Entrust Digital Signatures Help Protect ePassports

When the Department of State decided to move to digital passports -- also known as ePassports -- it also recognized there was an opportunity to add another layer of security to these credentials, and tapped Entrust Inc. to provide the public key infrastructure (PKI)-enabled digital signatures.

A function known as non-repudiation, the digital signature verifies that the digital credential has, in fact, been issued by the Department of State and that it has not been tampered with since its issuance. To date, the Department of State has surpassed the 18 million milestone mark for deploying the new ePassports.

"The digital signatures on the new passports illustrate how PKI technology is being used in a number of new applications, reinforcing PKI as the gold standard for digital security," said Entrust Chairman, President and CEO Bill Conner. "It's really a 'PKI 2.0' trend we're seeing in the market right now. More organizations are realizing the value and unprecedented scalability PKI technology affords them when deploying and managing security for digital identities and information -- especially on a mass scale like this."

Since August 2006 only ePassports have been issued in the United States. As security guidelines to travel between the United States, Mexico, Canada and the Caribbean now require a valid passport, the issuance of ePassports has risen dramatically. This increase is expected to continue, with an eventual production of 15 to 18 million ePassports annually.

"Along with the U.S., we have been able to help secure ePassports and national ID cards in Spain, Singapore, Saudi Arabia, New Zealand, Slovenia and others," Conner said. "This security feature can also help prevent these credentials from being counterfeited, which adds a greater level of assurance to both the border patrol officials, as well as the travelers themselves."

ePassport travel documents contain an electronic chip that stores sensitive personal information that can be verified against the data on the passport as well as against the individual at the border control point. Although U.S. ePassports currently store a digital facial image, the documents have the capability to securely include digitized photographs, fingerprints or other biometrics. To protect these assets, PKI is an integral technology for the security and verification infrastructure of ePassports. The Entrust Authority PKI portfolio is one of the leading solutions to support this capability.

The Department of State has employed a multilayered approach to protect the privacy of the information contained on the ePassport. In addition to a metallic cover that prevents skimming or eavesdropping of the information while the document is closed, Basic Access Control (BAC) technology is used to "unlock" the data on the chip. A PKI digital signature enables alteration or modification of the data on the chip to be detected and enables authorities to validate and authenticate the data.

Modular and fully integrated, the Entrust Authority PKI portfolio is built on the foundation of Entrust Authority Security Manager, the certification authority (CA) system responsible for issuing and managing digital identities. Optional components help organizations manage the entire lifecycle of PKI certificates. Approximately 1,000 government and commercial organizations have purchased Entrust PKI solutions since Entrust brought its first PKI to market in the 1990s.

On the horizon, the next generation of ePassport technology is already being considered. Enhanced security, known as Extended Access Control (EAC), provides an additional layer of security to control access to sensitive information, such as biometric fingerprints and iris scans on these next-generation ePassports. EAC also specifies protocols for authenticating the chip and inspection system to each other. Not based on the X.509 standard, EAC will leverage a different type of certificate known as a card verifiable (CV) certificate.

The EAC concept was introduced by the International Civil Aviation Organization (ICAO) in liaison with the International Organization for Standardization (ISO). EAC technical details, including certificate profiles and protocol specifications, are initially being defined by the Brussels Interoperability Group (BIG) for use within Europe. Entrust actively is participating in BIG as well as in the ISO Task Force on Security for ePassports. These next-generation ePassports, using EAC, will be required by all European Union (EU) Schengen member States by June 2009. Deployment mandates for the United States have yet to be determined.

Featured

  • Allegion, Comfort Technologies Implement Mobile Credentials at the Artisan Apartment Homes in Florida

    Artisan Apartment Homes, a luxury apartment complex in Dunedin, Florida, recently transitioned from mechanical keys to electronic locks and centralized system software with support from Allegion US, a leading provider of security solutions, technology and services, and Florida-based Comfort Technologies, which specializes in deploying multifamily access control, IoT devices and software management solutions. Read Now

  • Mall of America Deploys AI-Powered Analytics to Enhance Parking Intelligence

    Mall of America®, the largest shopping and entertainment complex in North America, announced an expansion of its ongoing partnership with Axis Communications to deploy cutting-edge car-counting video analytics across more than a dozen locations. With this expansion, Mall of America (MOA) has boosted operational efficiency, improved safety and security, and enabled more informed decision-making around employee scheduling and streamlining transportation for large events. Read Now

  • Security Industry Association Launches New “askSIA” AI Tool

    The Security Industry Association (SIA) has unveiled a brand-new SIA member benefit – askSIA, a conversational AI agent designed to help users get the most out of their SIA membership, easily access SIA resources and find the latest information on SIA’s training and courses, reports and publications, events, certification offerings and more. SIA members can easily find askSIA by visiting the SIA homepage or looking for the askSIA icon in the top left of webpages. Read Now

    • Industry Events
  • Industry Embraces Mobile Access, Biometrics and AI

    A combination of evolving workplace dynamics, technology innovation and new user expectations is changing how people enter and interact with physical spaces. Access control is at the heart of these changes. Combined with biometrics and AI, mobile access control has become increasingly crucial for deploying entry solutions that are seamless, secure and adaptive to user needs. Read Now

  • Sustainable Video Solution Delivered for Landmark City of London Office Development

    An advanced, end-to-end video solution from IDIS, with a focus on reducing waste and costs, has helped a major office development in the City of London align its security with sustainability objectives. Read Now

New Products

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.