FB pixel

When biometrics meet PKI: Nigeria’s next digital identity challenge

Categories Biometrics News  |  ID for All  |  In Depth
When biometrics meet PKI: Nigeria’s next digital identity challenge
 

Nigeria’s digital identity system is entering a new phase.

More than 136 million people are registered for a National Identification Number (NIN), up from 123.9 million in October 2025, with a target of 180 million by the end of 2026. That means adding roughly 44 million registrations in a country of about 238 million people, spread across 36 states and the Federal Capital Territory, with a substantial rural population.

The challenge is also changing. Nigeria is no longer focused only on getting people into the identity system. NIN is increasingly becoming a means of accessing public and private services.

The NIMC Act 2026 takes that evolution further. Replacing the NIMC Act 2007, the legislation expands the National Identity Management Commission’s (NIMC) responsibilities and positions it as the Root Certification Authority for Nigeria’s national Public Key Infrastructure (PKI) and Digital Public Infrastructure (DPI).

That brings two fundamentally different trust technologies — biometrics and PKI — closer together at enormous scale. There are many implications. Four areas deserve particular attention: technical, security, privacy and regulatory.

When the person changes but the digital identity remains

Consider a Nigerian who enrolled for a NIN years ago. Biometrics were captured at enrollment and became part of establishing the person’s identity.

As more services become digital, the citizen increasingly uses a smartphone to authenticate for financial, government or other services.

Then facial authentication starts failing more frequently.

The reference biometric was captured years earlier. The person has aged or their appearance has changed. Different cameras, lighting, pose and image quality can introduce further variation. Unlike cryptographic verification, biometric comparison is probabilistic: a new sample is compared with a reference and evaluated against a threshold.

Meanwhile, the cryptographic side may be functioning perfectly. The correct key is present and the certificate remains valid.

The PKI trusts the credential. The biometric system is becoming less certain about the person behind it.

The apparent solution is simple: capture a new biometric and refresh the reference. But that turns an authentication problem into something much larger.

Technical: two different lifecycles

PKI and biometrics behave fundamentally differently.

Cryptographic keys are deterministic. Certificates have defined validity periods and can be renewed, revoked and replaced.

Biometrics are probabilistic, and the underlying characteristic belongs to a human being who changes over time. A biometric reference therefore does not follow the predictable lifecycle of a certificate.

During authentication, the system effectively asks: Does this biometric sufficiently match the identity already on record?

During template refresh, the question becomes more consequential: Should this new biometric change what the system trusts as representing this person?

That distinction becomes increasingly important as millions of identities remain active for decades. Certificate expiration can be planned. Biometric degradation is less predictable.

Security: mobile self-service changes the threat model

At Nigeria’s scale, repeatedly requiring citizens to visit physical enrollment centers to maintain their digital identities could become impractical, particularly for rural and difficult-to-reach populations.

Mobile self-service offers scalability, but moves digital identity maintenance from controlled enrollment environments onto consumer devices.

NIMC must then consider three different questions: Can it trust the device? Can it trust the biometric capture? Can it trust the person behind the transaction?

Remote processes face presentation attacks using photographs, videos or masks, but the threat is expanding. Digitally injected images, virtual cameras, emulators, face swaps and AI-generated media can attempt to bypass the physical capture process altogether.

Template refresh raises the stakes further. An attacker who defeats one authentication may gain access to a service. An attacker who successfully changes the trusted biometric reference could potentially influence future authentications.

India provides an interesting practical precedent: while some Aadhaar information can be updated remotely, biometric updates remain tied to enrollment/update centers. The distinction demonstrates that mature identity systems may accept additional friction when the transaction changes a biometric trust anchor rather than merely uses it.

For Nigeria, mobile identity therefore expands the security problem beyond face matching to device integrity, capture provenance, presentation and injection attacks, and unauthorized template modification.

Privacy: connecting identity can also connect activity

A NIN linked with biometrics and cryptographic credentials could increasingly support banking, healthcare, travel, government benefits and other services.

That creates enormous utility, but also raises the possibility of linking a person’s identity and activity across different contexts.

The privacy question is therefore not simply how securely a biometric database is stored. It is how much identity information needs to move through the ecosystem.

A bank or government service may need confirmation that a person has been successfully authenticated. It does not necessarily need the person’s biometric template, raw selfie, matching score or biometric history.

The Philippines’ PhilSys provides an instructive example. Rather than requiring the foundational PhilSys Number to be exposed in every transaction, the system uses mechanisms including a tokenized identifier and digitally signed credentials to support verification while limiting unnecessary exposure of the foundational identity number.

At national scale, data minimization, purpose limitation, confidentiality and unlinkability become critical considerations, particularly given Nigeria’s previous controversies involving alleged unauthorized access to identity information.

Regulatory: who can change what the system trusts?

The ability to update a biometric technically does not answer the regulatory question of who should be permitted to do it.

Nigeria will need clarity around who may collect biometrics to update NIMC’s database, who may request authentication, what level of assurance is required before a biometric reference can be changed, and how long biometric captures and superseded templates can be retained.

Singapore’s Singpass illustrates another important principle. Biometrics such as Face Verification can provide additional assurance for sensitive transactions, but the ecosystem also provides alternative authentication paths rather than assuming that biometric verification will work for every person and every transaction.

That matters for essential services. A biometric false rejection should not automatically become denial of access to healthcare, government benefits or other critical services.

Accountability presents another challenge.

What happens when a citizen disputes a biometric update? Who is responsible if a fraudulent update subsequently enables misuse of a valid digital credential? When should suspected biometric compromise trigger suspension or revocation of cryptographic credentials?

Regulatory boundaries also matter as NIMC’s Root CA responsibilities intersect with other authorities involved in Nigeria’s electronic-signature and digital-trust ecosystem.

The stakes are different because biometrics and PKI fail differently. A compromised private key can be revoked and replaced. A compromised face or fingerprint cannot.

From enrollment to lifecycle management

Nigeria does not have to solve every one of these problems from scratch.

India demonstrates the importance of treating biometrics as a lifecycle rather than a one-time enrollment event. Singapore shows the value of different authentication mechanisms and fallback paths. The Philippines illustrates how a foundational identity can support transactions without unnecessarily exposing the underlying identifier. And the EU’s emerging wallet framework highlights the growing importance of binding the person, credential and device in remote identity transactions.

None provides a complete blueprint for Nigeria. But together they point toward an important shift in thinking.

Return to the citizen whose facial authentication has started failing. Refreshing the biometric sounds like routine maintenance. At national scale, that one transaction raises technical questions about biometric aging, security questions about mobile devices and synthetic media, privacy questions about newly collected biometric data, and regulatory questions about who is authorized to change an identity record.

Multiply that across potentially 180 million identities, years of use and an expanding range of digital services, and Nigeria’s next challenge becomes clear.

The next phase of digital identity will be less about how many people NIMC can enroll, and more about how trust in those identities is maintained long after enrollment is complete.

 

Related Posts

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Meta sued over alleged facial recognition training for smart glasses

Meta Platforms is facing a proposed nationwide class action lawsuit accusing the company of using photographs from Facebook and Instagram…

 

IATA urges EU to extend biometric border flexibility amid EES delays

The International Air Transport Association (IATA) is urging the European Union to extend temporary flexibility measures for its biometric Entry/Exit…

 

Thailand puts verifiable credentials at center of 2027 digital ID strategy

Thailand’s digital development agency is planning big moves for 2027 as it focuses on digital ID and digital transformation. The…

 

Albania gives ALBTrace broader role in digital identity infrastructure

Albania has expanded the mandate of state-owned identity services provider ALBTrace, giving it responsibility for the country’s digital identity infrastructure…

 

BEAC lays foundation for interoperable payments across Central Africa

The Bank of Central African States (BEAC) has rolled out some initiatives lately which suggest a coordinated push aimed at…

 

Procivis expands EUDI footprint as Europe’s wallet deadline approaches

Procivis has added France to a growing list of European digital identity environments where its technology can issue and verify…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events