Written evidence submitted by Sir John Adye,
Chairman of Identity Assurance Systems (BIO0031)
Summary
- Background on Identity Assurance Systems (IdAS), and declaration of interests.
- Five main future uses of biometric data and technologies.
- Four main challenges facing both Government and industry.
- Effectiveness of current legislation, and suggested action to develop it appropriately.
- Annex A briefly describes the conceptual design of a framework using biometric and other technologies to link various distributed identity verification systems in the global economy.
- Background on Identity Assurance Systems (IdAS)
1.1. Identity Assurance Systems Ltd (IdAS) is a small company registered in England and Wales. Its Chairman, Sir John Adye, was formerly the Director of GCHQ and an independent director of the National Biometric Security Project (NBSP), a US non-profit organisation hitherto funded by Congress. IdAS Ltd and its US sister company were founded in 2010 to take forward the work of NBSP when US Congressional funding ended.
1.2. IdAS purchased the intellectual property (IP) of NBSP with funds provided by Board members, who like its other officers - former members of UK and US defence, security and intelligence agencies - all currently contribute their work without payment at this stage.
1.3. The main aims of IdAS are:
- to assist in the development of international standards for design and use of biometrics and security techniques relevant to the management and assurance of individual identity
- to develop commercial systems in collaboration with governments and industry which comply with these standards, and can make a return on investment adequate to enable sustained provision of greater security, personal privacy and convenience to individual people who access the internet and other services of all kinds in the global economy.
- Declaration of interests
2.1. John Adye and IdAS colleagues have a potential commercial interest in development of the conceptual framework and systems mentioned above. No Government or other external funding has as yet been sought or provided to IdAS, except for payment by the British Standards Institution (BSI) of some expenses for taking part in international standards meetings overseas.
- Future uses of biometric data and technologies
3.1. In addition to the present uses summarised in the Select Committee's terms of reference for this Inquiry, IdAS expects to see a substantial and sustained increase in the use of biometric data and technologies in the global economy. The main examples are:
- Control of borders and international migration. Biometrics are already extensively used for border control by many governments, but some (e.g. USA) do not yet apply them to their own citizens. Use is likely to spread as public acceptance of biometrics in Western democracies increases for other purposes as suggested below. Anonymous data based on biometrics can reliably be used for international correlation of border control records, without breaking national or EU data protection laws and regulations. Control of and assistance to migrants (who may have no passports or other identity documents) by governments and the International Organization for Migration (IOM) can be greatly helped by the use of biometrics without needing any other proof of identity.
- Other government services. In the UK, biometrics are not yet used as credentials for public access to government services, other than e-passports and residence permits for non-EU citizens. This is largely due to the aborted identity card scheme, and apparently a consequent policy to avoid other schemes which might imply its backdoor revival. In view of successful programmes in many other countries, e.g. for biometric-enabled driving licences and access to social security benefits, this is likely to change at some time in future, maybe in conjunction with the introduction of biometrics for some of the other purposes mentioned here. The new identity assurance programme launched by the UK Government Digital Service, linked to licensed commercial identity service providers, may eventually accept the security and privacy-protection advantages of using biometrics with other credentials for public access to such services.
- Health care and medical records. So far there has been little use of biometrics in support of the NHS or UK private health care provision, but their use is already starting to spread in the USA. There are potentially great advantages: for patients in enabling consistency of treatment between visits to different places of care; for hospital management in the simplification of procedures for ensuring the correct identity of patients at various stages of treatment, and in managing medical and ancillary staff and recording their interaction with individual patients; and in support of medical and pharmaceutical research, for the reliable correlation of anonymous records collected over time and place from treatment of patients who consent, with the assurance that these records cannot reveal patients' names or any other personal identity data. To ensure anonymity in this last example, the use of biometrics must be combined with consistent data protection procedures and proven security techniques.
- Payment cards and other financial services. The PCI (payment card industry)'s very successful international chip-and-pin scheme for credit and debit cards could be made more secure by the addition of biometrics, which could also conveniently extend its use with the same credentials to a wide range of other financial and related services, such as internet access to bank accounts and (as indicated above) to government services like tax records and social security payments.
- Biometric sensors on mobile devices. In connection with the previous example, and other commercial transactions on the internet, it is probable that the security and privacy protection advantages of biometrics - when these come to be accepted by the public - will with technical advances in sensor miniaturisation spread to many apps designed for use on mobile phones and tablets.
- Challenges
4.1. There are four main challenges facing both Government and industry in developing, implementing and regulating new technologies that rely on biometric data:
- Difficulty of regulating internet use. Following on from the last example (use of biometrics on mobile devices) it will be increasingly difficult for governments in any country to control the spread and use of new technology, including biometrics. But with major international industries competing for government contracts, it will be possible to encourage compliance with best practice. This may best be done by more intensive and sustained development of international technical standards, through expert ISO/IEC discussion and consideration of UK proposals co-ordinated by BSI.
- Dominance of international and foreign companies. These companies may be influenced by UK Government procurement policy as suggested above, but the challenges they present to national public interests can also be tackled by policies supporting R & D and the competitive strength of British industry in this fast developing field of identity assurance, using biometrics and related security techniques. Another remedy is to ensure that the UK develops these techniques in ways which can influence public opinion, in this country and abroad, to prefer and purchase the products and services of any company that complies with the standards of security and personal privacy which are promoted in this country.
- Fast changes in available technology. This is a real but inspiring challenge for both Government and British industry, which can best be tackled by sustained investment by both sectors in scientific and technical research applied to these fields of development. The most difficult area to get right is the mobile use of biometrics (last point in Section 3 above), where the most reliable biometric modes (e.g. iris recognition) are technically challenging to implement - and where particular attention is needed to the risks of remote and uncontrolled use, to ensure that adequate means are used to verify live submission of biometric data by the authorised user of both the device and the service.
- Public distrust of biometrics. This remains prevalent in countries like the UK, USA and now Germany which rightly fear anything which smacks of "Big Brother" or the mass surveillance state. Such fears can only be allayed in democracies by informed public debate. Organisations such as the Biometrics Institute (IdAS is a member) and the large annual Biometrics exhibition and conference in Westminster can help, by informing influential media with a consistent message that biometrics, properly used, actually provide the strongest means of protecting people's personal security and privacy. The technical arguments and evidence in support of this perhaps contentious claim need detailed and expert examination in public, with encouragement of appropriate attention by journalists. This Inquiry by the Science and Technology Committee could provide an influential public forum for that to happen.
- Effectiveness of current legislation
5.1. The main area of current legislation relevant to this Inquiry is the Data Protection Act 1998 (which implements the relevant EC Directive 95/46/EC on data protection) together with related regulations which apply in the UK. Some other legislation such as the Protection of Freedom Act 2012 is also relevant.
5.2. IdAS has taken legal advice in support of design work on our proposed framework (for which see Annex A) and on component applications and techniques. In most cases the relevant force of the current legislation is clear and helpful in designing appropriate means of protecting Personal Data. This is defined in the Act as data relating to a living individual from which the individual can be identified, either from the data alone or from the data in combination with other information in possession of the relevant Data Controller. Any processing of Personal Data must comply with the eight data protection principles of the DPA, for example its collection, use, storage, retention and disclosure. If the data is anonymised it will fall outside of the requirements of the DPA.
5.3. The inter-relationship between legal definitions of Personal Data, and of biometric data at various stages of its acquisition and processing, is absolutely crucial to the future design and use biometric technology. Technical and related legal and regulatory issues are currently under discussion as part of the process of formulating the EU's draft Data Protection Regulation. Work done in this context by the Data Protection Working Party (an independent European advisory body set up under Article 29 of Directive 95/46/EC) may be relevant to this Inquiry, e.g.
5.4. Such questions are important because the design of secure identity assurance systems, including biometrics and other technologies, must obviously enable compliance with applicable law, and because developing legislation and regulations in the EU and other countries will be highly relevant to the commercial viability and operational use of systems which are designed for application in the UK and are also marketed internationally.
5.5. The following small extract from Section 2 of the Working Party's Opinion 03/2012 may help illustrate the points made above:
Biometric template: Key features can be extracted from the raw form of biometric data (e.g. facial measurements from an image) and stored for later processing rather than the raw data itself. This forms the biometric template of the data. The definition of the size (the quantity of information) of the template is a crucial issue. On the one hand, the size of the template should be wide enough to manage security (avoiding overlaps between different biometric data, or identity substitutions), on the other hand, the size of the template should not be too large so as to avoid the risks of biometric data reconstruction. The generation of the template should be a one-way process, in that it should not be possible to regenerate the raw biometric data from the template.
Under the current application of the EC Directive and the Data Protection Act 1998, this one-way process anonymises the biometric data (as mentioned in paragraph 5.2 above), so that it falls outside the data protection requirements of the DPA.
5.6. IdAS suggests that the Select Committee consider how further formulative work on the EU's draft Data Protection Regulation can best be directed and handled, to ensure that it takes full account of UK national policies on the freedom of individuals and the protection of their personal data, and also on support to British industry in the fast developing field of identity assurance, using biometric and related technologies.
5.7. If required, IdAS can provide further evidence on these questions and other parts of this written submission, including our Anonymous identity Assurance (AidA) design framework, which is briefly described in Annex A.
September 2014
Annex A Conceptual design by Identity Assurance Systems of a framework using biometric and other technologies to link distributed identity verification systems:
IDENTITY ASSURANCE SYSTEMS - IdAS and AidA
What is AidA?
Anonymous identity Assurance - a framework or architecture for linking and managing distributed identity verification systems in the global economy:
- AidA uses biometrics in any tried and tested form (e.g. iris, fingerprint, voice, vein geometry) as the most reliable means of establishing and verifying human identity.
- AidA protects people's privacy and security, by separating the credentials used for identification from all other sensitive personal and financial information, which is
- securely held by the organisation that first registered the individual, where it can be accessed for law enforcement with legal authority in the country of registration.
- In this way, AidA enables biometric-based identity information to be securely shared between authorised applications without breaching data protection regulations,
- giving individual users the option of using a single set of credentials to access a wide range of commercial, financial and government services in the global economy.
- AidA uses technical standards to establish the level of trust appropriate to each application, and is designed to operate in distributed mode, through API integration with existing or developing identity management systems, in any field of activity.
- AidA can use other appropriate credentials in place of biometrics for authentication within a PKI-secured transactional system.
- AidA can also be integrated with developing US, UK and EU initiatives for trusted identities in cyberspace, internet commerce and delivery of government services.
- AidA is based on 8 years design work by NBSP (the US National Biometric Security Project), from which IdAS has acquired IP and patent application rights, and is
- developing the system further for commercial application, with expertise derived from professional work in UK and US security, intelligence and defence agencies.
What does AidA offer to people, to governments and commercial partners of IdAS?
- AidA can give individual users wide access to services and more convenient use
- AidA helps to protect the privacy and security of people's personal and financial data
- AidA meets service providers’ security needs and helps promote their commercial use
- AidA complies with law enforcement, defence and security requirements
- AidA can start small, and be developed for any application in the global economy
- AidA is designed to provide growing revenue and return on investment; and to build public confidence, by being fully open to expert examination in public.