Electronic Identity Documents Security During the Document Transfer Phase

Вантажиться...
Ескіз

Дата

2025

Науковий керівник

Назва журналу

Номер ISSN

Назва тому

Видавець

КПІ ім. Ігоря Сікорського

Анотація

The subject matter of the article is security of electronic documents. Electronic documents security importance rises with the creation of new international standards for electronic identification (eID) and their adoption across the world. The eID security is crucial for both citizens and the government to ensure mutual trust and provide confidentiality, integrity and availability. Previous researches provide either a too general view on eID security without a required level of technical details, or analyze deeply a single specific domestic solution that doesn’t have worldwide interoperability. The goal is to evaluate security for the main electronic documents implementations compliant with the international standards, perform their comparative analysis, and provide security improvements. The tasks to be solved are to provide the eID security evaluation framework for assessing and comparing different implementation options of electronic identification solutions. Electronic identification security was analyzed only in the document transfer phase, and security targets like the holder documents storage authentication, the eavesdropping avoidance, the document cloning prevention, and verifier authentication were considered. The Electronic Machine Readable Travel Document (eMRTD), according to the ICAO Doc 9303, and the Mobile Driver License (mDL), according to the ISO/IEC 18013-5, solutions' security were analyzed. The main used method is a comparative analysis. Comparative analysis was provided for these implementation options to illustrate differences in reaching the same security targets, evaluate the overall security level, and emphasize existing trade-offs. The following results were obtained: security improvements were proposed to mitigate security threats like post-quantum cryptography attacks, attacks on the Diffie-Hellman key exchange, and hash collision attacks. Conclusions: Study findings can be used to improve the next revisions of ICAO of ISO/IEC specifications for electronic identification or to consider in the security design in a domestic server-based solution.

Опис

Ключові слова

electronic identification, eID, eMRTD, mDL, security, PQC, data security, cyber threats, електронна iдентифiкацiя особи, електронний машиннозчитуваний паспорт, мобiльне посвiдчення водiя, захист електронних документiв, атаки пiд час передачi iнформацiї, постквантова криптографiя, iнформацiйна безпека, системи шифрування

Бібліографічний опис

Leliak, A. V. Electronic Identity Documents Security During the Document Transfer Phase / Leliak A. V., Astrakhantsev A. A. // Вісник НТУУ «КПІ». Радіотехніка, радіоапаратобудування : збірник наукових праць. – 2025. – Вип. 102. – С. 66-82. – Бібліогр.: 43 назв.

ORCID