India’s “Aadhaar” Biometric ID: Structure, Security, and Vulnerabilities

Pratyush Ranjan Tiwari*, Dhruv Agarwal, Prakhar Jain, Swagam Dasgupta, Preetha Datta, Vineet Reddy, Debayan Gupta

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference article in proceedingsScientificpeer-review

3 Citations (Scopus)

Abstract

India’s Aadhaar is the largest biometric identity system in history, designed to help deliver subsidies, benefits, and services to India’s 1.4 billion residents. The Unique Identification Authority of India (UIDAI) is responsible for providing each resident (not each citizen) with a distinct identity—a 12-digit Aadhaar number—using their biometric and demographic details. We provide the first comprehensive description of the Aadhaar infrastructure, collating information across thousands of pages of public documents and releases, as well as direct discussions with Aadhaar developers. Critically, we describe the first known cryptographic issue within the system, and discuss how a workaround prevents it from being exploitable at scale. Further, we categorize and rate various security and privacy limitations and the corresponding threat actors, examine the legitimacy of alleged security breaches, and discuss improvements and mitigation strategies.

Original languageEnglish
Title of host publicationFinancial Cryptography and Data Security - 26th International Conference, FC 2022, Revised Selected Papers
EditorsIttay Eyal, Juan Garay
PublisherSpringer
Pages672-693
Number of pages22
ISBN (Print)978-3-031-18282-2
DOIs
Publication statusPublished - 2022
MoE publication typeA4 Conference publication
EventFinancial Cryptography and Data Security - Saint George, Grenada
Duration: 2 May 20226 May 2022

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume13411 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

ConferenceFinancial Cryptography and Data Security
Abbreviated titleFC
Country/TerritoryGrenada
CitySaint George
Period02/05/202206/05/2022

Keywords

  • Biometric
  • Resident identification
  • Security & privacy

Fingerprint

Dive into the research topics of 'India’s “Aadhaar” Biometric ID: Structure, Security, and Vulnerabilities'. Together they form a unique fingerprint.

Cite this