Semen Yurkov

dblp:292/3107 · DBLP profile ↗
← Back
4ranked-venue papers
0as first author
4since 2021 · last 2023
0000-0002-9200-4601ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Theory of computation · 2 · 2 since 2021
YearPublicationVenuePosition
2023 Provably Unlinkable Smart Card-based Payments
abstract
The most prevalent smart card-based payment method, EMV, currently offers no privacy to its users. Transaction details and the card number are sent in cleartext, enabling the profiling and tracking of cardholders. Since public awareness of privacy issues is growing and legislation, such as GDPR, is emerging, we believe it is necessary to investigate the possibility of making payments anonymous and unlikable without compromising essential security guarantees and functional properties of EMV. This paper draws attention to trade-offs between functional and privacy requirements in the design of such a protocol. We present the UTX protocol - an enhanced payment protocol satisfying such requirements, and we formally certify key security and privacy properties using techniques based on the applied π-calculus.
Sergiu Bursuc, Ross Horne, Sjouke Mauw, Semen Yurkov
CCS4
2023 When privacy fails, a formula describes an attack: A complete and compositional verification method for the applied π-calculus
Ross Horne, Sjouke Mauw, Semen Yurkov
Theor. Comput. Sci.3
2022 Unlinkability of an Improved Key Agreement Protocol for EMV 2nd Gen Payments
abstract
To address known privacy problems with the EMV standard, EMVCo have proposed a Blinded Diffie-Hellman key establishment protocol, which is intended to be part of a future 2nd Gen EMV protocol. We point out that active attackers were not previously accounted for in the privacy requirements of this proposal protocol, and demonstrate that an active attacker can compromise unlinkability within a distance of 100cm. Here, we adopt a strong definition of unlinkability that does account for active attackers and propose an enhancement of the protocol proposed by EMVCo. We prove that our protocol does satisfy strong unlinkability, while preserving authentication.
Ross Horne, Sjouke Mauw, Semen Yurkov
CSF3
2021 Compositional Analysis of Protocol Equivalence in the Applied π-Calculus Using Quasi-open Bisimilarity
abstract
Abstract This paper shows that quasi-open bisimilarity is the coarsest bisimilarity congruence for the applied $$\pi $$ π -calculus. Furthermore, we show that this equivalence is suited to security and privacy problems expressed as an equivalence problem in the following senses: (1) being a bisimilarity is a safe choice since it does not miss attacks based on rich strategies; (2) being a congruence it enables a compositional approach to proving certain equivalence problems such as unlinkability; and (3) being the coarsest such bisimilarity congruence it can establish proofs of some privacy properties where finer equivalences fail to do so.
Ross Horne, Sjouke Mauw, Semen Yurkov
ICTAC3