88
L. Hanzlik and M. Kutyłowski
the signature when only some D i are given, while for the remaining values D j only
Hash(D j ) is presented.) What is more, this data can be compared with the data
stored in the physical layer of the document.
The solution presented is called Passive Authentication (PA).
Unfortunately, it provides no protection against eID cloning as all digital data
stored in the eID can be presented to a reader in the course of a normal interaction.
5.3.2 Enforcing Owner’s Consent
An access control mechanism based on an activation password can be deployed in
order to protect against using an eID without the owner’s consent, Unfortunately, it
can turn out to be ineffective. There are at least two attack scenarios:
1. an adversary is communicating directly with an eID,
2. an adversary is eavesdropping on an interaction between honest parties.
In the former case, the adversary may try all possible passwords by starting an
interaction with the eID. However, the eID may increase its response time to say
1–2 s in order to slow down the attack.
Moreover, the password may include a code printed on the eID in a machine
readable zone (MRZ) and optically read by the reader. This code may have much
higher entropy than human memorizable passwords.
Because of this latter scenario, the password cannot be transmitted in a form that
would enable the adversary to learn it and reuse it later to communicate with the eID.
This has been taken into account in a solution adopted by the ICAO called Basic
Access Control (BAC). In this protocol a fixed password corresponding to an eID
is used (1) to encrypt random nonces used to derive a session key, and (2) to create
MACs authenticating the nonces. If on any side an incorrect password is used, then
the protocol will fail. The password is derived from data scanned optically from the
MRZ area—therefore an ePassport must be shown by its owner. Unfortunately, BAC
allows an offline attack, i.e., given a transcript of a communication an adversary can
apply a brute-force dictionary attack to learn the password [375].
The successor to BAC—Password Authenticated Connection Establishment
(PACE) introduced by the German Federal Office for Information Security (BSI)
in 2008—changes the situation. It becomes impossible to verify a password guess
given only a transcript of a communication between an eID and a reader. The PACE
protocol consists of four main phases (see Fig. 5.1 for details):
1. sending a ciphertext Enc(K π , s) to the reader, where s is random and the key K π
is derived from the password,
2. using a mapping function based on the secret s to derive new parameters ˆ
G with
a new generator ˆ
g for the Diffie-Hellman protocol,
3. applying Diffie-Hellman key exchange to derive a master secret key K,
4. exchanging message authentication tags T R , T C based on a key derived from K.
L. Hanzlik and M. Kutyłowski
the signature when only some D i are given, while for the remaining values D j only
Hash(D j ) is presented.) What is more, this data can be compared with the data
stored in the physical layer of the document.
The solution presented is called Passive Authentication (PA).
Unfortunately, it provides no protection against eID cloning as all digital data
stored in the eID can be presented to a reader in the course of a normal interaction.
5.3.2 Enforcing Owner’s Consent
An access control mechanism based on an activation password can be deployed in
order to protect against using an eID without the owner’s consent, Unfortunately, it
can turn out to be ineffective. There are at least two attack scenarios:
1. an adversary is communicating directly with an eID,
2. an adversary is eavesdropping on an interaction between honest parties.
In the former case, the adversary may try all possible passwords by starting an
interaction with the eID. However, the eID may increase its response time to say
1–2 s in order to slow down the attack.
Moreover, the password may include a code printed on the eID in a machine
readable zone (MRZ) and optically read by the reader. This code may have much
higher entropy than human memorizable passwords.
Because of this latter scenario, the password cannot be transmitted in a form that
would enable the adversary to learn it and reuse it later to communicate with the eID.
This has been taken into account in a solution adopted by the ICAO called Basic
Access Control (BAC). In this protocol a fixed password corresponding to an eID
is used (1) to encrypt random nonces used to derive a session key, and (2) to create
MACs authenticating the nonces. If on any side an incorrect password is used, then
the protocol will fail. The password is derived from data scanned optically from the
MRZ area—therefore an ePassport must be shown by its owner. Unfortunately, BAC
allows an offline attack, i.e., given a transcript of a communication an adversary can
apply a brute-force dictionary attack to learn the password [375].
The successor to BAC—Password Authenticated Connection Establishment
(PACE) introduced by the German Federal Office for Information Security (BSI)
in 2008—changes the situation. It becomes impossible to verify a password guess
given only a transcript of a communication between an eID and a reader. The PACE
protocol consists of four main phases (see Fig. 5.1 for details):
1. sending a ciphertext Enc(K π , s) to the reader, where s is random and the key K π
is derived from the password,
2. using a mapping function based on the secret s to derive new parameters ˆ
G with
a new generator ˆ
g for the Diffie-Hellman protocol,
3. applying Diffie-Hellman key exchange to derive a master secret key K,
4. exchanging message authentication tags T R , T C based on a key derived from K.
