EDBT 2026 Demo / reviewers in the wild / expert
Saar Drimer
dblp:54/136
· DBLP profile ↗
5ranked-venue papers
4as first author
0since 2021 · last 2010
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-authorSystems, architecture and hardware · 2 · 2 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Authentication and access control · 38% Hardware security and side channels · 30% Cryptographic protocols and secure computation · 16% |
Topics — the 8 heaviest of 9, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network security › attack strategy
man-in-the-middle attack |
0.1 | 1 | 2010 | Chip and PIN is Broken · IEEE Symposium on Security and Privacy 2010 |
Cryptographic protocols and secure computation
secure payment |
0.1 | 1 | 2010 | Chip and PIN is Broken · IEEE Symposium on Security and Privacy 2010 |
Hardware security and side channels › cryptographic hardware
smart card security |
0.1 | 2 | 2008 | Keep Your Enemies Close: Distance Bounding Against Smartcard Relay Attacks · USENIX Security Symposium 2007 Thinking Inside the Box: System-Level Failures of Tamper Proofing · SP 2008 |
Authentication and access control › user authentication
payment authentication |
0.1 | 1 | 2008 | Thinking Inside the Box: System-Level Failures of Tamper Proofing · SP 2008 |
Hardware security and side channels
tamper-resistant hardware |
0.1 | 1 | 2008 | Thinking Inside the Box: System-Level Failures of Tamper Proofing · SP 2008 |
Authentication and access control › proximity-based authentication
distance bounding protocols |
0.1 | 1 | 2007 | Keep Your Enemies Close: Distance Bounding Against Smartcard Relay Attacks · USENIX Security Symposium 2007 |
Authentication and access control › proximity-based authentication
relay attack |
0.1 | 1 | 2007 | Keep Your Enemies Close: Distance Bounding Against Smartcard Relay Attacks · USENIX Security Symposium 2007 |
Hardware security and side channels
trusted execution environments |
0.0 | 1 | 2008 | Thinking Inside the Box: System-Level Failures of Tamper Proofing · SP 2008 |
Methods — techniques the papers use, named apart from their topics
protocol analysis · 0.1practical attack demonstration · 0.1protocol reverse engineering · 0.1physical attack · 0.1certification analysis · 0.1distance bounding protocols · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2010 | Chip and PIN is BrokenabstractEMV is the dominant protocol used for smart card payments worldwide, with over 730 million cards in circulation. Known to bank customers as “Chip and PIN”, it is used in Europe; it is being introduced in Canada; and there is pressure from banks to introduce it in the USA too. EMV secures credit and debit card transactions by authenticating both the card and the customer presenting it through a combination of cryptographic authentication codes, digital signatures, and the entry of a PIN. In this paper we describe and demonstrate a protocol flaw which allows criminals to use a genuine card to make a payment without knowing the card's PIN, and to remain undetected even when the merchant has an online connection to the banking network. The fraudster performs a man-in-the-middle attack to trick the terminal into believing the PIN verified correctly, while telling the card that no PIN was entered at all. The paper considers how the flaws arose, why they remained unknown despite EMV's wide deployment for the best part of a decade, and how they might be fixed. Because we have found and validated a practical attack against the core functionality of EMV, we conclude that the protocol is broken. This failure is significant in the field of protocol design, and also has important public policy implications, in light of growing reports of fraud on stolen EMV cards. Frequently, banks deny such fraud victims a refund, asserting that a card cannot be used without the correct PIN, and concluding that the customer must be grossly negligent or lying. Our attack can explain a number of these cases, and exposes the need for further research to bridge the gap between the theoretical and practical security of bank payment systems. It also demonstrates the need for the next version of EMV to be engineered properly. Steven J. Murdoch, Saar Drimer, Ross J. Anderson, Mike Bond |
IEEE Symposium on Security and Privacy | 2 |
| 2010 | DSPs, BRAMs, and a Pinch of Logic: Extended Recipes for AES on FPGAsabstractWe present three lookup-table-based AES implementations that efficiently use the BlockRAM and DSP units embedded within Xilinx Virtex-5 FPGAs. An iterative module outputs a 32-bit AES round column every clock cycle, with a throughput of 1.67 Gbit/s when processing two 128-bit inputs. This construct is then replicated four times to provide a complete AES round per cycle with 6.7 Gbit/s throughput when processing eight input streams. This, in turn, is replicated ten times for a fully unrolled design providing over 52 Gbit/s of throughput. We also present implementations of a BRAM-based AES key-expansion, CMAC, and CTR modes of operation. Results for designs where DSPs are replaced by regular logic are also presented. The combination and arrangement of the specialized embedded functions available in the FPGA allows us to implement our designs using very few traditional user logic elements such as flip-flops and lookup tables, yet still achieve these high throughputs. HDL source code, simulation testbenches, and software tool commands to reproduce reported results for the three AES variants and CMAC mode are made publicly available. Our contribution concludes with a discussion on comparing cipher implementations in the literature, and why these comparisons can be meaningless without a common reporting methodology, or within the context of a constrained target application. Saar Drimer, Tim Güneysu, Christof Paar |
ACM Trans. Reconfigurable Technol. Syst. | 1 |
| 2008 | DSPs, BRAMs and a Pinch of Logic: New Recipes for AES on FPGAsabstractWe present an AES cipher implementation that is based on the BlockRAM and DSP units embedded within Xilinx's Virtex-5 FPGAs. An iterative "basic" module outputs a 32 bit column of an AES round each clock cycle, with a throughput of 1.76 Gbit/s when processing two 128 bit inputs. This construct is replicated four times for a 128 bit datapath for a full AES round with 6.21 Gbit/s throughput when processing eight inputs. Finally, the "round" module is replicated ten times for a fully unrolled design that yields over 55 Gbit/s of throughput. The combination and arrangement of the specialized embedded functions available in the FPGA allows us to implement our designs using very few traditional user logic elements such as flip-flops and lookup tables, yet still achieve these high throughputs. The complete source code for these designs is made publicly available for use in further research and for replicating our results. Our contribution ends with a discussion of comparing cipher implementations in the literature, and why these comparisons can be meaningless without a common reporting style, platform, or within the context of a specific constrained application. Saar Drimer, Tim Güneysu, Christof Paar |
FCCM | 1 |
| 2008 | Thinking Inside the Box: System-Level Failures of Tamper ProofingabstractPIN entry devices (PEDs) are critical security components in EMV smartcard payment systems as they receive a customer's card and PIN. Their approval is subject to an extensive suite of evaluation and certification procedures. In this paper, we demonstrate that the tamper proofing of PEDs is unsatisfactory, as is the certification process. We have implemented practical low-cost attacks on two certified, widely-deployed PEDs - the Ingenico 13300 and the Dione Xtreme. By tapping inadequately protected smartcard communications, an attacker with basic technical skills can expose card details and PINs, leaving cardholders open to fraud. We analyze the anti-tampering mechanisms of the two PEDs and show that, while the specific protection measures mostly work as intended, critical vulnerabilities arise because of the poor integration of cryptographic, physical and procedural protection. As these vulnerabilities illustrate a systematic failure in the design process, we propose a methodology for doing it better in the future. These failures also demonstrate a serious problem with the Common Criteria. So we discuss the incentive structures of the certification process, and show how they can lead to problems of the kind we identified. Finally we recommend changes to the Common Criteria framework in light of the lessons learned. Saar Drimer, Steven J. Murdoch, Ross J. Anderson |
SP | 1 |
| 2007 | Keep Your Enemies Close: Distance Bounding Against Smartcard Relay Attacks
Saar Drimer, Steven J. Murdoch |
USENIX Security Symposium | 1 |