Provision Of Pki Secured Services Around The National Entification Register (NIR) tendering job at National Identification and Registration Authority
PROVISION OF PKI SECURED SERVICES AROUND THE NATIONAL ENTIFICATION REGISTER (NIR)
1. Introduction
The National Identification and Registration Authority (NIRA) was established by the Registration of Persons Act (ROPA) 2015 to among other functions provide for the registration of Persons; to establish a National Identification Register, and to provide for the issuance of National/Alien Identification Numbers and National/ Allen Identification Cards.
NIRA established the National Identification Register (NIR) and a number of platforms to provide for access and use of the information contained in the NIR. Among the key functions of NIRA under this proposal are;
a) Create, manage, maintain and operate the NIR;
b) To verify and authenticate information relating to the registration and identification of persons;

c) To ensure the preservation, protection and security of any information or data collected, obtained, maintained or stored in the register;

2. Required Partner Services under this arrangement
In a bid to ensure efficiency and reliable delivery of services while verifying and/or authenticating information in the NIR, NIRA seeks to onboard competent, vetted, and registered providers with internationally certified technologies and experience in the operations of the Public Key Infrastructure as a Service (PKlaas) to facilitate the provision of third- party services around the NIR in a mode that is secure, accurate, reliable and ensures non-repudiation. The third- party services shall be provided at no cost to NIRA. The key services shall for the start include;
1) E-consent for eKYC- To provide a platform where citizens with information in the NIR can provide electronic consent to EKYC to third parties through data subjects matching fingerprint information in a secure and credible manner that relies on PKI infrastructure.
2) Verification services at Point of Service (POS) - To verify authenticity of digitally signed documents e.g. confirmation of information letter generated through the NIRA portal.

The provider shall be requested to submit a proposal that delineates;
a) Process Workflows
b) PKI infrastructure setup and system components c) Any other important information that enables the service to operate
The service shall maintain the confidentiality and integrity of the information verified or authenticated. The service provider's platform shall use PKI infrastructure for encryption of information in transit and at rest as well as signing for authentication.

1.1. Authentication services (e-consent)
The third-party service in this category shall facilitate the process ofe-Consentfrom data subjects where third parties seek information contained in the NIR. The solution shall ensure that e-consent is provided in asecure, verifiable, repeatable, idempotent, cannot be denied and is in the form required by ROPA 2015.

1.2. Verification services at Point of Service (POS)
Verification services are to provide third parties confidence of authenticity of information supplied. The desired outcome is providing secure, non repudiable, tamper proof means of ascertaining genuine documents printed off NIRA website and instantly identifying forged documents.
Please note that this is not a procurement and these services shall be at no service to NIRA

3. Main solution features/components
1.1. PKI Infrastructure
The envisaged solution shall incorporate a PKI module with the following key components,
a) Dedicated offline Named root CA (named after service provider)
b) Root CA Authority Information Access Point

c) Root CA CRL and OCSP Responder
d) Named Issuing CA with CDP and OCSP (named after service provider)
e) A Certificate Lifecycle management portal
f) Verifying KYC of certificate holders with national trust centres i.e. NIRA, URSB
g) Mobile application that verifies issued certificate signed data

For avoidance of doubt, the authority wishes to emphasize that this service is at no cost to NIRA. Furthermore, onboarded partners will be required to sign Memoranda of Understanding (MOUS) and will undergo security vetting. Their infrastructure may be subjected to rigorous security tests.
Contact the Director ICT for more Details at info@nira.go.ug
Job Info
Job Category: Tenders in Uganda
Job Type: Full-time
Deadline of this Job: 27 February 2024
Duty Station: Kampala
Posted: 13-02-2024
No of Jobs: 1
Start Publishing: 13-02-2024
Stop Publishing (Put date of 2030): 13-02-2068
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.