Welcome | Sign In
ECommerceTimes.com
Privacy

US Begins Rollout of RFID Passports

Print Version
E-Mail Article
Reprints
US Begins Rollout of RFID Passports

The United States this week announced that it has begun to issue passports that employ RFID technology to store holders' personal information. The U.S. State Department said it has developed a multi-layered security approach for using the passports, which are aimed at protecting citizens from identity theft and privacy breaches.


Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!

The United States government began issuing new electronic passports this week that include radio frequency identification technology (RFID) to store citizens' personal information.

The U.S. State Department referred in its announcement to the use of biometric technology and "a contactless chip," the latter a controversial device that will be embedded in each of the new passports.

At the Black Hat hacker conference in Las Vegas last month, a security consultant demonstrated a hack of such a passport and also described a relatively simple and inexpensive process for cloning one. The demonstration troubled many who have questioned the necessity for RFID technology, which transmits data wirelessly, in such personal documents.

Multiple Measures

The State Department, however, highlighted its "multi-layered" approach to protecting the new e-passports and mitigating the chances of the electronic data being "skimmed" -- i.e., intercepted or stolen.

First, the government said a metallic material in the passport cover and spine will prevent skimming when the passport is not open.

Second, the e-passport relies on Basic Access Control (BAC) technology, which requires that a special key on the passport be electronically read prior to data access being granted.

The U.S. also said a randomized unique identification (RUID) feature of the new e-passports will diminish the risk that its holder could be tracked.

Finally, an electronic signature, or PKI, will prevent alteration or modification of the information on the chip and will allow authorities to validate and authenticate it.

"The Department of State is confident that the new e-passport, including biometrics and other improvements, will take security and travel facilitation to a new level," said a Department statement.

Defeating the Purpose

In response to longstanding criticism over the privacy and security risks of passports using RFID technology, the government has said the new e-passports are consistent with global specifications from the International Civil Aviation Organization (ICAO). More importantly, officials have indicated there will be some exchange of information required prior to RFID transmission of data, according to Electronic Frontier Foundation (EFF) Senior Staff Attorney Lee Tien.

The added measures may help alleviate some security concerns. However, Tien told TechNewsWorld, if an exchange of information or other personal contact is required, it would defeat the purpose of the RFID technology.

"It's a solution in search of a problem," he said.

Inherent Risk

Tien and other RFID researchers and security experts have questioned the need for RFID in passports.

The over-the-air signals that will be transmitted from the passports may provide all the incentive that attackers need to attempt hacking the technology.

"For people who know what they're doing, [such a hack] is not really hard," Tien said.

Tien also expressed concern that the e-passport rollout may breed more trust in unattended transactions, which may actually serve to increase privacy and security dangers.


Print Version E-Mail Article Reprints More by Jay Lyman


Related News Alerts

Hacker Activate Alert | Search Archives

More by Jay Lyman

Open Source Developer Dumps Novell Over Microsoft Deal
December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux
December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0
December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network