Ad

Showing posts with label database. Show all posts
Showing posts with label database. Show all posts

Saturday, October 13, 2012

Virtual ID Cards. Facial Recognition. Fingerprinting. Retinal Identity Scan.

a very interesting pdf.
UN E-Government Readiness Program- survey 2012
http://unpan1.un.org/intradoc/groups/public/documents/un/unpan048065.pdf

........

Bridging India’s identity divide with a number


Enrolment of a child for an unique identity number in DelhiThe unique number promises India's first unimpeachable proof of identity for its residents

Related Stories

On a boiling afternoon in the city of Surat in Gujarat state, men and women are rolling into a cavernous hall in the local municipality building to sign up for India's most ambitious plan to give a definitive identity to millions of residents.
It takes all of 10 minutes for each person to have their details keyed into a laptop before they are photographed on a webcam and their fingerprints and iris are scanned in what is also the world's biggest biometric identity exercise.
Since it launched two years ago, 200 million Indians have already signed up to India's "unique identity" (UID) scheme.
By 2014, another 400 million people are expected to enrol to get a 12-digit unique identification number - also called Aadhaar or foundation - fulfilling the scheme's mandate to cover about half of India's people. The Economist magazine calls it an "astonishing outcome" in a country which struggles to meet its most fundamental challenges.
"I have no idea of how this will help me. I have heard that it will do us some good," says Neruben, a municipal sweeper, who is waiting for her turn in the municipality hall, which once served as a Mughal inn.
Faceless existence
Neruben earns 12,000 rupees ($218) a month and has a bank account, a voters' identity card and a Permanent Account Number (PAN) card from income tax authorities which helps in opening bank accounts and filing tax returns. Most Indians are not as fortunate as her.

In pictures: Who am I?

Pictures
Millions are bereft of what identity scheme chiefNandan Nilekani calls "any form of acknowledged existence", which essentially ends up depriving them of their rights and pushes them into a faceless existence.
Many have no birth certificates or school certificates. About 58% of the children born in India are registered at birth, according to Unicef. Of those who are registered, not all have birth certificates.
In one of the world's fastest growing economies, some 40% of people living in villages don't have bank accounts, the number rising to three-fifths of people living in the east and north-east of India. (It is another matter that more than 40% of India's earners have no savings.) One of the main reasons why they don't have a bank account is that they have no definitive proof of who they are.
Also, identity - when available - is fickle and dubious.
There are more than a dozen documents that are variously accepted as proof of identity - a'ration card' that enables the poor to buy cheap food and cooking fuel, a voters card which enables people to cast their ballots, a driving licence and a PAN card are only some of them.
But most of these can be obtained in a thriving black market by using fake documents and paying a hefty bribe - a ration card can be purchased for up to 60,000 rupees ($1,095), and in some slums in Mumbai I visited recently, residents openly spoke about "buying" PAN cards for 600 rupees ($11), 10 times the official rate, through agents.
Identity is also not easily movable in India.
'Cycle of documentation'
Papers that people have in villages are often of no value when they move to cities in a country which is witnessing migration on a scale never seen before. So every time a villager travels to a city to work, he is faced with the problem of securing new identification, often by paying bribes.
Sonu Yusuf SheikhSonu Yusuf Sheikh has no job because he does not have proof of ID
There is also what project head Nandan Nilekani calls the chokehold of the "cycle of documentation" on people. "To get a driver's licence you need a ration card, to get a ration card you need a birth certificate [and so on]," he says.
The unique identity number aims to equip people with one unimpeachable, portable national identity aimed at helping the poor to access state welfare, open bank accounts and protect them from rampant police harassment. It promises to slash corruption in India's multi-billion dollar rural jobs guarantee scheme by paying salaries through bank accounts linked to the identity number. It will also help pay pensions and salaries, as well as enabling people to obtain cooking gas and mobile phone connections.
Financial inclusion, say enthusiasts for the scheme, is one of the major ways the identity number can change India.
When the majority of people living in India's 60,000 villages have their identity number, they will be able to open bank accounts and access their money without trudging for miles to reach the nearest branch and lose out on a day's wages. (More than 80,000 commercial bank branches across India cater to only 5% of the villages.) Bank representatives - usually local people - will keep some money and use nifty mobile micro-automated teller machines to make instant small deposits and withdrawals.
But biometric identity is a contentious issue all over the world, and the unique number has also raised a number of thorny questions.
Is it an invasion of privacy? Eminent economist Jean Dreze has called it a "national security project in the garb of a social policy initiative". Will the identity database be more reliable than the existing lists of beneficiaries for welfare schemes for the poor? Don't bet on it, says Dr Dreze.
The overwhelming concern is over the danger of restricting civil liberties by creating what one critic of the scheme has called the "infrastructure of authoritarianism".
Last year a parliamentary panel echoed similar sentiments about access and misuse of personal information, surveillance, profiling and securing of confidential information by the government. Authorities insist that there are enough safeguards to ensure the data is secure and protected.
'Something good'
The real problem may be that some have begun believing that the number can be used to track down wrong-doers.
A fisherman holds an identity card in MumbaiIdentity is usually not portable in India
"Why can't we use this database to detect criminals? It would be good if we could do so," Anilbhai Biscuitwala, a senior businessman in Surat from the Hindu nationalist BJP party, told me.

.........


Why India's identity scheme is groundbreaking


A woman getting enrolled in a UID booth in SuratIndia is building the world's largest biometric database

Related Stories

In an audacious technological mission, India is building a near foolproof database of personal biometric identities for nearly a billion people, something that has never been attempted anywhere in the world. 
Poorer Indians who have no proof to offer of their existence will leapfrog into a national online system, another global first, where their identities can be validated anytime anywhere in a few seconds.
"India will outdo the world's biggest biometric databases including those of the Federal Bureau of Investigation and the US-VISIT visa programme," says Nandan Nilekani, the technology tycoon who heads the programme popularly called by its acronym UIDAI.
The United States' visa programme is a biometric database of 120 million.
In comparison, the UIDAI has already registered 200 million members, less than two years after the first enrolment. 
By 2014 half of India's population will have an identity tagged to a random, unique 12-digit number. 
Radical ideas
As more and more Indians have their fingerprints taken, irises scanned and photographs clicked, UIDAI's chief technology architect Pramod Varma describes the database structure as a "Google-meets-Facebook" scale out.
UIDAI Network operation centre in BangaloreThe information is stored in a fortress like data centre in Bangalore
With its internet-class open source backbone, the database will accommodate more than 12 billion fingerprints, 2.4 billion iris scans and 1.2 billion photographs. 
Even more groundbreaking, once established and stored, a person's identity can easily be verified and authenticated using a cell phone, smart phone, tablet or any other device hooked to the internet.
The information is stored in a fortress-like data centre in Bangalore with a triple layer of security, and travels in highly encrypted packets.
Many of the radical ideas for UIDAI's technology have come from the talent the project has drawn from the Indian diaspora - tech entrepreneurs like Bala Parthasarathy of HP-acquired photo service, Snapfish and Silicon Valley returnees like Srikanth Nadhamuni, formerly with Intel.
Mr Nilekani himself co-founded and built the multi-billion dollar outsourcing company Infosys before being drafted by the government to head the project.
The programme has studied global best practices in biometric identity databases.
Unlike the United States' social security number, which is guessable and China's, which adds the date of birth, India's 12-digit identity number is randomly generated.
The United States' visa database does not factor in iris scans while India has included them to provide a greater degree of accuracy. 
India's telecom revolution leapfrogged over several stages of technology in the past decade-and-a-half to great success. Similarly, the massive UIDAI will vault over older technologies. 
"By starting on a clean slate and reconfiguring the structure, we have opened up a whole new set of possibilities," says Mr Nilekani. 
The project will stay abreast of the latest in biometrics, cloud computing and connectivity.
Woman in Mysore having fingerprint checked by gas man for ID number in pilot projectPilot projects using the unique number have begun in parts of India
Costs though have been kept low, first, by adopting an open policy in selecting devices and software and encouraging multiple private vendors.
Second, the project is technology-neutral, not locking in to any particular hardware or software.
If the technology architecture is unique, so is its accuracy in validating identities.
"The combination of 10-finger biometrics, two-iris scans and photograph establishes the identity of a person with over 99.5% accuracy," says Krishnakumar Natarajan, CEO of Bangalore-based tech outsourcing firm MindTree, which is one of the firms building applications for the project.  
The best of the biometric databases in the world have a single de-duplication check, to ensure that every person is identified and tagged only once.
Real challenge
UIDAI will de-duplicate three times over, accuracy that is vital in a country which has had a massive population migration in the past decade and welfare programmes that now total $60bn in value, says Ashok Dalwai, deputy director general of UIDAI.
"A lack of identity has become the divide in India, denying needy Indians access to welfare programmes," Mr Dalwai says.
In a country where billions of dollars in welfare get siphoned off by middlemen using fake identities, the programme will "stem leakage and fraud", he adds. 
The real challenge for the project, however, will be in the applications built around the unique identities.
A slew of pilots are currently testing the robustness of the system.
In a trial in Tumkur near Bangalore, Indians armed with a new unique identity number are opening bank accounts electronically.
In the northern Jharkhand state, the government is electronically dispensing payments under an employment guarantee scheme directly into the recipients' bank accounts, which were opened after acquiring an identity number. 
A UID enrolment booth in SuratThe project is technology-neutral, not locking in to any particular hardware or software.
In another pilot in the same region, people are authenticating themselves on a simple device connected to the network and withdrawing money from their new bank accounts.
In the future, every outlet with such a device can potentially serve as a cash-dispensing "micro ATM".
In the coming years, UIDAI holds the promise of being a game changer.
With a unique identity, previously anonymous poor Indians can have access to services such as bank accounts, mobile connections and driving licences.

source:  http://www.bbc.co.uk/news/world-asia-india-18156858

............

National 'virtual ID card' scheme set for launch (Is there anything that could possibly go wrong?)

Central online identity scheme 'will be a target for criminals'
The Government will announce details this month of a controversial national identity scheme which will allow people to use their mobile phones and social media profiles as official identification documents for accessing public services.

People wishing to apply for services ranging from tax credits to fishing licences and passports will be asked to choose from a list of familiar online log-ins, including those they already use on social media sites, banks, and large retailers such as supermarkets, to prove their identity.

Once they have logged in correctly by computer or mobile phone, the site will send a message to the government agency authenticating that user’s identity.

The Cabinet Office is understood to have held discussions with the Post Office, high street banks, mobile phone companies and technology giants ranging from Facebook and Microsoft to Google, PayPal and BT.

Ministers are anxious that the identity programme is not denounced as a “Big Brother” national ID card by the back door, which is why data will not be kept centrally by any government department. Indeed, it is hoped the Identity Assurance Programme, which is being led by the Cabinet Office, will mean the end to any prospect of a physical national ID card being introduced in the UK.

The identification systems used by the private companies have been subjected to security testing before being awarded their “Identity Provider” (IDP) kitemark, meaning that they have made the list of between five and 20 approved organisations that will be announced on 22 October.

The public will be able to use their log-ins from a set list of “trusted” private organisations to access Government services, which are being grouped together on a single website called Gov.uk, which will be accessible by mobile.

A cross-section of social media companies, high street banks, mobile phone businesses and major retailers has been chosen in order to appeal to as wide a demographic as possible.

The system will be trialled when the Department of Work & Pensions starts the early roll out of the Universal Credit scheme, a radical overhaul of the benefits system, in April.

Users who access the Government’s online one-stop-shop of public services will be asked to identify themselves by choosing one organisation from a selection of logos. (This feature is called a “Nascar screen”, in reference to the logo-filled livery of the famous American racing cars.)

Major web sites are able to recognise individuals by their patterns of use, the device they are accessing from and its location. Facebook, for example, asks users who sign on from an unusual location to take a series of security questions including identifying friends in photographs.

Privacy campaigners are not wholly convinced by the programme. “Although this is a fine scheme in principle and is backed by ministers the danger is that it could be side-lined and used as a fig leaf by the data-hungry government departments,” said Guy Herbert, general secretary of No2ID, which has been consulted by the Cabinet Office.

Details of the “identity assurance” scheme are being finalised amid growing concerns over identity theft and other forms of cybercrime. Foreign Secretary William Hague and Cabinet Office minister Francis Maude, who is at the head of the Identity Assurance Programme, will today (Thurs) meet international experts at the Budapest Conference on Cyberspace. Mr Maude will give a keynote speech.

The Cabinet Office believes its new identity model will “prevent ‘login fatigue’ [from] having too many usernames and passwords” and save public money by increasing trust in online services. The system is likely to be adopted by local authorities nationwide. The Government hopes the identity system will form the basis of a universally-recognised online authentication process for commercial transactions on the Internet, boosting the economy and strengthening Britain’s position as a leader in e-commerce.

In recent weeks, the Cabinet Office’s Government Digital Service has backed a UK working group of the Open Identity Exchange, which was set up in America to bring organisations including Google, AOL, PayPal and Experian together to find a simple method of online verification that doesn’t require multiple passwords.

Members of the Cabinet Office team travelled to the White House in May to exchange ideas with American counterparts working on the National Strategy for Trusted Identities in Cyberspace (NSTIC). The heads of the British and American identity assurance programmes will debate the subject next week in London at the RSA cyber security conference.

The first law passed by the Coalition Government was to scrap the national ID scheme, a move said to have saved taxpayers £1 billion over ten years. But ministers want to use the Internet to cut the cost of public services.

In order to limit concerns over Government snooping, the Cabinet Office has been working closely with a range of privacy campaign groups and consumer organisations including No2ID, Big Brother Watch and Which? The programme’s Privacy and Consumer Group drew up a list of nine Privacy Principles which underpin the framework of the scheme.

As part of the attempt to reassure privacy campaigners, a private identity partner (IDP) which authorises a user of a public service will not know which Government department is seeking authentication.

The Post Office’s involvement in the Identity Assurance Programmes was revealed by a notice placed in the Official Journal of the European Union. The Royal Mail subsidiary sought a third party provider to help in assembling consumer data including name, date of birth, address, gender, passport and driving licence numbers, financial history, electoral roll status and telephone numbers.
Some commercial organisations have been concerned that their consumers will react negatively to their involvement with government. But commercial partners will benefit from marketing opportunities and the trust that comes with IDP status.

Without the identity assurance scheme there are fears that high levels of online fraud will cause the public to lose confidence in digital channels, undermining the amount of business done online.

Civil servants acknowledge that some people will still wish to access public services in person. They argue that the online scheme will release additional resources to assist people who lack confidence in making digital transactions.

Q&A: What the scheme involves
Q. Is this just an ID card scheme by the back door?
A. No, it's a way of combating the menace of identity theft.
Q. Will the Government be able to use it to follow our movements online?
A. Authentication is done by trusted third parties and data will not be held centrally by the Government.
Q. But won't the private companies find out personal information that is none of their business?
A. The identity providers (IdPs) don't know for which government agency they are authenticating.
Q. Is a social media log-in sufficiently secure for a major financial transaction?
A. Individual IdPs will need to convince the Cabinet Office that their security checks are enough to meet the Level of Assurance (LOA) needed for the public service being requested. For example, a passport application is a high-security LOA3.
Q. Will it be possible to apply for a passport on your phone?
A. It is anticipated that part of the process will be offered online but some physical ID will still need to be presented in person to achieve LOA3.
Q. Is this just about public services?
A. No, the Government is helping to bring together online companies and create an icon that would enable online payments to be done securely.
Q. What would be the advantages?
A. It would also reduce the need to memorise multiple passwords.
Q. Will it work?
A. That depends partly on the efficiency of the chosen IdPs.

Evolution and Trends in Terrorism Tradecraft


Evolution and Trends in Terrorism Tradecraft

October 11, 2012
By Scott Stewart
The terrorist tradecraft discussed in last week's Security Weekly does not happen in isolation. The practitioners of terrorist tradecraft conduct their activities in the midst of other people -- the authorities attempting to identify them and thwart their plans as well as civilians. Terrorist tradecraft also does not remain static. It is constantly evolving. These changes are prompted not only by countermeasures put in place to prevent terrorist attacks but also by advances in technology -- a powerful force that can serve to either nullify old tradecraft practices or to provide new tools to the purveyors of terror.
Terrorism is an enduring reality. While geopolitical changes may cause a shift in the actors who employ terrorism as a tactic, terrorism will continue to be used no matter what the next geopolitical cycle brings. It is, and will continue to be, a tactic used by militant actors who want to confront a militarily superior enemy. Focusing on the tradecraft used in attacks and charting its changes and trends not only permits observers to understand what is happening and why but also provides an opportunity to forecast what is coming next.

Documents

In the early terrorist plots of the late 1800s, many of the foundational tradecraft requirements were aided by the general simplicity of the times. Among the foundational tradecraft requirements discussed last week was procuring identification documents. Public records were very sparse, did not usually contain people's photographs and tended to be decentralized and not easily searched. (This is still true in some parts of the world today, such as in Afghanistan and Somalia.) There were no universal identification cards such as driver licenses, because automobiles had not yet become common. Passports and visas were not widely required for travel until after World War I, and even then the records of passport and visa issuance as well as traveler entries and exits were localized, hand-written entries into ledgers and were hard to search.
During this time, it was not difficult for Irish Fenian, nihilist or anarchist terrorist actors to travel, rent safe-houses or raise and transfer funds. Communication was certainly more difficult for everyone at that time -- authorities as well as terrorists. The mail system was slow, and while telegrams could be sent quickly, they were seen by many people. Law enforcement agencies did not communicate or coordinate very well across jurisdictional lines within one country, much less on an international scale.
During World War I, concerns over spies and saboteurs caused important changes to international travel, including stricter passport and visa requirements. This also had an impact on terrorist actors, such as Irish Republican Army members traveling to and from the United States or England, but early passports, visas and other identification documents were often hand-written and easily forged or altered. During this era, it was also still quite easy to assume the identity of an infant or young child who had died, because birth and death records were not often cross-referenced -- especially if they happened in different locations. This practice is referred to as an infant death identity in document-fraud investigations. Nazi and Soviet espionage agents used infant death identity quite frequently, which resulted in changes to the way records were kept, but domestic and international terrorist operatives continued to use infant death identities into the 1960s and 1970s.
Advances in technology in the 20th century allowed countries to make their identification documents more resistant, but not immune, to counterfeiting and alteration. The real difficulty in using counterfeit or altered documents started when the documents were linked to a central computerized database. This meant that counterfeit passports and visas did not show up in the databases and allowed a quick photo comparison to ensure that passports with altered photos could not be as easily used. In 1988, Japanese Red Army bombmaker Yu Kikumura was able to enter the United States using an altered Japanese passport.
In 1992, al Qaeda bombmaker Ahmed Ajaj was arrested trying to come through immigration at New York's John F. Kennedy International Airport using a Swedish passport in another name altered to bear his photo. His partner, Abdul Basit, ditched the altered passport he used to board the flight in Karachi, Pakistan, and used an authentic Iraqi passport in the name Ramzi Yousef to claim political asylum. In the 9/11 plot, and in all the follow-on al Qaeda plots directed against the United Sates, al Qaeda operatives have used authentic travel documents to enter, or attempt to enter, the United States. Some of the 9/11 operatives did commit document fraud in relation to driver licenses and state identification cards, but as outlined in the 9/11 Commission Report, that fraud almost resulted in the unraveling of the plot.
Changes in technology and enforcement in the United States and Europe have caused changes in identity and travel tradecraft for transnational jihadists, who are now searching for "clean skin" operatives who are unknown to law enforcement and who have the ability to travel internationally using legitimate travel documents.

Explosives

Bombing has been a staple of terrorism since Guy Fawkes and his co-conspirators' failed attempt to destroy the British Parliament in 1605 in the so-called Gunpowder Plot. The invention of dynamite in 1867 was a very big boon for early terrorists, who no longer had to use black powder, a low explosive, as the main charge in their devices. Dynamite was not only more stable and less sensitive to moisture than black powder but was also more powerful. Dynamite was widely used by Irish Fenians in their attacks, but perhaps the image of the anarchist bombthrower is the most iconic of that period.
In the age of modern terrorism, bombmakers have had the luxury of access to high-powered military explosives such as TNT, C-4 and Semtex. Technologies such as shaped charges, platter charges and explosively formed penetrators have also increased the impact of these powerful explosive compounds. Another development that has greatly altered the art of bombmaking has been the advent of microelectronics. Bombmakers can use sophisticated timers to activate a device days or even weeks after it is placed. They can also use sensors that detect motion, light, the presence of metal objects or changes in altitude in order to detonate the explosive device. Command-detonated devices using radio signals or cell phones have also been widely employed.
Perhaps one of the most influential bombmakers in the modern terrorist era is Abu Ibrahim, a former member of Black September, the Popular Front for the Liberation of Palestine and the 15 May Organization. Ibrahim is often referred to as the "grandfather of all bombmakers" for his innovative improvised explosive device design and his willingness to train other bombmakers in his dark arts. Ibrahim was an early adopter of electronics in his designs.
During the 1970s and 1980s, state sponsorship did a lot to help advance bombmaking tradecraft, as sabotage experts from the Soviet KGB and the East German Stasi passed on training and technology. (The Eastern bloc was also a very important source of funding and identification documents during this period.) In addition, state sponsorship meant that sponsors, such as Libya, could use the diplomatic pouch to transport weapons and explosive components to terrorist operatives in places like London and Paris.
Controls on the purchase of explosives, and even on items like ammonium nitrate fertilizer, which can be readily used to make homemade explosive mixtures, have made it more difficult in recent years to make improvised explosive mixtures. This has caused bombmakers to change to mixtures made from more readily available precursors, such as acetone and peroxide. But these mixtures tend to be not only more dangerous to brew -- the Palestinians refer to triacetone triperoxide, or TATP, as "the mother of Satan" -- they also have a limited shelf life, are less stable and more difficult to transport and correctly synthesize. In 2009, would-be New York City subway bomber Najibullah Zazi was frustrated in his attempts to manufacture viable TATP.
In the realm of targets and tactics, we've talked elsewhere of the arms race in aviation security and how it has caused the threat to aircraft to evolve, with the next likely step being non-metallic explosive devices hidden inside the bodies of suicide attackers. There has also been an evolution in the targeting of Western interests abroad. Embassies have become harder targets and Western hotels have been increasingly more desirable targets, although the Sept. 11, 2012, attack in Benghazi may shift terrorists' focus back to vulnerable diplomatic missions in volatile locations. 

Databases

Perhaps one of the most powerful inhibitors of terrorist tradecraft has been the use of computerized databases, allowing authorities to crunch a lot of data. One of the first well-documented uses of computers to locate terrorist suspects was the massive effort undertaken by the German Federal Criminal Police in the 1970s to combat the Red Army Faction. The German police created a database and then cross-referenced its information on a wide variety of indices. They then created a profile of the Red Army Faction safe-house with features such as young people living together, paying their rent and utility bills in cash and not registering with the local government or registering their motor vehicles. When a computer search identified addresses that matched the profile, they then dispatched detectives to investigate these possible safe-houses in person. This campaign was very successful in helping round up the first generation of Red Army Faction operatives.
Lists of terrorist suspects and their aliases have also proved quite useful in inhibiting terrorist travel, but it has not been without its failures or criticism. The U.S. State Department first adopted a database called TIPOFF in the 1980s designed to prevent terrorists from getting visas. The system was later turned it into the Visas Viper system after the 9/11 attacks. The United States has created the Terrorist Screening Center, which is charged with consolidating all the various U.S. government watch lists as well as administering the controversial terrorist watch list and the no-fly list.
Computers are also being used to monitor terrorist communication, whether by telephone, satellite phone or the Internet. But like the watch lists, these efforts have proved to be quite controversial. 
Seizing or freezing bank accounts associated with known terrorists and efforts to crack down on charities that were funding terrorist groups have been somewhat successful in limiting the money moving to terrorist entities. But the presence of significant informal money transfer networks has made it impossible to totally stop the flow. The ability of terrorist groups to use narcotics sales and other criminal activity to fund themselves has also been hard to stop.

Trends

Since the 9/11 attacks, the United States and its allies have spent billions of dollars on security improvements and have made great efforts to increase security and to counter the tradecraft used by terrorist groups. It is now more difficult for terrorist operatives to travel to the United States and Europe -- as evidenced by the lack of serious attacks and by the calls of groups such as al Qaeda in the Arabian Peninsula and the al Qaeda core group for grassroots terrorist operatives to conduct simple attacks where they are rather than travel overseas for training or to wage jihad. It has also led them to recruit individuals who have travel documents like Richard Reid, Najibullah Zazi and Faisal Shahzad for attacks rather than send well-trained operatives to conduct them.


Read more: Evolution and Trends in Terrorism Tradecraft | Stratfor