This story is from September 14, 2018
UIDAI system has multiple layers of security check to thwart manipulation: CEO
NEW DELHI: The UIDAI's system contains multiple layers of security checks, and any attempt of manipulation at the operator level will be detected and thwarted at the back-end, Aadhaar-issuing body's CEO
The comments of the Unique Identification Authority of India (UIDAI) chief came against the backdrop of a recent report alleging Aadhaar software hack.
"The whole Aadhaar system is designed in a manner that it has multiple layers of security. Because of multiple layers of security, if manipulation is done at the systems' front end, at the back-end the security checks will thwart that attempt," Pandey said.
Once the application for enrolment is received, validation or security checks are performed at the system's back-end too, Pandey said, adding that these safeguards allow rogue attempts to be detected.
"...all such attempts will get detected at the back-end and the enrolment packets then get rejected, and Aadhaar is not generated...we are also able to identify which operator has done this and, in such cases, the operator will be blacklisted...in appropriate cases we file prosecution under the Aadhaar Act," Pandey told PTI.
A report recently claimed that Aadhaar software and database have been compromised by a software patch that purportedly disables crucial safety features of the enrolment software.
The report had also said that the patch allegedly enabled unauthorised people to generate Aadhaar, a claim that has been refuted by the UIDAI.
In a statement earlier this week, UIDAI claimed that no operator can make or update Aadhaar unless an individual gives biometrics details.
"Therefore it is not possible to introduce ghost entries into Aadhaar database," the UIDAI statement had said.
When contacted, Jaideep Srivastava, Professor of Computer Science at University of Minnesota said that the generation of an Aadhaar number is the result of a full 'two-way handshake' between the client software and the server software.
"The former collects and sends a packet, and the latter then decides to accept or not accept the enrolment packet. Since the server-end decides the second, it has more power than the client software...Just because a rogue operator or compromised enrolment software tries to register an unauthorised person does not mean that the server will accept the packet and generate Aadhaar," Srivastava said in response to an e-mail query.
Ajay Bhushan Pandey
has said.The comments of the Unique Identification Authority of India (UIDAI) chief came against the backdrop of a recent report alleging Aadhaar software hack.
Once the application for enrolment is received, validation or security checks are performed at the system's back-end too, Pandey said, adding that these safeguards allow rogue attempts to be detected.
"...all such attempts will get detected at the back-end and the enrolment packets then get rejected, and Aadhaar is not generated...we are also able to identify which operator has done this and, in such cases, the operator will be blacklisted...in appropriate cases we file prosecution under the Aadhaar Act," Pandey told PTI.
The report had also said that the patch allegedly enabled unauthorised people to generate Aadhaar, a claim that has been refuted by the UIDAI.
In a statement earlier this week, UIDAI claimed that no operator can make or update Aadhaar unless an individual gives biometrics details.
When contacted, Jaideep Srivastava, Professor of Computer Science at University of Minnesota said that the generation of an Aadhaar number is the result of a full 'two-way handshake' between the client software and the server software.
"The former collects and sends a packet, and the latter then decides to accept or not accept the enrolment packet. Since the server-end decides the second, it has more power than the client software...Just because a rogue operator or compromised enrolment software tries to register an unauthorised person does not mean that the server will accept the packet and generate Aadhaar," Srivastava said in response to an e-mail query.
Top Comment
Abraham Joseph
2256 days ago
This is to draw kind attention of UIDAI to s different aspect; when Aadhar was introduced, it was declared to be the final of citizens identity document. But despite submitting Aadhar to banks, why banks should conform with their kyc requirement every year as before?Recently, my bank (PNB) threatened me if kyc not submitted, account will be frozen!Read allPost comment
Popular from India
- 'Cloaked in concern for journalists': Mumbai Press Club hits back at Rahul Gandhi’s 'slave' remarks
- No relaxation of GRAP-4 without court's nod: Supreme Court slams Delhi government over anti-pollution curbs delay
- 3 girls of Karnataka engineering college drown in resort pool
- Violence escalates in Manipur: Meitei supporters lock govt offices, Amit Shah chairs meeting; internet ban extended – top developments
- Bangladeshi 'infiltrators' poll pitch leaves Jharkhand district on edge
end of article
Trending Stories
- Taylor Swift may have no desire to return to Higmark Stadium to support Travis Kelce after feeling the full wrath of Bills Mafia in January
- Why some families are returning adopted kids in Tamil Nadu
- Cassie’s post-assault chat with Diddy reveals disturbing details: 'You hit me in the head two good times'
- Ali Khamenei’s son Mojtaba set to take over as Iran's supreme leader: Report
- “It hurt my feelings”: Cam Newton said he was hurt seeing his former teammates being honored at the stadium expect him
- Billionaire Harsh Goenka 'seeks help' to understand this interview of Pakistan cricket team captain Mohammad Rizwan
- Maharashtra elections: Dry days in Mumbai and other cities as liquor shops to remain closed
Visual Stories
- 10 easy South Indian snacks for Friday evenings
- 7 genetic traits that babies get from their dad
- 10 good habits of parents that make kids disciplined
- 7 low-maintenance animals to keep as pets
- 10 Korean dishes that are getting popular in India
UP NEXT