首页> 外文会议>International Conference of the Biometrics Special Interest Group >Security considerations on extending PACE to a biometric-based connection establishment
【24h】

Security considerations on extending PACE to a biometric-based connection establishment

机译:关于将PACE扩展到基于生物特征的连接建立的安全考虑

获取原文

摘要

The regulations of the European Union (EU) Council in 2004 are the basis of the deployment of electronic passports within the EU. Since then EU member states adopt the format and the access protocols to further electronic machine readable travel documents (eMRTD) like national electronic ID cards and electronic residence permits, respectively. The security protocols to communicate with an eMRTD are based on the paradigm of strong cohesion and loose coupling, i.e., each step is designed to ensure only a particular security goal like authorisation to access a certain data group, authenticity and integrity of the data, originality of the chip, or the linkage between the eMRTD and its holder. However, recently a discussion evolved to integrate the linkage security goal within the connection establishment, which currently only aims at limiting basic access of authorised terminals to the eMRTD. For instance, the BioPACE protocol proposes to replace the knowledge-based shared ‘secret’ of PACE by a biometric-based one. The goal of the paper at hand is twofold: First, we evaluate the BioPACE protocol and propose improvements to enhance its features. Second, we analyse the expediency of integrating our BioPACE version 2 into the eMRTD domain. Our initial evaluation shows that our BioPACE version 2 is expedient if the EAC protocols and the corresponding PKI are abandoned.
机译:欧盟(EU)理事会2004年的法规是在欧盟内部部署电子护照的基础。从那时起,欧盟成员国分别采用格式和访问协议来处理其他电子机读旅行证件(eMRTD),例如国家电子身份证和电子居留证。与电子机读旅行证件通信的安全协议基于强大的凝聚力和松散耦合的范式,即,每个步骤都旨在确保仅实现特定的安全目标,例如访问特定数据组的授权,数据的真实性和完整性,原创性。芯片或电子机读旅行证件与其持有人之间的联系。但是,近来进行了讨论以将链接安全目标集成到连接建立中,该讨论当前仅旨在限制授权终端对eMRTD的基本访问。例如,BioPACE协议提议将PACE的基于知识的共享“秘密”替换为基于生物特征的协议。本文的目的是双重的:首先,我们评估BioPACE协议并提出改进措施以增强其功能。其次,我们分析了将我们的BioPACE版本2集成到eMRTD域中的便利性。我们的初步评估表明,如果放弃EAC协议和相应的PKI,则BioPACE版本2是合适的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号