Towards a more secure and scalable verifying PKI of eMRTD.

Saved in:
Bibliographic Details
Title: Towards a more secure and scalable verifying PKI of eMRTD.
Authors: Buchmann, Nicolas1, Baier, Harald1
Source: Journal of Computer Security. 2014, Vol. 22 Issue 6, p1025-1049. 25p.
Subjects: Public key cryptography, Computer security research, Internet protocols, Biometric identification, Passports
Abstract: The new electronic passport stores biometric data on a contactless readable chip to uniquely link the travel document to its holder. This sensitive data is protected by a complex protocol called Extended Access Control (EAC) against unlawful readouts. EAC is manifold and thus needs a complex public key infrastructure (PKI). Additionally EAC is known to suffer from unsolved weaknesses, e.g., stolen (mobile) passport inspection systems due to its missing revocation mechanism. The article at hand seeks for potential approaches to solve these shortcomings. As a result we present an evaluation framework with special focus on security and scalability to assess the different candidates and to give a best recommendation. Instead of creating new protocols, we focus on solutions, which are based on well-known protocols from the Internet domain like the Network Time Protocol (NTP), the Online Certificate Status Protocol (OCSP), and the Server-based Certificate Validation Protocol (SCVP). These protocols are openly standardised, thoroughly tested, interoperable, and with the exception of SCVP all widely deployed. In addition to these Internet protocols we evaluate state-of-the-art security protocols proposed by the scientific community, e.g., the Hoepman protocol, the BioPACE V2 protocol and the On-line Secure E-Passport Protocol (OSEP). Our recommendation is that the EU EAC PKI would benefit most from introducing NTP and OCSP, or if fine-grained access control of EAC are considered dispensable by introducing the BioPACE V2 protocol. [ABSTRACT FROM AUTHOR]
Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Links:
  – Type: pdflink
Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 99988670
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Towards a more secure and scalable verifying PKI of eMRTD.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Buchmann%2C+Nicolas%22">Buchmann, Nicolas</searchLink><relatesTo>1</relatesTo><br /><searchLink fieldCode="AR" term="%22Baier%2C+Harald%22">Baier, Harald</searchLink><relatesTo>1</relatesTo>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Journal+of+Computer+Security%22">Journal of Computer Security</searchLink>. 2014, Vol. 22 Issue 6, p1025-1049. 25p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Public+key+cryptography%22">Public key cryptography</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security+research%22">Computer security research</searchLink><br /><searchLink fieldCode="DE" term="%22Internet+protocols%22">Internet protocols</searchLink><br /><searchLink fieldCode="DE" term="%22Biometric+identification%22">Biometric identification</searchLink><br /><searchLink fieldCode="DE" term="%22Passports%22">Passports</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: The new electronic passport stores biometric data on a contactless readable chip to uniquely link the travel document to its holder. This sensitive data is protected by a complex protocol called Extended Access Control (EAC) against unlawful readouts. EAC is manifold and thus needs a complex public key infrastructure (PKI). Additionally EAC is known to suffer from unsolved weaknesses, e.g., stolen (mobile) passport inspection systems due to its missing revocation mechanism. The article at hand seeks for potential approaches to solve these shortcomings. As a result we present an evaluation framework with special focus on security and scalability to assess the different candidates and to give a best recommendation. Instead of creating new protocols, we focus on solutions, which are based on well-known protocols from the Internet domain like the Network Time Protocol (NTP), the Online Certificate Status Protocol (OCSP), and the Server-based Certificate Validation Protocol (SCVP). These protocols are openly standardised, thoroughly tested, interoperable, and with the exception of SCVP all widely deployed. In addition to these Internet protocols we evaluate state-of-the-art security protocols proposed by the scientific community, e.g., the Hoepman protocol, the BioPACE V2 protocol and the On-line Secure E-Passport Protocol (OSEP). Our recommendation is that the EU EAC PKI would benefit most from introducing NTP and OCSP, or if fine-grained access control of EAC are considered dispensable by introducing the BioPACE V2 protocol. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=99988670
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.3233/JCS-140522
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 25
        StartPage: 1025
    Subjects:
      – SubjectFull: Public key cryptography
        Type: general
      – SubjectFull: Computer security research
        Type: general
      – SubjectFull: Internet protocols
        Type: general
      – SubjectFull: Biometric identification
        Type: general
      – SubjectFull: Passports
        Type: general
    Titles:
      – TitleFull: Towards a more secure and scalable verifying PKI of eMRTD.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Buchmann, Nicolas
      – PersonEntity:
          Name:
            NameFull: Baier, Harald
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 12
              Text: 2014
              Type: published
              Y: 2014
          Identifiers:
            – Type: issn-print
              Value: 0926227X
          Numbering:
            – Type: volume
              Value: 22
            – Type: issue
              Value: 6
          Titles:
            – TitleFull: Journal of Computer Security
              Type: main
ResultId 1