This paper presents AttApp, a novel mechanism for attestation in Authenticated Key Exchange + Secure Channel (AKE+SC) electronic identification (eID) schemes. AttApp enhances auditability and enables the use of AKE+SC in scenarios that require proof of authentication, such as Know Your Customer compliance. By leveraging a Trusted Execution Environment, AttApp ensures the integrity of authentication attestations while mitigating insider threats. Furthermore, it is specifically designed for deployment on resource-constrained Security Microcontrollers (ICCs). We implement AttApp as a JavaCard applet, demonstrating its feasibility and evaluating its performance on commercially available ICCs. The key contributions of this work include (i) a novel attestation framework for eID schemes based on Extended Access Control as an instance of AKE+SC, (ii) a JavaCard-based implementation compatible with existing ICCs, (iii) a security analysis of the proposed approach, and (iv) an empirical assessment of its performance on real-world hardware.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Attestation of Electronic Identification Schemes Based on Secure Channels Through Security Microcontrollers

  • Stefan Genchev,
  • Lars Wüstrich,
  • Georg Carle

摘要

This paper presents AttApp, a novel mechanism for attestation in Authenticated Key Exchange + Secure Channel (AKE+SC) electronic identification (eID) schemes. AttApp enhances auditability and enables the use of AKE+SC in scenarios that require proof of authentication, such as Know Your Customer compliance. By leveraging a Trusted Execution Environment, AttApp ensures the integrity of authentication attestations while mitigating insider threats. Furthermore, it is specifically designed for deployment on resource-constrained Security Microcontrollers (ICCs). We implement AttApp as a JavaCard applet, demonstrating its feasibility and evaluating its performance on commercially available ICCs. The key contributions of this work include (i) a novel attestation framework for eID schemes based on Extended Access Control as an instance of AKE+SC, (ii) a JavaCard-based implementation compatible with existing ICCs, (iii) a security analysis of the proposed approach, and (iv) an empirical assessment of its performance on real-world hardware.