In this system, the collecting authority
doesn’t know who submitted diagnosis keys.
If you assume a malicious app installed on both party’s phones, then you might be able to do it... but then again, if you have that you don’t really need this system to track contacts.
(I think on one side, you’d have to collect the daily keys and associate them when a person’s identity. Then, when you want to check a contact, you would then need to trigger an “infection” because otherwise the keys don’t leave the device. This requires user interaction, BTW, so there would be some kind of special social engineering effort to get someone to report themself as infected or else you the phone needs to be unlocked in the possession of a malicious party — or you have to hope to get “lucky” in that the person actually gets infected within 14 days of the timeframe of interest.
For the other party, you’d have to feed only the specific ids of the known people you want to check against to the matching API — it only tells you if there’s a match, not which match, so unless you’re checking only one, you’d have to use a process of elimination to work it down to a specific person. I wonder if that API might be throttled, though, or otherwise limited to make that less effective.
With the requirement to have malicious, cooperating apps on both sides you don’t need the Apple/Google system and you could get more useful info, like location, and with less user interaction.)