Tim Van hamme

dblp:202/6739 · DBLP profile ↗
← Back
10ranked-venue papers
5as first author
7since 2021 · last 2026
0000-0003-0366-4470ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 5 first-author · 6 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 One Space To Match Them All: Template Inversion and Impersonation under Realistic Post-Breach Conditions
Willem Verheyen, Tim Van hamme, Davy Preuveneers, Wouter Joosen
EuroS&P2
2024 A Self-Sovereign Identity Approach to Decentralized Access Control with Transitive Delegations
abstract
In this paper, we introduce a new decentralized access control framework with transitive delegation capabilities that tackles the performance and scalability limitations of the existing state-of-the-art solutions. In order to accomplish this, the proposed solution is anchored in the self-sovereign identity (SSI) paradigm, which embodies a distributed identity management system. By adopting this paradigm, we obviate slow cryptographic premises such as identity-based encryption (IBE) that were used in prior work. Furthermore, we enhance the existing verifiable credentials (VCs) from this paradigm by introducing our own decentralized permission objects to support the concept of transitive delegations. This concept allows delegates to further delegate their access to resources with the same or fewer privileges to other entities within the framework. This renders our solution suitable for diverse scenarios, including applications in decentralized building access management. To the best of our knowledge, we are the first to introduce the concept of transitive delegations in this paradigm. Finally, our performance experiments show a performance enhancement of three orders of magnitude compared to the prevailing state-of-the-art solutions.
Pieter-Jan Vrielynck, Tim Van hamme, Rawad Ghostin, Bert Lagaisse, Davy Preuveneers, Wouter Joosen
SACMAT2
2024 A Novel Evaluation Framework for Biometric Security: Assessing Guessing Difficulty as a Metric
abstract
Biometric authentication systems have traditionally relied on the False Match Rate (FMR) to evaluate security against impersonation threats. However, this metric alone is insufficient for assessing vulnerabilities to statistical attacks because it cannot account for the non-uniformity of mismatches and atypical inputs that adversaries may manipulate. To address this issue, we propose a new evaluation framework that overcomes these limitations. The framework includes an estimate of the effective key space of biometrics and metrics that consider non-uniformity in the biometric embedding space. Our findings demonstrate that our framework provides a nuanced understanding of biometric security. Moreover, optimizing for the proposed metric leads to better security against statistical attacks than optimizing the FMR. Furthermore, the framework provides a comparative security analysis with traditional methods like passwords and PIN codes. It also quantifies the impact on security when adversaries partially know their victims, e.g., demographics.
Tim Van hamme, Giuseppe Garofalo, Enrique Argones-Rúa, Davy Preuveneers, Wouter Joosen
IEEE Trans. Inf. Forensics Secur.1
2023 Beware the Doppelgänger: Attacks against Adaptive Thresholds in Facial Recognition Systems
abstract
Biometric recognition systems typically use a fixed threshold to differentiate between legitimate users and imposters. Yet, this method can be problematic due to differences in individual user performance, whereas some users are more easily recognizable than others. Furthermore, fixed thresholds require extensive tuning on a large test set a priori to determine an optimal threshold value. Adaptive thresholds address these shortcomings by adjusting threshold values based on population characteristics. However, our research demonstrates that adaptive thresholds suffer from a significant weakness as they inadvertently increase the attack surface against face recognition systems. We do so by introducing a novel attack, the doppelgänger attack, where a malicious actor inserts adversarial examples that mimic legitimate users and increase the false rejection rate for these legitimate users by 70%.
Willem Verheyen, Tim Van hamme, Sander Joos, Davy Preuveneers, Wouter Joosen
ARES2
2023 Masterkey attacks against free-text keystroke dynamics and security implications of demographic factors
abstract
This paper presents and systematically evaluates the first masterkey attack against free-text keystroke dynamics. A masterkey is a typing sequence that matches, hence successfully impersonates, a large part of the population. Therefore, masterkeys are effective tools for an adversary who aims to impersonate someone without knowledge of their typing behavior. On top of the attack itself, we present a new unifying evaluation framework for masterkey attacks that allow for the comparison with knowledge-based authentication factors. In other words, we unify the evaluation of password security with that of masterkey attacks and demonstrate that typing biometrics is approximately 20 times less secure than passwords and approximately two times less secure than a 4-digit pin. Lastly, we study the effect of demographics on typing biometrics, which, among others, provides novel insights into the effect of being a well-versed typist on security.
Tim Van hamme, Giuseppe Garofalo, Davy Preuveneers, Wouter Joosen
EuroS&P1
2022 PIVOT: Private and Effective Contact Tracing
abstract
We propose, design, and evaluate PIVOT, a privacy-enhancing and effective contact tracing solution that aims to strike a balance between utility and privacy: one that does not collect sensitive information yet allowing effective tracing and notifying the close contacts of diagnosed users. PIVOT requires a considerably low degree of trust in the entities involved compared to centralized alternatives while retaining the necessary utility. To protect users’ privacy, it uses local proximity tracing based on broadcasting and recording constantly changing anonymous public keys via short-range communication. These public keys are used to establish a shared secret key between two people in close contact. The three keys (i.e., the two public keys and the established shared key) are then used to generate two unique per-user-per-contact hashes: one for infection registration and one for exposure score query. These hashes are never revealed to the public. To improve utility, user exposure score computation is performed centrally, which provides health authorities with minimal, yet insightful and actionable data. Data minimization is achieved by the use of per-user-per-contact hashes and by enforcing role separation: the health authority act as a mixing node, while the matching between reported and queried hashes is outsourced to a third entity, an independent matching service (MS). This separation ensures that out-of-scope information, such as users’ social interactions, is hidden from the health authorities, whereas the MS does not learn users’ sensitive information. To sustain our claims, we conduct a practical evaluation that encompasses anonymity guarantees and energy requirements.
Giuseppe Garofalo, Tim Van hamme, Davy Preuveneers, Wouter Joosen, Aysajan Abidin, Mustafa A. Mustafa
IEEE Internet Things J.2
2021 On the Security of Biometrics and Fuzzy Commitment Cryptosystems: A Study on Gait Authentication
abstract
As biometric templates consist of highly correlated features, the real security level offered by biometric authentication systems remains an open research question. In this work we provide new approximations and a lower bound of the security offered by fuzzy commitment schemes. Fuzzy commitment cryptosystems and in general biometric template protection schemes play an important role in allowing for remote storage and processing of biometric data, as they mitigate the threat of biometric template leakage. The use of such schemes would alleviate some of the usability constraints imposed by the state-of-practice local use of biometrics. As such we conduct an in-depth security analysis for IMU based gait authentication systems, where we evaluate the effectiveness of attacks within the scope of two well-defined threat models that target both unprotected and protected systems. A pivotal enabler of our analysis is the development of nine different approaches to gait authentication, which allows us to perform intramodal fusion on these distinct, yet highly correlated biometric templates, and to protect them with a strengthened fuzzy commitment scheme. Our analysis clearly demonstrates the high correlation between the different biometric templates, which, among others, further showcases the threat of biometric template leakage. Furthermore, as our analysis incorporates a threat model that assumes biometric template leakage, it provides metrics for the security provided by the biometric modality itself.
Tim Van hamme, Enrique Argones-Rúa, Davy Preuveneers, Wouter Joosen
IEEE Trans. Inf. Forensics Secur.1
2020 A Practical Approach for Taking Down Avalanche Botnets Under Real-World Constraints
Victor Le Pochat, Tim Van hamme, Sourena Maroofi, Tom van Goethem, Davy Preuveneers, Andrzej Duda, Wouter Joosen, Maciej Korczynski
NDSS2
2018 Managing distributed trust relationships for multi-modal authentication
Tim Van hamme, Davy Preuveneers, Wouter Joosen
J. Inf. Secur. Appl.1
2017 Improving Resilience of Behaviometric Based Continuous Authentication with Multiple Accelerometers
Tim Van hamme, Davy Preuveneers, Wouter Joosen
DBSec1