首页> 外文会议>Financial Cryptography and Data Security >ePassport: Securing International Contacts with Contactless Chips
【24h】

ePassport: Securing International Contacts with Contactless Chips

机译:电子护照:使用非接触式芯片确保国际联系

获取原文
获取原文并翻译 | 示例

摘要

Electronic passports (ePassports) have known a wide and fast deployment all around the world since the International Civil Aviation Organization published their specifications in 2004. Based on an integrated circuit, ePassports are significantly more secure than their predecessors. Forging an ePassport is definitely thwarted by the use of cryptographic means. In spite of their undeniable benefit, ePassports have raised questions about personal data protection, since attacks on the basic access control mechanism came into sight. Keys used for that purpose derive from the nothing but predictable machine readable zone data, and so suffer from weak entropy. We provide an in-depth evaluation of the basic access key entropy, and prove that Belgian passport, recipient of Interpol "World's most secure passport" award in 2003, provides the worst basic access key entropy one has ever seen. We also state that two-thirds of Belgian ePassports in circulation do not implement any data protection mechanism. We demonstrate our claims by means of practical attacks. We then provide recommendations to amend the ePassport security, and directions for further work.
机译:自国际民航组织于2004年发布其技术规范以来,电子护照(ePassports)在世界范围内得到了广泛而快速的部署。基于集成电路,电子护照比其前身安全得多。使用密码方式肯定会阻碍伪造ePassport。尽管带来了不可否认的好处,但是自从出现对基本访问控制机制的攻击以来,ePassports仍对个人数据保护提出了疑问。用于此目的的密钥仅来自可预测的机器可读区域数据,因此熵弱。我们对基本访问密钥熵进行了深入评估,并证明比利时护照(2003年国际刑警组织“世界上最安全的护照”奖获得者)提供了有史以来最差的基本访问密钥熵。我们还声明,三分之二的比利时电子护照未实施任何数据保护机制。我们通过实际攻击来证明我们的主张。然后,我们提供了修改ePassport安全性的建议以及进一步工作的指导。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号