90
L. Hanzlik and M. Kutyłowski
An important feature of password-based schemes is how to respond to authentication attempts with a wrong password. In any case, a failed attempt is information
indicating incorrectness of the password. The important point is that no other
information should be revealed to the attacker. Note that PACE has this property:
first, the ciphertext of a random number s does not reveal any information about
the password dependent encryption key. Second, the random challenges exchanged
within the final Diffie-Hellman key exchange are stochastically independent of the
password. The password dependent message T C is sent after positive verification of
T R —so T C is not transmitted, if the password is incorrect!
5.3.3 EID Authentication and Preventing Cloning
The threat of eID cloning is also called an impersonation attack, since a user of
a cloned eID may impersonate its legitimate owner. This kind of attack can be
easily performed in the case of passive authentication, as all data in an eID are
also available outside it. An obvious remedy to this problem is to use an eID public
key as part of the data authenticated by the document issuer, store the corresponding
secret key in the memory of the eID, and run an authentication protocol based on
these keys. Obviously, this solution makes sense only if it is infeasible to export the
secret key from the eID.
The ICAO standard for Machine Readable Travel Documents specifies two
cryptographic protocols that can be used to authenticate a chip. The first is called
Active Authentication (AA) and relies on the challenge-response paradigm. The
terminal sends a challenge to the ePassport, which responds with a signature under
this challenge. Finally the terminal verifies the signature with respect to the public
key stored in the authenticated data read from the ePassport’s memory.
The second solution called Chip Authentication v.2 (ChA v.2) was introduced
by the BSI as part of the so-called Extended Access Control (EAC) protocol stack,
where within the same protocol the rights of the terminal are checked. ChA v.2
is a static Diffie-Hellman protocol: it is simply the Diffie-Hellman key exchange
protocol where the challenge from the eID is replaced by its public key, say y = g x .
As in the Diffie-Hellman key exchange protocol deriving the shared key is possible
provided that one knows the discrete logarithm of the challenge, the ability of the
eID to derive the secret key serves as evidence that it knows the secret key x.
The main advantage of ChA v.2 is that it generates a new session key that can
be used to secure communication between the eID and the terminal. Note that the
protocols discussed in the previous subsection establish a secure channel between
the eID and a reader, which is not necessarily part of the terminal. For example, if
the eID is used for online activities the card reader is at best a part of the user’s
system.
The main disadvantage of both solutions is that they require additional computations that are expensive, i.e., exponentiations. For this reason the ICAO adopted
a protocol called PACE with Chip Authentication mapping (PACE-CAM) that
L. Hanzlik and M. Kutyłowski
An important feature of password-based schemes is how to respond to authentication attempts with a wrong password. In any case, a failed attempt is information
indicating incorrectness of the password. The important point is that no other
information should be revealed to the attacker. Note that PACE has this property:
first, the ciphertext of a random number s does not reveal any information about
the password dependent encryption key. Second, the random challenges exchanged
within the final Diffie-Hellman key exchange are stochastically independent of the
password. The password dependent message T C is sent after positive verification of
T R —so T C is not transmitted, if the password is incorrect!
5.3.3 EID Authentication and Preventing Cloning
The threat of eID cloning is also called an impersonation attack, since a user of
a cloned eID may impersonate its legitimate owner. This kind of attack can be
easily performed in the case of passive authentication, as all data in an eID are
also available outside it. An obvious remedy to this problem is to use an eID public
key as part of the data authenticated by the document issuer, store the corresponding
secret key in the memory of the eID, and run an authentication protocol based on
these keys. Obviously, this solution makes sense only if it is infeasible to export the
secret key from the eID.
The ICAO standard for Machine Readable Travel Documents specifies two
cryptographic protocols that can be used to authenticate a chip. The first is called
Active Authentication (AA) and relies on the challenge-response paradigm. The
terminal sends a challenge to the ePassport, which responds with a signature under
this challenge. Finally the terminal verifies the signature with respect to the public
key stored in the authenticated data read from the ePassport’s memory.
The second solution called Chip Authentication v.2 (ChA v.2) was introduced
by the BSI as part of the so-called Extended Access Control (EAC) protocol stack,
where within the same protocol the rights of the terminal are checked. ChA v.2
is a static Diffie-Hellman protocol: it is simply the Diffie-Hellman key exchange
protocol where the challenge from the eID is replaced by its public key, say y = g x .
As in the Diffie-Hellman key exchange protocol deriving the shared key is possible
provided that one knows the discrete logarithm of the challenge, the ability of the
eID to derive the secret key serves as evidence that it knows the secret key x.
The main advantage of ChA v.2 is that it generates a new session key that can
be used to secure communication between the eID and the terminal. Note that the
protocols discussed in the previous subsection establish a secure channel between
the eID and a reader, which is not necessarily part of the terminal. For example, if
the eID is used for online activities the card reader is at best a part of the user’s
system.
The main disadvantage of both solutions is that they require additional computations that are expensive, i.e., exponentiations. For this reason the ICAO adopted
a protocol called PACE with Chip Authentication mapping (PACE-CAM) that
