5 ms·
Cryptography could still prevent the usage of copies of valid passports. I.e. where you have all valid names and numbers on the front, but cannot copy the passp
by c00lio 3y ago
Cryptography could still prevent the usage of copies of valid passports. I.e. where you have all valid names and numbers on the front, but cannot copy the passport's secret key and digital signature.
- anticristi 3y agoWait! Is ePassport verification as advanced as to have a challenge-response protocol or similar?
- noodlesUK 3y agoYes. Modern passports use the data in the MRZ to support a protocol called PACE, which is essentially a password based key exchange. You can look up the spec in ICAO 9303. It’s really quite well designed. EU passports support a further level of mutual authentication in order to get the fingerprints, where the terminal is verified by the passport as well.
- iancarroll 3y agoPACE authenticates that the reader knows the MRZ data and derives a key for communication, but (AFAIK) does not prove the passport is real or original. A cloned passport would also know the MRZ data to complete BAC/PACE. There is a further step called Active Authentication where the reader sends the passport random data and it signs this data with a public key that can be verified as authentic.
- ipython 3y agoWithout active authentication, you can copy the electronic data from one valid passport to a cloned document. As far as I know, AA is not widely implemented and passports have ~10 year lifespans.