Sergei P. Skorobogatov

dblp:50/270 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
0since 2021 · last 2014
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
5 papers
Hardware security and side channels · 40% Cryptographic protocols and secure computation · 25% Network security · 25%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Storage systems · 100%

Topics — the 11 heaviest of 12, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › attack strategy
man-in-the-middle attack
0.212014
Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014
Cryptographic protocols and secure computation
secure payment
0.212014
Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014
Hardware security and side channels › side-channel attack
power analysis
0.112006
Optically Enhanced Position-Locked Power Analysis · CHES 2006
Hardware security and side channels
side-channel attack
0.112006
Optically Enhanced Position-Locked Power Analysis · CHES 2006
Authentication and access control › authentication
authentication protocols
0.112014
Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014
Hardware security and side channels › memory security
data remanence
0.112005
Data Remanence in Flash Memory Devices · CHES 2005
Hardware security and side channels
fault attacks
0.012002
Optical Fault Induction Attacks · CHES 2002
Hardware security and side channels › hardware attacks
side-channel and fault attacks
0.022006
Optically Enhanced Position-Locked Power Analysis · CHES 2006
Optical Fault Induction Attacks · CHES 2002
Privacy and data protection › privacy compliance
data use policy enforcement
0.012006
Cryptographic Processors-A Survey · Proc. IEEE 2006
Storage systems
flash and SSD
0.012005
Data Remanence in Flash Memory Devices · CHES 2005
Storage systems › secure storage
flash memory security
0.012005
Data Remanence in Flash Memory Devices · CHES 2005

Methods — techniques the papers use, named apart from their topics

protocol analysis · 0.2field experiment · 0.2survey · 0.1
YearPublicationVenuePosition
2014 Chip and Skim: Cloning EMV Cards with the Pre-play Attack
abstract
EMV, also known as "Chip and PIN", is the leading system for card payments worldwide. It is used throughout Europe and much of Asia, and is starting to be introduced in North America too. Payment cards contain a chip so they can execute an authentication protocol. This protocol requires point-of-sale (POS) terminals or ATMs to generate a nonce, called the unpredictable number, for each transaction to ensure it is fresh. We have discovered two serious problems: a widespread implementation flaw and a deeper, more difficult to fix flaw with the EMV protocol itself. The first flaw is that some EMV implementers have merely used counters, timestamps or home-grown algorithms to supply this nonce. This exposes them to a "pre-play" attack which is indistinguishable from card cloning from the standpoint of the logs available to the card-issuing bank, and can be carried out even if it is impossible to clone a card physically. Card cloning is the very type of fraud that EMV was supposed to prevent. We describe how we detected the vulnerability, a survey methodology we developed to chart the scope of the weakness, evidence from ATM and terminal experiments in the field, and our implementation of proof-of-concept attacks. We found flaws in widely-used ATMs from the largest manufacturers. We can now explain at least some of the increasing number of frauds in which victims are refused refunds by banks which claim that EMV cards cannot be cloned and that a customer involved in a dispute must therefore be mistaken or complicit. The second problem was exposed by the above work. Independent of the random number quality, there is a protocol failure: the actual random number generated by the terminal can simply be replaced by one the attacker used earlier when capturing an authentication code from the card. This variant of the pre-play attack may be carried out by malware in an ATM or POS terminal, or by a man-in-the-middle between the terminal and the acquirer. We explore the design and implementation mistakes that enabled these flaws to evade detection until now: shortcomings of the EMV specification, of the EMV kernel certification process, of implementation testing, formal analysis, and monitoring customer complaints. Finally we discuss countermeasures. More than a year after our initial responsible disclosure of these flaws to the banks, action has only been taken to mitigate the first of them, while we have seen a likely case of the second in the wild, and the spread of ATM and POS malware is making it ever more of a threat.
Mike Bond, Marios O. Choudary, Steven J. Murdoch, Sergei P. Skorobogatov, Ross J. Anderson
IEEE Symposium on Security and Privacy4
2009 Using Optical Emission Analysis for Estimating Contribution to Power Analysis
abstract
This paper shows that optical emissions from an operating chip have a good correlation with power traces and can therefore be used to estimate the contribution of different areas within the chip. I present a low-cost approach using inexpensive CCD cameras. The technique was used to recover data stored in SRAM, EEPROM and flash of a 0.9 ¿m microcontroller. The result of a backside approach in analysing a 0.13 ¿m chip is also presented. Practical limits for this analysis in terms of sample preparation, operating conditions and chip technology are also discussed. Optical emission analysis can be used for partial reverse engineering of the chip structure by spotting the active areas. This can assist in carrying out optical fault injection attacks later, thereby saving the time otherwise required for exhaustive search.
Sergei P. Skorobogatov
FDTC1
2006 Optically Enhanced Position-Locked Power Analysis
Sergei P. Skorobogatov
CHES1
2006 Cryptographic Processors-A Survey
abstract
Tamper-resistant cryptographic processors are becoming the standard way to enforce data-usage policies. Their origins lie with military cipher machines and PIN processing in banking payment networks, expanding in the 1990s into embedded applications: token vending machines for prepayment electricity and mobile phone credit. Major applications such as GSM mobile phone identification and pay TV set-top boxes have pushed low-cost cryptoprocessors toward ubiquity. In the last five years, dedicated crypto chips have been embedded in devices such as game console accessories and printer ink cartridges, to control product and accessory after markets. The "Trusted Computing" initiative will soon embed cryptoprocessors in PCs so they can identify each other remotely. This paper surveys the range of applications of tamper-resistant hardware and the array of attack and defense mechanisms which have evolved in the tamper-resistance arms race.
Ross J. Anderson, Mike Bond, Jolyon Clulow, Sergei P. Skorobogatov
Proc. IEEE4
2005 Data Remanence in Flash Memory Devices
Sergei P. Skorobogatov
CHES1
2002 Optical Fault Induction Attacks
Sergei P. Skorobogatov, Ross J. Anderson
CHES1