Author:
Suhaimi Ahmad Iqbal Hakim bin,Noordin Nurulhuda,Ya’kub Mohd Faizul bin
Abstract
Abstract
Malaysia was the 1st country in the world to issue biometric passports (e-Passport) in 1998. Recent years, a number of vulnerabilities in e-Passport have been identified in the first and second generation of e-Passports. These vulnerabilities can lead to crucial security issues. Due to lack of case studies conducted to review the Malaysian e-Passport, the objectives of this study are to identify the security risk in Malaysian e-Passport PKI and to recommend the feasible solution for future enhancement. A qualitative method was used in this study where a set of interview questions prepared and interviews been conducted to four participants. The data been analyzed using Thematic Analysis and presented based on risk assessment methodology in ISO 27000 series International Standards. The risk assessment consists of two approaches; risk analysis and risk evaluation. The risk analysis identified resource identification and valuation, risk identification and risk measurement of Malaysian e-Passport PKI. While in risk evaluation, it focuses on risk mitigation and prioritizing protection activities for future enhancement. The results reveal that the Cloning, Man in the Middle, Spoofing and server related issues are the risk of Malaysian e-Passport. For recommendation, the result is to implement Password Authenticated Connection Establishment (PACE) and follow ICAO standards. The significance of this research will help policy-makers to make better decision on the future direction of Malaysian e-Passport in order to ensure Malaysian citizens having secured e-Passport.
Subject
General Physics and Astronomy
Reference30 articles.
1. A Survey of Security and Privacy Issues in e-Passport Protocols;Avoine;ACM Computing Surveys,2016
2. epassport: Securing international contacts with contactless chips;Avoine,2008
3. Biometric passports (ePassports);Atanasiu,2010
4. A Survey on the evolution of cryptographic protocols in ePassports;Nithyanand,2009
5. Security and Privacy Issues in e-Passport;Juels,2005
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献