A Traceability Attack against e-Passports

被引:0
|
作者
Chothia, Tom [1 ]
Smirnov, Vitaliy [1 ]
机构
[1] Univ Birmingham, Sch Comp Sci, Birmingham B15 2TT, W Midlands, England
来源
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Since 2004, many nations have started issuing "e-passports" containing an RFID tag that, when powered, broadcasts information. It is claimed that these passports are more secure and that our data will be protected from any possible unauthorised attempts to read it. In this paper we show that there is a flaw in one of the passport's protocols that makes it possible to trace the movements of a particular passport, without having to break the passport's cryptographic key. All an attacker has to do is to record one session between the passport and a legitimate reader, then by replaying a particular message, the attacker can distinguish that passport from any other. We have implemented our attack and tested it successfully against passports issued by a range of nations.
引用
收藏
页码:20 / 34
页数:15
相关论文
共 50 条
  • [1] Biometrics and their use in e-passports
    Schouten, Ben
    Jacobs, Bart
    [J]. IMAGE AND VISION COMPUTING, 2009, 27 (03) : 305 - 312
  • [2] Cloning and tampering threats in e-Passports
    Calderoni, Luca
    Maio, Dario
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2014, 41 (11) : 5066 - 5070
  • [3] Securing E-passports with Elliptic Curves
    Chabanne, Herve
    Tibouchi, Mehdi
    [J]. IEEE SECURITY & PRIVACY, 2011, 9 (02) : 75 - 78
  • [4] Replacing lost or stolen e-passports
    Yong, Jianming
    Bertino, Elisa
    [J]. COMPUTER, 2007, 40 (10) : 89 - 91
  • [5] Security and privacy issues in e-passports
    Juels, A
    Molnar, D
    Wagner, D
    [J]. First International Conference on Security and Privacy for Emerging Areas in Communications Networks, Proceedings, 2005, : 74 - 85
  • [6] Increasing Privacy Threats in the Cyberspace: The Case of Italian E-Passports
    Auletta, Vincenzo
    Blundo, Carlo
    De Caro, Angelo
    De Cristofaro, Emiliano
    Persiano, Giuseppe
    Visconti, Ivan
    [J]. FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, 2010, 6054 : 94 - +
  • [7] Smart Boarding System with e-Passports for Secure and Independent Interoperability
    Mohamed Azman
    Kunal Sharma
    [J]. SN Computer Science, 2022, 3 (1)
  • [8] e-Passports as a means towards a Globally Interoperable Public Key Infrastructure
    Lekkas, Dimitrios
    Gritzalis, Dimitris
    [J]. JOURNAL OF COMPUTER SECURITY, 2010, 18 (03) : 379 - 396
  • [9] Breaking Unlinkability of the ICAO 9303 Standard for e-Passports Using Bisimilarity
    Filimonov, Ihor
    Horne, Ross
    Mauw, Sjouke
    Smith, Zach
    [J]. COMPUTER SECURITY - ESORICS 2019, PT I, 2019, 11735 : 577 - 594
  • [10] THE USE OF E-PASSPORTS FOR INBOUND AIRPORT BORDER SECURITY SCREENING: THE PASSENGER PERSPECTIVE
    Kneale, David K.
    Baxter, Glenn S.
    Wild, Graham
    [J]. AVIATION, 2014, 18 (04) : 193 - 202