5 ePassport and eID Technologies
83
5.1.2 Actors and Scenarios
Determining the actors of the process involving an eID enables us to see the variety
of solutions associated with this term. Below we list a number of cases:
• Owner–eID–Reader: Example: border control booth.
A traveler presents their ePassport to an eGate. No border control officer is
involved in this process (unless additional processing is needed or the traveler
needs assistance). The holder of the ePassport is involved in the protocol as
biometric data are scanned and compared with the data stored in the ePassport. In
some data protection scenarios, providing the password of the ePassport holder
is required.
• eID–Reader: Example: vending machine with age verification.
A vending machine selling stuff for adults only (alcohol, etc.) has to verify the
age of the buyer. The process must work smoothly without annoying the buyer.
The protocol should guarantee that a genuine eID is involved, and that this eID
has been issued for a person that has reached the legal age. No other data about
the eID holder should be revealed.
• Owner–eID–Reader–Terminal: Example: submitting claims to an egovernment authority.
In this case the reader serves as a man-in-the-middle transmission device located
between the eID and the remote terminal. It provides technical means to establish
a channel between them, while the essential part of the protocol is run between
the eID and the terminal. The second role of the reader is to enable authorization
of the eID owner to perform some actions with the eID—such as signing a digital
document submitted to the terminal.
• eID–Reader(s)–eID: Example: vehicle to vehicle communication.
In the near future a new application area may emerge where autonomous devices,
such as vehicles, communicate directly and make decisions about their behavior.
In many cases this will require strong authentication. For instance:
– One has to recognize non-authorized devices that may work in a malicious
way or merely misuse the protocol for their own profit.
– It might be necessary to identify traffic rules violators and vehicles responsible
for traffic accidents.
At the same time the privacy of the authenticating parties should be protected.
• eID–PC: Example: user presence verification.
In certain cases a user operates a terminal and apart from the initial authentication
we need continuous verification of their presence. This concerns cases such
as operating a terminal for performing certain financial operations or safetyrelevant operations (e.g., in railway or air traffic). We have to make sure that an
unauthorized person will not be able to perform any action when the authorized
person leaves the terminal without closing a session.
Another major application area is medical services and, in particular, authenticating medical records presented to an insurance company. Evidence of presence
Précédent

- 95/268

Suivant