5 ePassport and eID Technologies
85
• personal data: data about the document owner including name and other
identification attributes that are printed on the physical layer of the identity
document,
• sensitive data: data stored in the electronic layer of the eID, which are not
present on the physical layer (typically, biometric data about the document
owner: iris scan, fingerprint, etc.).
On the other hand, there are assets related to a property or state of a protocol
execution. The following assets fall into this category:
• authenticity of data: we consider the integrity and originality of the data stored
in the memory of the eID,
• authenticity of eID: the integrity and originality of the eID as a device,
• confidentiality of communication: preventing access of unauthorized parties to
data exchanged over communication channels established with an eID,
• access limited to authorized terminals: limiting access to sensitive data to
authorized terminals,
• privacy of eID usage and location: confidentiality of data regarding eID usage,
including for instance the identity of terminals involved in an interaction, the
interaction time, and the data exchanged.
Note that in some scenarios a proof that the document interacted with a reader
is required. However, in general user privacy should be protected and access to
the data should be confined to authorized parties.
• robustness: an eID must work properly regardless of previous, possibly faulty,
executions.
5.2.2 Threats
A major threat against identification documents is forgeries. An attacker may
attempt to create a fake eID that behaves like a genuine one and presents data that
will be accepted just like in the case of interaction with a genuine eID.
An adversary may attempt to clone an eID.
A clone can be used by a person with a similar appearance as well as in remote
applications, unless protection via biometric authentication or password verification
continues to work effectively. In particular, eID cloning may enable identity theft
with profound consequences. Note that breaking the secret key of an eID may be
regarded as a partial forgery or cloning.
Another threat is using an eID without the owner’s consent. This is particularly
likely in the case of wireless communication, where interaction with an eID can
be initiated even without the owner’s knowledge. Typically, an eID is secured
via a password either entered manually by the owner or read optically from the
document’s surface.
Since the password has usually low entropy (e.g., 4–6 digits in the case of a
PIN) it might be guessed by an adversary. A common protection mechanism is to
Précédent

- 97/268

Suivant