DNH Sahar

One person. One record. One lifetime.

Foundational identity is the hardest thing a government builds, because it has to be right for everybody, work for forty years, and never quietly exclude anyone. DNH builds these systems end to end — enrolment, deduplication, issuance, authentication and the credentials people carry.

A fingerprint's ridge pattern with minutiae points marked, overlaid on an enrolment record
Six stages. Most vendors sell you two.
01Establish

Breeder documents, civil registration, and the exception path for people who have no paper at all. This stage decides who gets included, and it's the stage most programmes underinvest in.

02Enrol

Demographic capture, biometric capture with live quality scoring, consent capture, and an audit trail attached to the operator, the device and the site.

03Deduplicate

ABIS matching against the full gallery. Multi-modal fusion, threshold tuning against your population, and a human adjudication queue for the cases the algorithm shouldn't decide alone.

04Issue

Number allocation, credential personalisation, and physical or digital delivery with a chain of custody that survives an audit.

05Authenticate

Online and offline verification: 1:1 biometric match, PIN, OTP, QR, NFC, FIDO2, and API-based assertions for relying parties — with consent and purpose recorded on every call.

06Maintain

Updates, corrections, address changes, lost-and-stolen handling, re-issue, revocation, death registration and archival. This is where the system lives for decades, and where most designs are thin.

How the pieces fit.
Channels

How people and relying parties reach the system — fixed sites, outreach units and digital front doors.

In this layer

  • Enrolment kiosk
  • Mobile unit
  • Portal
  • App
Physical, digital, or both.
National ID card
ISO/IEC 7810, 14443
Polycarbonate or composite, contact/contactless chip
ePassport
ICAO Doc 9303
LDS, BAC/PACE/EAC, polycarbonate data page
eVisa / eResidency
ICAO 9303 alignment
Digital-first with printed fallback
Driving licence
ISO/IEC 18013, mDL
Including the mobile driving licence profile
Mobile credential
ISO/IEC 18013-5, W3C VC
Selective disclosure, offline verification
Civil certificates
Birth, death, marriage; verifiable and tamper-evident
Health / functional IDs
Derived credentials bound to the foundational identity

Physical production runs through Security Printing; capture and verification through Biometric Devices.

The system has to work for the person it's hardest for.

Manual labourers with worn fingerprints. Elderly people with cataracts. Amputees. Infants. Nomadic and pastoralist communities. Refugees with no breeder documents. People who cannot read the consent form they're being asked to sign.

If your identity system fails these groups, it hasn't hit an edge case — it has found the people it was built to exclude. We design the exception paths first and treat their failure rates as a primary KPI, reported alongside throughput.

What that means concretely

  • Multi-modal capture so a failure in one modality isn't a failure to enrol
  • Documented alternative-evidence and community-attestation routes
  • Mobile and outreach enrolment as core scope, not a pilot
  • Assisted and witnessed consent flows with a real audit trail
  • Exception-rate dashboards broken down by age, gender, region and occupation
  • Grievance and correction processes with published turnaround times
Designed to hold less, share less, and prove both.

Data minimisation

Capture only what the legal basis supports; no “collect it in case”.

Purpose binding

Every relying-party request declares a purpose and is enforced against it.

Template protection

Biometric templates encrypted at rest, separated from demographic data, revocable where the modality allows.

Consent as a record

A citizen-viewable log of who accessed what, when, and why.

Tamper-evident audit

Append-only logs the auditor can verify independently of DNH.

Alignment

UAE PDPL, GDPR, the AU Malabo Convention, and the national data-protection laws of the countries in scope.

The specifications our work is written against.

Documents

  • ICAO Doc 9303

Biometrics

  • ISO/IEC 19794
  • ISO/IEC 29794
  • ISO/IEC 30107-3

Cards

  • ISO/IEC 7816
  • ISO/IEC 14443
  • ISO/IEC 18013-5

Authentication

  • FIDO2 / WebAuthn
  • NIST SP 800-63

Interoperability

  • OpenID Connect
  • SAML
  • W3C VC / DID
  • OpenID4VP

Data protection

  • UAE PDPL
  • GDPR

Conformance matrices and reference architectures available under NDA.

Questions an architect asks.

Do you supply your own ABIS or integrate a third party's?

Both are supported. We'll benchmark candidate matchers against a sample of your own population before recommending one — vendor-published accuracy figures are measured on datasets that look nothing like your country.

How do you handle an algorithm reaching end of life?

By keeping raw biometric images alongside templates, so the gallery can be re-templated when you migrate. Systems that store only templates from one vendor are locked in permanently.

Can this integrate with our existing national ID?

Yes. Most of our identity work is modernisation or extension, not a system built from nothing.

Who holds the signing keys?

You do. Always. In your HSMs, in your jurisdiction.

How long does a national programme take?

Design 3–6 months, first production increment 6–12 months, national enrolment coverage typically 18–36 months depending on population size, geography and the number of enrolment points. The programme scenarios set out the phases in detail.

Bring us your hardest population.

The interesting conversation isn't about throughput at a city registration office. It's about the district where enrolment is failing and nobody's sure why.