They should only accept infection reports that are signed with a trust chain terminating with an Apple/Google internal CA, and sign keys provided by governments with their root CA.
Alternatively, the system could be configured to connect to the "infected keys server" run by the local government(s), as determined by the countries of the cell network the user connected to in the last 30 days.