Increasing Privacy Threats in the Cyberspace: The Case of Italian E-Passports

被引:0
|
作者
Auletta, Vincenzo [1 ]
Blundo, Carlo [1 ]
De Caro, Angelo [1 ]
De Cristofaro, Emiliano [2 ]
Persiano, Giuseppe [1 ]
Visconti, Ivan [1 ]
机构
[1] Univ Salerno, Dipartimento Informat & Applicaz, I-84084 Fisciano, SA, Italy
[2] Univ Calif Irvine, Irvine, CA 92617 USA
来源
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The recent introduction of electronic passports (e-Passports) motivates the need of a thorough investigation on potential security and privacy issues. In this paper, we focus on the e-Passport implementation adopted in Italy. Leveraging previous attacks to e-Passports adopted in other countries, we analyze (in)security of Italian e-Passports and we investigate additional critical issues. Our work makes several contributions. 1. We show that in some concrete scenarios, Italian e-Passports are prone to eavesdropping attacks, where one can unnoticeably obtain private data stored in the e-Passport using RF communication, while the passport is stored in a bag/pocket. Moreover, we show how to trace e-Passports by successfully linking two or more communication transcripts related to the same e-Passport. 2. We propose a set of open-source tools that build successful attacks to the security of Italian e-Passports. Among them, we provide a simulator that produces attacks without requiring physical passports and RFID equipment. 3. We show that the random number generator included in the RFID chips produces bits that are noticeably far from the uniform distribution, thus potentially exposing Italian e-Passports to several other attacks.
引用
收藏
页码:94 / +
页数:3
相关论文
共 50 条
  • [21] Multidimensional Threats and Military Engagement: The Case of the Italian Intervention in Libya
    Ceccorulli, Michela
    Coticchia, Fabrizio
    [J]. MEDITERRANEAN POLITICS, 2015, 20 (03) : 303 - 321
  • [22] E-space inclusion: A case for the Americans with Disabilities Act in cyberspace
    Schaefer, K
    [J]. JOURNAL OF PUBLIC POLICY & MARKETING, 2003, 22 (02) : 223 - 227
  • [23] Modeling the Propagation of Security Threats: An E- Learning Case Study
    Rjaibi, Neila
    Gannouni, Nawel
    Rabai, Latifa Ben Arfa
    Ben Aissa, Anis
    [J]. 2014 THIRD INTERNATIONAL CONFERENCE ON CYBER SECURITY, CYBER WARFARE AND DIGITAL FORENSIC (CYBERSEC), 2014, : 32 - 37
  • [24] How to develop e-Government: The Italian case
    Resca, A
    [J]. KNOWLEDGE MANAGEMENT IN ELECTRONIC GOVERNMENT, PROCEEDINGS, 2004, 3025 : 174 - 184
  • [25] Based on GDPR privacy in UML: case of e-learning program
    Virvou, Maria
    Mougiakou, Eirini
    [J]. 2017 8TH INTERNATIONAL CONFERENCE ON INFORMATION, INTELLIGENCE, SYSTEMS & APPLICATIONS (IISA), 2017, : 563 - 570
  • [26] Do we need new rights in Cyberspace? Discussing the case of how to define on-line privacy in an Internet Bill of Rights
    Casacuberta, David
    Senges, Max
    [J]. ENRAHONAR-QUADERNS DE FILOSOFIA, 2008, (40-41): : 99 - 111
  • [27] Privacy protection laws and public perception of data privacy: The case of Dubai e-health care services
    Sarabdeen, Jawahitha
    Moonesar, Immanuel Azaad
    [J]. BENCHMARKING-AN INTERNATIONAL JOURNAL, 2018, 25 (06) : 1883 - 1902
  • [28] E-banking, governance and local banks: The Italian case
    Giovanni Ferri
    Donato Masciandaro
    [J]. Journal of International Banking Regulations, 2002, 4 (1): : 72 - 83
  • [29] Social Media Tools and (E)Destination: An Italian Case Study
    Paiano, Anna Paola
    Valente, Lara
    Ndou, Valentina
    Del Vecchio, Pasquale
    [J]. TOURISM, CULTURE AND HERITAGE IN A SMART ECONOMY, 2017, : 251 - 272
  • [30] Innovating e-Recruitment Services: An Italian Case Study
    Iannotta, Michela
    Gatti, Mauro
    [J]. EMPOWERING ORGANIZATIONS: ENABLING PLATFORMS AND ARTEFACTS, 2016, 11 : 103 - 114