Facial Authentication Set for Oct. 1 Introduction Faces Challenge Over Foreigners' Mobile Lines
IT DAILY ·

✦ AI Summary
The facial authentication system will be introduced on Oct. 1 to strengthen the blocking of fraudulent mobile phone activations.
However, there are calls for separate identity verification and management systems for mobile lines registered under foreigners' names and prepaid SIM cards.
The Ministry of Science and ICT is preparing separate management measures for mobile lines registered under foreigners' names, while the industry is proposing staged verification based on risk level.
The facial authentication system set to be introduced on Oct. 1 is a measure to block fraudulent mobile phone activations. Ahead of the full rollout of facial authentication, the goal is to strengthen verification procedures at the mobile phone activation stage.
However, even if facial authentication is implemented, experts say a separate identity verification process will be needed for mobile lines registered under foreigners' names. That is because cases of mobile phones opened under stolen identities and used for voice phishing and other crimes continue to occur. "Daepo phone" refers to a mobile phone activated using another person's ID card or borrowed name, and to a line whose registered subscriber with the carrier does not match the actual user.
Cases have also been confirmed in which mobile lines registered under foreigners' names and prepaid SIM cards were used in the distribution of daepo phones. Recently, a distribution ring that illegally collected foreigners' passport information, then mass-opened prepaid SIM cards and handed them over to voice phishing organizations, was uncovered. The group is suspected of illegally activating 11,353 prepaid SIM cards from budget mobile carriers by unlawfully collecting copies of foreigners' passports from Feb. 2023 to May this year.
The Ministry of Science and ICT announced that 20,000 daepo phones were detected last year. Accordingly, there is also a growing need to strengthen the activation and management system for mobile lines registered under foreigners' names alongside the introduction of facial authentication.
One of the main domestic cases among the channels through which daepo phones and fraudulent activations occur is the use of "naegujjae loans." The domestic method involves opening a mobile phone line in one's own name and then handing it over to a broker. Naegujjae loans are illegal private financing schemes in which a person opens a mobile phone line or leases an item under their own name, hands it over to a broker, and receives cash.
As for methods involving foreigners, authorities cite schemes in which a copy of a passport and personal information are illegally secured before a SIM card is activated and distributed. As fraudulent activations through identity theft continued, the government moved to introduce a facial authentication system to prevent them. The Ministry of Science and ICT has been pursuing the introduction of the facial authentication system since Dec. 23 last year.
Under the facial authentication method, the face photo on the ID presented during mobile phone activation is compared in real time with the actual face of the person holding it. The facial authentication system is provided through the PASS app operated by Korea's three mobile carriers. It applies to face-to-face and non-face-to-face activation channels used by the three carriers and budget mobile operators, and its core purpose is to verify whether the ID holder and the actual applicant are the same person. Accordingly, it is expected to help block fraudulent activations through identity theft.
Users who experience an error in facial authentication or refuse to undergo it must present a resident registration certificate issued on the same day or the Ministry of the Interior and Safety's mobile ID app.
However, the industry points out that facial authentication is applied uniformly to domestic users, so an additional verification system that reflects the characteristics of mobile lines registered under foreigners' names is needed. It also says facial authentication alone has limits in blocking the illicit circulation of passport information and in preventing prepaid SIM cards opened in foreigners' names from being transferred to criminal organizations.
In response, the Ministry of Science and ICT is preparing separate management measures for mobile lines registered under foreigners' names and plans to push ahead with cooperation between the ministry and the Ministry of Justice within the second half of this year. It also plans to sequentially upgrade the system for verifying the authenticity of foreigners' IDs and tighten line activation requirements. In addition, it will apply the one person, one line principle, allow additional activations when there is a separate explanation, and operate activation standards strictly.
Some in the industry say verification levels should be differentiated according to user risk rather than uniformly strengthening authentication for foreigners. The point is that the same level of authentication should not be applied simply on the basis of whether someone is a foreigner; instead, the risk level of each user should first be assessed and the strength of verification adjusted accordingly.
Along with this view, there were calls to apply the financial sector's "risk-based approach (RBA)" to mobile phone activation procedures as well. RBA is a methodology that assesses a customer's risk level and then applies verification procedures suited to that risk.
Kim Seong-su, head of the solution business division at Alchera, said it is necessary to divide risk levels into low, medium, and high when activating mobile phones and differentiate verification procedures by stage. He also said that imposing the same verification on everyone would create unnecessary procedural burdens even for groups whose identity is clear and risk is low.
As a concrete example, he suggested requiring high-risk users to submit additional documents such as proof of residence, tax payment receipts, or certificates of residence in addition to an ID card. By contrast, he cited the option of applying relatively simple verification procedures to low-risk users.
Although facial authentication will be fully implemented on Oct. 1, tasks remain beyond technical identity verification methods. In particular, the design of a separate verification system for mobile lines registered under foreigners' names has been raised as an issue, and the scope of that system covers the entire process of activation, distribution, and management.
Kim said it is necessary to take the characteristics of voice phishing and daepo phones into account. He said stronger verification should be applied to high-risk users during the activation process, simple verification should be applied to low-risk users, and policy standards should be established in stages according to risk level. He also said policy discussions are needed on the required level of identity verification by category of user.
Source: IT DAILY · Seong Won-young
Original: https://www.itdaily.kr/news/articleView.html?idxno=241879
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.