ADVERTISEMENT
Get Started
  • About Homebase Tv | Hbtvghana.com
  • Advertise
  • Broadcast Live
  • Disclaimer
  • Privacy & Policy
  • Terms and Conditions
  • Vacancies
  • Contact Us – Connect With Us
Homebase Tv - Hbtvghana.com
  • Home
  • General News
  • Business News
  • Health
  • Life & Style
  • Politics
    • Press Release
    • Parliament
  • Sports
No Result
View All Result
  • Home
  • General News
  • Business News
  • Health
  • Life & Style
  • Politics
    • Press Release
    • Parliament
  • Sports
No Result
View All Result
Homebase Tv - Hbtvghana.com
No Result
View All Result
ADVERTISEMENT
ADVERTISEMENT

Desmond Israel: Clandestine SIM-linkage in Ghana

Wed, Apr 26 2023 9:25 PM
in Ghana General News
desmond israel clandestine sim linkage in ghana
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on TelegramShare on Whatsapp
ADVERTISEMENT

Background

For the past two weeks, I have followed some media stories concerning the linking of multiple phone numbers to national identity cards in Ghana (also known as the Ghana Card). 

The concerns are that unscrupulous persons are able to clandestinely link their SIM card, also known as a subscriber identity module, which is a smart card that stores identification information that pinpoints a smartphone to a specific mobile network to the Ghana Card of unsuspecting members of the public. This essentially creates concerns around identity theft and related identity-base risk when these phone numbers are engaged in any sort of malpractice and crime.

The risk outcome of the linking SIM-to-Ghanacard process can be traced to data integrity, data integrity is an integral component of the Data Protection Act of Ghana under the principles that cover data quality and data security, and it is further an obligation on data controllers to ensure that data quality principles are applied. 

As a matter of fact, from 1st October 2021 when the SIM re-registration exercise commenced in Ghana until after its extension sometime on 31st July 2022 and the subsequent new deadline on 30th September 2023, the Minister in charge made it emphatically clear that the exercise was meant to achieve integrity of the SIM Database for the service providers by using the national identity database to ensure unique SIM subscribers.

Therefore in the process, citizens are required to validate and verify their SIM cards against the national identity database through their various telecom service providers. The exercise received legislative backing through substantive national identity laws and sub-legislations covering the SIM re-registration. 

ReadAbout

John Mahama’s cost-cutting measures signal new era of fiscal discipline

John Mahama’s cost-cutting measures signal new era of fiscal discipline

End the Scholarship Waste & Invest in Skills That Build Nations

The Logic Flaw Issue

The policy position of the registration and verification process was that Subscribers who are Ghanaians would be able to register ten SIM cards to one Ghanacard (e.i. 1:10 SIM to Ghanacard link ratio), the process also made provision for three SIM cards to one Ghanacard for foreigners (e.i. 1:3 SIM to Ghanacard link ratio). In summary, one can have ten SIM cards registered to their Ghanacard number. 

With the benefit of hindsight and repeating the process of registration via a *404# USSD services, the clandestine multiple linkages are leveraging on what I will term a process gap vulnerability (PGV), which can be categorized as a logic flaw in the process design. The PGV as earlier stated, does exist in the USSD registration, it has not been determined at the writing of the article if this is repeatable in the web/mobile application too.

The vulnerability manifests because when a user attempts to register (or link) a SIM to a Ghanacard; the system allows entry of the Ghanacard details intended to be linked with the SIM, and in the process, a one-time password (OTP) is sent for verification, now instead of using a primary contact verification (PCV), which normally should be the first ever SIM registered to the Ghanacard in question, the system by design delivers the verification to the new number attempting the linkage, the OTP is then potentially delivered to the attacker or the unscrupulous person doing the clandestine SIM-linkage. Indeed, needless to say, the Ghana Card details are taken by the system based on a user-trust-process rather than a system-independent validation of the source, I hazard a guess that this was for operational efficacy and, therefore, it would have been essential to resolve the PGV flaw by allowing the OTP to delivered to the PCV, and therefore give the original Ghanacard holder the verification leverage, and in the absence of that opening up for the ongoing clandestine registration.

Best Practice

Let me attempt to pass on an opinion on best practices. The ideal situation is that such a system should have three levels of data integrity check both at the process and data storage. Without being unnecessarily verbose, we can start firstly with “identity compliance”, this level is designed to meet regulatory standards and pass pre-set quality (Examples include ensuring required data points are captured. Fingerprints, biodata, images, ID details, etc) 

The second level proposed is “data uniqueness”, at this level of integrity check, the system has to focus on the uniqueness of subscribers using digital and biometric record verification processes (it was indicated that this process is currently infused in the current system),  still on this level the system should also be able to check for blacklisted subscribers for the purposes of crime, national security or reported malfeasance based on service level agreement violations. Still, under the data uniqueness level, it is expected that the de-duplication engine should be implemented to flag duplicated registration where necessary and also the new capture feature validation which assesses the validity of new registrations by using a PCV; for example, delivery of the OTP to PCV. 

The third and final best practice for data integrity is proposed as “registration audit” (normally found with platforms like the one under discussion), SIM Registration tracking activities (including location point, date/timestamps, user details, and registration information); this process must cover self-service registration, agent-support registration, and authorized-personnel registration to ensure that the entire supply chain in the process of registration can be tracked even in the event of clandestine SIM registrations.

Desmond Israel: Clandestine SIM-linkage in Ghana
Graphical representation of the best practices discussed

Conclusion

The writer notes that there are different components of the registration systems, which may have independent functions and access-level requirements may vary depending on internal policies, business needs, and statutory obligations among others. It will be ideal for the national identity database to have some level of “true” integration with the SIM registration database; it may vary from real-time, delayed, or on-demand integrations to ensure that the national identity database at all material times necessary will have a recent version of the SIM registration records to ensure the ongoing data integrity touted as the crux of the SIM re-registration exercise a consistent reality.

In a nutshell, the SIM re-registration is an exercise worth the country’s investment and efforts, it is important to pay attention to the data integrity issues which undoubtedly even if we are pretentious about its existence may cause the true value of this investment.

*****

Desmond Israel (GW Law Merit Scholar | Lawyer & Data Privacy/Information Security Practitioner | Founder, Information Security Architects Ltd | Research Lead, Child Safety Framework for the Metaverse, XRSI -California | Affiliate, Child Online Africa)

DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policies of Homebase Television Ltd.

  • President Commissions 36.5 Million Dollars Hospital In The Tain District
  • You Will Not Go Free For Killing An Hard Working MP – Akufo-Addo To MP’s Killer
  • I Will Lead You To Victory – Ato Forson Assures NDC Supporters

Visit Our Social Media for More

About Author

c16271dd987343c7ec4ccd40968758b74d64e6d6c084807e9eb8de11a77c1a1d?s=150&d=mm&r=g

hbtvghana

See author's posts

Discover interesting ones too

Bawku conflict: Your support to Otumfuo is commendable – Prez Mahama to Naa Yiri

Bawku conflict: Your support to Otumfuo is commendable – Prez Mahama to Naa Yiri

0
Team Technocrafts Innowear of Services Primary & JHS champions of 2025 GSTEP challenge

Team Technocrafts Innowear of Services Primary & JHS champions of 2025 GSTEP challenge

0

Policy rate cut could fuel inflation – UG Economist warns

Cedi to end 2025 against dollar at GH¢11.45 on interbank market – IC Research

Drum of Bawku, A Poem for Peace

Photos: Mahama receives delegation from the Overlord of Mamprugu Kingdom at Jubilee House

Make choices that represent Ghanaians – Ken Agyapong tells party delegates

Government Communications Minister urges PR officers to embody efficiency and professionalism

Government Communications Minister urges PR officers to embody efficiency and professionalism

John Mahama’s cost-cutting measures signal new era of fiscal discipline

  • Dr. Musah Abdulai: If the Chief Justice returns: Will it lead to reset, redemption, or rupture?

    Dr. Musah Abdulai: If the Chief Justice returns: Will it lead to reset, redemption, or rupture?

    0 shares
    Share 0 Tweet 0
  • OSP declares former Finance Ministry Advisor wanted over SML corruption probe

    0 shares
    Share 0 Tweet 0
  • Ghana and Japan agree to pursue UN Security Council reforms

    0 shares
    Share 0 Tweet 0
  • Ken Ofori-Atta’s extradition: FBI clears first major hurdle – No witch-hunt

    0 shares
    Share 0 Tweet 0
  • I resigned because of Prez. Mahama, NDC – former GBA President

    0 shares
    Share 0 Tweet 0
ADVERTISEMENT
ADVERTISEMENT

Follow Homebase Tv

  • About Homebase Tv | Hbtvghana.com
  • Advertise
  • Broadcast Live
  • Disclaimer
  • Privacy & Policy
  • Terms and Conditions
  • Vacancies
  • Contact Us – Connect With Us

© 2014 Total Enjoyment & Proper News

No Result
View All Result

© 2014 Total Enjoyment & Proper News

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.