Content deleted Content added
→Security: ce Tags: Mobile edit Mobile web edit Advanced mobile edit |
→Security: ce Tags: Mobile edit Mobile web edit Advanced mobile edit |
||
Line 13:
In other words, the data used as an encryption key has low [[entropy]], meaning that guessing the session key is possible via a modest [[brute force attack]].
This effect increases when passport numbers are issued sequentially or contain a redundant [[checksum]]. Both are proven to be the case in passports issued by the [[Netherlands]]
The [[German passport]] serial-number format (previously 10-digit, all-numeric, sequentially assigned) was modified on 1 November 2007, in response to concerns about the low entropy of BAC session keys. The new 10-character serial number is alphanumeric and generated with the help of a specially-designed [[block cipher]], to avoid a recognizable relationship with the expiry date and increase entropy. In addition, a public-key based [[extended access control]] mechanism is now used to protect any information in the RFID chip that goes beyond the minimum ICAO requirements, in particular fingerprint images.
|