4 ms·
I worked at a project on automated border gates a while back and those automated scanners are really interesting. They usually scan the document in several sta
by blensor 5y ago
I worked at a project on automated border gates a while back and those automated scanners are really interesting.
They usually scan the document in several stages using different light sources to check UV/ IR / visible light features and sometimes illuminated from different angles but usually with a fixed camera position.
This leads to the interesting effect that you could present different images in quick succession to show the correct image for each spectrum even if you don't have a document that can appear correct in all spectral ranges at once.
You can't obviously do that by hand but we ended up using a display (even a high dpi smartphone) that synced up to the scanning process for security testing.
[1] if you are interested
[1] https://ieeexplore.ieee.org/abstract/document/6975597 https://ieeexplore.ieee.org/abstract/document/6975597
- closeparen 5y agoInteresting that an automated scanner would care so much about the physical security measures. It’s not sufficient to look up the passport number to find the details it should contain, or check the digital signature?
- icegreentea2 5y agoI assume it would part of layered defense, and specifically targeting someone replicating credentials.
- deleted 5y ago[deleted]
- user5994461 5y ago>>> It’s not sufficient to look up the passport number to find the details it should contain, or check the digital signature? That would require access to the passport database of each country and 24/7 network connectivity. For border control in an airport, maybe it's possible to operate in these conditions. However the product certainly has more use cases.
- blensor 5y agoExactly. And there would be a lot more hurdles since countries generally don't give such access without good reason. Another issue would be reliability. Doing an attack on the network to break the verification backend would cause a fallback to manual border control which is a problem if your whole process is already relying on the automated gates and you have scaled back the available agents. Doing that during a time with very high demand would allow an "attacker" to use it to get more people through due to less attention of the border guards. If I remember correctly the usual timespan a border agent is considered to be attentive enough is 2 hours, at which point they would need to be rotated out, but if your demand has unexpectedly increased so much that you operate twice the manual gates you don't have the people for the normal rotation
- closeparen 5y agoI had no idea passport control would be offline in this day and age. TIL. Thanks!
- LorenPechtel 5y agoObservation: China, a few years back. The train system has been going from a paper ticket approach to a ID-based approach. (You've had to show ID to buy the paper tickets anyway.) They also work on a system where you scan your ticket upon leaving, also--it catches someone who rides further than they paid for. At the time some cities were fully converted and were willing to accept (with some difficulty, the scanners were picky!) our passports others only had the local ID readers. (The local ID has embedded RFID, you just touch it to the scanner plate and the gate opens.) However, others were not--a couple of times security simply let us out without doing any sort of check.
- rahimnathwani 5y agoChecking a digital signature (as proposed by GP) would not require database access or network connectivity. If the biographic details were cryptographically signed, you'd need only a public key for each passport-issuing country. I'm not sure how you'd deal with key revocation in situations like this.
- blensor 5y agoNot sure how much I am able to say, it's already several years old but the bottom line is there are so many different documents that it's not always possible to check the digital signature, either because it does not have a digital signature (we are not only talking about passports but all possible documents), can't read it because the chip is damaged, or has no way to verify the signature because the scanner does not have the certificate chain. And there are attacks where you simply forward the communication over the network to a remote reader so that the gate thinks it's talking to a real passport but the physical passport is somewhere else. And older passports use weaker hash functions to verify the integrity of the data
- alexcnwy 5y agoVery cool. Can you give some more detail on how you process the different images?
- blensor 5y agoWell we cheated a bit there as we used the images the document scanner recorded and put that on a phone. So we had exactly the images the scanner expected, but it is not an unreasonable assumption that a document forger would have access to such a device. In the final version we had it running on an Android device. We did know the exact scanning sequence and timing (first IR, second visible light, third UV exposure) so the phone showed the IR image by default and used the brightness sensor to detect the first flash of the recording, then an internal timer ran to determine when to switch to the second and third image. If I recall correctly the digital part was done with JMRTD [1] flashed to an empty smart card The certificate check obviously would have failed, but as mentioned in a comment above that is not always an issue. [1] https://jmrtd.org/about.shtml https://jmrtd.org/about.shtml