Paper published in a book (Scientific congresses, symposiums and conference proceedings)
Breaking Unlinkability of the ICAO 9303 Standard for e-Passports using Bisimilarity
Horne, Ross James; Mauw, Sjouke; Smith, Zachary Daniel et al.
2019In Breaking Unlinkability of the ICAO 9303 Standard for e-Passports using Bisimilarity
Peer reviewed
 

Files


Full Text
esorics-2019-unlinkability.pdf
Author postprint (254.91 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Security Protocols; e-passports; bisimilarity
Abstract :
[en] We clear up confusion surrounding privacy claims about the ICAO 9303 standard for e-passports. The ICAO 9303 standard includes a Basic Access Control (BAC) protocol that should protect the user from being traced from one session to another. While it is well known that there are attacks on BAC, allowing an attacker to link multiple uses of the same passport, due to differences in implementation; there still remains confusion about whether there is an attack on unlinkability directly on the BAC protocol as specified in the ICAO 9303 standard. This paper clarifies the nature of the debate, and sources of potential confusion. We demonstrate that the original privacy claims made are flawed, by uncovering attacks on a strong formulation of unlinkability. We explain why the use of the bisimilarity equivalence technique is essential for uncovering our attacks. We also clarify what assumptions lead to proofs of formulations of unlinkability using weaker notions of equivalence. Furthermore, we propose a fix for BAC within the scope of the standard, and prove that it is correct, again using a state-of-the-art approach to bisimilarity.
Disciplines :
Computer science
Author, co-author :
Horne, Ross James ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Mauw, Sjouke ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Smith, Zachary Daniel ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Other collaborator :
Filimonov, Ihor;  University of Luxembourg > Master's Student
External co-authors :
no
Language :
English
Title :
Breaking Unlinkability of the ICAO 9303 Standard for e-Passports using Bisimilarity
Publication date :
23 September 2019
Event name :
The European Symposium on Research in Computer Security
Event organizer :
University of Luxembourg
Event place :
Luxembourg, Luxembourg
Event date :
from 23-09-2019 to 27-09-2019
Audience :
International
Main work title :
Breaking Unlinkability of the ICAO 9303 Standard for e-Passports using Bisimilarity
Pages :
18
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Available on ORBilu :
since 15 January 2020

Statistics


Number of views
71 (5 by Unilu)
Number of downloads
191 (3 by Unilu)

Scopus citations®
 
12
Scopus citations®
without self-citations
7
OpenCitations
 
4
WoS citations
 
8

Bibliography


Similar publications



Contact ORBilu