<?xml version="1.0" encoding="UTF-8"?>
<collection>
<dc:dc xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:invenio="http://invenio-software.org/elements/1.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd"><dc:identifier>doi:10.1049/iet-ifs.2017.0299</dc:identifier><dc:language>eng</dc:language><dc:creator>Rodríguez, R.J.</dc:creator><dc:creator>Garcia-Escartin, J.C.</dc:creator><dc:title>Security assessment of the Spanish contactless identity card</dc:title><dc:identifier>ART-2017-103610</dc:identifier><dc:description>The theft of personal information to fake the identity of a person is a common threat normally performed by individual criminals, terrorists, or crime rings to commit fraud or other felonies Recently, the Spanish identity card, which provides enough information to hire online products such as mortgages or loans, was updated to incorporate a near-field communication chip as electronic passports do. This contactless interface brings a new attack vector for criminals, who might take advantage of the radio-frequency identification communication to virtually steal personal information. In this study, the authors consider as case study the recently deployed contactless Spanish identity card assessing its security against identity theft. In particular, they evaluated the security of one of the contactless access protocol as implemented in the contactless Spanish identity card, and found that no defences against online brute-force attacks were incorporated. They then suggest two countermeasures to protect against these attacks. Furthermore, they also analysed the pseudo-random number generator within the card, which passed all the performed tests with good results.</dc:description><dc:date>2017</dc:date><dc:source>http://zaguan.unizar.es/record/71110</dc:source><dc:doi>10.1049/iet-ifs.2017.0299</dc:doi><dc:identifier>http://zaguan.unizar.es/record/71110</dc:identifier><dc:identifier>oai:zaguan.unizar.es:71110</dc:identifier><dc:relation>info:eu-repo/grantAgreement/ES/MINECO/TIN2014-58457-R</dc:relation><dc:relation>info:eu-repo/grantAgreement/ES/UZ/CUD2016-TEC-06</dc:relation><dc:identifier.citation>IET Information Security 11, 6 (2017), 386-393</dc:identifier.citation><dc:rights>All rights reserved</dc:rights><dc:rights>http://www.europeana.eu/rights/rr-f/</dc:rights><dc:rights>info:eu-repo/semantics/openAccess</dc:rights></dc:dc>

</collection>