VLDB 2026 Research / reviewers in the wild / expert
Jorge Toro-Pozo
dblp:180/7312 · also Jorge L. Toro, Jorge Luis Toro Pozo
· DBLP profile ↗
9ranked-venue papers
0as first author
5since 2021 · last 2024
0000-0001-6615-1600ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 4 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Getting Chip Card Payments RightabstractAbstract EMV is the international protocol standard for smart card payments and is used in billions of payment cards worldwide. Despite the standard’s advertised security, various issues have been previously uncovered, deriving from logical flaws that are hard to spot in EMV’s lengthy and complex specification. We have formalized various models of EMV in Tamarin, a symbolic model checker for cryptographic protocols. Tamarin was extremely effective in finding critical flaws, both known and new, and in many cases exploitable on actual cards. We report on these past problems as well as followup work where we verified the latest, improved version of the protocol, the EMV kernel C8. This work puts C8’s correctness on a firm, formal basis, and clarifies which guarantees hold for C8 and under which assumptions. Overall our work supports the thesis that cryptographic protocol model checkers like Tamarin have an essential role to play in improving the security of real-world payment protocols and that they are up to this challenge. David A. Basin, Xenia Hofmeier, Ralf Sasse, Jorge Toro-Pozo |
FM (1) | 4 |
| 2023 | SealClub: Computer-aided Paper Document AuthenticationabstractPaper documents, where digital signatures are not directly applicable, are still widely utilized due to usability and legal reasons. We propose a novel approach to authenticating paper documents by taking short videos of them with smartphones. Our solution combines cryptographic and image comparison techniques to detect and highlight semantic-changing attacks on rich documents, containing text and graphics. We provide geometrical arguments for the security of our novel comparison algorithm, and prove that its combination with a cryptographic protocol is secure against strong adversaries capable of compromising different system components. We also measure its accuracy on a set of 128 videos of paper documents and a set of 960 synthetically generated warped documents, half containing subtle forgeries. Our algorithm finds all forgeries accurately with no false positives. The highlighted regions are large enough to be visible to users, but small enough to precisely locate forgeries. Martín Ochoa, Hernán Vanegas, Jorge Toro-Pozo, David A. Basin |
ACSAC | 3 |
| 2023 | Inducing Authentication Failures to Bypass Credit Card PINs
David A. Basin, Patrick Schaller, Jorge Toro-Pozo |
USENIX Security Symposium | 3 |
| 2021 | The EMV Standard: Break, Fix, VerifyabstractEMV is the international protocol standard for smartcard payment and is used in over 9 billion cards worldwide. Despite the standard’s advertised security, various issues have been previously uncovered, deriving from logical flaws that are hard to spot in EMV’s lengthy and complex specification, running over 2,000 pages.We formalize a comprehensive symbolic model of EMV in Tamarin, a state-of-the-art protocol verifier. Our model is the first that supports a fine-grained analysis of all relevant security guarantees that EMV is intended to offer. We use our model to automatically identify flaws that lead to two critical attacks: one that defrauds the cardholder and a second that defrauds the merchant. First, criminals can use a victim’s Visa contactless card to make payments for amounts that require cardholder verification, without knowledge of the card’s PIN. We built a proof-of-concept Android application and successfully demonstrated this attack on real-world payment terminals. Second, criminals can trick the terminal into accepting an unauthentic offline transaction, which the issuing bank should later decline, after the criminal has walked away with the goods. This attack is possible for implementations following the standard, although we did not test it on actual terminals for ethical reasons. Finally, we propose and verify improvements to the standard that prevent these attacks, as well as any other attacks that violate the considered security properties. The proposed improvements can be easily implemented in the terminals and do not affect the cards in circulation. David A. Basin, Ralf Sasse, Jorge Toro-Pozo |
SP | 3 |
| 2021 | Card Brand Mixup Attack: Bypassing the PIN in non-Visa Cards by Using Them for Visa Transactions
David A. Basin, Ralf Sasse, Jorge Toro-Pozo |
USENIX Security Symposium | 3 |
| 2019 | Post-Collusion Security and Distance BoundingabstractVerification of cryptographic protocols is traditionally built upon the assumption that participants have not revealed their long-term keys. However, in some cases, participants might collude to defeat some security goals, without revealing their long-term secrets. Sjouke Mauw, Zach Smith, Jorge Toro-Pozo, Rolando Trujillo-Rasua |
CCS | 3 |
| 2018 | Automated Identification of Desynchronisation Attacks on Shared Secrets
Sjouke Mauw, Zach Smith, Jorge Toro-Pozo, Rolando Trujillo-Rasua |
ESORICS (1) | 3 |
| 2018 | Distance-Bounding Protocols: Verification without Time and LocationabstractDistance-bounding protocols are cryptographic protocols that securely establish an upper bound on the physical distance between the participants. Existing symbolic verification frameworks for distance-bounding protocols consider timestamps and the location of agents. In this work we introduce a causality-based characterization of secure distance-bounding that discards the notions of time and location. This allows us to verify the correctness of distance-bounding protocols with standard protocol verification tools. That is to say, we provide the first fully automated verification framework for distance-bounding protocols. By using our framework, we confirmed known vulnerabilities in a number of protocols and discovered unreported attacks against two recently published protocols. Sjouke Mauw, Zach Smith, Jorge Toro-Pozo, Rolando Trujillo-Rasua |
IEEE Symposium on Security and Privacy | 3 |
| 2016 | A Class of Precomputation-Based Distance-Bounding ProtocolsabstractDistance-bounding protocols serve to thwart various types of proximity-based attacks, such as relay attacks. A particular class of distance-bounding protocols measures round trip times of a series of one-bit challenge-response cycles, during which the proving party must have minimal computational overhead. This can be achieved by precomputing the responses to the various possible challenges. In this paper we study this class of precomputation-based distance-bounding protocols. By designing an abstract model for these protocols, we can study their generic properties, such as security lower bounds in relation to space complexity. Further, we develop a novel family of protocols in this class that resists well to mafia fraud attacks. Sjouke Mauw, Jorge Toro-Pozo, Rolando Trujillo-Rasua |
EuroS&P | 2 |