86
L. Hanzlik and M. Kutyłowski
block an eID after a limited number of failed attempts, but this would allow an
adversary to mount a denial of service attack—especially in the case of wireless
communication. In the case of non-blocking passwords, an adversary can try to
guess the correct password using a brute-force dictionary attack. If the protocol
execution is artificially slowed down so that a single interaction takes, say, 2 s, the
threat is only reduced.
On the other hand there is a threat of offline attacks, where the attacker analyzes
transcripts of communications between the eID and honest as well as dishonest
readers. Another scenario is simply leaking passwords from a malicious reader.
A different kind of threat comes from malicious terminals that interact with the
electronic layer of an eID and attempt to receive more data than allowed. This may
concern eID identity (e.g., if no password has been provided by the eID holder)
or sensitive data such as biometric data (if the terminal has not been properly
authenticated). In any case we are talking about escalating access rights via
bypassing the access control mechanism employed by the eID. Note that breaking
the secret key used for terminal authentication is essentially a step of such an attack.
Malicious terminals as well as parties observing communication may use an
interaction with an eID to convince a third party of their location and activities.
In the weaker form of location and activity tracing an attacker derives these data
for its own purposes, e.g., by observing interaction or initiating a session with the
purpose of learning the identity of eIDs within its range.
An adversary can also try to extract personal data by eavesdropping on
secure and authenticated communication between an honest eID and an honest
reader/terminal. To perform this kind of attack, the adversary has to break the confidentiality of the communication channel or hijack a session already established.
In Table 5.1 we summarize the dependencies between the above assets and
threats.
5.3 Cryptographic Protocols for eIDs
In this section we present some cryptographic protocols that are implemented and
used in various existing eID solutions and which tackle the problems described
above.
5.3.1 Preventing eID Forgeries
A simple approach adopted, among others, by the ICAO (International Civil
Aviation Organization) (see [291]), is to store all relevant data D 1 , . . . , D n in the
electronic layer, compute h := Hash(Hash(D 1 ), . . . , Hash(D n )) and an electronic
signature of the eID issuer on h. Then, it is possible to check the signature and
verify that the data D 1 , . . . , D n are authentic. (Note that it is also possible to verify
Précédent

- 98/268

Suivant