Academia.eduAcademia.edu
Unique Identification Number Project: Challenges and Recommendations Authors: Haricharan Rengamani*, Ponnurangam Kumaraguru^, g , Rajarishi j Chakraborty*, y , H Raghav g Rao* *SUNY Buffalo; ^IIIT Delhi Presented at Third Intl. Conf. Ethics and Policy of Biometrics and International Data Sharing – Hong Kong, January 4-5, 2010 Agenda About UID project  Challenges Faced in SSN  National Identifier in UK  Unique identifiers in European Countries:   UK, Belgium, Estonia and Netherlands UID and its Biometric Approach  Ot Other e cchallenges a e ges for o UID U  Recommendations  Conclusions C l  About UID Project  Unique Identification Authority of India (UIDAI) Headed by Mr. Nandan Nilekani  First country to implement Biometric based unique ID system on such a large scale.  Responsible for implementing Multipurpose National Identity card or Unique Identification Card.  UIDAI to build a central database on details of every Indian resident including demographic and biometric information. information  Implemented p to save identityy verification costs for business through online verification of authentication of identity. About SSN in USA:  Started in November 1936  Nine digit g number issued to U.S Citizens,, Permanent Residents and temporary residents under Social Security Act.  Skeleton of SSN is XXX-XX-XXXX  Primary purpose is to track individuals for taxation purposes.  Evolved to become a defacto national identification number in the recent years. Challenges Faced in SSN  Privacy  Identity Theft  Terror Related crimes  Oth iissues Other National ID in UK Challenges in Existing System:  Technical complexity of the scheme  Associated cost  Protecting Privacy of citizens Purpose:  To maintain one identity document that can be used internally by all departments of Government.  To avail better access to services provided by both public and private sectors.  To track eligible workers in UK and to combat identity theft, Identity fraud and the issue of illegal immigrants. g National ID in Belgium BELPIC is the largest e-ID e ID scheme in Europe  Challenges and Solutions ◦ Goal was to enable citizens to authenticate themselves for accessing e-government applications like social security and give them a secure ID. ◦ Solution was based on a new PKI infrastructure along with information support and 24/7 helpdesk for lost cards. The framework relies on X.509v3 certificates. ◦ BELPIC doesn’t completely address the issue of interoperability te ope ab ty across ac oss administrative a st at ve units. u ts. ◦ Takeaways – Use of ‘Kids Card’. A variant of the e-ID for kids between 12 – 18 years. years National ID in Estonia Governed according to the Digital Signature Act (DSA).  98% of Estonians have national ID card  Digital signature embedded in card  ◦ Authentication and Digital Signing  I Issues that h may help h l in UID design: d ◦ Signature validity verification:  Solved by Online Certificate Status Protocol (OCSP). (OCSP) ◦ Lack of widespread digital signature implementation:  Solved by DigiDoc, a server-side and client-side software ◦ International interoperability:  Addressed through OpenXAdes project for universal understanding of legally binding National ID in Netherlands        Very similar to SSN in US – number assigned by Office of Tax Administration Unique Citizen Service Number ( (Dutch: Burgerservicenummer i or BSN) S ) for f citizens and workers. Corrections related to a BSN handled by Municipal Personal Records Database BSN is very limited for private organization Name is not linked with a BSN in the database BSN is used as an index for all information collected by Govt Databases protected by the Personal Data Protection Act. UID System y www.uidai.gov.in UID Agencies g www.uidai.gov.in UID Architecture www.uidai.gov.in Challenges g in India Identityy Card Privacy aspects of Biometric Technologies Technology Positive privacy aspects Negative privacy aspects Finger g print p Can pprovide different fingers g for different systems; large variety of vendors with different templates and algorithms p Strongg de-identification capabilities Face recognition Changes in hairstyle, facial hair, texture, position, lighting reduce ability of technology to match without user intervention Easily captured without user consent or knowledge Iris recognition Current technology requires high degree of user cooperation difficult to acquire image without consent Very strong de-identification capabilities; development of technology may lead to covert acquisition capability; most iris templates can be compared against each other - no vendor heterogeneity Privacy aspects of Biometric Technologies Contd.. Technology Positive privacy aspects Negative privacy aspects Retina scan Requires high degree of user cooperation; image cannot be captured without user consent Very strong deidentification capabilities Voice scan Voice is text dependent, the Can be captured without user has to speak p the enrollment consent or knowledge g of password to be verified the user Hand geometry Physiological biometric, but not capable of identification yet; requires proprietary device None Other challenges in Biometric technologies  Privacy invasions  Social Implications  Ethics Recommendations  Administrative Department ◦ Public Awareness ◦ Process for handling immigrants , Dual citizenships ◦ Enrolling and tracking citizens by multitude of technologies  Legal Department ◦ To make amendments to existing legal system for accommodating UID cards ◦ Restricting multiple issuance of cards, Access Restriction should be handled  Technical Department ◦ Random number ggeneration for UID card number ◦ Self check digits ◦ Effective Encryption and Decryption schemes and to architect system better for handling security issues Contributions 1 1. Identification of Technical, Technical Administrative and Legal Challenges in implementation of UID in India 2. Present a portal for learning from similar i l implementation t ti challenges h ll ffaced d iin other countries Conclusions      Better access to a host of government services Eliminates fake and duplicate identities which assist government to stem exchequer losses arising out of ghost identification or duplication Clearer view of ppopulation p and other demographic g p indicators. Provides major impetus to e-Governance programs and services Internal security scenario can be monitored well with UID’s being used to track criminals. Future work   To investigate the social implications of UID system in India To develop a formal framework for comparing various UID systems around the world ◦ Commonalities and differences