Skip to the content

Follow us @UKAuthority

Covid-19 app developers aim for overseas interoperability

12/10/20

An effort has begun to make the Covid-19 contact tracing app for England and Wales interoperable with those of other countries.

Contact tracing app screen

The National Cyber Security Centre (NCSC), which has led the security work in the app’s development, has revealed the plan along with a report on recent improvements.

Its chief information security officer for the app, named as Stuart H, said the work on interoperability is aimed at providing the next major feature for the app, which was developed with NHSX and launched nationally last month.

He said it should make it possible to travel across borders without having to download a new app and reduce the risk of travelling abroad. But he warned that it will not be simple to ensure this can be done safely.

“The good news is that there is a plan to progress interoperability using a safe and phased approach,” he said.

“The first stage is getting interoperability across the CTA (the Common Travel Area comprising the UK, Jersey, Guernsey, Isle of Man and Ireland). Later we hope to branch out to Europe and further afield.”

Security steps

Stuart H said that main security improvements have included ensuring the app uses the most secure location within a device to store encryption keys, refactoring back end APIs to make them more robust, and automation data exchange processes to ensure it uses the most up-to-date data.

In addition, protective monitoring for the back end infrastructure has been improved, and access management and policies of the cloud infrastructure have been bolstered.

“These aren't features that users will see, but continuous security improvements are crucial in maintaining a secure and high availability system which can adapt to threats,” he said.

Image from NCSC, Open Government Licence v3.0

Register For Alerts

Keep informed - Get the latest news about the use of technology, digital & data for the public good in your inbox from UKAuthority.