EDBT 2026 Demo / reviewers in the wild / expert
Iwen Coisel
dblp:70/5358
· DBLP profile ↗
12ranked-venue papers
2as first author
2since 2021 · last 2024
0000-0001-6571-8441ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 1 first-author · 2 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | A comprehensive evaluation on the benefits of context based password cracking for digital forensicsabstractPassword-based authentication systems have many weaknesses, yet they remain overwhelmingly used and their announced disappearance is still undated. The system admin overcomes the imperfection by skilfully enforcing a strong password policy and sane password management on the server side. But in the end, the user behind the password is still responsible for the password’s strength. A poor choice can have dramatic consequences for the user or even for the service behind, especially considering critical infrastructure. On the other hand, law enforcement can benefit from a suspect’s weak decisions to recover digital content stored in an encrypted format. Generic password cracking procedures can support law enforcement in this matter — however, these approaches quickly demonstrate their limitations. This article proves that more targeted approaches can be used in combination with traditional strategies to increase the likelihood of success when contextual information is available and can be exploited. Aikaterini Kanta, Iwen Coisel, Mark Scanlon |
J. Inf. Secur. Appl. | 2 |
| 2021 | PCWQ: A Framework for Evaluating Password Cracking Wordlist Quality
Aikaterini Kanta, Iwen Coisel, Mark Scanlon |
ICDF2C | 2 |
| 2019 | Improved Forensic Recovery of PKZIP Stream Cipher PasswordsabstractData archives are often compressed following the PKZIP format and can optionally be encrypted with either the PKZIP stream cipher or the AES block cipher. In this article, we present new implementations of two attacks against the PKZIP stream cipher. To our knowledge, this is the first time those attacks have been demonstrated on Graphical Processing Unit (GPU). Our first implementation is retrieving archive passwords using the internal state of the PKZIP stream cipher obtained through the known-plaintext attack of Biham and Kocher. Passwords up to length 14 can be recovered within a month considering a single Nvidia 1080 Ti GPU. If one hundred of those cards are available, passwords up to length 15 would be recovered in less than 27 days. The second implementation is a more direct attack designed to retrieve an archive’s password without requiring any additional knowledge than the ciphertext. Experimental results show that our two implementations are at least ten times faster than the state of the art. This is an undeniable asset for investigators who may be particularly interested in further deepening their forensic analysis on an encrypted archive. Sein Coray, Iwen Coisel |
ICISSP | 2 |
| 2017 | Pan-European personal data breaches: Mapping of current practices and recommendations to facilitate cooperation among Data Protection AuthoritiesabstractThe emergence of frequent personal data breaches of a cross-border and even pan-European dimension coupled with the current lack of harmonized and systematic approaches to tackle them have motivated the need for further research leading to possible improvement of those cooperation challenges. In this respect, we report here on the organization, execution and analysis of the 1st Pan-European Personal Data Breaches Exercise that was conducted at the end of 2015 by the Directorate-General Joint Research Centre in collaboration with the Directorate-General for Justice and Consumers of the European Commission and the Data Protection Authorities of seven EU Member States. This cyber-exercise aimed at promoting and improving collaboration between Member States when cross-border incidents of personal data breaches occur, by serving as training exercise, mapping existing procedures and by helping identify best practices to handle such incidents. This scientific initiative constitutes a direct support of the recently adopted General Data Protection Regulation. Analysis of results led to some very interesting findings. In particular, communication issues were the ones that were highlighted as the most important ones. There is an evident lack of a global communication list of competent officers from Data Protection Authorities and this hinders cooperation. Moreover, there are no established current practices on handling such incidents and accordingly their management is still performed in an ad hoc manner. The outcome of the exercise illustrated the need for putting in place systematic procedures, as well as tools and frameworks to support communication and interaction between all interested stakeholders. Apostolos Malatras, Laurent Beslay, Iwen Coisel, Ioannis Vakalis, Giuseppe D'Acquisto, Manuel García Sánchez, Matthieu Grall, Marit Hansen, Vasilios Zorkadis |
Comput. Law Secur. Rev. | 4 |
| 2017 | A New Multimodal Approach for Password Strength Estimation - Part I: Theory and AlgorithmsabstractAfter more than two decades of research in the field of password strength estimation, one clear conclusion may be drawn: no password strength metric by itself is better than all other metrics for every possible password. Building upon this certainty and also taking advantage of the knowledge gained in the area of information fusion, in this paper, we propose a novel multimodal strength metric that combines several imperfect individual metrics to benefit from their strong points in order to overcome many of their weaknesses. The final multimodal metric comprises different modules based both on heuristics and statistics, which, after their fusion, succeed to provide in real time a realistic and reliable feedback regarding the “guessability” of passwords. The validation protocol and the test results are presented and discussed in a companion paper. Javier Galbally, Iwen Coisel |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | A New Multimodal Approach for Password Strength Estimation - Part II: Experimental EvaluationabstractA novel multimodal method for the estimation of password strength was presented in Part I of this series of two papers. In this paper, the experimental framework used for the evaluation of the novel approach is described. The method is evaluated following a reproducible protocol, which includes a three-dimensional approach: 1) deterministic assessment; 2) statistical assessment; and 3) third parties assessment (thanks to the availability upon request of an executable application that integrates the multimodal meter). The key experiment of the protocol compares, from a probabilistic point of view, the strength distributions assigned to passwords broken with increasingly complex attacking approaches, following a common strategy in a typical password cracking session. The experimental evaluation is carried out not only for the new meter, but also for other strength estimators from the state of the art, comparing their overall performance. In addition to its consistent results, the proposed method is highly flexible and can be adjusted to specific environments or to a certain password policy. Furthermore, it can also evolve over time in order to naturally adjust to new password selection trends followed by users. Javier Galbally, Iwen Coisel |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | Improved Cryptanalysis of the DECT Standard Cipher
Iwen Coisel |
CHES | 1 |
| 2015 | Physical attacks against the lack of perfect forward secrecy in DECT encrypted communications and possible countermeasuresabstractDigital Enhanced Cordless Telecommunications (DECT) is a world-wide wireless standard sustained by ETSI and widely used in cordless telephony. Whilst domestic DECT cordless phones were primarily designed to be used in connection with the Public Switched Telephone Network, their presence in Unified Communications systems has become increasingly common given their reliability, flexibility and interoperability. The DECT protocol foresees the usage of authentication and encryption in order to protect the privacy of the voice communications. Unfortunately, the cryptographic mechanisms envisaged by the standard do not provide support for forward secrecy. As a consequence, the compromise of the long-term secret cryptographic key leads to the decryption of any previous, present and future encrypted communication. In this paper, we describe and demonstrate experimentally a new physical attack, able to recover the long-term cryptographic key from the memory of DECT devices and use it to decrypt voice communications previously intercepted in encrypted form. In order to mitigate this threat to the privacy of the DECT communications, we propose a set of countermeasures and proposals for modification of the standards to provide forward secrecy in the communications. Iwen Coisel, David Shaw |
IWCMC | 1 |
| 2014 | Untraceability Model for RFIDabstractAfter several years of research on cryptographic models for privacy in RFID systems, it appears that no universally model exists yet. Experience shows that security experts usually prefer using their own ad-hoc model than the existing ones. In particular, the impossibility of the models to refine the privacy assessment of different protocols has been highlighted in several studies. The paper emphasizes the necessity to define a new model capable of comparing protocols meaningfully. It introduces an untraceability model that is operational where the previous models are not. The model aims to be easily usable to design proofs or describe attacks. This spirit led to a modular model where adversary actions (oracles), capabilities (selectors and restrictions), and goals (experiment) follow an intuitive and practical approach. This design enhances the ability to formalize new adversarial assumptions and future evolutions of the technology, and provide a finest privacy evaluation of protocols. Gildas Avoine, Iwen Coisel, Tania Martin |
IEEE Trans. Mob. Comput. | 2 |
| 2013 | Toward Generic Method for Server-Aided Cryptography
Sébastien Canard, Iwen Coisel, Julien Devigne, Cécilia Gallais, Thomas Peters, Olivier Sanders |
ICICS | 2 |
| 2012 | A privacy-restoring mechanism for offline RFID systemsabstractAuthentication protocols are usually designed to face an adversary who is able to tamper with the channel, possibly with the prover, but rarely with the verifier. When considering large-scale RFID applications, e.g., mass transportation or ticketing, the last threat is no longer a fiction. A typical case is the loss or theft of a handheld reader. If the protocol is expected to be privacy-friendly, and run by offline readers, there is no solution currently to restore the privacy once the readers are compromised except renewing all the tags, which is definitely impractical. Gildas Avoine, Iwen Coisel, Tania Martin |
WISEC | 2 |
| 2007 | Complex Zero-Knowledge Proofs of Knowledge Are Easy to Use
Sébastien Canard, Iwen Coisel, Jacques Traoré |
ProvSec | 2 |