E-passport EAC scheme based on Identity-Based Cryptography

被引:5
作者
Li, C. H. [1 ]
Zhang, X. F. [1 ]
Jin, H. [1 ]
Xiang, W. [1 ]
机构
[1] Huazhong Univ Sci & Technol, Sch Comp Sci & Technol, Wuhan 430074, Peoples R China
关键词
E-passport security; Extended Access Control; Identity-Based Cryptography; Safety/security in digital systems;
D O I
10.1016/j.ipl.2010.10.006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Extended Access Control (EAC) is a security mechanism specified to allow only authorized Inspection System (IS) to read sensitive biometric data such as fingerprints from e-passports. Although European Union EAC scheme offers more flexibility than Singapore scheme, there is clearly room for improvement. By adopting Identity-Based Cryptography (IBC) technology, a simple and secure EAC implementation scheme (IBC-EAC) is proposed. The authorization mechanism based on IBC is more trustable because the access right to sensitive data is granted directly to the IS through Authorized Smartcard. A new authentication protocol based on IBC is performed between the e-passport chip and the Authorized Smartcard. The protocol also provides an important contribution towards terminal revocation. By using IBC-EAC scheme, the complexity of deploying and managing PKI can be reduced. And the computational cost for e-passport to verify the certificate chain in EU-EAC scheme can be saved. (c) 2010 Elsevier B.V. All rights reserved.
引用
收藏
页码:26 / 30
页数:5
相关论文
共 12 条
[1]  
[Anonymous], TR03110 BSI FED OFF
[2]  
[Anonymous], PKI MACH READ TRAV D
[3]  
[Anonymous], TAGMRTD17WP11 ICAO
[4]  
[Anonymous], TR03110 BSI FED OFF
[5]  
[Anonymous], MACH READ TRAV DOC D
[6]  
[Anonymous], LNI
[7]  
[Anonymous], IEEE SECURITY PRIVAC
[8]  
[Anonymous], IDENTITY FRAUD THEFT
[9]   Identity-based encryption from the Weil pairing [J].
Boneh, D ;
Franklin, M .
SIAM JOURNAL ON COMPUTING, 2003, 32 (03) :586-615
[10]  
Pasupathinathan V, 2008, LECT NOTES COMPUT SC, V4991, P14