Estonian Electronic Identity Card: Security Flaws in Key Management
Arnis Parsovs
摘要
The Estonian electronic identity card (ID card) is considered to be one of the most successful deployments of smart cardbased national ID card systems in the world. The publickey cryptography and private keys stored on the card enable Estonian ID card holders to access e-services, give legally binding digital signatures and even cast an i-vote in national elections. In this paper, we describe several security flaws found in the ID card manufacturing process. The flaws have been discovered by analyzing public-key certificates that have been collected from the public ID card certificate repository. In particular, we find that in some cases, contrary to the security requirements, the ID card manufacturer has generated private keys outside the chip. In several cases, copies of the same private key have been imported in the ID cards of different cardholders, allowing them to impersonate each other. In addition, as a result of a separate flaw in the manufacturing process, corrupted RSA public key moduli have been included in the certificates, which in one case led to the full recovery of the corresponding private key. This paper describes the discovery process of these findings and the incident response taken by the authorities.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper3
- Flip Feng Shui: Hammering a Needle in the Software StackKaveh Razavi, Ben Gras, Erik Bosman, Bart Preneel 等USENIX Security 2016 · 被引用 306 次
- The Return of Coppersmith's Attack: Practical Factorization of Widely Used RSA ModuliMatús Nemec, Marek Sýs, Petr Svenda, Dusan Klinec 等CCS 2017 · 被引用 147 次
- A Touch of Evil: High-Assurance Cryptographic Hardware from Untrusted ComponentsVasilios Mavroudis, Andrea Cerulli, Petr Svenda, Dan Cvrcek 等CCS 2017 · 被引用 30 次
相关 Paper
- Open to a fault: On the passive compromise of TLS keys via transient errorsGeorge Arnold Sullivan, Jackson Sippe, Nadia Heninger, Eric WustrowUSENIX Security 2022
- How not to prove your election outcomeThomas Haines, Sarah Jamie Lewis, Olivier Pereira, Vanessa TeagueS&P 2020 · 被引用 57 次
- The Million-Key Question - Investigating the Origins of RSA Public KeysPetr Svenda, Matús Nemec, Peter Sekan, Rudolf Kvasnovský 等USENIX Security 2016 · 被引用 38 次
- On the Unnecessary Complexity of Names in X.509 and Their Impact on ImplementationsYuteng Sun, Joyanta Debnath, Wenzheng Hong, Omar Chowdhury 等FSE 2025
- Reversing, Breaking, and Fixing the French Legislative Election E-Voting ProtocolAlexandre Debant, Lucca HirschiUSENIX Security 2023
