Towards a more secure and scalable verifying PKI of eMRTD.
Saved in:
| Title: | Towards a more secure and scalable verifying PKI of eMRTD. |
|---|---|
| Authors: | Buchmann, Nicolas1, Baier, Harald1 |
| Source: | Journal of Computer Security. 2014, Vol. 22 Issue 6, p1025-1049. 25p. |
| Subjects: | Public key cryptography, Computer security research, Internet protocols, Biometric identification, Passports |
| Abstract: | The new electronic passport stores biometric data on a contactless readable chip to uniquely link the travel document to its holder. This sensitive data is protected by a complex protocol called Extended Access Control (EAC) against unlawful readouts. EAC is manifold and thus needs a complex public key infrastructure (PKI). Additionally EAC is known to suffer from unsolved weaknesses, e.g., stolen (mobile) passport inspection systems due to its missing revocation mechanism. The article at hand seeks for potential approaches to solve these shortcomings. As a result we present an evaluation framework with special focus on security and scalability to assess the different candidates and to give a best recommendation. Instead of creating new protocols, we focus on solutions, which are based on well-known protocols from the Internet domain like the Network Time Protocol (NTP), the Online Certificate Status Protocol (OCSP), and the Server-based Certificate Validation Protocol (SCVP). These protocols are openly standardised, thoroughly tested, interoperable, and with the exception of SCVP all widely deployed. In addition to these Internet protocols we evaluate state-of-the-art security protocols proposed by the scientific community, e.g., the Hoepman protocol, the BioPACE V2 protocol and the On-line Secure E-Passport Protocol (OSEP). Our recommendation is that the EU EAC PKI would benefit most from introducing NTP and OCSP, or if fine-grained access control of EAC are considered dispensable by introducing the BioPACE V2 protocol. [ABSTRACT FROM AUTHOR] |
| Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Database: | Engineering Source |
| FullText | Links: – Type: pdflink Text: Availability: 0 |
|---|---|
| Header | DbId: egs DbLabel: Engineering Source An: 99988670 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 0 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: Towards a more secure and scalable verifying PKI of eMRTD. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Buchmann%2C+Nicolas%22">Buchmann, Nicolas</searchLink><relatesTo>1</relatesTo><br /><searchLink fieldCode="AR" term="%22Baier%2C+Harald%22">Baier, Harald</searchLink><relatesTo>1</relatesTo> – Name: TitleSource Label: Source Group: Src Data: <searchLink fieldCode="JN" term="%22Journal+of+Computer+Security%22">Journal of Computer Security</searchLink>. 2014, Vol. 22 Issue 6, p1025-1049. 25p. – Name: Subject Label: Subjects Group: Su Data: <searchLink fieldCode="DE" term="%22Public+key+cryptography%22">Public key cryptography</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security+research%22">Computer security research</searchLink><br /><searchLink fieldCode="DE" term="%22Internet+protocols%22">Internet protocols</searchLink><br /><searchLink fieldCode="DE" term="%22Biometric+identification%22">Biometric identification</searchLink><br /><searchLink fieldCode="DE" term="%22Passports%22">Passports</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: The new electronic passport stores biometric data on a contactless readable chip to uniquely link the travel document to its holder. This sensitive data is protected by a complex protocol called Extended Access Control (EAC) against unlawful readouts. EAC is manifold and thus needs a complex public key infrastructure (PKI). Additionally EAC is known to suffer from unsolved weaknesses, e.g., stolen (mobile) passport inspection systems due to its missing revocation mechanism. The article at hand seeks for potential approaches to solve these shortcomings. As a result we present an evaluation framework with special focus on security and scalability to assess the different candidates and to give a best recommendation. Instead of creating new protocols, we focus on solutions, which are based on well-known protocols from the Internet domain like the Network Time Protocol (NTP), the Online Certificate Status Protocol (OCSP), and the Server-based Certificate Validation Protocol (SCVP). These protocols are openly standardised, thoroughly tested, interoperable, and with the exception of SCVP all widely deployed. In addition to these Internet protocols we evaluate state-of-the-art security protocols proposed by the scientific community, e.g., the Hoepman protocol, the BioPACE V2 protocol and the On-line Secure E-Passport Protocol (OSEP). Our recommendation is that the EU EAC PKI would benefit most from introducing NTP and OCSP, or if fine-grained access control of EAC are considered dispensable by introducing the BioPACE V2 protocol. [ABSTRACT FROM AUTHOR] – Name: AbstractSuppliedCopyright Label: Group: Ab Data: <i>Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=99988670 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.3233/JCS-140522 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 25 StartPage: 1025 Subjects: – SubjectFull: Public key cryptography Type: general – SubjectFull: Computer security research Type: general – SubjectFull: Internet protocols Type: general – SubjectFull: Biometric identification Type: general – SubjectFull: Passports Type: general Titles: – TitleFull: Towards a more secure and scalable verifying PKI of eMRTD. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Buchmann, Nicolas – PersonEntity: Name: NameFull: Baier, Harald IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 12 Text: 2014 Type: published Y: 2014 Identifiers: – Type: issn-print Value: 0926227X Numbering: – Type: volume Value: 22 – Type: issue Value: 6 Titles: – TitleFull: Journal of Computer Security Type: main |
| ResultId | 1 |