Justice K.S.Puttaswamy(Retd) vs Union Of India on 26 September, 2018
(a) PKI-2048 encryption from the time of capture, (b) adoption of best-in-class security standards
and practices, and (c) strong audit and traceability as well as fraud detection.
50) It was explained that the security and data privacy is ensured in the following way:
(i) The data sent to ABIS is completely anonymised. The ABIS systems do not have access to
residents demographic information as they are only sent biometric information of a resident with a
reference number and asked to de-duplicate. The de-duplication result with the reference number is
mapped back to the correct enrolment number by the Authorities own enrolment server.
(ii) The ABIS providers only provide their software and services. The data is stored in UIDAI storage
and it never leaves the secure premises.
(iii) The ABIS providers do not store the biometric images (source). They only store template for the
purpose of de- duplication (with reference number).
(iv) The encrypted enrolment packet sent by the enrolment client software to the CIDR is decrypted
by the enrolment server but the decrypted packet is never stored.
(v) The original biometric images of fingerprints, iris and face are archived and stored offline.
Hence, they cannot be accessed through an online network.
(vi) The biometric system provides high accuracy of over 99.86%. The mixed biometric have been
adopted only t enhance the accuracy and to reduce the errors which may arise on account of some
residents either not having biometrics or not having some particular biometric.
51) Above all, there is an oversight by Technology and Architecture Review Board (TARB) and
Security Review Committee. This Board and Committee consists of very high profiled officers. The
aforesaid security measures are shown by the Authority in the following manner:
52) We may point out at this stage that to the powerpoint presentation by Dr. Pandey on the
aforesaid lines, certain questions were put to him by Mr. Shyam Divan as well as Mr. Vishwanathan,
senior advocates, and the answers thereto were given by Dr. Pandey. In order to have the complete
picture, we will be well advised to reproduce these questions and their answers as well, which are as
follows:
53) Questions and Answers to the queries raised by the petitioners in W.P. (C) No. 1056 of 2017
entitled Nachiket Udupa & Anr. v. Union of India (1) What are the figures for authentication
failures, both at the national and state level? Please provide a breakup, between fingerprints and
iris.
Ans.: UIDAI cannot provide authentication failure rates at the state level since it does not track the
location of the authentication transactions. Authentication failure rate at national level is as below:
Indian Kanoon - http://indiankanoon.org/doc/127517806/
31