FB pixel

Protecting trust in ID takes stronger defense as DPI increases attack surface

Turing Cyber Threat Observatory workshop explores why and how
Categories Biometrics News  |  ID for All  |  In Depth
Protecting trust in ID takes stronger defense as DPI increases attack surface
 

As nations around the world build up their digital public infrastructure as a mechanism of social inclusion and economic development, cyber vulnerabilities emerge that can impede public trust. Yet techniques and technologies to find and mitigate those vulnerabilities are even newer than the concept of DPI, in many cases, leaving governments underprepared to protect digital IDs and other critical systems.

The Cyber Threat Observatory at the Turing Institute addressed these risks in a workshop this week on “Trustworthy Digital Infrastructure for Identity Systems.”

Governance and transparency are key, but governments are better equipped to build the necessary foundations than to operationalize them in a way that builds trust.

Several presentations noted that AI is boosting all kinds of threats. Synthetic identities and forged IDs are defeating biometric liveness detection, Parankusha Seshadri said. The scale of the problem is escalating quickly, he says, citing the figure of over 300 million biometric injection attack attempts by 2028 from Biometric Update and Goode Intelligence’s 2026 Injection Attack Detection Market Report and Buyer’s Guide.

Later, Idris Zakariyya presented a comparative study pitting biometric PAD against IAD. He found that while PAD can detect most presentation attacks, biometric injection attacks are more likely to defeat IAD protections.

Turing Institute researchers are looking into the impacts of AI on scams and identity forgeries and how they can be mitigated, the relationship between governance frameworks and policy interventions like coordinated vulnerability disclosures (CVDs) and user trust.

A researcher from the University of Warwick examined the asymmetry in cybersecurity governance and how it effects the trustworthiness of digital identity. Shah Mahmood found that laws tend to be the aspect of governance which is furthest along, while state capacity to enforce these regulations, or even observe their compliance, is most often where the system’s effectiveness falls apart.

Dr. Salim Awudu compared the digital ID governance layer system in Ghana to that in India and Kenya. He found that while the technical solutions deployed are not sufficient to inspire public trust, governance determines outcomes and low and middle-income countries need greater accountability within the system to demonstrate legitimacy and popular benefit.

The challenge of identifying and prioritizing DPI risks

The interdependency within DPI creates risks which are getting little attention from the community so far, said Gates Foundation DPI Team Senior Program Officer Assane Gueye in an opening presentation, particularly in the context of increasing AI use.

The 2021 Aadhaar outage shows how systems often treated as discrete can have dramatic impacts on people’s lives through their effect on related systems, like the rations and benefits disbursements in the Indian government was using its digital ID system for.

In a current example, the Pi SPI unified regional payment system operated by the Central Bank of West African States (BCEAO) is supposed to work for 147 million people, but struggles with fragmented ID and data exchange systems, Gueye says.

Risk arises in the gaps between areas that regulators are responsible for, and AI is creating more of these gaps. A single word in a local dialect misunderstood by an LLM could lead to cascading problems with identification or payments that have life-or-death consequences, as AI-powered DPI extends into areas like healthcare.

Tools exist to detect systemic harm in individual components of DPI, but not to see these gaps between the components. There is, however, Gueye notes, an existing body of research into the resilience of interdependent systems that could help understand how to consider DPI systems as a whole to find and fix governance gaps.

Resilience metrics loom large among the tasks the DPI community must tackle to address interdependency-related risks.

When risks are discovered, it is difficult for governments and other organizations to know how to prioritize them.

Professor Carston Maple spoke about the findings in the Turing Institute’s recent report co-authored with the World Bank Group on “Enhancing the Cyber Resilience of Identification (ID) Ecosystems,” which addresses this challenge.

He introduced the Work-Averse Vulnerability Evaluation (WAVE), a tool to triage vulnerabilities so those most likely to be exploited are patched first.

Experiences of Senegal, Niger

CNN Member Mouhamed Tidiane Seck presented Senegal’s experiences fending off hackers attempting to disrupt the country’s DPI.

Senegal’s DPI development created a much larger digital attack surface, which led to several successful attacks. One of those breached biometrics from the national ID database operated by the DAF, which wound up on the dark web.

Seck shared a series of insights culminating in six key recommendations, such as implementing zero trust architecture to shared security monitoring.

WURI Niger IT Expert Ismael Amadou Seyni spoke about securing his country’s National Population Register (RNP).

The RNP builds biometrics into Niger’s civil registry, based on a legislative foundation completed in April as part of its new MOSIP-based ID system.

Securing it has meant building cybersecurity and policy skills, and extensive coordination with clearly defined roles.

Related Posts

Article Topics

 |   |   |   | 

Latest Biometrics News

 

Biometrics handling new frontiers and changed expectations, from agents to gait

Successes in airport biometrics are driving deployments and expansions all over the world. But the technology cannot perform miracles like…

 

Financial institutions stumbling into phishing-resistant MFA gaps, report warns

Financial institutions seem aware that phishing is worsening, but that awareness has not translated into stronger authentication across the workforce….

 

Proof, Enigma link KYB to authorized people, AI agents with biometrics

Proof and Enigma have launched Business Certificates, a cryptographic credential that connects a verified business identity to the people and…

 

Investors back Lissi, Gataca’s expansions to meet EU Digital Identity Wallet moment

A pair of European digital wallet developers have new resources to pursue market share in the nascent continental ecosystem for…

 

New Incode age estimation tool processes biometrics on-device

Prompted by the introduction of online safety regulations globally, Incode has released an on-device age estimation product. An announcement from…

 

Western Australia privacy commissioner not consulted on police facial recognition trial

The Office of the Information Commissioner of Western Australia (OIC WA) says it was not invited to participate in any…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

DIGITAL ID for ALL NEWS

Featured Company

ID for ALL FEATURE REPORTS

BIOMETRICS WHITE PAPERS

BIOMETRICS EVENTS

EXPLAINING BIOMETRICS