An impact and risk assessment framework for national electronic identity (eID) systems

Edu, J. and Hooper, M. and Maple, C. and Crowcroft, J.; (2023) An impact and risk assessment framework for national electronic identity (eID) systems. In: International Conference on AI and the Digital Economy (CADE 2023). IET, ITA, pp. 124-133. ISBN 9781839539596 (https://doi.org/10.1049/icp.2023.2596)

[thumbnail of Edu-etal-CADE2023-An-impact-and-risk-assessment-framework-for-national-electronic-identity-eID-systems]
Preview
Text. Filename: Edu-etal-CADE2023-An-impact-and-risk-assessment-framework-for-national-electronic-identity-eID-systems.pdf
Accepted Author Manuscript
License: Strathprints license 1.0

Download (859kB)| Preview

Abstract

Electronic identification (eID) systems allow citizens to assert and authenticate their identities for various purposes, such as accessing government services or conducting financial transactions. These systems improve user access to rights, services, and the formal economy. As eID systems become an essential facet of national development, any failure, compromise, or misuse can be costly and damaging to the government, users, and society. Therefore, an effective risk assessment is vital for identifying emerging risks to the system and assessing their impact. However, developing a comprehensive risk assessment for these systems must extend far beyond focusing on technical security and privacy impacts and must be conducted with a contextual understanding of stakeholders and the communities these systems serve. In this study, we posit that current risk assessments do not address risk factors for all key stakeholders and explore how potential compromise could impact them each in turn. In the examination of the broader impact of risks and the potentially significant consequences for stakeholders, we propose a framework that considers a wide range of factors, including the social, economic, and political contexts in which these systems were implemented. This provides a holistic platform for a better assessment of risk to the eID system.