Increasing Privacy Threats in the Cyberspace: The Case of Italian E-Passports

被引:0
|
作者
Auletta, Vincenzo [1 ]
Blundo, Carlo [1 ]
De Caro, Angelo [1 ]
De Cristofaro, Emiliano [2 ]
Persiano, Giuseppe [1 ]
Visconti, Ivan [1 ]
机构
[1] Univ Salerno, Dipartimento Informat & Applicaz, I-84084 Fisciano, SA, Italy
[2] Univ Calif Irvine, Irvine, CA 92617 USA
来源
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The recent introduction of electronic passports (e-Passports) motivates the need of a thorough investigation on potential security and privacy issues. In this paper, we focus on the e-Passport implementation adopted in Italy. Leveraging previous attacks to e-Passports adopted in other countries, we analyze (in)security of Italian e-Passports and we investigate additional critical issues. Our work makes several contributions. 1. We show that in some concrete scenarios, Italian e-Passports are prone to eavesdropping attacks, where one can unnoticeably obtain private data stored in the e-Passport using RF communication, while the passport is stored in a bag/pocket. Moreover, we show how to trace e-Passports by successfully linking two or more communication transcripts related to the same e-Passport. 2. We propose a set of open-source tools that build successful attacks to the security of Italian e-Passports. Among them, we provide a simulator that produces attacks without requiring physical passports and RFID equipment. 3. We show that the random number generator included in the RFID chips produces bits that are noticeably far from the uniform distribution, thus potentially exposing Italian e-Passports to several other attacks.
引用
收藏
页码:94 / +
页数:3
相关论文
共 50 条
  • [1] Cloning and tampering threats in e-Passports
    Calderoni, Luca
    Maio, Dario
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2014, 41 (11) : 5066 - 5070
  • [2] Security and privacy issues in e-passports
    Juels, A
    Molnar, D
    Wagner, D
    [J]. First International Conference on Security and Privacy for Emerging Areas in Communications Networks, Proceedings, 2005, : 74 - 85
  • [3] Biometrics and their use in e-passports
    Schouten, Ben
    Jacobs, Bart
    [J]. IMAGE AND VISION COMPUTING, 2009, 27 (03) : 305 - 312
  • [4] A Traceability Attack against e-Passports
    Chothia, Tom
    Smirnov, Vitaliy
    [J]. FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, 2010, 6052 : 20 - 34
  • [5] Securing E-passports with Elliptic Curves
    Chabanne, Herve
    Tibouchi, Mehdi
    [J]. IEEE SECURITY & PRIVACY, 2011, 9 (02) : 75 - 78
  • [6] Replacing lost or stolen e-passports
    Yong, Jianming
    Bertino, Elisa
    [J]. COMPUTER, 2007, 40 (10) : 89 - 91
  • [7] Smart Boarding System with e-Passports for Secure and Independent Interoperability
    Mohamed Azman
    Kunal Sharma
    [J]. SN Computer Science, 2022, 3 (1)
  • [8] e-Passports as a means towards a Globally Interoperable Public Key Infrastructure
    Lekkas, Dimitrios
    Gritzalis, Dimitris
    [J]. JOURNAL OF COMPUTER SECURITY, 2010, 18 (03) : 379 - 396
  • [9] Breaking Unlinkability of the ICAO 9303 Standard for e-Passports Using Bisimilarity
    Filimonov, Ihor
    Horne, Ross
    Mauw, Sjouke
    Smith, Zach
    [J]. COMPUTER SECURITY - ESORICS 2019, PT I, 2019, 11735 : 577 - 594
  • [10] THE USE OF E-PASSPORTS FOR INBOUND AIRPORT BORDER SECURITY SCREENING: THE PASSENGER PERSPECTIVE
    Kneale, David K.
    Baxter, Glenn S.
    Wild, Graham
    [J]. AVIATION, 2014, 18 (04) : 193 - 202