VLDB 2026 Research / reviewers in the wild / expert
Mike Bond
dblp:b/MikeBond
· DBLP profile ↗
9ranked-venue papers
5as first author
0since 2021 · last 2014
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 5 first-authorApplied, interdisciplinary, general and emerging computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
5 papers |
Cryptographic protocols and secure computation · 35% Network security · 35% Hardware security and side channels · 13% |
Topics — the 6 heaviest of 9, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network security › attack strategy
man-in-the-middle attack |
0.3 | 2 | 2014 | Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014 Chip and PIN is Broken · IEEE Symposium on Security and Privacy 2010 |
Cryptographic protocols and secure computation
secure payment |
0.3 | 2 | 2014 | Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014 Chip and PIN is Broken · IEEE Symposium on Security and Privacy 2010 |
Authentication and access control › authentication
authentication protocols |
0.1 | 1 | 2014 | Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014 |
Hardware security and side channels
side-channel attack |
0.0 | 1 | 2002 | Experience Using a Low-Cost FPGA Design to Crack DES Keys · CHES 2002 |
Privacy and data protection › privacy compliance
data use policy enforcement |
0.0 | 1 | 2006 | Cryptographic Processors-A Survey · Proc. IEEE 2006 |
Hardware security and side channels
fault attacks |
0.0 | 1 | 2001 | Attacks on Cryptoprocessor Transaction Sets · CHES 2001 |
Methods — techniques the papers use, named apart from their topics
protocol analysis · 0.3field experiment · 0.2practical attack demonstration · 0.1survey · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2014 | Chip and Skim: Cloning EMV Cards with the Pre-play AttackabstractEMV, also known as "Chip and PIN", is the leading system for card payments worldwide. It is used throughout Europe and much of Asia, and is starting to be introduced in North America too. Payment cards contain a chip so they can execute an authentication protocol. This protocol requires point-of-sale (POS) terminals or ATMs to generate a nonce, called the unpredictable number, for each transaction to ensure it is fresh. We have discovered two serious problems: a widespread implementation flaw and a deeper, more difficult to fix flaw with the EMV protocol itself. The first flaw is that some EMV implementers have merely used counters, timestamps or home-grown algorithms to supply this nonce. This exposes them to a "pre-play" attack which is indistinguishable from card cloning from the standpoint of the logs available to the card-issuing bank, and can be carried out even if it is impossible to clone a card physically. Card cloning is the very type of fraud that EMV was supposed to prevent. We describe how we detected the vulnerability, a survey methodology we developed to chart the scope of the weakness, evidence from ATM and terminal experiments in the field, and our implementation of proof-of-concept attacks. We found flaws in widely-used ATMs from the largest manufacturers. We can now explain at least some of the increasing number of frauds in which victims are refused refunds by banks which claim that EMV cards cannot be cloned and that a customer involved in a dispute must therefore be mistaken or complicit. The second problem was exposed by the above work. Independent of the random number quality, there is a protocol failure: the actual random number generated by the terminal can simply be replaced by one the attacker used earlier when capturing an authentication code from the card. This variant of the pre-play attack may be carried out by malware in an ATM or POS terminal, or by a man-in-the-middle between the terminal and the acquirer. We explore the design and implementation mistakes that enabled these flaws to evade detection until now: shortcomings of the EMV specification, of the EMV kernel certification process, of implementation testing, formal analysis, and monitoring customer complaints. Finally we discuss countermeasures. More than a year after our initial responsible disclosure of these flaws to the banks, action has only been taken to mitigate the first of them, while we have seen a likely case of the second in the wild, and the spread of ATM and POS malware is making it ever more of a threat. Mike Bond, Marios O. Choudary, Steven J. Murdoch, Sergei P. Skorobogatov, Ross J. Anderson |
IEEE Symposium on Security and Privacy | 1 |
| 2013 | The Low-Call Diet: Authenticated Encryption for Call Counting HSM Users
Mike Bond, George French, Nigel P. Smart, Gaven J. Watson |
CT-RSA | 1 |
| 2010 | Chip and PIN is BrokenabstractEMV is the dominant protocol used for smart card payments worldwide, with over 730 million cards in circulation. Known to bank customers as “Chip and PIN”, it is used in Europe; it is being introduced in Canada; and there is pressure from banks to introduce it in the USA too. EMV secures credit and debit card transactions by authenticating both the card and the customer presenting it through a combination of cryptographic authentication codes, digital signatures, and the entry of a PIN. In this paper we describe and demonstrate a protocol flaw which allows criminals to use a genuine card to make a payment without knowing the card's PIN, and to remain undetected even when the merchant has an online connection to the banking network. The fraudster performs a man-in-the-middle attack to trick the terminal into believing the PIN verified correctly, while telling the card that no PIN was entered at all. The paper considers how the flaws arose, why they remained unknown despite EMV's wide deployment for the best part of a decade, and how they might be fixed. Because we have found and validated a practical attack against the core functionality of EMV, we conclude that the protocol is broken. This failure is significant in the field of protocol design, and also has important public policy implications, in light of growing reports of fraud on stolen EMV cards. Frequently, banks deny such fraud victims a refund, asserting that a card cannot be used without the correct PIN, and concluding that the customer must be grossly negligent or lying. Our attack can explain a number of these cases, and exposes the need for further research to bridge the gap between the theoretical and practical security of bank payment systems. It also demonstrates the need for the next version of EMV to be engineered properly. Steven J. Murdoch, Saar Drimer, Ross J. Anderson, Mike Bond |
IEEE Symposium on Security and Privacy | 4 |
| 2010 | Caveat venditor
George French, Mike Bond |
Inf. Secur. Tech. Rep. | 2 |
| 2006 | A pact with the devil
Mike Bond, George Danezis |
NSPW | 1 |
| 2006 | Integrity of intention (a theory of types for security APIs)
Mike Bond, Jolyon Clulow |
Inf. Secur. Tech. Rep. | 1 |
| 2006 | Cryptographic Processors-A SurveyabstractTamper-resistant cryptographic processors are becoming the standard way to enforce data-usage policies. Their origins lie with military cipher machines and PIN processing in banking payment networks, expanding in the 1990s into embedded applications: token vending machines for prepayment electricity and mobile phone credit. Major applications such as GSM mobile phone identification and pay TV set-top boxes have pushed low-cost cryptoprocessors toward ubiquity. In the last five years, dedicated crypto chips have been embedded in devices such as game console accessories and printer ink cartridges, to control product and accessory after markets. The "Trusted Computing" initiative will soon embed cryptoprocessors in PCs so they can identify each other remotely. This paper surveys the range of applications of tamper-resistant hardware and the array of attack and defense mechanisms which have evolved in the tamper-resistance arms race. Ross J. Anderson, Mike Bond, Jolyon Clulow, Sergei P. Skorobogatov |
Proc. IEEE | 2 |
| 2002 | Experience Using a Low-Cost FPGA Design to Crack DES Keys
Richard Clayton 0001, Mike Bond |
CHES | 2 |
| 2001 | Attacks on Cryptoprocessor Transaction Sets
Mike Bond |
CHES | 1 |