EDBT 2026 Demo / reviewers in the wild / expert
Sergei P. Skorobogatov
dblp:50/270
· DBLP profile ↗
6ranked-venue papers
4as first author
0since 2021 · last 2014
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
5 papers |
Hardware security and side channels · 40% Cryptographic protocols and secure computation · 25% Network security · 25% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Storage systems · 100% |
Topics — the 11 heaviest of 12, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network security › attack strategy
man-in-the-middle attack |
0.2 | 1 | 2014 | Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014 |
Cryptographic protocols and secure computation
secure payment |
0.2 | 1 | 2014 | Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014 |
Hardware security and side channels › side-channel attack
power analysis |
0.1 | 1 | 2006 | Optically Enhanced Position-Locked Power Analysis · CHES 2006 |
Hardware security and side channels
side-channel attack |
0.1 | 1 | 2006 | Optically Enhanced Position-Locked Power Analysis · CHES 2006 |
Authentication and access control › authentication
authentication protocols |
0.1 | 1 | 2014 | Chip and Skim: Cloning EMV Cards with the Pre-play Attack · IEEE Symposium on Security and Privacy 2014 |
Hardware security and side channels › memory security
data remanence |
0.1 | 1 | 2005 | Data Remanence in Flash Memory Devices · CHES 2005 |
Hardware security and side channels
fault attacks |
0.0 | 1 | 2002 | Optical Fault Induction Attacks · CHES 2002 |
Hardware security and side channels › hardware attacks
side-channel and fault attacks |
0.0 | 2 | 2006 | Optically Enhanced Position-Locked Power Analysis · CHES 2006 Optical Fault Induction Attacks · CHES 2002 |
Privacy and data protection › privacy compliance
data use policy enforcement |
0.0 | 1 | 2006 | Cryptographic Processors-A Survey · Proc. IEEE 2006 |
Storage systems
flash and SSD |
0.0 | 1 | 2005 | Data Remanence in Flash Memory Devices · CHES 2005 |
Storage systems › secure storage
flash memory security |
0.0 | 1 | 2005 | Data Remanence in Flash Memory Devices · CHES 2005 |
Methods — techniques the papers use, named apart from their topics
protocol analysis · 0.2field experiment · 0.2survey · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2014 | Chip and Skim: Cloning EMV Cards with the Pre-play AttackabstractEMV, also known as "Chip and PIN", is the leading system for card payments worldwide. It is used throughout Europe and much of Asia, and is starting to be introduced in North America too. Payment cards contain a chip so they can execute an authentication protocol. This protocol requires point-of-sale (POS) terminals or ATMs to generate a nonce, called the unpredictable number, for each transaction to ensure it is fresh. We have discovered two serious problems: a widespread implementation flaw and a deeper, more difficult to fix flaw with the EMV protocol itself. The first flaw is that some EMV implementers have merely used counters, timestamps or home-grown algorithms to supply this nonce. This exposes them to a "pre-play" attack which is indistinguishable from card cloning from the standpoint of the logs available to the card-issuing bank, and can be carried out even if it is impossible to clone a card physically. Card cloning is the very type of fraud that EMV was supposed to prevent. We describe how we detected the vulnerability, a survey methodology we developed to chart the scope of the weakness, evidence from ATM and terminal experiments in the field, and our implementation of proof-of-concept attacks. We found flaws in widely-used ATMs from the largest manufacturers. We can now explain at least some of the increasing number of frauds in which victims are refused refunds by banks which claim that EMV cards cannot be cloned and that a customer involved in a dispute must therefore be mistaken or complicit. The second problem was exposed by the above work. Independent of the random number quality, there is a protocol failure: the actual random number generated by the terminal can simply be replaced by one the attacker used earlier when capturing an authentication code from the card. This variant of the pre-play attack may be carried out by malware in an ATM or POS terminal, or by a man-in-the-middle between the terminal and the acquirer. We explore the design and implementation mistakes that enabled these flaws to evade detection until now: shortcomings of the EMV specification, of the EMV kernel certification process, of implementation testing, formal analysis, and monitoring customer complaints. Finally we discuss countermeasures. More than a year after our initial responsible disclosure of these flaws to the banks, action has only been taken to mitigate the first of them, while we have seen a likely case of the second in the wild, and the spread of ATM and POS malware is making it ever more of a threat. Mike Bond, Marios O. Choudary, Steven J. Murdoch, Sergei P. Skorobogatov, Ross J. Anderson |
IEEE Symposium on Security and Privacy | 4 |
| 2009 | Using Optical Emission Analysis for Estimating Contribution to Power AnalysisabstractThis paper shows that optical emissions from an operating chip have a good correlation with power traces and can therefore be used to estimate the contribution of different areas within the chip. I present a low-cost approach using inexpensive CCD cameras. The technique was used to recover data stored in SRAM, EEPROM and flash of a 0.9 ¿m microcontroller. The result of a backside approach in analysing a 0.13 ¿m chip is also presented. Practical limits for this analysis in terms of sample preparation, operating conditions and chip technology are also discussed. Optical emission analysis can be used for partial reverse engineering of the chip structure by spotting the active areas. This can assist in carrying out optical fault injection attacks later, thereby saving the time otherwise required for exhaustive search. Sergei P. Skorobogatov |
FDTC | 1 |
| 2006 | Optically Enhanced Position-Locked Power Analysis
Sergei P. Skorobogatov |
CHES | 1 |
| 2006 | Cryptographic Processors-A SurveyabstractTamper-resistant cryptographic processors are becoming the standard way to enforce data-usage policies. Their origins lie with military cipher machines and PIN processing in banking payment networks, expanding in the 1990s into embedded applications: token vending machines for prepayment electricity and mobile phone credit. Major applications such as GSM mobile phone identification and pay TV set-top boxes have pushed low-cost cryptoprocessors toward ubiquity. In the last five years, dedicated crypto chips have been embedded in devices such as game console accessories and printer ink cartridges, to control product and accessory after markets. The "Trusted Computing" initiative will soon embed cryptoprocessors in PCs so they can identify each other remotely. This paper surveys the range of applications of tamper-resistant hardware and the array of attack and defense mechanisms which have evolved in the tamper-resistance arms race. Ross J. Anderson, Mike Bond, Jolyon Clulow, Sergei P. Skorobogatov |
Proc. IEEE | 4 |
| 2005 | Data Remanence in Flash Memory Devices
Sergei P. Skorobogatov |
CHES | 1 |
| 2002 | Optical Fault Induction Attacks
Sergei P. Skorobogatov, Ross J. Anderson |
CHES | 1 |