E-Passport Testing. Ensuring Global Acceptance. Jos Chehin Date: 17 November 2006 Location: ASML



Similar documents
Security by Politics - Why it will never work. Lukas Grunwald DN-Systems GmbH Germany DefCon 15 Las Vegas USA

Implementation of biometrics, issues to be solved

Preventing fraud in epassports and eids

A Note on the Relay Attacks on e-passports

Keep Out of My Passport: Access Control Mechanisms in E-passports

TÜBİTAK BİLGEM ULUSAL ELEKTRONİK & KRİPTOLOJİ ARAŞTIRMA ENSTİTÜSÜ AKİS PROJESİ AKİS V1.4N

New Attacks against RFID-Systems. Lukas Grunwald DN-Systems GmbH Germany

eidas as blueprint for future eid projects cryptovision mindshare 2015 HJP Consulting Holger Funke

Modular biometric architecture with secunet biomiddle

Biometrics for Public Sector Applications

MOBILE IDENTIFICATION:

Statewatch Briefing ID Cards in the EU: Current state of play

Entrust Smartcard & USB Authentication

Landscape of eid in Europe in 2013

Electronic Passports in a Nutshell

Position Paper European Citizen Card: One Pillar of Interoperable eid Success

MACHINE READABLE TRAVEL DOCUMENTS

Full page passport/document reader Regula model 70X4M

Common Criteria Protection Profile. Machine Readable Travel Document with ICAO Application, Basic Access Control BSI-CC-PP-0055

Information about the European Union is available on the Internet. It can be accessed through the Europa server (

Establishing and Managing the Schengen Masterlist of CSCAs

Moving to the third generation of electronic passports

European Electronic Identity Practices Country Update of Portugal

Transaction Security. Test Tools & Simulators

Overview of Contactless Payment Cards. Peter Fillmore. July 20, 2015

Operational and Technical security of Electronic Passports

Informationsteknologi Personlig identifikation ISO-overensstemmende kørekort Del 4: Prøvningsmetoder

Common Criteria Protection Profile for Inspection Systems (IS) BSI-CC-PP Version 1.01 (15 th April 2010)

ID Document Scanning and Biometric Solutions

Doc. Machine. authority

Smart Card. Smart Card applications

Functional Specification of the OpenPGP application on ISO Smart Card Operating Systems

Advanced Security Mechanisms for Machine Readable Travel Documents and eidas Token

NFC & Biometrics. Christophe Rosenberger

W.A.R.N. Passive Biometric ID Card Solution

FAQs Electronic residence permit

CERTIFICATION REPORT

Transaction Security. Training Academy

Core Fittings C-Core and CD-Core Fittings

PKD Board ICAO PKD unclassified B-Tec/37. Procedures for the ICAO Public Key Directory

European Electronic Identity Practices

EESTEL. Association of European Experts in E-Transactions Systems. Apple iphone 6, Apple Pay, What else? EESTEL White Paper.

Machine Readable Travel Documents

Standards for Identity & Authentication. Catherine J. Tilton 17 September 2014

RVS Seminar Deployment and Performance Analysis of JavaCards in a Heterogenous Environment. Carolin Latze University of Berne

Hacking the NFC credit cards for fun and debit ;) Renaud Lifchitz BT Hackito Ergo Sum 2012 April 12,13,14 Paris, France

Best Solutions for Biometrics and eid

Test plan for eid and esign compliant terminal software with EACv2

ETSI TS V1.2.1 ( )

NACCU Migrating to Contactless:

MACHINE READABLE TRAVEL DOCUMENTS

The Implementation of Signing e-document by Using the Wireless Identity Module in Cellular Phone

ISO Information Security Management Systems Professional

Introducing etoken. What is etoken?

Java Card. Smartcards. Demos. . p.1/30

Specifications for the Smart-Card Operating System for Transport Applications (SCOSTA)

Banking. Extending Value to Customers. KONA Banking product matrix. is leading the next generation of payment solutions.

Optical Memory Cards in Federal Government

I N F O R M A T I O N S E C U R I T Y

Smart Card Application Standard Draft

E-passport testing equipment

I N F O R M A T I O N S E C U R I T Y

Smart Card Application Development Using Java

AN1304. NFC Type MIFARE Classic Tag Operation. Application note PUBLIC. Rev October Document information

MIFARE ISO/IEC PICC

ON IDENTITY CARDS. Based on Article 65 (1) of the Constitution of the Republic of Kosovo, LAW ON IDENTITY CARDS CHAPTER I GENERAL PROVISIONS

Global eid Developments. Detlef Eckert Chief Security Advisor Microsoft Europe, Middle East, and Africa

Efficient Implementation of Electronic Passport Scheme Using Cryptographic Security Along With Multiple Biometrics

Electronic machine-readable travel documents (emrtds) The importance of digital certificates

CERTIFICATION REPORT

End-to-end security with advanced biometrics technology

End-to-end security with advanced biometrics technology

October 2014 Issue No: 2.0. Good Practice Guide No. 44 Authentication and Credentials for use with HMG Online Services

Advanced Authentication

Common Criteria Protection Profile

39 myths about e-passports

Federal Identity, Credentialing, and Access Management. Personal Identity Verification Interoperable (PIV-I) Test Plan. Version 1.1.

Multi-Factor Authentication of Online Transactions

Identity Management Initiatives in identity management and emerging standards Presented to Fondazione Ugo Bordoni Rome, Italy

Biometrics for public sector applications

Smart Card Technology Capabilities

Self Testing and Product Qualification Processes

QUESTIONS & ANSWERS. How did the Department decide on the cost of the Passport Card?

Published International Standards Developed by ISO/IEC JTC 1/SC 37 - Biometrics

Moving to Multi-factor Authentication. Kevin Unthank

AN2598 Application note

Synergy between Registered Traveler Programs and Visa-Processing for frequent travelers

Combatting Counterfeit Identities: The Power of Pairing Physical & Digital IDs

Protection Profile for UK Dual-Interface Authentication Card

GLOSSARY ABTC APEC API ASEAN

NOAA HSPD-12 PIV-II Implementation October 23, Who is responsible for implementation of HSPD-12 PIV-II?

MIFARE CONTACTLESS CARD TECHNOLOLGY AN HID WHITE PAPER

Government Smart Card Interoperability Specification

SIM CARD PROTOCOLS. This paper attempts in broad strokes to outline the construction of these protocols and how they are used.

Standardizing contactless communication between ticketing equipment and fare media Transport Ticketing 2014

PKD Board ICAO PKD unclassified B-Tec/36. Regulations for the ICAO Public Key Directory

EPASSPORT WITH BASIC ACCESS CONTROL AND ACTIVE AUTHENTICATION

The EMV Readiness. Collis America. Guy Berg President, Collis America

OpenFlow Conformance Test Program

ACER ProShield. Table of Contents

Transcription:

E-assport Testing Ensuring Global Acceptance By: Jos Chehin Date: 17 ovember 2006 Location: ASML

Global Acceptance of the e-assport Global Acceptance Interoperability Functionality Security Test Standards e-assport Standards www.collis.nl 2

Agenda The e-assport The ICAO/ISO e-assport Standards Test coverage of the Application rotocol and Logical Data Structure Test Standard Findings and Conclusions www.collis.nl 3

The e-assport Contactless chip rocessing capability Data storage KI Biometrics (Face, fingerprint, eyes) Secure electronic identification www.collis.nl 4

The e-assport Standards ISO 14443 ublic Key Cryptography conform to the ICAO KI standard The ISO 7816-4 Standard Standard for the e-assport Logical Data Structure (LDS) ICAO LDS ersonalisation OSI Layer 6-7 ICAO KI ISO 7816-4,8 ISO 14443 Application Hardware OSI Layer 6-7 OSI Layer 1-4 www.collis.nl 5

Testing the e-assport Hardware Collis SmartWave box Reads/simulates Test Suite s Low level interoperability Low level interoperability test events (ISO 14443): Cross-over testing interoperability rates 93% in Singapore 87% in Berlin Readable ISO/ICAO conformance www.collis.nl 6

e-assport Security Mechanisms Security mechanisms: assive Authentication (Mandatory) Active Authentication (Optional) Basic Access Control (Optional) Extended Access Control (Optional) Issuing States MAY choose additional security, using more complex ways of securing the chip and its data. ICAO KI Application OSI Layer 6-7 www.collis.nl 7

e-assport Smartcard Commands e-assport to reader communication on ADU level assive Authentication Active Authentication Basic Access Control Extended Access Control SELECT READ BIARY(B0/B1) SELECT READ BIARY(B0/B1) ITERAL AUTHETICATE SELECT GET CHALLEGE MUTUAL AUTHETICATE ISO 7816-4,8 Application OSI Layer 6-7 www.collis.nl 8

The e-assport LDS ICAO LDS ersonalisation www.collis.nl 9

Testing the e-assport Application and LDS ICAO/ISO Test Standard Security Security Mechanisms Smartcard commands ositive egative The LDS Encoding of the LDS data objects www.collis.nl 10

Test Coverage of the ICAO KI Test Standard assive Auth. Active Auth. Basic Access Control Extended Access Control assive Auth. Active Auth. Basic Access Control Extended Access Control Mandatory EU US Mandatory EU US www.collis.nl 11

Test Coverage of the ICAO LDS Test Standard EF.COM DG1 Machine Readable Zone (MRZ) DG2 Encoded Face DG3 Encoded Finger (s) DG4 Encoded Eye (s) DG5 Displayed Identification features : DG7 Mandatory EU US DG8 Encoded Security Features : DG10 DG11 Additional personal details DG12 Additional Document Details DG13 Optional Details Dg14 Reserved for future use DG15 Active Authentication k DG16 ersons to notify www.collis.nl 12 EF.SOD

Test Coverage of the ICAO LDS Test Standard EF.COM DG1 Machine Readable Zone (MRZ) DG2 Encoded Face DG3 Encoded Finger (s) DG4 Encoded Eye (s) DG5 Displayed Identification features : DG7 Mandatory EU US DG8 Encoded Security Features : DG10 DG11 Additional personal details DG12 Additional Document Details DG13 Optional Details Dg14 Reserved for future use DG15 Active Authentication k DG16 ersons to notify www.collis.nl 13 EF.SOD

Smartcard Command ADU Tests umber of ositive / egative tests defined per ISO 7816 command 12 10 11 8 6 6 7 4 2 0 3 3 22 1 1 1 1 0 0 0 00 SL B0 B1 B0sfi B1sfi GC MA AA ositive Tests Defined egative Tests Defined www.collis.nl 14

ISO 7816 Command Test Coverage Matrix CLA 1 2 Lc Crypt Data CC TLV Offset SM Le Rtrn bytes B1sfi B0sfi B0 B1 SEL GC MA IA www.collis.nl 15

Findings Some optional, but important security features not covered by the ICAO test standard (AA, EA) e-assport chip response on incorrect commands not tested thouroughly (negative tests) Gaps in the test specification Global Acceptance Interoperability Functionality Security Test Standards E-assport Standards www.collis.nl 16

Recommendation Additional tests need to be developed to fill up gaps in the test specification Global Acceptance Interoperability Functionality Security Test Standards E-assport Standards www.collis.nl 17

-End- www.collis.nl 18