{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T16:16:18Z","timestamp":1784736978425,"version":"3.55.0"},"reference-count":0,"publisher":"Centre pour la Communication Scientifique Directe (CCSD)","license":[{"start":{"date-parts":[[2021,6,2]],"date-time":"2021-06-02T00:00:00Z","timestamp":1622592000000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,6,2]],"date-time":"2021-06-02T00:00:00Z","timestamp":1622592000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,6,2]],"date-time":"2021-06-02T00:00:00Z","timestamp":1622592000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"accepted":{"date-parts":[[2025,4,1]]},"abstract":"<jats:p>We uncover privacy vulnerabilities in the ICAO 9303 standard implemented by ePassports worldwide. These vulnerabilities, confirmed by ICAO, enable an ePassport holder who recently passed through a checkpoint to be reidentified without opening their ePassport. This paper explains how bisimilarity was used to discover these vulnerabilities, which exploit the BAC protocol - the original ICAO 9303 standard ePassport authentication protocol - and remains valid for the PACE protocol, which improves on the security of BAC in the latest ICAO 9303 standards. In order to tackle such bisimilarity problems, we develop here a chain of methods for the applied $\\pi$-calculus including a symbolic under-approximation of bisimilarity, called open bisimilarity, and a modal logic, called classical FM, for describing and certifying attacks. Evidence is provided to argue for a new scheme for specifying such unlinkability problems that more accurately reflects the capabilities of an attacker.<\/jats:p>","DOI":"10.23638\/lmcs-17(2:24)2021","type":"journal-article","created":{"date-parts":[[2025,4,3]],"date-time":"2025-04-03T17:47:46Z","timestamp":1743702466000},"source":"Crossref","is-referenced-by-count":4,"title":["Discovering ePassport Vulnerabilities using Bisimilarity"],"prefix":"10.23638","volume":"Volume 17, Issue 2","author":[{"given":"Ross","family":"Horne","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sjouke","family":"Mauw","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"25203","published-online":{"date-parts":[[2021,6,2]]},"container-title":["Logical Methods in Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/arxiv.org\/pdf\/2002.07309v5","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/arxiv.org\/pdf\/2002.07309v5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,3]],"date-time":"2025-04-03T17:47:46Z","timestamp":1743702466000},"score":1,"resource":{"primary":{"URL":"http:\/\/lmcs.episciences.org\/6117"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,6,2]]},"references-count":0,"URL":"https:\/\/doi.org\/10.23638\/lmcs-17(2:24)2021","relation":{"has-preprint":[{"id-type":"arxiv","id":"2002.07309v4","asserted-by":"subject"},{"id-type":"arxiv","id":"2002.07309v3","asserted-by":"subject"},{"id-type":"arxiv","id":"2002.07309v2","asserted-by":"subject"},{"id-type":"arxiv","id":"2002.07309v1","asserted-by":"subject"}],"is-same-as":[{"id-type":"arxiv","id":"2002.07309","asserted-by":"subject"},{"id-type":"doi","id":"10.48550\/arXiv.2002.07309","asserted-by":"subject"}]},"ISSN":["1860-5974"],"issn-type":[{"value":"1860-5974","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,6,2]]},"article-number":"6117"}}