--- layout: default title: "An Open Letter to the Finance Committee: SCOSTA Standards" description: "A CIS blog post presenting an open letter to the Parliamentary Standing Committee on Finance, comparing the SCOSTA smart card standard with the Aadhaar biometric standard for identity authentication." authors: ["Elonnai Hickok"] categories: [Elonnai Hickok] date: 2011-01-06 source: "Centre for Internet and Society" permalink: /elonnai/an-open-letter-to-the-finance-committee-scosta-standards/ created: 2026-08-05 --- **"An Open Letter to the Finance Committee: SCOSTA Standards"** is a blog post by [Elonnai Hickok](/elonnai/) published by the [Centre for Internet and Society](/cis/) on 6 January 2011. It details a civil society submission to the Parliamentary Standing Committee on Finance evaluating identity authentication mechanisms within the Unique Identification (UID) scheme. The piece presents a comparative technical analysis between the Smart Card Operating System for Transport Applications (SCOSTA) standard and the Aadhaar biometric standard, advocating for the adoption of decentralized smart card authentication to enhance security, protect domestic industry, and reduce single points of failure. ## Contents 1. [Article Details](#article-details) 2. [Full Text](#full-text) 3. [Context and Background](#context-and-background) 4. [External Link](#external-link) ## Article Details
đź“° Published by:
Centre for Internet and Society
đź“… Date:
6 January 2011
✍️ Author:
Elonnai Hickok
đź“„ Type:
Blog post
đź”— Original Link:
Read the original post
## Full Text

The UID Bill has been placed to the Finance Committee for review and approval. Through a series of open letters to the Finance Committee, civil society is asking the committee to take into consideration and change certain aspects of the Bill and the project. The below note compares the SCOSTA standard with the Aadhaar biometric standard, and explains why we believe the SCOSTA standard should replace the Aadhaar biometric standard for the authentication process in the UID scheme.


Introduction

This note is intended to demonstrate how the Aadhaar biometric standard is weaker than the SCOSTA standard. Through a comparison of the SCOSTA standard-based smart card and the Aadhaar biometric-based identification number, it will show how the SCOSTA standard is a more secure, structurally sound, and cost-effective approach to authentication of identity for India. Though we recognize that Aadhaar biometrics are useful for the de-duplication and identification of individuals, we believe that the SCOSTA standard is more appropriate for the authentication of individuals. Thus, we ask that the Aadhaar biometric-based authentication process be replaced with a SCOSTA standard-based authentication process.

A background of the two standards

The SCOSTA standard is used in smart cards and was developed by the National Informatics Centre in India. It is:

  1. Compliant with the international standard ISO-7816 for smart cards.
  2. Based on a public/private key and pin authentication factor
  3. Authentication factor refers to an individual's keys, pass-phrases, and pin.

The biometric standard authenticates the identity of an individual based on his or her physical fingerprints and iris scans (in the case of the UID). The standard:

  1. Verifies if the individual exists within a known population by comparing the biometric data to those of other individuals stored in a secured centralized database.
  2. Based on a symmetric authentication factor

A comparison of the two standards

Standard SCOSTA MNIC smart card Aadhaar Biometric - UID number
Architecture Decentralized
SCOSTA standards require a pair and key combination with a pin, and thus can be structured in a decentralized manner
Centralized
Aadhaar biometric standards require symmetric authentication factors, and thus must be structured in a centralized manner
Standards for Technology Open standard
Creates security through transparency
Closed standard
Creates security through obscurity
Points of failure Multiple points of failure
The SCOSTA standard has multiple points of failure, because of decentralized structure, thus if one database is compromised all data is not lost.
Single point of failure
The Aadhaar Biometric standard has one single point of failure, because of centralized structure, thus if the database is compromised all data is lost
Impact on local industry Encourages
Open standards allow local industry to compete in manufacturing technology
Discourages
Closed standards allow foreign players to monopolize the manufacturing of technology
Cost analysis Cost-effective
Increased competition keeps prices low
Cost-ineffective
Decreased competition keeps prices high
Revocation Revocable
If the key pair and pin are stolen, a new set of passwords can be issued
Permanent
If the biometrics of an individual are stolen, they cannot be re-issued
Possibility of fraudulent authentication Lower
A thief must steal your smart card and your secret pin to commit fraud
Higher
A thief only needs to collect your fingerprints using a glass tumbler to commit fraud
Viability of Technology Proven effective for large populations Not proven effective for large populations
{% include back-to-top.html %} ## Context and Background In early 2011, parliamentary scrutiny of the National Identification Authority of India Bill, 2010 provided a formal mechanism for technical and policy interventions by civil society groups. As the Parliamentary Standing Committee on Finance evaluated the proposed legislation, open letters were submitted to highlight architectural vulnerabilities in the Unique Identification Authority of India (UIDAI) design. A key aspect of this advocacy was differentiating between de-duplication—where biometrics ensure an individual is registered only once in a database—and routine authentication, which verifies an individual's identity during day-to-day transactions. The technical comparison centered on the Smart Card Operating System for Transport Applications (SCOSTA), an open standard developed domestically by the National Informatics Centre (NIC). SCOSTA utilizes public-key cryptography and personal identification numbers (PINs) embedded within microchip smart cards, allowing verification to occur offline or via decentralized networks. In contrast, the Aadhaar model relies on real-time, symmetric biometric matching against a central repository. Civil society experts argued that centralizing authentication requests creates systemic risks, including single points of failure, network dependency, and potential exposure of sensitive personal data during transmission. Security, economic, and operational considerations further supported the case for smart-card-based authentication. From a security standpoint, compromised cryptographic keys or PINs can be revoked and reissued, whereas compromised biometrics—such as latent fingerprints—are permanent physical traits that cannot be altered once replicated. Economically, open technical standards like SCOSTA foster competitive local manufacturing and vendor neutrality, avoiding dependence on proprietary foreign biometric technologies and specialized hardware. Ultimately, the open letter advocated for a hybrid identity architecture that limits biometric processing strictly to initial database de-duplication. By substituting centralized biometric queries with decentralized, user-controlled smart card authentication for routine transactions, the proposal aimed to strengthen systemic security, protect individual privacy, and establish a resilient framework for public service delivery across India. ## External Link - [An Open Letter to the Finance Committee: SCOSTA Standards](https://cis-india.org/internet-governance/blog/privacy/letter-to-finance-committee) {% include navbox-elonnai.html %}