5 ePassport and eID Technologies
89
:
r
e
d
a
e
r
:
D
I
e
password p, parameters G
password p, parameters G
PROTOCOL EXECUTION
K p = KDF(p)
K p = KDF(p)
choose s Z q
z = Enc(K p , s)
z
s = Dec(K p , z)
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .Mapping Function . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
ˆ
G = Map(G, s)
ˆ
G = Map(G, s)
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
choose y
C
Z ∗
q
choose y
R
Z ∗
q
Y
C = ˆ
g
y
C
Y
R
Y
R = ˆ
g y
R
abort if Y
R = Y R
Y
C
abort if Y
C = Y C
K = Y
R
y
C
K = Y
C
y
R
K Enc = KDF Enc (K)
K Enc = KDF Enc (K)
K Mac = KDF Mac (K)
K Mac = KDF Mac (K)
K
Mac = KDF(K, 4)
K
Mac = KDF(K, 4)
if Verify(K
Mac , (Y
A , G), T R ) = 0,
T R
T R = Mac(K
Mac , (Y
C , G 1 ))
then abort
T C = Mac(K
Mac , (Y
R , G 1 ))
T C
if Verify(K
Mac , (Y
B , G), T C ) = 0,
then abort
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
key = (K Enc , K Mac )
key = (K Enc , K Mac )
Fig. 5.1 PACE protocol
There are two variants of the mapping function specified in the ICAO standard:
Generic and Integrated Mapping. In the former case, ˆ
g = h · g s , where h is the
secret key generated using a standard Diffie-Hellman protocol for parameters G. In
the latter case, ˆ
g := Hash(s, r) where r is a random number chosen by the reader.
The security of the Generic Mapping version of the protocol is based on the
following argument. We can create a virtual protocol, where h is not derived by
the Diffie-Hellman protocol but is a random element. Such a change cannot be
detected by an adversary performing an offline attack due to the hardness of the
Diffie-Hellman Problem. However, in the virtual protocol all data exchanged are
stochastically independent of s. Therefore, it is impossible to derive any information
about s. A similar argument applies to Integrated Mapping. Note that ˆ
g never occurs
in the communication and the values Y
C , Y
R are uniformly distributed, as the group
used has a prime order. The only relation to ˆ
g is hidden in the way the protocol
partners derive K. However, again we can consider a virtual protocol where K is
replaced by a random element. The change is not observable to the attacker even
if they learn the key K. Some partial security proofs for the PACE protocol were
presented by Bender et al. [72] and for the PACE Integrated Mapping by Coron et
al. [153].
Précédent

- 101/268

Suivant