Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Mike Bond

dblp:b/MikeBond · DBLP profile ↗
← Back
9ranked-venue papers
5as first author
0since 2021 · last 2014
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 5 first-authorApplied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
5 papers
Cryptographic protocols and secure computation · 35% Network security · 35% Hardware security and side channels · 13%

Topics — the 6 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › attack strategy
man-in-the-middle attack
0.322014
Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014
Chip and PIN is Broken · IEEE Symposium on Security and Privacy 2010
Cryptographic protocols and secure computation
secure payment
0.322014
Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014
Chip and PIN is Broken · IEEE Symposium on Security and Privacy 2010
Authentication and access control › authentication
authentication protocols
0.112014
Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014
Hardware security and side channels
side-channel attack
0.012002
Experience Using a Low-Cost FPGA Design to Crack DES Keys · CHES 2002
Privacy and data protection › privacy compliance
data use policy enforcement
0.012006
Cryptographic Processors-A Survey · Proc. IEEE 2006
Hardware security and side channels
fault attacks
0.012001
Attacks on Cryptoprocessor Transaction Sets · CHES 2001

Methods — techniques the papers use, named apart from their topics

protocol analysis · 0.3field experiment · 0.2practical attack demonstration · 0.1survey · 0.1
YearPublicationVenuePosition
2014 Chip and Skim: Cloning EMV Cards with the Pre-play Attack
abstract
EMV, also known as "Chip and PIN", is the leading system for card payments worldwide. It is used throughout Europe and much of Asia, and is starting to be introduced in North America too. Payment cards contain a chip so they can execute an authentication protocol. This protocol requires point-of-sale (POS) terminals or ATMs to generate a nonce, called the unpredictable number, for each transaction to ensure it is fresh. We have discovered two serious problems: a widespread implementation flaw and a deeper, more difficult to fix flaw with the EMV protocol itself. The first flaw is that some EMV implementers have merely used counters, timestamps or home-grown algorithms to supply this nonce. This exposes them to a "pre-play" attack which is indistinguishable from card cloning from the standpoint of the logs available to the card-issuing bank, and can be carried out even if it is impossible to clone a card physically. Card cloning is the very type of fraud that EMV was supposed to prevent. We describe how we detected the vulnerability, a survey methodology we developed to chart the scope of the weakness, evidence from ATM and terminal experiments in the field, and our implementation of proof-of-concept attacks. We found flaws in widely-used ATMs from the largest manufacturers. We can now explain at least some of the increasing number of frauds in which victims are refused refunds by banks which claim that EMV cards cannot be cloned and that a customer involved in a dispute must therefore be mistaken or complicit. The second problem was exposed by the above work. Independent of the random number quality, there is a protocol failure: the actual random number generated by the terminal can simply be replaced by one the attacker used earlier when capturing an authentication code from the card. This variant of the pre-play attack may be carried out by malware in an ATM or POS terminal, or by a man-in-the-middle between the terminal and the acquirer. We explore the design and implementation mistakes that enabled these flaws to evade detection until now: shortcomings of the EMV specification, of the EMV kernel certification process, of implementation testing, formal analysis, and monitoring customer complaints. Finally we discuss countermeasures. More than a year after our initial responsible disclosure of these flaws to the banks, action has only been taken to mitigate the first of them, while we have seen a likely case of the second in the wild, and the spread of ATM and POS malware is making it ever more of a threat.
Mike Bond, Marios O. Choudary, Steven J. Murdoch, Sergei P. Skorobogatov, Ross J. Anderson
IEEE Symposium on Security and Privacy1
2013 The Low-Call Diet: Authenticated Encryption for Call Counting HSM Users
Mike Bond, George French, Nigel P. Smart, Gaven J. Watson
CT-RSA1
2010 Chip and PIN is Broken
abstract
EMV is the dominant protocol used for smart card payments worldwide, with over 730 million cards in circulation. Known to bank customers as “Chip and PIN”, it is used in Europe; it is being introduced in Canada; and there is pressure from banks to introduce it in the USA too. EMV secures credit and debit card transactions by authenticating both the card and the customer presenting it through a combination of cryptographic authentication codes, digital signatures, and the entry of a PIN. In this paper we describe and demonstrate a protocol flaw which allows criminals to use a genuine card to make a payment without knowing the card's PIN, and to remain undetected even when the merchant has an online connection to the banking network. The fraudster performs a man-in-the-middle attack to trick the terminal into believing the PIN verified correctly, while telling the card that no PIN was entered at all. The paper considers how the flaws arose, why they remained unknown despite EMV's wide deployment for the best part of a decade, and how they might be fixed. Because we have found and validated a practical attack against the core functionality of EMV, we conclude that the protocol is broken. This failure is significant in the field of protocol design, and also has important public policy implications, in light of growing reports of fraud on stolen EMV cards. Frequently, banks deny such fraud victims a refund, asserting that a card cannot be used without the correct PIN, and concluding that the customer must be grossly negligent or lying. Our attack can explain a number of these cases, and exposes the need for further research to bridge the gap between the theoretical and practical security of bank payment systems. It also demonstrates the need for the next version of EMV to be engineered properly.
Steven J. Murdoch, Saar Drimer, Ross J. Anderson, Mike Bond
IEEE Symposium on Security and Privacy4
2010 Caveat venditor
George French, Mike Bond
Inf. Secur. Tech. Rep.2
2006 A pact with the devil
Mike Bond, George Danezis
NSPW1
2006 Integrity of intention (a theory of types for security APIs)
Mike Bond, Jolyon Clulow
Inf. Secur. Tech. Rep.1
2006 Cryptographic Processors-A Survey
abstract
Tamper-resistant cryptographic processors are becoming the standard way to enforce data-usage policies. Their origins lie with military cipher machines and PIN processing in banking payment networks, expanding in the 1990s into embedded applications: token vending machines for prepayment electricity and mobile phone credit. Major applications such as GSM mobile phone identification and pay TV set-top boxes have pushed low-cost cryptoprocessors toward ubiquity. In the last five years, dedicated crypto chips have been embedded in devices such as game console accessories and printer ink cartridges, to control product and accessory after markets. The "Trusted Computing" initiative will soon embed cryptoprocessors in PCs so they can identify each other remotely. This paper surveys the range of applications of tamper-resistant hardware and the array of attack and defense mechanisms which have evolved in the tamper-resistance arms race.
Ross J. Anderson, Mike Bond, Jolyon Clulow, Sergei P. Skorobogatov
Proc. IEEE2
2002 Experience Using a Low-Cost FPGA Design to Crack DES Keys
Richard Clayton 0001, Mike Bond
CHES2
2001 Attacks on Cryptoprocessor Transaction Sets
Mike Bond
CHES1