News

Latest stories from POSTECH EE.

[Leaders Forum] What the Personal Information Protection Bill Needs to Address

Articles | 2010-01-14

Related article: Electronic Times. By Pil Joong Lee, Professor of Electrical Engineering.

Worldwide interest and recurring security incidents prompted personal information protection bills last year, and they are expected to pass the National Assembly soon. Yet the bills proposed by the Ministry of Public Administration and Security, the Grand National Party and the Democratic Party all overlook certain points.

Article 2(1) of the ministry's bill defines personal information as information about a living person that identifies that individual, including information that can readily be combined with other information to identify them. I agree with this. But nowhere does the bill distinguish personal information used as an identifier from that used as an authenticator.

Identification distinguishes someone from others; authentication verifies the claimed identity. In computer login, the ID is an identifier and the password an authenticator. Both are personal information but clearly differ. An identifier must distinguish people and may be publicly known, like a name. An authenticator must be unique and consist of something only that person knows or possesses, or a physical characteristic unique to them. Information or possessions shared with others, and indistinguishable physical features, cannot serve this purpose.

First, information usable for authentication should be classified as sensitive and given special protection. Article 22 defines sensitive information to include beliefs, trade-union or political-party membership and withdrawal, political views, health, sex life and other information likely to seriously infringe privacy. Sensitivity varies by person, but everyone would agree that authentication information is even more sensitive.

Second, the bill should expressly prohibit using resident registration numbers as online authenticators. Article 23, restricting processing of unique identifiers, treats resident registration numbers as sensitive and emphasizes safeguards. Yet their intrinsic sensitivity is much lower than the information in Article 22. The real problem with mass leaks is not the sensitive information encoded in those numbers; it is their use for online authentication.

Third, the law and subsequent guidelines should address separate storage of sensitive information. More attention should be paid to permanent unique identifiers—unavoidably possessed from birth and unchanged until death—than to identifiers assigned under law. Biometric information such as DNA and fingerprints is an example. Its potential use for authentication makes it especially important.

Finally, the more unique and permanent personal information is, the greater the harm caused by exposure. Such information deserves stricter protection, and these factors should be considered when enacting the bill.

Pil Joong Lee, POSTECH Professor and Honorary President of the Korea Institute of Information Security and Cryptology.

Original source link

ee2_10_17_12634344885780.jpg
Back to list