A survey of system security in contactless electronic passports

نویسنده

  • Anshuman Sinha
چکیده

A traditional paper-based passport contains a MachineReadable Zone (MRZ) and a Visual Inspection Zone (VIZ). The MRZ has two lines of the holder’s personal data, some document data, and verification characters encoded using the Optical Character Recognition font B (OCRB). The encoded data includes the holder’s name, date of birth, and other identifying information for the holder or the document. The VIZ contains the holder’s photo and signature, usually on the data page. However, the MRZ and VIZ can be easily duplicated with normal document reproduction technology to produce a fake passport which can pass traditional verification. Neither of these features actively verify the holder’s identity; nor do they bind the holder’s identity to the document. A passport also contains pages for stamps of visas and of country entry and exit dates, which can be easily altered to produce fake permissions and travel records. The electronic passport, supporting authentication using secure credentials on a tamper-resistant chip, is an attempt to improve on the security of the paper-based passport at minimum cost. This paper surveys the security mechanisms built into the firstgeneration of authentication mechanisms and compares them with second-generation passports. It analyzes and describes the cryptographic protocols used in Basic Access Control (BAC) and Extended Access Control (EAC).

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

An Overview of Electronic Passport Security Features

Electronic passports include contactless chip which stores personal data of the passport holder, information about the passport and the issuing institution. In its simplest form an electronic passport contains just a collection of read-only files, more advanced variants can include sophisticated cryptographic mechanisms protecting security of the document and / or privacy of the passport holder...

متن کامل

e-Passports as a means towards a Globally Interoperable Public Key Infrastructure

Millions of citizens around the world have already acquired their new electronic passport. The e-passport is equipped with contactless communication capability, as well as with an Integrated Circuit Chip enabling cryptographic functionality. Countries are required to build a national Public Key Infrastructure to support digital signatures, as this is considered the basic mechanism to prove the ...

متن کامل

Security of Wireless Embedded Devices in the Real World

In the past years, wireless embedded devices have become omnipresent. Portable tokens communicating via an RF (Radio Frequency) interface are employed in contactless applications such as access control, identification, and payments. The survey presented in this paper focuses on those devices that employ cryptographic mechanisms as a protection against ill-intended usage or unauthorizedly access...

متن کامل

Model-Based Testing of Electronic Passports

Understanding the speci cations and constructing the model was most of the work. After that using TorXakis to automatically run test cases was quick and easy. We started with a coarse model, which allowed us to run tests early on in the project. The model was then subsequently re ned. In this project model-based testing has clearly proven its value. Electronic passports contain a contactless sm...

متن کامل

E-Passports as a Means Towards the First World-Wide Public Key Infrastructure

Millions of citizens around the world have already acquired their new electronic passport. The e-passport is equipped with contactless communication capability, as well as with a smart card processor enabling cryptographic functionality. Countries are required to build a Public Key Infrastructure to support digital signatures, as this is considered the basic tool to prove the authenticity and i...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • IJCIP

دوره 4  شماره 

صفحات  -

تاریخ انتشار 2011