Dynamic Protocol Selection for Secure Travel Document Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Travel documents using the Basic Access Control (BAC) protocol are insecure due to its symmetric cryptography mechanism, making them vulnerable to attacks, and there is a need to secure both BAC and PACE protocols to ensure the privacy and anonymity of document holders.
Innovation Solution
An electronic device with means to block the less secure BAC protocol while allowing the more secure PACE protocol to access the same secure data, using a mechanism that can be activated or deactivated based on specific conditions such as a reference date or usage thresholds, ensuring only the PACE protocol is used after a certain date or when security thresholds are met.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the BAC protocol is used for authentication in travel documents, then upward compatibility and ease of operation are maintained, but security is compromised due to symmetric cryptography and MRZ-based keys
Solution Approach 1:
The patent implements dynamic protocol selection where the authentication protocol is not fixed but can switch between BAC and PACE based on the reader's capabilities. The system determines which protocol to use during runtime based on compatibility requirements and security considerations, making the security mechanism adaptive rather than static.
Solution Approach 2:
The patent changes the cryptographic parameters used for authentication based on the selected protocol. When PACE is chosen, asymmetric cryptography with certificate-based keys is used instead of symmetric cryptography with MRZ-derived keys, fundamentally changing the security parameters while maintaining protocol functionality.
2Adaptability or versatility
If both BAC and PACE protocols are supported during migration period, then upward compatibility is maintained, but the system becomes vulnerable to attacks targeting the less secure BAC protocol
Solution Approach 1:
The patent introduces an intermediary selection mechanism that evaluates reader capabilities and determines the appropriate protocol. This intermediary layer (the protocol selection logic) mediates between the two authentication protocols, choosing PACE when the reader supports it to avoid vulnerability, while still maintaining the ability to use BAC for compatibility.
Solution Approach 2:
Instead of defaulting to the less secure BAC protocol for compatibility and hoping for PACE support, the patent inverts the approach by prioritizing PACE when available and only falling back to BAC when absolutely necessary. This reversal of the default protocol selection strategy reduces exposure to attacks.
3Reliability
If the PACE protocol is mandated for all travel documents from end of 2014, then security is improved through asymmetric cryptography, but device complexity increases due to dual protocol implementation
Solution Approach 1:
The patent implements a universal authentication framework where a single authentication module can handle both BAC and PACE protocols. The system is designed with multi-functionality, allowing the same hardware and software infrastructure to support multiple authentication methods, thereby reducing the actual complexity increase despite supporting dual protocols.
Data Source
Figure 1A~1C
Figure 2A~2B
Figure 2C
AI summary
The device (102) has a memory (MEM) for storing a secure data (DS) i.e. biometric data, and a communication unit for enabling communication with a reader (1) for application of an authentication protocol e.g. VAT protocol, and another authentication protocol e.g. PACE protocol. Each of the authentication protocol is operable and able to reach the secure data. A blocking unit is arranged to block the former protocol without blocking the latter protocol on reception of information. An error message is sent to the reader if the former protocol is blocked. An independent claim is also included for a process for securing an electronic device.