Skip to content

India’s “Aadhaar” Biometric ID: Structure, Security, and Vulnerabilities

Notifications You must be signed in to change notification settings

agdhruv/aadhaar-security

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

64 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

aadhaar-security

A research project exploring India’s "Aadhaar" Biometric ID. The paper is titled: India’s “Aadhaar” Biometric ID: Structure, Security, and Vulnerabilities.

Abstract

India's Aadhaar is the largest biometric identity system in history, designed to help deliver subsidies, benefits, and services to India's 1.36 billion residents. The Unique Identification Authority of India (UIDAI) is responsible for providing each resident (not each citizen) with a distinct identity---a 12-digit Aadhaar number---using their biometric and demographic details. We provide the first comprehensive description of the Aadhaar infrastructure, collating information across thousands of pages of public documents and releases, as well as direct discussions with Aadhaar developers. Critically, we describe the first known cryptographic issue within the system, and discuss how a workaround prevents it from being exploitable at scale. Further, we categorize and rate various security and privacy limitations and the corresponding threat actors, examine the legitimacy of alleged security breaches, and discuss improvements and mitigation strategies.

Collaborators

  • Debayan Gupta
  • Dhruv Agarwal
  • Prakhar Jain
  • Preetha Datta
  • Pratyush Ranjan Tiwari
  • Rohan Poddar
  • Swagam Dasgupta
  • Vineet Reddy

About

India’s “Aadhaar” Biometric ID: Structure, Security, and Vulnerabilities

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 4

  •  
  •  
  •  
  •