Identity Document Skimming Resistance via Segmented Cryptography
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity documents with machine-readable electronic chips face risks of data leakage and fraud due to inadequate security measures, particularly with RFID interfaces, and existing solutions fail to provide a universally accepted and compliant security standard across different countries.
Innovation Solution
A secured identity document with an externally readable chip storing a cryptographic configuration and a private key, along with an optically readable area encoding both non-ciphered and ciphered cryptographic data, allows for secure communication without terminal authentication, using a contactless interface and cryptographic key pair for authentication and secure channel establishment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If RFID interface is used for contactless communication with the chip, then ease of operation is improved, but security against skimming attacks deteriorates
Solution Approach 1:
The cryptographic configuration is segmented into two distinct forms: a non-ciphered version for optical readability and a ciphered version stored in the chip. This segmentation allows the system to provide contactless optical reading convenience while maintaining cryptographic security through the separate ciphered storage in the chip that requires proper authentication.
Solution Approach 2:
The optically readable area acts as an intermediary between the physical document and the cryptographic verification process. It provides machine-readable cryptographic configuration data that can be verified optically without requiring direct chip access, thereby preventing skimming attacks while maintaining ease of operation.
2Ease of operation
If cryptographic configuration is stored in non-ciphered form for optical reading, then ease of operation is improved, but security against fraud deteriorates
Solution Approach 1:
The cryptographic configuration is divided into non-ciphered data for optical display and ciphered data stored in the chip. The non-ciphered portion enables optical reading and verification without exposing the actual cryptographic keys, while the ciphered portion in the chip prevents fraudulent access.
Solution Approach 2:
Different parts of the cryptographic configuration have different security properties: the optically readable area contains non-ciphered data suitable for verification, while the chip contains ciphered data with higher security. This local differentiation of security quality allows both optical reading and fraud prevention.
3Object-affected harmful factors
If ciphered cryptographic configuration is stored in the chip, then security against fraud is improved, but device complexity increases
Solution Approach 1:
The cryptographic configuration is prepared in advance in both non-ciphered and ciphered forms during document issuance. The non-ciphered version is optically readable and the ciphered version is stored in the chip, eliminating the need for complex real-time conversion or processing during verification.
4Reliability
If aluminum shielding is applied to the chip, then security against RFID skimming is improved, but ease of operation deteriorates
Solution Approach 1:
The optically readable area serves as an intermediary that provides verification capability without requiring physical access to the chip. Users can verify the cryptographic configuration optically through the readable area without opening the document or exposing the shielded chip.
Data Source
AI summary
The invention relates to a secured identity document having an externally readable chip storing a cryptographic configuration of the chip, defining the cryptographic security levels supported by the chip, for establishing a secure communication with a controlling terminal, storing a private key of a cryptography key pair and adapted to cipher data based on the stored private key; a support to which the chip is fastened, the support having a machine optically readable area, the data encoded in this area including the cryptographic configuration of the chip for establishing a secure communication with a controlling terminal in non ciphered form and the cryptographic configuration of the chip ciphered based on said private key.


