首页> 外文会议>International Symposium on Security and Privacy in Social Networks and Big Data >Insecurity of Anonymous Login with German Personal Identity Cards
【24h】

Insecurity of Anonymous Login with German Personal Identity Cards

机译:与德国个人身份证的匿名登录不安全

获取原文

摘要

One of the major inventions of the new personal identity cards in Germany is supporting anonymous authentication. The Restricted Identification protocol enables to authenticate in an unlimited number of domains with passwords created with strong asymmetric cryptography and not using the insecure login-password mechanism. Moreover, the RI scheme guarantees unlinkability of user's authentication in different domains. The Achilles Heel of the RI scheme is Chip Authentication procedure. The terminal must make sure that it is talking with a genuine identification card and authentication via so-called group key is used. The group key is shared by many ID's in order to create a sufficiently large anonymity set. We present an attack, where the party holding the group key and eavesdropping the communication between a card and a terminal can learn the pseudonym and later authenticate as this user in this domain. In this way the party issuing the cards may get an unlimited access to citizens' accounts. We show how to solve the problem by slight changes in the protocol.
机译:德国新个人身份证的主要发明之一是支持匿名认证。受限制的识别协议使得能够在无限数量的域中进行身份验证,密码以强不对称加密创建,而不是使用不安全的登录密码机制。此外,RI方案可确保用户在不同域中的身份验证的可不可释放。 RI方案的Achilles脚后跟是芯片认证程序。终端必须确保它与真正的识别卡和通过所谓的组密钥进行身份验证。组密钥由许多ID共享,以创建一个足够大的匿名集。我们展示了一个攻击,举办持有组密钥并窃听卡片和终端之间的通信的派对可以在此域中学习假名,然后在此域中进行身份验证。通过这种方式,发布卡片的派对可能会获得对公民的账户无限的访问。我们展示了如何通过协议的略微变化来解决问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号