Denis Pinkas

Proposal(s) title:
  • Age-restricted accesses to services while preserving the privacy of individuals
Proposal(s) topic:

Cybersecurity/Network and Information security

Impact on SMEs:

If successful, the impact will not be restricted to European SMEs and/or European societies. As my contributions are both for ISO and the IETF, the impact can be worldwide. However, I have not observed the presence of another European expert motivated by the topic of Age assurance systems that participates both in ISO JTC1 SC 27 and in the IETF.

Impact on society:

The societal impacts can be important. Age assurance which entails age verification, age estimation and age inference is applicable for a large variety of use cases. Protection of children is the most prominent use case.

Contribution impact:
  • New standard development
Proposal(s) title:
  • Privacy preserving age assurance systems for online or in-person access to services or goods
Impact on society:

Access to pornographic content and age-restricted services or products available online, like alcohol, diets, self-harm or suicide information, needs to be better controlled. Legislation is necessar,y but will not be sufficient: efficient methods need to be put in place. Two main categories of solutions are promising: age estimation using AI facial analysis and digital identity wallets. The AI Act published in the Official Journal (OJ) of the European Union on 12 July 2024 considers applications using AI for age estimation as “high-risk applications”. The EUDIW (EU Digital Identity Wallet) is expected to be usable for performing age verification in both online and proximity modes. Besides these usages, age verification, estimation, or inference will be useful in other areas, such as controlling the age of teenagers or elderly people, so that they can obtain rebates. This will speed up controls and avoid the presentation of physical identity documents.

Contribution impact:
  • New standard development
  • Update of existing work items
Proposal(s) title:
  • Online and local access to services or goods subject to age restrictions to comply with various laws
Proposal(s) topic:

Cybersecurity/Network and Information security

Societal, Economic or Technological Impacts:

Protecting children is of paramount importance. 

This applies particularly to access to social media, an area where countries wish to impose varying minimum age limits—such as 14, 15, or 16. There also the need to protect the children from predators that would not be in the same age range. Parental control can be used as a complement.

Minors must not be able to purchase alcohol online or enter establishments where alcohol is sold.

Teenagers have fully mastered the use of mobile devices and laptops. They will do everything they can to bypass control measures. If a technique for bypassing control measures is discovered, it will be rapidly shared within a vast community.

A major security vulnerability has been identified: the potential for collusion-based attacks between individuals, the classic example being the "Alice and Bob" collusion attack (ABC attack)". At the moment, this vulnerability is ignored by the SDOs.

Contribution impact:
  • New standard development
  • My activities are primarily related to documents developed ISO/IEC JTC 1/SC 27/WG 5.
    There are two main topics:
    a) The ISO/IEC 27566 series of standards about Information security, cybersecurity and privacy protection — Age assurance systems. I am co-editor of the ISO/IEC 27566 series that includes three parts.
    b) The ISO/IEC PWI 25863 "Exploration of security and privacy characteristics for digital identity wallets managing digital credentials". I am one of the six experts working on this PWI.

Value of Research

Age-restricted accesses to services while preserving the privacy of individuals France Cybersecurity
Pinkas
Full Name: Denis Pinkas
Title & Organisation Name: CEO, DP Security Consulting SAS
Country: France
Socials:
Standards Development Organisation: