NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Registration
Slice by Program

Encrypt biometric data, urges Ontario privacy czar

By: Lisa Williams, senior writer, InterGovWorld(03-20-2007)

Biometrics and encryption aren't exactly new. For most of us, neither is wildly exciting either. But the prospect of combining these two security pieces has sparked a call to action by Ontario's privacy commissioner.

Ann Cavoukian has released the findings of a study on biometric encryption in a white paper she co-authored with Toronto-based biometrics scientist Alex Stoianov, entitled "Biometric Encryption: A Positive Sum Technology that Achieves Strong Authentication, Security and Privacy."

Cavoukian believes the full potential of biometric encryption - meaning both the encryption of biometric data and using biometric keys to decrypt data - can significantly reduce the risk of a breach of privacy, offering greater protection and control of sensitive data.

Biometric data typically contain sensitive personal information that must adhere to strict protection policies and security measures, asserts Cavoukian.

If a government collects biometric information on an individual, it will retain that sample data in a database, she explains.

Governments usually collect this kind of information for a good purpose (national security, for example), and the individual subsequently has no control over it. The possibility then arises for government to use this data in other areas, such as surveillance or profiling, says Cavoukian.

"This is the 'Big Brother' picture that privacy advocates fear when you talk about biometrics," she says. "The reason the fear is so strong is because it (biometrics) is the ultimate unique identifier."

As for using encryption alone, the same privacy concerns remain from within the government, law enforcement and intelligence communities, says Cavoukian, because "they are the ones encrypting the data, they possess the keys to decrypt the data."

She adds: "Simply applying encryption to biometrics is not the ultimate solution in terms of a privacy-enhancing solution."

What's unique about biometric encryption is that the keys to that information are under the control of the individual, notes the commissioner.

A fingerprint is coded using an individual's actual finger, and that biometrically encrypted template is then stored in a database. If it needs to be decrypted, the only one who can do this is the individual whose finger will be run across the fingerprint scanner, she explains.

"We're not saying no to using biometrics, but realistically that's not going to fly anymore," says Cavoukian. "Since 9-11 there has been such widespread growth and adoption in the areas of biometrics that we know it's futile to say don't do it - it's happening."

She notes that in Deloitte and Touche's technology predictions for 2007, biometrics was identified as one of the largest growth areas.

"A lot of the biometric technologies have been around for quite a while, the most common being the fingerprint technology and the iris scan," says John Ruffolo of Deloite and Touche Canada.

"The difference now is that the biometric technologies have gotten a lot more reliable, in particular for the iris scan where they can now actually detect differences between identical twins," adds Ruffolo. "And the cost of the technologies has really dropped over the past number of years."

He notes that the biggest buyers of biometrics have been within government (airports) and what Ruffolo deems the more "security sensitive" industries.

But there hasn't been a lot of political uptake to adapting biometric encryption technology, says Cavoukian. "Governments and law enforcement communities don't want privacy-protected solutions to biometrics or anything else. It's in their interests to have identifiable versions of biometrics."

Cavoukian says privacy officials want uses and applications of biometrics that enhance privacy. "Biometric encryption gives you both the privacy and security benefits. It advances the view of privacy that you build privacy into the technology to really have true privacy protection."

She says that with the release of the whitepaper, her office is hoping to attract technology companies and businesses to look at biometric encryption, and develop market applications. "You need the technological savvy and the political will to make this happen."

Related content:

Airports give thumbs-up to ID system

A whole new (biometrics) world

Flawed biometrics offers false sense of security

Biometrics battle fraud down under

US-Canadian group suspends certification for open-source app

Digital fingerprinting system set to launch Canada-wide

Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Stalled PCI DSS compliance efforts put Canadian organizations in limbo: Hereb�s how to get back on track
You might have long ago abandoned your efforts to achieve full PCI DSS compliance, but herebs a report that offers some helpful ideas to get back on track again. It highlights the five bsticking pointsb that typically hinders PCI DSS compliance progress and suggests how to get unglued from the mess.
Advertisement
2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada