Back to Search Start Over

Using the Estonian Electronic Identity Card for Authentication to a Machine

Authors :
Arnis Parsovs
Danielle Morgan
Source :
Secure IT Systems ISBN: 9783319702896, NordSec
Publication Year :
2017
Publisher :
Springer International Publishing, 2017.

Abstract

The electronic chip of the Estonian ID card is widely used in Estonia to identify the cardholder to a machine. For example, the electronic ID card can be used to collect rewards in customer loyalty programs, authenticate to public printers and self-checkout machines in libraries, and even unlock doors and gain access to restricted areas. This paper studies the security aspects of using the Estonian ID card for this purpose. The paper shows that the way the ID card is currently being used provides little to no assurance to the terminal about the identity of the cardholder. To demonstrate this, an ID card emulator is built, which emulates the electronic chip of the Estonian ID card as much as possible and is able to successfully impersonate the real ID card to the terminals deployed in practice. The exact mechanisms used by the terminals to authenticate the ID card are studied and possible security improvements for the Estonian ID card are discussed.

Details

ISBN :
978-3-319-70289-6
ISBNs :
9783319702896
Database :
OpenAIRE
Journal :
Secure IT Systems ISBN: 9783319702896, NordSec
Accession number :
edsair.doi...........4ef7a7d2205dd9230d5f7910e6188afa
Full Text :
https://doi.org/10.1007/978-3-319-70290-2_11