首页> 外文会议>Software, Telecommunications amp; Computer Networks, 2009. SoftCOM 2009 >Securing ePassport system: A proposed Anti-Cloning and Anti-Skimming Protocol
【24h】

Securing ePassport system: A proposed Anti-Cloning and Anti-Skimming Protocol

机译:保护ePassport系统:建议的防克隆和防遗漏协议

获取原文

摘要

Despite the fact that RFID based ePassport (a.k.a biometric passport) has increased the efficiency of passport systems, it has created many new threats concerning personal data protection. Cryptographic tools are used to counter these threats but vulnerabilities are discovered in the implementation of these tools. For instance, Basic Access Control (BAC) is used to thwart data skimming from the ePassport to an illegitimate reader. Study reveals that the BAC keys suffer from very low practical entropy, therefore BAC cannot be considered as an effective tool against skimming attacks. Moreover, Active Authentication (AA), a measure against chip cloning, can be bypassed by amending the EF.COM file of the passport chip. In this paper, an Anti-Cloning and Anti-Skimming Protocol (ACASP) is proposed that provides a counter solution to the aforementioned vulnerabilities. It takes advantage of publicprivate key pair stored in the chip and optional data storage capacity in Machine Readable Zone (MRZ) of the passport. It increases BAC keys entropy from 30–40 bits to 56 bits and provides an entirely different approach to avoid chip cloning. ACASP can be implemented without any change in hardware of reader and tag. It also requires no change in Logical Data Structure (LDS) of the RFID chip. However, application software of reader and tag needs to be modified as required.
机译:尽管基于RFID的ePassport(也称为生物特征护照)提高了护照系统的效率,但它却带来了许多有关个人数据保护的新威胁。密码工具用于应对这些威胁,但是在实施这些工具时发现了漏洞。例如,基本访问控制(BAC)用于阻止从ePassport到非法读取器的数据浏览。研究表明,BAC密钥的实用熵非常低,因此BAC不能被认为是抵御掠夺攻击的有效工具。此外,可以通过修改护照芯片的EF.COM文件来绕过主动身份验证(AA)(一种防止芯片克隆的措施)。在本文中,提出了一种防克隆和防遗漏协议(ACASP),该协议为上述漏洞提供了对策。它利用了存储在芯片中的公私钥对以及护照的机读区(MRZ)中的可选数据存储容量。它将BAC密钥的熵从30-40位增加到56位,并提供了一种完全不同的方法来避免芯片克隆。无需更改阅读器和标签的硬件即可实施ACASP。它还不需要更改RFID芯片的逻辑数据结构(LDS)。但是,需要根据需要修改阅读器和标签的应用软件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号