VLDB 2026 Research / reviewers in the wild / expert
Konstantinos Markantonakis
dblp:m/ConstantinosMarkantonakis · also Constantinos Markantonakis
· DBLP profile ↗
73ranked-venue papers
7as first author
6since 2021 · last 2025
0000-0003-3975-9033ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 60 · 7 first-author · 4 since 2021Systems, architecture and hardware · 4 · 1 since 2021Computer networks · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2Applied, interdisciplinary, general and emerging computing · 2Artificial intelligence and machine learning · 1Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Control-flow attestation: Concepts, solutions, and open challenges
Zhanyu Sha, Carlton Shepherd, Amir Rafi, Konstantinos Markantonakis |
Comput. Secur. | 4 |
| 2024 | A Side-Channel Analysis of Sensor Multiplexing for Covert Channels and Application Profiling on Mobile DevicesabstractMobile devices often distribute measurements from physical sensors to multiple applications using software multiplexing. On Android devices, the highest requested sampling frequency is returned to all applications, even if others request measurements at lower frequencies. In this paper, we comprehensively demonstrate that this design choice exposes practically exploitable side-channels using frequency-key shifting. By carefully modulating sensor sampling frequencies in software, we show how unprivileged malicious applications can construct reliable spectral covert channels that bypass existing security mechanisms. Additionally, we present a novel variant that allows an unprivileged malicious application to profile other active, sensor-enabled applications at a coarse-grained level. Both methods do not impose any special assumptions beyond accessing standard mobile services available to developers. As such, our work reports side-channel vulnerabilities that exploit subtle yet insecure design choices in Android sensor stacks. Carlton Shepherd, Jan Kalbantner, Benjamin Semal, Konstantinos Markantonakis |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | A First Look at Digital Rights Management Systems for Secure Mobile Content DeliveryabstractDigital rights management (DRM) solutions aim to prevent the copying or distribution of copyrighted material. On mobile devices, a variety of DRM technologies have become widely deployed. However, a detailed security study comparing their internal workings, and their strengths and weaknesses, remains missing in the existing literature. In this paper, we present the first detailed security analysis of mobile DRM systems, addressing the modern paradigm of cloud-based content delivery followed by major platforms, such as Netflix, Disney+, and Amazon Prime. We extensively analyse the security of three widely used DRM solutions—Google Widevine, Apple FairPlay, and Microsoft PlayReady—deployed on billions of devices worldwide. We then consolidate their features and capabilities, deriving common features and security properties for their evaluation. Furthermore, we identify some design-level shortcomings that render them vulnerable to emerging attacks within the state of the art, including micro-architectural side-channel vulnerabilities and an absence of post-quantum security. Lastly, we propose mitigations and suggest future directions of research. Amir Rafi, Carlton Shepherd, Konstantinos Markantonakis |
TrustCom | 3 |
| 2023 | Investigating Black-Box Function Recognition Using Hardware Performance CountersabstractThis paper presents new methods and results for recognising black-box program functions using hardware performance counters (HPC), where an investigator can invoke and measure function calls. Important use cases include analysing compiled libraries, e.g. static and dynamic link libraries, and trusted execution environment (TEE) applications. We develop a generic approach to classify a comprehensive set of hardware events, e.g. branch mis-predictions and instruction retirements, to recognise standard benchmarking and cryptographic library functions. This includes various signing, verification and hash functions, and ciphers in numerous modes of operation. Three architectures are evaluated using off-the-shelf Intel/X86-64, ARM, and RISC-V CPUs. Next, we show that several known CVE-numbered OpenSSL vulnerabilities can be detected using HPC differences between patched and unpatched library versions. Further, we demonstrate that standardised cryptographic functions within ARM TrustZone TEE applications can be recognised using non-secure world HPC measurements, applying to platforms that insecurely perturb the performance monitoring unit (PMU) during TEE execution. High accuracy was achieved in all cases (86.22–99.83%) depending on the application, architectural, and compilation assumptions. Lastly, we discuss mitigations, outstanding challenges, and directions for future research. Carlton Shepherd, Benjamin Semal, Konstantinos Markantonakis |
IEEE Trans. Computers | 3 |
| 2021 | Physical fault injection and side-channel attacks on mobile devices: A comprehensive analysis
Carlton Shepherd, Konstantinos Markantonakis, Nico van Heijningen, Driss Aboulkassimi, Clément Gaine, Thibaut Heckmann, David Naccache |
Comput. Secur. | 2 |
| 2021 | Privacy-Preserving Group Authentication for RFID Tags Using Bit-Collision PatternsabstractWhen authenticating a group of radio-frequency identification tags, a common method is to authenticate each tag with some challenge-response exchanges. However, sequentially authenticating individual tags one by one might not be desirable, especially when considering that a reader often has to deal with multiple tags within a limited period, since it will incur long scanning time and heavy communication costs. To address these problems, we put forward a novel efficient group authentication protocol, where a group of tags can be authenticated simultaneously with only one challenge and one response. The protocol is built on a newly designed symmetric key-based algorithm and the bit-collision pattern technique, so that authentication responses transmitted by multiple tags in a group at the same time will result in a verifiable bit-collision pattern that represents the authentication response for the entire group. The proposed approach can significantly reduce the authentication time and communication cost in the sense that the verifier can authenticate the entire group within a period that is comparable to the time taken to perform a single-tag authentication and requires only one challenge. In addition, we extend our protocol to support the privacy-preserving property, which prevents the tagged items from being tracked by illegitimate parties. A thorough security analysis shows that the proposed protocol can resist common practical attacks and experimental results show that the protocol is very efficient in terms of time and communication costs. We also discuss important practical aspects that should be considered when implementing these protocols. Anjia Yang, Dutliff Boshoff, Qiao Hu 0005, Gerhard P. Hancke 0002, Xizhao Luo, Jian Weng 0001, Keith Mayes, Konstantinos Markantonakis |
IEEE Internet Things J. | 8 |
| 2020 | Return-Oriented Programming on RISC-VabstractThis paper provides the first analysis on the feasibility of Return-Oriented programming (ROP) on RISC-V, a new instruction set architecture targeting embedded systems. We show the existence of a new class of gadgets, using several Linear Code Sequences And Jumps (LCSAJ), undetected by current Galileo-based ROP gadget searching tools. We argue that this class of gadgets is rich enough on RISC-V to mount complex ROP attacks, bypassing traditional mitigation like DEP, ASLR, stack canaries, G-Free and some compiler-based backward-edge CFI, by jumping over any guard inserted by a compiler to protect indirect jump instructions. We provide examples of such gadgets, as well as a proof-of-concept ROP chain, using C code injection to leverage a privilege escalation attack on two standard Linux operating systems. Additionally, we discuss some of the required mitigations to prevent such attacks and provide a new ROP gadget finder algorithm that handles this new class of gadgets. Georges-Axel Jaloyan, Konstantinos Markantonakis, Raja Naeem Akram, David Robin, Keith Mayes, David Naccache |
AsiaCCS | 2 |
| 2020 | Leaky Controller: Cross-VM Memory Controller Covert Channel on Multi-core Systems
Benjamin Semal, Konstantinos Markantonakis, Raja Naeem Akram, Jan Kalbantner |
SEC | 2 |
| 2020 | One Covert Channel to Rule Them All: A Practical Approach to Data Exfiltration in the CloudabstractThe sharing of hardware platforms in multi-tenant environments is a growing security concern. Microarchitectural timing-based covert channels allow tunneling information out of a compromised cloud instance, thus bypassing information flow policies. Significant research efforts have been carried out in order to address the super-set of timing channels. Nevertheless, new attacks keep on being published while disregarding the latest academic efforts, arguing that the relevant defences have not yet been deployed. In order to bridge the gap between vulnerabilities and countermeasures, we challenge state-of-the-art mitigation techniques by constructing the first cross-VM covert channel that is resilient against all known defences, whether they are already deployed or still theoretical. Defence strategies that are relevant with covert channels are surveyed, and a list of requirements is constructed for the new attack. Then, we re-visit the exploitation of the x86 memory bus lock, and launch the proposed covert communication channel across two AWS EC2 instances. While simple in design, the proposed implementation shows that x86 microarchitectures still present salient vulnerabilities, and that state-of-the-art defence strategies-even theoretical ones-remain unsuccessful at hindering data leakage in multi-tenant environments. Finally, a strategy to mitigate the remaining vulnerability is suggested, along with a comparison against the ARMv8 processor architecture. Benjamin Semal, Konstantinos Markantonakis, Keith Mayes, Jan Kalbantner |
TrustCom | 2 |
| 2020 | A Session Hijacking Attack Against a Device-Assisted Physical-Layer Key AgreementabstractPhysical-layer key agreement is used to generate a shared key between devices on demand. Such schemes utilize the characteristics of the wireless channel to generate the shared key from the device-to-device channel. As all characteristics are time-dependent and location-dependent, it is hard for eavesdroppers to get the key. However, most research works in this area use passive attack models whereas active attacks that aim at manipulating the channel and key are also possible. Physical-layer key agreement with User Introduced Randomness (PHYUIR) is a solution similar to the Diffie-Hellman protocol against such a kind of active attack. The users (devices) introduce their own randomness to help to prevent active attacks. In this paper, we analyze the possibility of launching a session hijacking attack on PHY-UIR to allow an attacker to control the shared key established. The session hijacking attack manipulates the key agreement through a man-in-the-middle interaction and forces legitimate devices to run the PHY-UIR protocol with the attacker. Our simulation and experiment results validate our attack and show the high performance of our attack on manipulating the generated key. We also propose PHY-UIR± where devices simultaneously exchange information about the established shared keys, which allows them to detect whether they have agreed to different keys with a third party. Qiao Hu 0005, Bianxia Du, Konstantinos Markantonakis, Gerhard P. Hancke 0002 |
IEEE Trans. Ind. Informatics | 3 |
| 2019 | Location Tracking Using Smartphone Accelerometer and Magnetometer TracesabstractWe demonstrate a breach in smartphone location privacy through the accelerometer and magnetometer's footprints. The merits or otherwise of explicitly permissioned location sensors are not the point of this paper. Instead, our proposition is that other non-location-sensitive sensors can track users accurately when the users are in motion, as in travelling on public transport, such as trains, buses, and taxis. Through field trials, we provide evidence that high accuracy location tracking can be achieved even via non-location-sensitive sensors for which no access authorisation is required from users on a smartphone. Khuong Nguyen, Raja Naeem Akram, Konstantinos Markantonakis, Zhiyuan Luo 0001, Chris Watkins |
ARES | 3 |
| 2019 | Ensuring Secure Application Execution and Platform-Specific Execution in Embedded DevicesabstractThe Internet of Things (IoT) is expanding at a large rate, with devices found in commercial and domestic settings from industrial sensors to home appliances. However, as the IoT market grows, so does the number of attacks made against it with some reports claiming an increase of 600% in 2017. This work seeks to prevent code replacement, injection, and exploitation attacks by ensuring correct and platform specific application execution. This combines two previously studied problems: secure application execution and binding hardware and software. We present descriptions of both problems and requirements for ensuring both simultaneously. We then propose a scheme extending previous work that meets these requirements, and describe our implementation of the soft-core Secure Execution Processor developed and tested on Xilinx Spartan-6 FPGA. Finally, we analyse the scheme and our implementation according to performance and the requirements listed. Robert P. Lee, Konstantinos Markantonakis, Raja Naeem Akram |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2018 | Deep Learning Application in Security and Privacy - Theory and Practice: A Position Paper
Julia A. Meister, Raja Naeem Akram, Konstantinos Markantonakis |
WISTP | 3 |
| 2018 | Remote Credential Management with Mutual Attestation for Trusted Execution Environments
Carlton Shepherd, Raja Naeem Akram, Konstantinos Markantonakis |
WISTP | 3 |
| 2018 | Reprint of "You can't touch this: Consumer-centric android application repackaging detection"
Iakovos Gurulian, Konstantinos Markantonakis, Lorenzo Cavallaro, Keith Mayes |
Future Gener. Comput. Syst. | 2 |
| 2017 | Artificial Ambient Environments for Proximity Critical ApplicationsabstractIn the field of smartphones a number of proposals suggest that sensing the ambient environment can act as an effective anti-relay mechanism. However, existing literature is not compliant with industry standards (e.g. EMV and ITSO) that require transactions to complete within a certain time-frame (e.g. 500ms in the case of EMV contactless payments). In previous work the generation of an artificial ambient environment (AAE), and especially the use of infrared light as an AAE actuator was shown to have high success rate in relay attacks detection. In this paper we investigate the application of infrared as a relay attack detection technique in various scenarios, namely, contactless transactions (mobile payments, transportation ticketing, and physical access control), and continuous Two-Factor Authentication. Operating requirements and architectures are proposed for each scenario, while taking into account industry imposed performance requirements, where applicable. Protocols for integrating the solution into the aforementioned scenarios are being proposed, and formally verified. The impact on the performance is assessed through practical implementation. Proposed protocols are verified using Scyther, a formal mechanical verification tool. Finally, additional scenarios, in which this technique can be applied to prevent relay or other types of attacks, are discussed. Iakovos Gurulian, Konstantinos Markantonakis, Raja Naeem Akram, Keith Mayes |
ARES | 2 |
| 2017 | Provisioning Software with Hardware-Software BindingabstractSmart cities are a concept of interest to many industrial, academic and government organisations. However, smart cities present a large attack surface to adversaries if every traffic light, power relay and water pipe are connected to the internet. This paper describes the problem of distributing software in a smart city when strong protection of device software, software installation and update provision are required. A set of requirements for a secure software provisioning system is presented and two models for the software distribution are proposed. Three protocols for distributing software are presented that meet the requirements stated. A formal analysis using Tamarin Prover is described that proves the security of the proposed protocols. Finally, an implementation has been developed using a laptop and Raspberry Pi 3 to demonstrate the proposed protocols in action and the performance of them. Robert P. Lee, Konstantinos Markantonakis, Raja Naeem Akram |
ARES | 2 |
| 2017 | Establishing Mutually Trusted Channels for Remote Sensing Devices with Trusted Execution EnvironmentsabstractRemote and largely unattended sensing devices are being deployed rapidly in sensitive environments, such as healthcare, in the home, and on corporate premises. A major challenge, however, is trusting data from such devices to inform critical decision-making using standardised trust mechanisms. Previous attempts have focused heavily on Trusted Platform Modules (TPMs) as a root of trust, but these forgo desirable features of recent developments, namely Trusted Execution Environments (TEEs), such as Intel SGX and the GlobalPlatform TEE. In this paper, we contrast the application of TEEs in trusted sensing devices with TPMs, and raise the challenge of secure TEE-to-TEE communication between remote devices with mutual trust assurances. To this end, we present a novel secure and trusted channel protocol that performs mutual remote attestation in a single run for small-scale devices with TEEs. This is evaluated on two ARM development boards hosting GlobalPlatform-compliant TEEs, yielding approximately four-times overhead versus untrusted world TLS and SSH. Our work provides strong resilience to integrity and confidentiality attacks from untrusted world adversaries, facilitates TEE interoperability, and is subjected to mechanical formal analysis using Scyther. Carlton Shepherd, Raja Naeem Akram, Konstantinos Markantonakis |
ARES | 3 |
| 2017 | May the Force Be with You: Force-Based Relay Attack Detection
Iakovos Gurulian, Gerhard P. Hancke 0002, Konstantinos Markantonakis, Raja Naeem Akram |
CARDIS | 3 |
| 2017 | Comparison of dynamic biometrie security characteristics against other biometricsabstractBiometrie data can be used as “something you are” in authentication systems, but if a biometrie is compromised by a malicious entity, the genuine user can no longer use it because it cannot be easily changed. Dynamic biometrics may offer a practical alternative, as they capture both an inherence factor along with a changeable knowledge factor in a single step. This paper investigates dynamic biometrics and whether they offer useful security authentication properties compared to conventional biometrics. In particular the paper focuses on one type of dynamic biometry, authentication based on Gesture Recognition, and presents a proof of concept experiment. Security characteristics of examples from three classes of dynamic biometrics are compared to a selection of common physiological (“fixed”) biometrics, leading to the conclusion that in addition to providing one-step, two factor authentication, dynamic biometry may provide privacy benefits in some circumstances. Benoit Ducray, Sheila Cobourne, Keith Mayes, Konstantinos Markantonakis |
ICC | 4 |
| 2017 | An Exploratory Analysis of the Security Risks of the Internet of Things in Finance
Carlton Shepherd, Fabien A. P. Petitcolas, Raja Naeem Akram, Konstantinos Markantonakis |
TrustBus | 4 |
| 2017 | A Secure and Trusted Channel Protocol for UAVs Fleets
Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes, Pierre-François Bonnefoi, Amina Cherif, Damien Sauveron, Serge Chaumette |
WISTP | 2 |
| 2017 | Philanthropy on the Blockchain
Danushka Jayasinghe, Sheila Cobourne, Konstantinos Markantonakis, Raja Naeem Akram, Keith Mayes |
WISTP | 3 |
| 2017 | EmLog: Tamper-Resistant System Logging for Constrained Devices with TEEs
Carlton Shepherd, Raja Naeem Akram, Konstantinos Markantonakis |
WISTP | 3 |
| 2016 | Log Your Car: Reliable Maintenance Services Record
Hafizah Mansor, Konstantinos Markantonakis, Raja Naeem Akram, Keith Mayes, Iakovos Gurulian |
Inscrypt | 2 |
| 2016 | Tokenisation Blacklisting Using Linkable Group Signatures
Assad Umar, Iakovos Gurulian, Keith Mayes, Konstantinos Markantonakis |
SecureComm | 4 |
| 2016 | You can't touch this: Consumer-centric android application repackaging detection
Iakovos Gurulian, Konstantinos Markantonakis, Lorenzo Cavallaro, Keith Mayes |
Future Gener. Comput. Syst. | 2 |
| 2016 | Recovering from a lost digital wallet: A smart cards perspective extended abstract
Raja Naeem Akram, Konstantinos Markantonakis, Damien Sauveron |
Pervasive Mob. Comput. | 2 |
| 2015 | Don't Brick Your Car: Firmware Confidentiality and Rollback for VehiclesabstractIn modern cars, there are a number of controllers that play a major role in the overall operations of the vehicles. The secure and updated firmware of these controllers is crucial to the overall security and reliability of the vehicle and its electronic system (s). Therefore, the life cycle of these controllers should be carefully managed. In this paper, we examine the vehicular firmware updates process and their associated security issues. We have analysed the security of the firmware update protocol proposed in the EVITA project, referred as EVITA protocol, which is considered as a main industrial effort in this field and found some potential shortcomings. Based on the analysis, in this paper we have suggested a number of improvements to the EVITA protocol, related with safety and security measures. The proposed improved protocol, also referred as EVITA+ protocol includes a rollback mechanism while preserving the confidentiality of the firmware. The integrity and authenticity of the flash driver are also considered in the EVITA+ protocol. The EVITA+ protocol is formally analysed using Casper FDR and Scyther to ensure the security of the firmware update process. Finally, we provide an insight analysis and our experience in relation to the efficiency, suitability and performance of the aforementioned tools in the field of automotive security. Hafizah Mansor, Konstantinos Markantonakis, Raja Naeem Akram, Keith Mayes |
ARES | 2 |
| 2015 | Enhancing Java Runtime Environment for Smart Cards Against Runtime Attacks
Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes |
ESORICS (2) | 2 |
| 2015 | Let's Get Mobile: Secure FOTA for Automotive System
Hafizah Mansor, Konstantinos Markantonakis, Raja Naeem Akram, Keith Mayes |
NSS | 2 |
| 2015 | A novel consumer-centric card management architecture and potential security issues
Raja Naeem Akram, Konstantinos Markantonakis, Damien Sauveron |
Inf. Sci. | 2 |
| 2014 | Practical Attacks on Virtual Worlds
Graham Hili, Sheila Cobourne, Keith Mayes, Konstantinos Markantonakis |
CRiSIS | 4 |
| 2014 | Precise Instruction-Level Side Channel Profiling of Embedded Processors
Mehari Msgna, Konstantinos Markantonakis, Keith Mayes |
ISPEC | 2 |
| 2014 | Secure Mobile Payment on NFC-Enabled Mobile Phones Formally Analysed Using CasperFDRabstractNear Field Communication (NFC) mobile phones can be used as payment devices and can emulate credit cards. Although NFC mobile services promise a fruitful future, several issues have been raised by academics and researchers. Among the main concerns for the use and deployment of NFC-enabled mobile phones is the potential loss of security and privacy. More specifically, mobile phone users involved in a payment transaction conducted over a mobile handset require that such a system does not reveal their identity or any sensitive data. Furthermore, that all entities participating in the transaction are legitimate. To this end, we proposed a protocol that meets the mobile user's requirements. The proposed protocol attempts to address the main security concerns and protects the customer privacy from any third party involved in the transaction. We formally analysed the protocol using CasperFDR and did not find any feasible attacks. Sarah Abughazalah, Konstantinos Markantonakis, Keith Mayes |
TrustCom | 2 |
| 2014 | Collaborative and Ubiquitous Consumer Oriented Trusted Service ManagerabstractNear Field Communication (NFC) enables a mobile phone to emulate a contactless smart card. This has reinvigorated the multiapplication smart card initiative. Trusted Service Manager (TSM) is an entity that is trusted by all stakeholders in the proposed and trialled NFC-based smart card ecosystem. However, TSM-based models have the potential to create market segregation that might lead to limited or slow adoption. In addition, all major stakeholders (e.g. Telecom and banks) are pushing for their own TSM models and this might hinder deployment. In this paper we present a Collaborative and Ubiquitous Consumer Oriented Trusted Service Manager (CO-TSM) based model that combines different TSM models while providing scalability to the overall architecture. In addition, our proposal also provides flexibility to both consumers and application providers. To support our proposal, we present a core architecture based on two contrasting approaches: the Issuer Centric Smart Card Ownership Model (ICOM) and the User Centric Smart Card Ownership Model (UCOM). Based on the core architecture, we then describe our proposal for an application download framework and a secure channel protocol. Finally, the implementation experience and performance measurements for the secure channel protocol are discussed. Raja Naeem Akram, Konstantinos Markantonakis, Damien Sauveron |
TrustCom | 2 |
| 2014 | CAN Bus Risk Analysis Revisit
Hafizah Mansor, Konstantinos Markantonakis, Keith Mayes |
WISTP | 2 |
| 2013 | Vulnerability Analysis of a Commercial .NET Smart Card
Behrang Fouladi, Konstantinos Markantonakis, Keith Mayes |
CARDIS | 2 |
| 2013 | Remote Attestation Mechanism for User Centric Smart Cards Using Pseudorandom Number Generators
Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes |
ICICS | 2 |
| 2013 | Using the Smart Card Web Server in Secure Branchless Banking
Sheila Cobourne, Keith Mayes, Konstantinos Markantonakis |
NSS | 3 |
| 2013 | A Vulnerability in the Song Authentication Protocol for Low-Cost RFID Tags
Sarah Abughazalah, Konstantinos Markantonakis, Keith Mayes |
SEC | 2 |
| 2013 | The B-Side of Side Channel Leakage: Control Flow Security in Embedded Systems
Mehari Msgna, Konstantinos Markantonakis, Keith Mayes |
SecureComm | 2 |
| 2013 | Editorial: advanced semantic and social multimedia technologies for future computing environment
Seungmin Rho, Damien Sauveron, Konstantinos Markantonakis |
Multim. Tools Appl. | 3 |
| 2012 | Distributed e-voting using the Smart Card Web ServerabstractVoting in elections is the basis of democracy, but citizens may not be able or willing to go to polling stations to vote on election days. Remote e-voting via the Internet provides the convenience of voting on the voter's own computer or mobile device, but Internet voting systems are vulnerable to many common attacks, affecting the integrity of an election. Distributing the processing of votes over many web servers installed in tamper-resistant, secure environments can improve security: this is possible by using the Smart Card Web Server (SCWS) on a mobile phone Subscriber Identity Module (SIM). This paper proposes a generic model for a voting application installed in the SIM/SCWS, which uses standardised Mobile Network Operator (MNO) management procedures to communicate (via HTTPs) with a voting authority to vote. The generic SCWS voting model is then used with the e-voting system Prêt à Voter. A preliminary security analysis of the proposal is carried out, and further research areas are identified. As the SCWS voting application is used in a distributed processing architecture, e-voting security is enhanced because to compromise an election, an attacker must target many individual mobile devices rather than a centralised web server. Lazaros Kyrillidis, Sheila Cobourne, Keith Mayes, Song Dong, Konstantinos Markantonakis |
CRiSIS | 5 |
| 2012 | Coopetitive Architecture to Support a Dynamic and Scalable NFC Based Mobile Services Architecture
Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes |
ICICS | 2 |
| 2012 | A Privacy Preserving Application Acquisition ProtocolabstractIn the smart card industry, the application acquisition process involves the card issuers and application providers. During this process, the respective card issuer reveals the identity of the smart card user to the individual application providers. In certain application scenarios it might be necessary (e.g. banking and identity applications). However, with introduction of the Trusted Service Manager (TSM) architecture there might be valid cases where revealing the card user's identity is not necessary. At the moment, the secure channel protocols for traditional smart card architecture including the TSM does not preserve the privacy of the card users. In this paper, we propose a secure and trusted channel protocol that provide such feature along with satisfying the requirements of an open and dynamic environment referred as User Centric Smart Card Ownership Model (UCOM). A comparison is provided between the proposed protocol and selected smart card protocols. In addition, we provide an informal analysis along with mechanical formal analysis using CasperFDR. Finally, we provide the test implementation and performance results. Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes |
TrustCom | 2 |
| 2011 | Application-Binding Protocol in the User Centric Smart Card Ownership Model
Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes |
ACISP | 2 |
| 2011 | Cross-Platform Application Sharing MechanismabstractThe application sharing mechanism in multi application smart cards facilitates corroborative schemes between applications in a secure and reliable manner. Traditional application sharing can only be realised if both applications are installed on the same device. In this paper, we extend the smart card firewall to include the application sharing mechanism between applications installed on different smart cards. We propose Platform and Application Binding Protocols that enables two smart-cards / applications to authenticate and ascertain the trustworthiness before sharing resources. Furthermore, we provide an informal analysis of the protocols along with comparison with existing protocols. Subsequently, mechanical formal analysis based on the CasperFDR, and the implementation experience is presented. Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes |
TrustCom | 2 |
| 2011 | Considerations for mobile authentication in the Cloud
Zaheer Ahmad, Keith Mayes, Song Dong, Konstantinos Markantonakis |
Inf. Secur. Tech. Rep. | 4 |
| 2010 | Firewall Mechanism in a User Centric Smart Card Ownership Model
Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes |
CARDIS | 2 |
| 2010 | Simulator Problem in User Centric Smart Card Ownership ModelabstractThe Issuer Centric Smart Card Ownership Model (ICOM) gives complete control of smart cards to their respective card issuers, enabling them to install, modify or delete applications remotely, in a secure manner. However, the User Centric Smart Card Ownership Model (UCOM) delegates the ownership of smart cards to their users, entitling them to install or delete any application according to their requirements. In the UCOM there might be no off-card relationship between a smart card and an application provider, referred to as a Service Provider, which is the cornerstone of the ICOM security framework. Therefore, this creates unique security issues like the simulator problem, in which a malicious user may simulate the smart card environment on a computing device and requests installation of an application. Following this, it might be possible to retrieve sensitive application data by reverse engineering. In this paper, we analyse the simulator problem, how it affects the UCOM and propose a possible solution. Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes |
EUC | 2 |
| 2010 | A Dynamic and Ubiquitous Smart Card Security Assurance and Validation Mechanism
Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes |
SEC | 2 |
| 2010 | Website Credential Storage and Two-Factor Web Authentication with a Java SIM
Jonathan Hart, Konstantinos Markantonakis, Keith Mayes |
WISTP | 2 |
| 2009 | A Secure and Efficient Mutual Authentication Protocol for Low-Cost RFID SystemsabstractIn this work we propose a mutual authentication protocol for RFID (Radio Frequency Identification) systems incorporating low-cost RFID tags. These tags, due to their limited computational capabilities do not incorporate advanced cryptographic primitives. As a result, there are various threats against userspsila privacy and against the security of such systems. Our protocol, PMM, utilizes a hash function and a pseudorandom number generator that can be hardware implemented in a low-cost RFID tag. As we will demonstrate, our protocol offers a high level of security by preventing replay attacks, Denial-of-Service attacks, tracking attacks, tag spoofing and by offering forward security and an enhanced protection of user privacy. George Poulopoulos, Konstantinos Markantonakis, Keith Mayes |
ARES | 2 |
| 2009 | Select-Response Grouping Proof for RFID TagsabstractIn this paper, we investigate a scenario of RFID applications referred to enable a group of RFID tags which have been scanned simultaneously by a reading device, is literally called grouping proof problems. After examining the existing ldquoYoking Proofrdquo protocols of RFID, this paper proposes a protocol called ldquoSelect-Responserdquo Grouping Proof. Instead of waiting the computation result from the tags as previous protocols, the new protocol uses a new mechanism that the reader actively selects the demanded tags to fulfill the verification. With this fundamental change, our protocol neutralizes the threats of denial of service attack, which is suffered by the ldquoYoking Proofrdquo protocols, and provide collision-free and missing tag identification properties, which would offer great help in the practical applications. Xuefei Leng, Yuanhung Lien, Keith Mayes, Konstantinos Markantonakis, Jung-Hui Chiu |
ACIIDS | 4 |
| 2009 | Confidence in smart token proximity: Relay attacks revisited
Gerhard P. Hancke 0002, Keith Mayes, Konstantinos Markantonakis |
Comput. Secur. | 3 |
| 2009 | Attacking smart card systems: Theory and practice
Konstantinos Markantonakis, Michael Tunstall, Gerhard P. Hancke 0002, Ioannis G. Askoxylakis, Keith Mayes |
Inf. Secur. Tech. Rep. | 1 |
| 2009 | Transport ticketing security and fraud controls
Keith Mayes, Konstantinos Markantonakis, Gerhard P. Hancke 0002 |
Inf. Secur. Tech. Rep. | 2 |
| 2008 | Fraud Detection and Prevention in Smart Card Based Environments Using Artificial Intelligence
Wael William Zakhari Malek, Keith Mayes, Konstantinos Markantonakis |
CARDIS | 3 |
| 2008 | Mobile communication security controllers an evaluation paper
Keith Mayes, Konstantinos Markantonakis |
Inf. Secur. Tech. Rep. | 2 |
| 2007 | A Comparative Analysis of Common Threats, Vulnerabilities, Attacks and Countermeasures Within Smart Card and Wireless Sensor Network Node Technologies
Kevin Eagles, Konstantinos Markantonakis, Keith Mayes |
WISTP | 2 |
| 2006 | Practical Fair-Exchange E-Payment Protocol for Anonymous Purchase and Physical DeliveryabstractIn this paper, a practical electronic-payment (epayment) protocol is presented for use over the internet. The protocol applies the principle of true fair-exchange to the process of purchase and physical delivery via an ecommerce system without the involvement of third party, whilst maintaining customer and merchant anonymity. Qing Zhang 0002, Konstantinos Markantonakis, Keith Mayes |
AICCSA | 2 |
| 2006 | Design, Installation and Execution of a Security Agent for Mobile Stations
William G. Sirett, John A. MacDonald, Keith Mayes, Konstantinos Markantonakis |
CARDIS | 4 |
| 2006 | On the potential of high density smart cards
Keith Mayes, Konstantinos Markantonakis |
Inf. Secur. Tech. Rep. | 2 |
| 2005 | On the Performance of Certificate Revocation Protocols Based on a Java Card Certificate Client Implementation
K. Papapanagiotou, Konstantinos Markantonakis, Qing Zhang 0002, William G. Sirett, Keith Mayes |
SEC | 2 |
| 2004 | An Asymmetric Cryptography Secure Channel Protocol for Smart CardsabstractSmart card secure channel protocols based on public key cryptography are not widely utilised mainly due to processing overheads introduced in the underlying smart card microprocessors and the complexities introduced by the operation of a PKI infrastructure. In this paper we analyse the significance of public key secure channel protocols in multi application smart cards. We believe that multi application smart card technology (e.g. the GlobalPlatform smart card specification) should benefit more from the advantages of public key cryptography specifically for the initiation and maintenance of a secure channel. This paper introduces a public key based cryptographic protocol for secure entity authentication, data integrity and data confidentiality. The proposed secure channel protocol uses a combination of public key, secret key and the main idea behind the Diffie-Hellmann key establishment protocols in order to achieve the desired goals. Konstantinos Rantos, Konstantinos Markantonakis |
SEC | 2 |
| 2003 | An overview of the GlobalPlatform smart card specification
Konstantinos Markantonakis, Keith Mayes |
Inf. Secur. Tech. Rep. | 1 |
| 2003 | Are we smart about security?
Keith Mayes, Konstantinos Markantonakis |
Inf. Secur. Tech. Rep. | 2 |
| 2001 | Is the Performance of Smart Card Cryptographic Functions the Real Bottleneck?
Konstantinos Markantonakis |
SEC | 1 |
| 1999 | Boundary Conditions that Influence Decisions about Log File Formats in Multi-Application Smart Cards
Konstantinos Markantonakis |
ICICS | 1 |
| 1999 | Interfacing with smartcard applications - (ThOpen Card Framework and PC/SC)
Konstantinos Markantonakis |
Inf. Secur. Tech. Rep. | 1 |
| 1998 | Secure Log File Download Mechanisms for Smart Cards
Konstantinos Markantonakis |
CARDIS | 1 |
| 1998 | Java card technology and security
Konstantinos Markantonakis |
Inf. Secur. Tech. Rep. | 1 |