap-Henk Hoepman|arXiv (Cornell University)|Dec 9, 2020
COVID-19 Digital Contact Tracing6 citations
TL;DR

This paper critiques the Google Apple Exposure Notification (GAEN) framework, arguing that by embedding contact tracing at the operating system level, it enables dormant mass surveillance capabilities, undermines national health authorities' control over implementation, and increases risks of function creep and commercial exploitation—despite its privacy-preserving design intent.

ABSTRACT

As a response to the COVID-19 pandemic digital contact tracing has been proposed as a tool to support the health authorities in their quest to determine who has been in close and sustained contact with a person infected by the coronavirus. In April 2020 Google and Apple released the Google Apple Exposure Notification (GAEN) framework, as a decentralised and more privacy friendly platform for contact tracing. The GAEN framework implements exposure notification mostly at the operating system layer, instead of fully at the app(lication) layer. In this paper we study the consequences of this approach. We argue that this creates a dormant functionality for mass surveillance at the operating system layer. We show how it does not technically prevent the health authorities from implementing a purely centralised form of contact tracing (even though that is the stated aim). We highlight that GAEN allows Google and Apple to dictate how contact tracing is (or rather isn't) implemented in practice by health authorities, and how it introduces the risk of function creep.

Motivation & Objective

  • To analyze the implications of moving contact tracing from the app layer to the operating system layer in the GAEN framework.
  • To investigate how GAEN undermines national health authorities' autonomy in designing and deploying contact tracing systems.
  • To assess the risk of function creep, where exposure notification systems are repurposed for surveillance beyond public health.
  • To evaluate the potential for commercial or state surveillance due to OS-level access and Google/Apple's control over the framework.
  • To highlight the lack of technical enforcement for privacy guarantees, despite stated commitments by Google and Apple.

Proposed method

  • Analyzing the technical architecture of the GAEN framework, particularly its OS-level integration and access to Bluetooth low-level APIs.
  • Comparing the GAEN model with decentralized (DP-3T) and centralized (PEPP-PT, TraceTogether) contact tracing systems to highlight design trade-offs.
  • Examining the role of Google and Apple as gatekeepers, with unilateral control over API access and app allowlisting decisions.
  • Evaluating real-world examples of function creep in existing contact tracing systems, such as law enforcement access in Singapore and Australia.
  • Assessing the commercial potential of exposure notification data through beacon-based tracking and integration with existing platforms like Facebook.
  • Highlighting the absence of verifiable enforcement mechanisms for privacy promises, relying solely on trust in Google and Apple.

Experimental results

Research questions

  • RQ1How does moving contact tracing to the OS layer in GAEN affect the balance of power between national health authorities and tech giants?
  • RQ2To what extent can the GAEN framework technically prevent the implementation of centralized contact tracing systems?
  • RQ3What are the risks of function creep in exposure notification systems, and how does GAEN enable or exacerbate them?
  • RQ4How does the OS-level integration of GAEN create dormant capabilities for mass surveillance?
  • RQ5What are the implications of Google and Apple’s unilateral control over access to the GAEN framework for privacy and democratic oversight?

Key findings

  • The GAEN framework enables a dormant global mass surveillance capability at the operating system level, even if not actively used.
  • Despite its decentralized design intent, GAEN does not technically prevent health authorities from implementing centralized contact tracing systems.
  • Google and Apple retain unilateral control over which government apps are allowed to use the GAEN framework, undermining national sovereignty in public health policy.
  • Function creep is already evident in real-world deployments, such as Singapore’s police access to contact tracing data and Australia’s intelligence agencies collecting data from the COVIDSafe app.
  • The framework increases the risk of commercial exploitation, such as using beacon-based tracking for targeted advertising or location monitoring.
  • There is no independent verification mechanism to ensure Google and Apple uphold their privacy commitments, making the system reliant on trust rather than technical enforcement.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.