Attestation of Electronic Identification Schemes Based on Secure Channels Through Security Microcontrollers
摘要
This paper presents AttApp, a novel mechanism for attestation in Authenticated Key Exchange + Secure Channel (AKE+SC) electronic identification (eID) schemes. AttApp enhances auditability and enables the use of AKE+SC in scenarios that require proof of authentication, such as Know Your Customer compliance. By leveraging a Trusted Execution Environment, AttApp ensures the integrity of authentication attestations while mitigating insider threats. Furthermore, it is specifically designed for deployment on resource-constrained Security Microcontrollers (ICCs). We implement AttApp as a JavaCard applet, demonstrating its feasibility and evaluating its performance on commercially available ICCs. The key contributions of this work include (i) a novel attestation framework for eID schemes based on Extended Access Control as an instance of AKE+SC, (ii) a JavaCard-based implementation compatible with existing ICCs, (iii) a security analysis of the proposed approach, and (iv) an empirical assessment of its performance on real-world hardware.