140 likes | 335 Views
Technical Report. PKI for Machine Readable Travel Documents offering ICC read-only access. TAG_15 Montreal, 2004-05-18 Tom Kinneging. Authenticity and Integrity. Document Security Object Standardized data structure (RFC3369) Containing hash-representations of LDS data groups
E N D
Technical Report PKI for Machine Readable Travel Documents offering ICC read-only access TAG_15 Montreal, 2004-05-18 Tom Kinneging
Authenticity and Integrity • Document Security Object • Standardized data structure (RFC3369) • Containing hash-representations of LDS data groups • Digitally signed by issuing State
Document Security Object LDS SOD Data Group 1 (MRZ) Hash DG_1 Data Group 2 (Encoded Face) Hash DG_2 Data Group 3 (Encoded Finger) Hash DG_3 Data Group 4 (Encoded Iris) Hash DG_5 Data Group 5 (Displayed Face) Digital Signature Data Group 6 (Future use) Data Group 7 - 15 Data Group 16 (Persons to notify)
Key Management • Document Signer Certificates • Country Signing CA Certificates • Certificate Revocation • ICAO Public Key Directory
Document Signer Certificate Country Signing CA Certificate Key Management Country Signing CA Document Signer 1 1 2 Issue & sign Issue & Sign Sign SOD Hash DG_1 1 2 Hash DG_2 Hash DG_3 Hash DG_5 Digital Signature Document Security Object Inspection system MRTD chip
Additional options • Basic Access Control • Active Authentication • Securing additional biometrics
Basic Access Control • MRZ based key derivation • Skimming • Access to chip data • Eavesdropping • Secure communications chip / reader
Basic Access Control 10011101111001 Inspection system
Active Authentication • Chip Substitution • Data Copying • Document’s Key pair
Active Authentication LDS SOD Data Group 1 (MRZ) Hash DG_1 Data Group 2 (Encoded Face) Hash DG_2 Data Group 3 (Encoded Finger) Hash DG_3 Data Group 4 (Encoded Iris) Hash DG_5 Data Group 5 (Displayed Face) Hash DG_15 Data Group 6 (Future use) Digital Signature Data Group 7 - 14 Data Group 15 (AA Public Key) AA Private Key Data Group 16 (Persons to notify)
Next steps • Implementation experiences • Further development
Frequently Asked Questions • TAG-MRTD-WP/10 • Keep up-to-date
Action by the TAG/MRTD The TAG/MRTD is invited to endorse the Technical Report, “PKI for Machine Readable Travel documents Offering ICC Read-only Access”, Version 1.0.