5 ePassport and eID Technologies
93
CAM—where identity information is revealed after establishing a secure channel.
Even password related data are transmitted in a very careful way—via a ciphertext
of a random value s. For ChA v.2 the situation is slightly more complicated: if PACE
is executed first, then ChA v.2 is secured by the secret channel established by PACE.
Otherwise, transmission of the public key used for static Diffie-Hellman reveals the
identity of the eID. This was one of the reasons for designing ChA v.3, where the
protocol starts with the regular Diffie-Hellman key exchange.
5.3.7 Eavesdropping
While most of the discussed protocols run key exchange protocols and automatically
support confidentiality of the established session, there are some subtle issues
concerning for instance the threat of hijacking of a session. Especially if the
protocols are executed one after another, the protocol partners need to be sure that
in the meantime an adversary has not taken over the communication on one side.
For instance, TA v.2 and ChA v.2 are coupled by a signature created during TA v.2
execution for a fingerprint of the terminal’s ephemeral key used during execution of
ChA v.2. Similarly, while PACE is not resilient to MiTM attacks (by an adversary
knowing the password), it seems to be infeasible to run an active attack enabling the
eID and the reader to establish the shared key K, so that it would be known also to
the adversary.
Summary
Table 5.2 depicts threats addressed successfully by the protocols discussed above.
Table 5.2 Threats addressed by the discussed protocols
Threat/protocol
PA
PACE
ChA v.2
TA
PACE-CAM
eID forgery
eID cloning
Lack of owner’s consent
Unauthorized data access
Location and activity tracing
Eavesdropping
Indirectly
Précédent

- 105/268

Suivant