Biometric Passport from a Security Perspective
Abstract
Biometric passports, also known as ePassports, benefit from cryptographic mechanisms to guarantee their unforgeability. Since the first release of the ePassport standard, in 2004, the security of the biometric passports have been significantly improved. In this talk, we will review the cryptographic mechanisms used by the biometric passport and we will detail the past and current security weaknesses in terms of design, implementation, and use of these mechanisms. This talk will so address the following topics: security, cryptography, privacy, and contactless devices.
Full text
Biometric Passport from a Security Perspective Gildas Avoine INSA Rennes/IRISA Institut Universitaire de France
SUMMARY Passport Primer Memory Content Cryptographic Mechanisms defined by ICAO Additional Cryptographic Mechanisms Vulnerabilities Conclusion and Further Reading
PASSPORT PRIMER Passport Primer Memory Content Cryptographic Mechanisms defined by ICAO Additional Cryptographic Mechanisms Vulnerabilities Conclusion and Further Reading
History 1944: International Civil Aviation Organization (ICAO). 1968: ICAO starts working on MRTD. ◦“A Machine Readable Travel Document (MRTD) is an international travel document (eg. a passport or visa) containing eye-and machine-readable data.” (ICAO). 1980: Standard DOC 9303 (ISO/IEC 7501 since 1991). ◦Includes an OCR Machine Readable Zone. Gildas Avoine Biometric Passport from a Security Perspective 4
History 1988: Securing passports with chip: Davida & Desmedt Eurocrypt’88. 1998: First (not ICAO-compliant) electronic passports in Malaysia. 1998: ICAO initiated some work on biometric identification systems and associated means. 2004: ICAO released a new version of DOC 9303, endorsed by ISO/IEC 7501, that defines passports with biometrics and contactless Integrated Circuit (IC), so-called ePassport. Gildas Avoine Biometric Passport from a Security Perspective 5
Integrated Circuit IC is contactless. IC does not contain any battery. IC has a microprocessor. Communication range is about 10 cm. Memory (EEPROM) is about 32KB. IC is compliant ISO 14443,ISO 7816. Gildas Avoine Biometric Passport from a Security Perspective 6
MEMORY CONTENT Passport Primer Memory Content Cryptographic Mechanisms defined by ICAO Additional Cryptographic Mechanisms Vulnerabilities Conclusion and Further Reading
Machine Readable Zone Line 1 ◦Document type ◦Issuing country ◦Holder name Line 2 ◦Document number (+ checksum) ◦Nationality ◦Date of birth (+ checksum) ◦Gender ◦Date of expiry (+ checksum) ◦Options ◦Composite check digit Gildas Avoine Biometric Passport from a Security Perspective 8
Memory Content Data groups (DG). ◦Access requires an authentication: BAC or EAC. List of data groups (COM). Cryptographic material: certificate, signature and hashes (SOD). Gildas Avoine Biometric Passport from a Security Perspective 9
Certificates in the ICAO Directory RSA Exponent Number of certificates 3 191 44591 1 65427 1 65537 2937 Total 3130 RSA Exponents in DS Certificates RSA Exponent Number of certificates 3 9 38129 2 43459 1 65537 112 Total 124 RSA Exponents in CSCA Certificates Gildas Avoine Biometric Passport from a Security Perspective 16
Certificates in the ICAO Directory Revoked DS Certificates Country Nb Revoked Certificates No Reason Key Compromise Superseded Cessation Unspecified New Zealand 2 2 Malaysia 3 3 AU 4 1 2 1 USA 3 1 2 UK 724 724 Canada 15 7 8 UNO 3 3 Singapore 6 3 3 Total 760 17 5 2 12 724 Gildas Avoine Biometric Passport from a Security Perspective 17
Active Authentication The Active Authentication is an optional security mechanism. Aim is to prove that EF.SOD belongs to the authentic passport, i.e. it is not a cloned one. Two-pass CR protocol ISO 9796-2 DSS 1 (RSA,DSA,ECDSA). Passport’s public key is stored in DG15 (encoded as RFC 3280). Gildas Avoine Biometric Passport from a Security Perspective 18
Active Authentication Protocol Reader (IFD) Passport (ICC) Generate M2 M2 −−−−−−−−−−−−−→ Create T Generate M1of LM1bits M=M1kM0 2 H= hash(M) F=6AkM1kHkT S= ENCPrK(F) S ←−−−−−−−−−−−−− Decrypt S0with PuKDG15 D= hash(M0 1kM2) Check if D=H0 IFD: InterFace Device ICC: Integrated Circuit Card Gildas Avoine Biometric Passport from a Security Perspective 19
Basic Access Control General View Reader MAC Key Kr, Kp Basic Access Control Secure Messaging Encryption Key Session Encryption Key Session MAC Key MRZ Expiration Date Birth Date Passport Number Reader Passport Authenticated Query Encrypted Data Passport Cp a = ENC(Cp, Cr, Kr), MAC(a) b = ENC(Cp, Cr, Kp), MAC(b) Gildas Avoine Biometric Passport from a Security Perspective 20
Basic Access Control Protocol Reader (IFD) Passport (ICC) Generate RNDICC RNDICC ←−−−−−−−−−−−−− Generate RNDIFD Generate KIFD S= RNDIFDkRNDICCkKIFD EIFD = ENCKENC (S) MIFD = MACKMAC (EIFD) EIFDkMIFD −−−−−−−−−−−−−→ Check MAC Decrypt EIFD If RND0 ICC = RNDICC Generate KICC R= RNDICCkRND0 IFDkKICC EICC = ENCKENC (R) MICC = MACKMAC (EICC) EICCkMICC ←−−−−−−−−−−−−− Kseed =KIFD ⊕KICC Kseed =KIFD ⊕KICC Calculate KSENC Calculate KSENC Calculate KSMAC Calculate KSMAC Calculate SSC Calculate SSC Gildas Avoine Biometric Passport from a Security Perspective 21
Basic Access Control Standards Three-pass CR protocol according to ISO 11770-2 Key Establishment Mechanism 6, 2-key 3DES as block cipher. Nonces should be 8-byte long. Encryption done using 3DES in CBC mode with zero-IV according to ISO 11568-2. A cryptographic checksum is calculated over: ISO 9797-1 MAC Algorithm 3 (i.e. Retail-MAC), based on DES, zero-IV, ISO 9797-1 Padding Method 2. Encryption and MAC keys derived from the MRZ using SHA-1. Gildas Avoine Biometric Passport from a Security Perspective 22
Secure Messaging Algorithms and Standards The encryption uses 3DES in CBC mode with a zero IV, and a padding compliant with ISO/IEC 9797-1 padding method 2. The MAC is computed using ISO/IEC 9797-1 MAC algorithm 3 with DES, a zero IV, and the ISO/IEC 9797-1 padding method 2. Before the MAC is computed, the Send Sequence Number is incremented and prepended to the ciphertext. The original value for SSD is the concatenation of the 4 less significant bytes of each RNDICC and RNDIFD. Gildas Avoine Biometric Passport from a Security Perspective 23
Basic Access Control and Secure Messaging Key Derivation Kseed =trunc16(SHA-1 (MRZ info)) or (Kr ⊕Kp). Set D=Kseed ||00000001. Compute H= SHA-1(D). First 16 bytes of Hare set to the 2-key 3DES KENC . Set D=Kseed ||00000002. Compute H= SHA-1(D). First 16 bytes of Hare set to the 2 DES keys KMAC . Adjust the parity bits of DES keys. Gildas Avoine Biometric Passport from a Security Perspective 24
ADDITIONAL CRYPTOGRAPHIC MECHANISMS Passport Primer Memory Content Cryptographic Mechanisms defined by ICAO Additional Cryptographic Mechanisms Vulnerabilities Conclusion and Further Reading
VULNERABILITIES Passport Primer Memory Content Cryptographic Mechanisms defined by ICAO Additional Cryptographic Mechanisms Vulnerabilities Conclusion and Further Reading
Vulnerabilities Five vulnerabilities were identified so far in the literature. Vulnerabilities on the protocol designs or their implementation. Issues related to the certificates are not discussed here. None of them allows an adversary to forge a passport. ◦Recognition of a batch of passports (e.g., country). ◦Recognition of an individual passport. ◦Obtaining a proof of presence. ◦Obtaining the data contained in the passport. Gildas Avoine Biometric Passport from a Security Perspective 33
1/5 MRZ Low Entropy Fields No information Country known Visual access Document number 1.02 ×1014 from 6.76 ×108 – to 104 Date of birth 36525 days – 1825 days Date of expiration 3652.5 days from 3652.5 days – to 1250 days Total No information Country known Visual access Country+Visual 1.36 ×1022 from 9.02 ×1016 6.8×1020 from 4.51 ×1015 to 4.57 ×1011 to 2.28 ×1010 73.52 bits from 56.32 bits 69.20 bits from 52.00 bits to 38.73 bits to 34.41 bits Gildas Avoine Biometric Passport from a Security Perspective 34
2/5 Response-Time Vulnerability When the reader sends (Ciphertext, MAC) during BAC, the passport recomputes MAC and compares it to the received one. If they do not match, the passport sends an error message. Otherwise it decrypts Ciphertext and check if RND0 ICC = RNDICC If they do not match the passport sends an error mesage. Otherwise the BAC process continues. Decrypting ciphertext and comparing nonces takes milliseconds. This discloses if BAC failed at the MAC comparison (wrong key) or at nonces comparison (correct key but unexpected nonce). Chothia and Smirnov also noticed that old French passports send a different error message when the BAC failed. Gildas Avoine Biometric Passport from a Security Perspective 35
3/5 Fingerprinting the Passport Error messages. Result of the select command (can be used before BAC). Answer to select (ATS) depends on the implementation. UID (random or not). Response time to APDUs depends on the implementation. Physical layer characteristics. Gildas Avoine Biometric Passport from a Security Perspective 36
4/5 MRZ Lookup Table (Italian Passport) A vulnerability pointed out by Sportiello targets old generations of Italian passports. By manipulating the get challenge command (LEset to 01), it is possible to force the passport to send a 8-byte challenge with the 7 less significant bytes set to 00. Probability that a given nonce appears is 1/28. Perform a brute force attack on the MRZ space (CPA). Precomputations are possible because it is a chosen plaintext attack, encrypted with 3DES in CBC mode with an IV = 0 and a key KENC derived from the MRZ. Gildas Avoine Biometric Passport from a Security Perspective 37
4/5 MRZ Lookup Table (Italian Passport) Reader MITM ePassport Get 8-byte challenge −−−−−−−−−−−−−→ 1 Get 1-byte challenge −−−−−−−−−−−−−→ RNDICC =NNk{0x00}7 RNDICC0 ←−−−−−−−−−−−−− if RNDICC06= 0x00 : jump to 1 RNDICC={0x00}8 ←−−−−−−−−−−−−− Calculate S EIFD = ENCKENC (S) MIFD = MACKMAC (EIFD) EIFDkMIFD −−−−−−−−−−−−−→ EIFDkMIFD −−−−−−−−−−−−−→ Calculate R EICC = ENCKENC (R) MICC = MACKMAC (EICC) EICCkMICC ←−−−−−−−−−−−−− Lookup for KENC where : ENCKENC ({0x00}8) = EICC EICCkMICC ←−−−−−−−−−−−−− ... ... ... Gildas Avoine Biometric Passport from a Security Perspective 38
5/5 Early Active Authentication There exists passports that accept to execute AA before BAC. Signature evidence. Traceability attacks due to the RSA modulus. Gildas Avoine Biometric Passport from a Security Perspective 39
CONCLUSION AND FURTHER READING Passport Primer Memory Content Cryptographic Mechanisms defined by ICAO Additional Cryptographic Mechanisms Vulnerabilities Conclusion and Further Reading
Conclusion ICAO’s passport is a pretty well-defined secure application. Complex security mechanisms. Security weaknesses due to misuse and short time-to-market. Security level is improved over time. Avoine et al., A Survey of Security and Privacy Issues in the ePassport Protocols, ACM Computing Surveys, 2016. Gildas Avoine Biometric Passport from a Security Perspective 41