Biometric Passport: Security and Privacy Aspects of Machine Readable Travel Documents

Authors: Hesam Kolahan, Tejendra Thapaliya

Supervisor: Prof. Andreas Meier, Luis Teran

Biometric Passports


E-passports are widely deployed in most of the developed countries that stores the biometric information on a tiny Radio Frequency Identification (RFID) chip. The stored information is used to authenticate the identity of individual via wireless interface to reader. E-passport uses two technologies, RFID and Biometrics. The objective of the e-passport is to provide strong authentication, prevent identity fraud issues and border control. Even though, Biometrics is advanced authentication mechanism, it leads to many privacy and security issues. Major privacy and security issues on RFID chips were identified and analyzed. Similarly, Biometric security threats that applied to e-passport have been analyzed and some recommendations were provided. Cryptography technology and several protocols are used to countermeasure the threats and attacks.  Due to increase in standard of attack level and insufficient specification for e-passports are creating difficulties in providing security goals.


Table of Contents

1.      Introduction
1.1.       Objective and Problem Definition
2.      Biometrics
2.1.       Machine Readable Travel Document (MRTD)
2.2.       E-Passport
2.3.       Radio Frequency Identification (RFID)
2.4.       Chip Inside Symbol
3.      Privacy and Security Issues
3.1.       Eavesdropping
3.2.       Reverse Engineering
3.3.       Clandestine Scanning and Tracking
3.4.       Cloning
3.5.       Biometric Data-Leakage
3.6.       Cryptographic Weaknesses
3.7.       Skimming
4.      Biometric System Model
5.      Biometric Security Threats
6.      Cryptography in e-passports
6.1.       The ICAO specification
6.2.       Passive Authentication (PA)
6.3.       Active Authentication (AA)
6.4.       Basic Access Control (BAC)
6.5.       Extended Access Control (EAC)
6.6.       Cryptography Threats
7.      Discussions on Security and privacy risks with the E-Passport
8.      Recommendation
9.      Conclusion
10.    References



