EDBT 2026 Demo / reviewers in the wild / expert
Chris J. Mitchell
dblp:m/ChrisJMitchell
· DBLP profile ↗
100ranked-venue papers
39as first author
7since 2021 · last 2025
0000-0002-6118-0055ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 74 · 23 first-author · 4 since 2021Theory of computation · 11 · 10 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 4 first-author · 1 since 2021Computer networks · 5 · 1 first-authorSystems, architecture and hardware · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Orientable and negative orientable sequencesabstractAnalogously to de Bruijn sequences, orientable sequences have application in automatic position-location applications and, until recently, studies of these sequences focused on the binary case. In recent work by Alhakim et al., a range of methods of construction were described for orientable sequences over arbitrary finite alphabets; some of these methods involve using negative orientable sequences as a building block. In this paper we describe three techniques for generating such negative orientable sequences, as well as upper bounds on their period. We then go on to show how these negative orientable sequences can be used to generate orientable sequences for every non-binary alphabet size and for every tuple length. In doing so we use two closely related approaches described by Alhakim et al. The periods of both negative orientable and orientable sequences that we construct are of the same order of magnitude as the upper bounds. Chris J. Mitchell, Peter R. Wild |
Discret. Appl. Math. | 1 |
| 2023 | Special Issue on Failed Approaches and Insightful Losses in Cryptology - ForewordabstractThe importance of the notion of Publish or Perish for academic research is indisputable. This message, cynical as it may sound, guides students and researchers alike in planning their career path, and as a consequence shapes scientific progress as a whole. Opting for rational behavior, many researchers choose to work on topics that are uncontroversial, incremental and easily published, and stay away from riskier areas. Yet science, as the reader surely knows, advances most through adversity and failure. CFail, The Conference for Failed Approaches and Insightful Losses in Cryptology, has since 2019 been a venue for the cryptography community to share scientific progress that has not come to fruition in the traditional sense. Encouraged by the high engagement and positive feedback, the CFail 2021 team sought to better align the conference’s vision with traditional academic incentives. Partnering with The Computer Journal, authors of eligible submissions to the conference were invited to submit a full version of their work to be considered for inclusion in a special issue. Tomer Ashur, Chris J. Mitchell |
Comput. J. | 2 |
| 2022 | Constructing Orientable SequencesabstractThis paper describes new, simple, recursive methods of construction fororientable sequences, i.e. periodic binary sequences in which any$n$-tuple occurs at most once in a period in either direction. As has been previously described, such sequences have potential applications in automatic position-location systems, where the sequence is encoded onto a surface and a reader needs only examine$n$consecutive encoded bits to determine its location and orientation on the surface. The only previously described method of construction (due to Daiet al.) is somewhat complex, whereas the new techniques are simple to both describe and implement. The methods of construction cover both the standard ‘infinite periodic’ case, and also the aperiodic, finite sequence, case. Both the new methods build on the Lempel homomorphism, first introduced as a means of recursively generating de Bruijn sequences. Chris J. Mitchell, Peter R. Wild |
IEEE Trans. Inf. Theory | 1 |
| 2021 | Automating the Evaluation of Trustworthiness
Marc Sel, Chris J. Mitchell |
TrustBus | 2 |
| 2021 | Privacy-Preserving Biometric Matching Using Homomorphic EncryptionabstractBiometric matching involves storing and processing sensitive user information. Maintaining the privacy of this data is thus a major challenge, and homomorphic encryption offers a possible solution. We propose a privacy-preserving biometrics-based authentication protocol based on fully homomorphic en-cryption, where the biometric sample for a user is gathered by a local device but matched against a biometric template by a remote server operating solely on encrypted data. The design ensures that 1) the user's sensitive biometric data remains private, and 2) the user and client device are securely authenticated to the server. A proof-of-concept implementation building on the TFHE library is also presented, which includes the underlying basic operations needed to execute the biometric matching. Performance results from the implementation show how complex it is to make FHE practical in this context, but it appears that, with implementation optimisations and improvements, the protocol could be used for real-world applications. Gaëtan Pradel, Chris J. Mitchell |
TrustCom | 2 |
| 2021 | How not to secure wireless sensor networks: a plethora of insecure polynomial-based key pre-distribution schemesabstractAbstract Three closely related polynomial‐based group key pre‐distribution schemes have recently been proposed, aimed specifically at wireless sensor networks. The schemes enable any subset of a predefined set of sensor nodes to establish a shared secret key without any communications overhead. It is claimed that these schemes are both secure and lightweight, that is, making them particularly appropriate for network scenarios where nodes have limited computational and storage capabilities. Further studies have built on these schemes, for example, to propose secure routing protocols for wireless sensor networks. Unfortunately, as shown by the author, all three schemes are completely insecure; whilst the details of their operation vary, they share common weaknesses. In two cases, we show that an attacker equipped with the information built into just one sensor node can compute all possible group keys, including those for which the attacked node is not a member; this breaks a fundamental design objective. In the other case, an attacker equipped with the information built into at most two sensor nodes can compute all possible group keys. In the latter case, the attack can also be achieved by an attacker armed with the information from a single node together with a single group key to which this sensor node is not entitled. Repairing the schemes appears difficult, if not impossible. The existence of major flaws is not surprising given the complete absence of any rigorous proofs of security for the proposed schemes. A further recent work proposes a group membership authentication and key establishment scheme based on one of the three key pre‐distribution schemes analysed here; as the author demonstrates, this scheme is also insecure, as the attack we describe on the corresponding pre‐distribution scheme enables the authentication process to be compromised. Chris J. Mitchell |
IET Inf. Secur. | 1 |
| 2021 | Yet another insecure group key distribution scheme using secret sharing
Chris J. Mitchell |
J. Inf. Secur. Appl. | 1 |
| 2020 | The impact of quantum computing on real-world security: A 5G case study
Chris J. Mitchell |
Comput. Secur. | 1 |
| 2019 | Security issues in a group key establishment protocolabstractMajor shortcomings in a recently published group key establishment protocol are described; this protocol enables any participant to choose and broadcast a secret key to a group of other participants. We show that any valid recipient of a broadcast can successfully impersonate the originator of that broadcast to send a new key to the original set of recipients. Also, if a broadcast key is ever compromised, then any party (insider or outsider) who learns this key can force its reuse indefinitely. These shortcomings are sufficiently serious that the protocol should not be used. Chris J. Mitchell |
Comput. J. | 1 |
| 2018 | Beyond Cookie Monster Amnesia: Real World Persistent Online Tracking
Nasser Mohammed Al-Fannah, Wanpeng Li, Chris J. Mitchell |
ISC | 3 |
| 2018 | Mitigating CSRF attacks on OAuth 2.0 SystemsabstractMany millions of users routinely use Google, Facebook and Microsoft to log in to websites supporting OAuth 2.0 and/or OpenID Connect. The security of OAuth 2.0 and OpenID Connect is therefore of critical importance. Unfortunately, as previous studies have shown, real-world implementations of both schemes are often vulnerable to attack, and in particular to cross-site request forgery (CSRF) attacks. In this paper we propose a new and practical technique which can be used to mitigate CSRF attacks against both OAuth 2.0 and OpenID Connect. Wanpeng Li, Chris J. Mitchell, Thomas M. Chen |
PST | 2 |
| 2017 | Trashing IMSI catchers in mobile networksabstractWe address the decades-old privacy problem of disclosure of the permanent subscriber identity (IMSI) that makes IMSI catchers a real threat to all generations of mobile networks. A number of possible modifications to existing protocols have been proposed to address the problem; however, most require significant changes to existing deployed infrastructures. We propose a novel authentication approach for 3G and 4G systems that does not affect intermediate entities, notably the serving network and mobile equipment. It prevents disclosure of the subscriber's IMSI by using a dynamic pseudo-IMSI that is only identifiable by the home network for the USIM. A major challenge in using dynamic pseudo-IMSIs is possible loss of identity synchronisation between USIM and home network, an issue that has not been adequately addressed in previous work. We present an approach for identity recovery to be used in the event of pseudo-IMSI desynchronisation. The scheme requires changes to the home network and the USIM, but not to the serving network, mobile phone or other internal network protocols, enabling simple, transparent and evolutionary migration. We provide a detailed analysis of the scheme, and verify its correctness and security properties using ProVerif. Mohammed Shafiul Alam Khan, Chris J. Mitchell |
WISEC | 2 |
| 2016 | Analysing the Security of Google's Implementation of OpenID Connect
Wanpeng Li, Chris J. Mitchell |
DIMVA | 2 |
| 2016 | Password Generators: Old Ideas and New
Fatma Al Maqbali, Chris J. Mitchell |
WISTP | 2 |
| 2016 | Editorial for the 25th anniversary issue
Dieter Jungnickel, Jennifer D. Key, Chris J. Mitchell, Ronald C. Mullin, Peter R. Wild |
Des. Codes Cryptogr. | 3 |
| 2016 | On the Security of 2-Key Triple DESabstractThis paper reconsiders the security offered by two-key triple DES, an encryption technique that remains widely used despite recently being de-standardised by NIST. A generalization of the 1990 van Oorschot-Wiener attack is described, constituting the first advance in cryptanalysis of two-key triple DES since 1990. We give further attack enhancements that together imply that the widely used estimate that two-key triple DES provides 80 bits of security can no longer be regarded as conservative; the widely stated assertion that the scheme is secure as long as the key is changed regularly is also challenged. The main conclusion is that, whilst not completely broken, the margin of safety for two-key triple DES is slim, and efforts to replace it, at least with its three-key variant, and preferably with a more modern cipher such as AES, should be pursued with some urgency. Chris J. Mitchell |
IEEE Trans. Inf. Theory | 1 |
| 2014 | Another Look at Privacy Threats in 3G Mobile Telephony
Mohammed Shafiul Alam Khan, Chris J. Mitchell |
ACISP | 2 |
| 2014 | Security Issues in OAuth 2.0 SSO Implementations
Wanpeng Li, Chris J. Mitchell |
ISC | 2 |
| 2013 | Analysing the IOBC Authenticated Encryption Mode
Chris J. Mitchell |
ACISP | 1 |
| 2013 | Ubiquitous One-Time Password Service Using the Generic Authentication Architecture
Chun-Hua Chen 0002, Chris J. Mitchell, Shaohua Tang |
Mob. Networks Appl. | 2 |
| 2013 | Enabling interoperation between Shibboleth and Information Card systemsabstractABSTRACT Whilst the growing number of identity management systems have the potential to reduce the threat of identity attacks, major deployment problems remain because of the lack of interoperability between such systems. In this paper, we propose a scheme to provide interoperability between two widely discussed identity systems, namely Shibboleth and Information Card systems such as CardSpace or Higgins. When using this scheme, Information Card users are able to obtain an assertion token from a Shibboleth‐enabled identity provider that can be processed by an Information Card‐enabled relying party. The scheme is based on a browser extension and operates with both the CardSpace and the Higgins identity selectors without any modification. We specify the operation of the scheme and also describe an implementation of a proof‐of‐concept prototype. Additionally, security and operational analyses are provided. Copyright © 2012 John Wiley & Sons, Ltd. Haitham S. Al-Sinani, Chris J. Mitchell |
Secur. Commun. Networks | 2 |
| 2012 | Building General-Purpose Security Services on EMV Payment Cards
Chun-Hua Chen 0002, Shaohua Tang, Chris J. Mitchell |
SecureComm | 3 |
| 2012 | Generating certification authority authenticated public keys in ad hoc networksabstractABSTRACT In anad hocnetwork, nodes may face the need to generate new public keys. To be verifiably authentic, these newly generated public keys need to be certified. However, because of the absence of a permanent communication infrastructure, a certification authority (CA) that can issue certificates may not always be reachable. The downside is that secure communication channels cannot be established. Previously proposed solutions do not guarantee that identities contained in certificates are valid or, when they do, they rely on neighbors to validate user‐key bindings. However, there is no guarantee that nodes that are known in advance will always be present in the network. Therefore, neighbors are not always able to verify a node's identity before certificate issuance. In this paper we define a scheme that permits nodes to generate, on‐demand, and independently of any third entity, public keys that can be authenticated with the aid of a unique certificate, issued by a CA at initialization. This certificate binds a valid identity to a hash code. We then extend this scheme to a solution permitting certificates to be generated, on‐demand, and independently of any third entity, that can be authenticated with a unique signature generated by a CA. Finally we solve the problem of updated revocation information. Copyright © 2010 John Wiley & Sons, Ltd. Gina Kounga, Chris J. Mitchell, Thomas Walter 0001 |
Secur. Commun. Networks | 2 |
| 2011 | Enhancing CardSpace Authentication Using a Mobile Device
Haitham S. Al-Sinani, Chris J. Mitchell |
DBSec | 2 |
| 2011 | Extending the Scope of cardspaceabstractThe recently-proposed PassCard scheme enables CardSpace to be used as a password manager, thereby both improving the usability and security of passwords as well as encouraging CardSpace adoption. However, this scheme does not work with sites using HTTPS, seriously limiting its practicality. In this paper we extend PassCard to support sites using both HTTP and HTTPS. Usernames and passwords are stored in CardSpace personal cards, and these cards can be used to sign on transparently to corresponding websites. PassCard does not require any changes to login servers, default browser security settings or to the CardSpace identity selector; in particular, it does not require websites to support CardSpace. PassCard operates with both the CardSpace and the Higgins identity selectors without any modification. We describe how this new version of PassCard operates, and give security and usability analyses. Haitham S. Al-Sinani, Chris J. Mitchell |
SIN | 2 |
| 2011 | SSL/TLS Session-Aware User Authentication Using a GAA Bootstrapped Key
Chun-Hua Chen 0002, Chris J. Mitchell, Shaohua Tang |
WISTP | 2 |
| 2011 | Scalable RFID security protocols supporting tag ownership transfer
Boyeon Song, Chris J. Mitchell |
Comput. Commun. | 2 |
| 2009 | Scalable RFID Pseudonym ProtocolabstractIn this paper we address the issue of scalability in RFID pseudonym protocols. Many previously proposed protocols suffer from scalability issues because they require a linear search to identify or authenticate a tag. Some RFID protocols, however, only require constant time for tag identification, but, unfortunately, all previously proposed schemes of this type have serious shortcomings. We propose a novel RFID authentication protocol based on the Song-Mitchell protocol, that takesO(1) work to authenticate a tag, and meets the privacy, security and performance requirements identified here. The proposed scheme also supports tag delegation and ownership transfer in an efficient way. Boyeon Song, Chris J. Mitchell |
NSS | 2 |
| 2009 | Improving the Security of CardSpaceabstractCardSpace (formerly known as InfoCard) is a digital identity management system that has recently been adopted by Microsoft. In this paper we identify two security shortcomings in CardSpace that could lead to a serious privacy violation. The first is its reliance on user judgements of the trustworthiness of service providers, and the second is its reliance on a single layer of authentication. We also propose a modification designed to address both flaws. The proposed approach is compatible with the currently deployed CardSpace identity metasystem, and should enhance the privacy of the system whilst involving only minor changes to the current CardSpace framework. We also provide a security and performance analysis of the proposal. 1 Waleed A. Alrodhan, Chris J. Mitchell |
EURASIP J. Inf. Secur. | 2 |
| 2008 | Using Non-adaptive Group Testing to Construct Spy Agent RoutesabstractWe consider a network of remote agent platforms that are tested by roaming spy agents in order to identify those that are malicious, based on the outcome of each agent. It is shown that, given a set of spying requirements, the task of choosing the sets of platforms which spy agents visit can be abstracted as a group testing problem. Non-adaptive group testing, in particular, is considered in greater detail, and a simple combinatorial construction for a set of agent routes is presented which combines known results from the prior art. Although existing techniques enable us to construct efficient sets of agent routes, optimality remains an open problem. Georgios Kalogridis, Chris J. Mitchell |
ARES | 2 |
| 2008 | A Device Management Framework for Secure Ubiquitous Service DeliveryabstractIn a mobile ubiquitous environment, service interactions between a user device and a service provider should be secure, regardless of the type of device used to access or consume a service. We present a secure device management framework (SDMF), designed to securely deliver services to user devices, whilst also hiding (some of) the complexity of security management from users. Key to this framework is the device management entity (DME), that manages a user device's security credentials, and interacts with service providers on its behalf. This framework also provides users with assurance that a compromised device cannot consume the delivered service, and, at the same time, prevents users from illegally sharing their credentials with other users. We achieve these objectives using trusted computing functionality and certain other security mechanisms. Adrian Leung, Chris J. Mitchell |
IAS | 2 |
| 2008 | RFID authentication protocol for low-cost tagsabstractIn this paper, we investigate the possible privacy and security threats to RFID systems, and consider whether previously proposed RFID protocols address these threats. We then propose a new authentication protocol which provides the identified privacy and security features and is also efficient. The new protocol resists tag information leakage, tag location tracking, replay attacks, denial of service attacks, backward traceability, forward traceability (under an assumption), and server impersonation (also under an assumption). We also show that it requires less tag-side storage and computation than other similarly structured RFID protocols. Boyeon Song, Chris J. Mitchell |
WISEC | 2 |
| 2007 | Digital rights management using a mobile phoneabstractThis paper focuses on the problem of preventing illegal copying of digital assets without jeopardising the right of legitimate licence holders to transfer content between their own devices, which make up a domain. Our novel idea involves the use of a domain-specific mobile phone and the mobile phone network operator to authenticate the domain owner before devices can join a domain. This binds devices in a domain to a single owner, that, in turn, enables the binding of domain licences to the domain owner. In addition, the way in which we control domain membership, and the use of the domain-specific mobile phone that enables a domain owner to add devices wherever he/she is physically present, ensures that devices joining the domain are in physical proximity to the mobile phone, preventing illicit content proliferation. Imad M. Abbadi, Chris J. Mitchell |
ICEC | 2 |
| 2007 | Security vulnerabilities in DNS and DNSSECabstractWe present an analysis of security vulnerabilities in the domain name system (DNS) and the DNS security extensions (DNSSEC). DNS data that is provided by name servers lacks support for data origin authentication and data integrity. This makes DNS vulnerable to man in the middle (MITM) attacks, as well as a range of other attacks. To make DNS more robust, DNSSEC was proposed by the Internet Engineering Task Force (IETF). DNSSEC provides data origin authentication and integrity by using digital signatures. Although DNSSEC provides security for DNS data, it suffers from serious security and operational flaws. We discuss the DNS and DNSSEC architectures, and consider the associated security vulnerabilities Suranjith Ariyapperuma, Chris J. Mitchell |
ARES | 2 |
| 2007 | Addressing privacy issues in CardSpaceabstractCardSpace (formerly known as InfoCard) is a Digital Identity Management system that has recently been adopted by Microsoft. In this paper we identify two security flaws in CardSpace that may lead to a serious privacy violation. The first flaw is the reliance on Internet user judgements of the trustworthiness of service providers, and the second is the reliance of the system on a single layer of authentication. We also propose a solution designed to address both flaws. Our solution is compatible with the currently deployed CardSpace identity metasystem, and should enhance the privacy of the system with minor changes to the current CardSpace framework. We also provide a security and performance analysis of the proposed solution. Waleed A. Alrodhan, Chris J. Mitchell |
IAS | 2 |
| 2007 | Ninja: Non Identity Based, Privacy Preserving Authentication for Ubiquitous Environments
Adrian Leung, Chris J. Mitchell |
UbiComp | 2 |
| 2007 | Cryptanalysis of the EPBC Authenticated Encryption Mode
Chris J. Mitchell |
IMACC | 1 |
| 2007 | ID-based cryptography using symmetric primitives
Chris J. Mitchell, Fred Piper, Peter R. Wild |
Des. Codes Cryptogr. | 1 |
| 2006 | A Service Discovery Threat Model for Ad Hoc Networks
Adrian Leung, Chris J. Mitchell |
SECRYPT | 2 |
| 2006 | Modelling E-Business Security Using Business Processes
Sharon Nachtigal, Chris J. Mitchell |
SECRYPT | 2 |
| 2006 | Cryptanalysis of a hybrid authentication protocol for large mobile networks
Qiang Tang 0001, Chris J. Mitchell |
J. Syst. Softw. | 2 |
| 2005 | Cryptanalysis of Two Variants of PCBC Mode When Used for Message Integrity
Chris J. Mitchell |
ACISP | 1 |
| 2005 | Analysis of the Bit-Search Generator and Sequence Compression Techniques
Aline Gouget, Hervé Sibert, Côme Berbain, Nicolas T. Courtois, Blandine Debraize, Chris J. Mitchell |
FSE | 6 |
| 2005 | Padding Oracle Attacks on CBC-Mode Encryption with Secret and Random IVs
Arnold K. L. Yau, Kenneth G. Paterson, Chris J. Mitchell |
FSE | 3 |
| 2005 | Security Properties of Two Authenticated Conference Key Agreement Protocols
Qiang Tang 0001, Chris J. Mitchell |
ICICS | 2 |
| 2005 | Partial Key Recovery Attacks on XCBC, TMAC and OMAC
Chris J. Mitchell |
IMACC | 1 |
| 2005 | Error Oracle Attacks on CBC Mode: Is There a Future for CBC Mode Encryption?
Chris J. Mitchell |
ISC | 1 |
| 2005 | Improving IP Address Autoconfiguration Security in MANETs Using Trust Modelling
Shenglan Hu, Chris J. Mitchell |
MSN | 2 |
| 2005 | Overcoming Channel Bandwidth Constraints in Secure SIM Applications
John A. MacDonald, William G. Sirett, Chris J. Mitchell |
SEC | 3 |
| 2005 | Matching key recovery mechanisms to business requirements
Konstantinos Rantos, Chris J. Mitchell |
Comput. Secur. | 2 |
| 2005 | Dynamic content attacks on digital signaturesabstractPurpose Aims to address some of the problems that arise when signing digital documents that contain dynamic content. Design/methodology/approach Briefly introduces the problem of signing digital documents with dynamic content and discusses possible locations for signature functionality in a computer system. Outlines existing solutions to the problems and introduces a novel solution. Finally, discusses issues and unresolved problems. Findings The suggested solution requires all document handling applications to possess application awareness of the digital signature program in order to function properly. Every application must implement a COM interface and register itself in the Registry, in a locale specific to the digital signature program to sign the digital document. Originality/value Provides a new solution to the problem of digitally signing a digital document. Adil Alsaid, Chris J. Mitchell |
Inf. Manag. Comput. Security | 2 |
| 2005 | Partial Key Recovery Attack Against RMAC
Lars R. Knudsen, Chris J. Mitchell |
J. Cryptol. | 2 |
| 2004 | Impostor: a single sign-on system for use from untrusted devicesabstractAt present, network users have to manage a set of authentication credentials (usually a username/password pair) for every service with which they are registered. Single sign-on (SSO) has been proposed as a solution to the usability, security and management implications of this situation. Under SSO, users need to manage only one set of authentication credentials in order to log into the services they subsequently use. This paper presents the design of an SSO system that is based on a trusted proxy, and that is suitable for use from an untrusted network access device. Unlike existing proxy-based SSO schemes, which require an infrastructure to be in place between the proxy and the service providers, the one presented here does not. An open-source implementation of the scheme, called 'Impostor', is also described. The prototype is implemented as an HTTP proxy, resulting in a system that works with common Web browsers. Andreas Pashalidis, Chris J. Mitchell |
GLOBECOM | 2 |
| 2003 | A Taxonomy of Single Sign-On Systems
Andreas Pashalidis, Chris J. Mitchell |
ACISP | 2 |
| 2003 | Security Protocols for Biometrics-Based Cardholder Authentication in Smartcards
Luciano Rila, Chris J. Mitchell |
ACNS | 2 |
| 2003 | Remote User Authentication Using Public Information
Chris J. Mitchell |
IMACC | 1 |
| 2003 | Single Sign-On Using Trusted Platforms
Andreas Pashalidis, Chris J. Mitchell |
ISC | 2 |
| 2003 | Analysis of 3gpp-MAC and Two-key 3gpp-MAC
Lars R. Knudsen, Chris J. Mitchell |
Discret. Appl. Math. | 2 |
| 2002 | Security Analysis of Smartcard to Card Reader Communications for Biometric Cardholder Authentication
Luciano Rila, Chris J. Mitchell |
CARDIS | 2 |
| 2001 | New CBC-MAC Forgery Attacks
Karl Brincat, Chris J. Mitchell |
ACISP | 2 |
| 2001 | Undetachable Threshold Signatures
Niklas Borselius, Chris J. Mitchell |
IMACC | 2 |
| 2001 | Key Recovery Attacks on MACs Based on Properties of Cryptographic APIs
Karl Brincat, Chris J. Mitchell |
IMACC | 2 |
| 2001 | Key Recovery Scheme Interoperability - A Protocol for Mechanism Negotiation
Konstantinos Rantos, Chris J. Mitchell |
IMACC | 2 |
| 2000 | Key Recovery and Forgery Attacks on the MacDES MAC Algorithm
Don Coppersmith, Lars R. Knudsen, Chris J. Mitchell |
CRYPTO | 3 |
| 2000 | PKI standards
Chris J. Mitchell |
Inf. Secur. Tech. Rep. | 1 |
| 1998 | Panel Introduction: The Security Impact of Distributed Computing Technologies
Peter Y. A. Ryan, Dieter Gollmann, Günter Karjoth, Chris J. Mitchell |
CSFW | 5 |
| 1998 | Perfect Factors from Cyclic Codes and InterleavingabstractIn this paper, we introduce new construction methods for Perfect Factors. These are based on the theory of cyclic codes, interleaving techniques and the Lempel homomorphism. The constructions enable us to settle the existence question for Perfect Factors for window sizes at most six. Chris J. Mitchell, Kenneth G. Paterson |
SIAM J. Discret. Math. | 1 |
| 1998 | On Integer-Valued Rational Polynomials and Depth Distributions of Binary CodesabstractThe notion of the depth of a binary sequence was introduced by Etzion. In this correspondence we show that the set of infinite sequences of finite depth corresponds to a set of equivalence classes of rational polynomials. We go on to characterize infinite sequences of finite depth in terms of their periodicity. We conclude by giving the depth distributions for all linear cyclic codes. Chris J. Mitchell |
IEEE Trans. Inf. Theory | 1 |
| 1997 | Secret Sharing with Reusable Polynomials
Liqun Chen 0002, Dieter Gollmann, Chris J. Mitchell, Peter R. Wild |
ACISP | 3 |
| 1997 | An anonymous and undeniable payment scheme
Liqun Chen 0002, Chris J. Mitchell |
ICICS | 2 |
| 1997 | Authentication using cryptography
Chris J. Mitchell |
Inf. Secur. Tech. Rep. | 1 |
| 1997 | De Bruijn Sequences and Perfect FactorsabstractIn this paper we describe new constructions for de Bruijn sequences and Perfect Factors. These constructions are all based upon the idea of constructing one sequence (or set of sequences) from another. As a result of this fact, the sequences obtained from these construction methods possess simple decoding algorithms based on decoding the sequences used to construct them. Such decoding algorithms are of importance in position--location applications. Chris J. Mitchell |
SIAM J. Discret. Math. | 1 |
| 1996 | Tailoring authentication protocols to match underlying mechanisms
Liqun Chen 0002, Dieter Gollmann, Chris J. Mitchell |
ACISP | 3 |
| 1996 | Redundant Integer Representations and Fast Exponentiation
Dieter Gollmann, Yongfei Han, Chris J. Mitchell |
Des. Codes Cryptogr. | 3 |
| 1996 | Authentication Schemes, Perfect Local Randomizers, Perfect Secrecy and Secret Sharing Schemes
Chris J. Mitchell, Fred Piper, Michael Walker 0001, Peter R. Wild |
Des. Codes Cryptogr. | 1 |
| 1996 | The royal holloway TTP-based key escrow scheme
Chris J. Mitchell |
Inf. Secur. Tech. Rep. | 1 |
| 1996 | A method for constructing decodable de Bruijn sequencesabstractWe present two related methods of construction for de Bruijn (1946) sequences, both based on interleaving "smaller" de Bruijn sequences. Sequences obtained using these construction methods have the advantage that they can be "decoded" very efficiently, i.e., the position within the sequence of any particular "window" can be found very simply. Sequences with simple decoding algorithms are of considerable practical importance in position location applications. Chris J. Mitchell, Tuvi Etzion, Kenneth G. Paterson |
IEEE Trans. Inf. Theory | 1 |
| 1995 | Key distribution without individual trusted authentification serversabstractSome recent research on key distribution systems has focussed on analysing trust in authentication servers, and constructing key distribution protocols which operate using a number of authentication servers, which have the property that a minority of them may be untrustworthy. This paper proposes two key distribution protocols with multiple authentication servers using a cross checksum scheme. Both protocol are based on the use of symmetric encryption for verifying the origin and integrity of messages. In these protocols it is not necessary for clients to trust an individual authentication server. A minority of malicious and colluding servers cannot compromise security and can be detected. The first 'parallel' protocol can prevent a minority of servers disrupting the service. The second 'cascade' protocol has to work with other security mechanisms in order to prevent a server breaking the procedure by refusing to cooperate. As compared with other proposed protocols with similar properties these two protocols require less exchanged messages. Liqun Chen 0002, Dieter Gollmann, Chris J. Mitchell |
CSFW | 3 |
| 1995 | Minimal Weight k-SR Representations
Yongfei Han, Dieter Gollmann, Chris J. Mitchell |
IMACC | 3 |
| 1995 | A Storage Complexity Based Analogue of Maurer Key Establishment Using Public Channels
Chris J. Mitchell |
IMACC | 1 |
| 1995 | Distributing Trust Amongst Multiple Authentication ServersabstractSome recent research on key distribution systems has focussed on analysing trust in authentication servers, and constructing key distribution protocols which operate using a number of authentication servers, a minority of them may be untrusted. This Liqun Chen 0002, Dieter Gollmann, Chris J. Mitchell |
J. Comput. Secur. | 3 |
| 1995 | Aperiodic and semi-periodic perfect mapsabstractPaterson (see ibid., vol.40, p.743, 1993) has shown that the trivial necessary conditions are sufficient for the existence of a (binary) perfect map. These periodic structures can be transformed very simply into corresponding aperiodic and semi-periodic perfect maps. However, aperiodic and semi-periodic perfect maps can exist for parameter sets for which the corresponding periodic perfect maps cannot. In this paper it is shown, by construction, that (binary) aperiodic and semi-periodic perfect maps exist for all possible parameter sets.> Chris J. Mitchell |
IEEE Trans. Inf. Theory | 1 |
| 1994 | Constructing c-ary Perfect Factors
Chris J. Mitchell |
Des. Codes Cryptogr. | 1 |
| 1994 | Decoding Perfect Maps
Chris J. Mitchell, Kenneth G. Paterson |
Des. Codes Cryptogr. | 1 |
| 1994 | The Combinatorics of Perfect Authentication SchemesabstractThe purpose of this paper is to prove the equivalence of perfect authentication schemes and maximum distance separable codes. Chris J. Mitchell, Michael Walker 0001, Peter R. Wild |
SIAM J. Discret. Math. | 1 |
| 1994 | Parameter Selection for Server-Aided RSA Computation SchemesabstractThe security, complexity, and application of two schemes for using an untrusted auxiliary processor to aid smart card RSA signature computations are reviewed, including detailed analysis of possible methods of attack. Guidance is given on practical, secure use of these schemes.> John Burns 0003, Chris J. Mitchell |
IEEE Trans. Computers | 2 |
| 1993 | Standardising Authentication Protocols Based on Public-Key Techniques
Chris J. Mitchell, Andy Thomas |
J. Comput. Secur. | 1 |
| 1992 | Authenticating Multicast Internet Electronic Mail Messages Using a Bidirectional MAC is InsecureabstractThe 1988 version of the message encryption and authentication procedures for Internet electronic mail makes use of bidirectional MAC (BMAC). When used for multicast electronic mail it is important that this BMAC act as a one-way function. It is shown that it is not a one-way function, which means that the BMAC technique should not be used for authenticating multicast messages.> Chris J. Mitchell |
IEEE Trans. Computers | 1 |
| 1991 | Modified forms of cipher block chaining
Chris J. Mitchell, Vijay Varadharajan |
Comput. Secur. | 1 |
| 1990 | A Secure Messaging Architecture Implementing the X.400-1988 Security FeaturesabstractThe 1988 version of the X.400 Recommendations now include a number of security features designed to enable the provision of security services for Message Handling Systems. This paper describes one way in which the provided features can be used to provide a secure electronic mail system. Chris J. Mitchell, Dave Rush, Michael Walker 0001 |
Comput. J. | 1 |
| 1990 | A security scheme for resource sharing over a network
John Burns 0003, Chris J. Mitchell |
Comput. Secur. | 2 |
| 1990 | Key-Minimal Crytosystems for Unconditional SecrecyabstractThis paper is concerned with cryptosystems offering perfect or unconditional secrecy. For those perfect-secrecy systems which involve using keys just once, the theory is well established; however, this is not the case for those systems which involve using a key several times. This paper takes a rigorous approach to the definition of such systems, and exhibits some new families of examples of systems providing perfect secrecy for which the number of keys is minimal. Philippe Godlewski, Chris J. Mitchell |
J. Cryptol. | 2 |
| 1990 | Enumerating Boolean Functions of Cryptographic Significance
Chris J. Mitchell |
J. Cryptol. | 1 |
| 1989 | Multi-Destination Secure Electronic MailabstractElectronic mail messages are often sent to more than one destination; this gives rise to problems when security is required. A recent draft for a standard for securing electronic mail messages suggests a novel mechanism for solving the problem. Unfortunately, as shown herein, the solution is flawed and can allow the construction of fake messages which will pass the authenticity tests. Chris J. Mitchell |
Comput. J. | 1 |
| 1989 | Another Postage Stamp ProblemabstractThe postage stamp problem requires the selection of a set of k postage stamp denominations such that sums of h (or fewer) of these denominations can realise all the numbers 1,2,…,n for n as large as possible (given k). In this paper we consider a natural analogue of this problem to the case where each stamp denomination is allowed to occur a negative number of times, so long as the sum of the absolute values of the numbers of occurrences is at most h. Interestingly, for the case h=2, the problem considered here is also an analogue of the Golomb Ruler problem. For the case h=2, constructions are shown which give a lower bound on the maximum n achievable. Chris J. Mitchell |
Comput. J. | 1 |
| 1989 | A remark on hash functions for message authentication
Chris J. Mitchell, Dave Rush, Michael Walker 0001 |
Comput. Secur. | 1 |
| 1989 | One-stage one-sided rearrangeable switching networksabstractSwitching networks consisting of subscriber lines and crosswires connected by switches are considered. A connection between two subscribers is made along one crosswire via two switches. The minimum number of switches necessary for such a switching network to be rearrangeably nonblocking is determined and a switching arrangement which achieves this minimum for any (even) number of subscriber lines is constructed. Two procedures for assignment of crosswires to subscriber line pairs are described. One makes the correct choice of connection route without backtracking provided all connections are known beforehand; the other determines a rearrangement of existing assignments when a new connection is required. The switching networks which have the minimum number of switches for networks with up to eight subscriber lines and give nonisomorphic solutions for larger networks are characterized.> Chris J. Mitchell, Peter R. Wild |
IEEE Trans. Commun. | 1 |
| 1988 | Solutions to the multidestination secure electronic mail problem
Chris J. Mitchell, Michael Walker 0001 |
Comput. Secur. | 1 |
| 1988 | Key storage in secure networks
Chris J. Mitchell, Fred Piper |
Discret. Appl. Math. | 1 |
| 1987 | The cost of reducing key-storage requirements in secure networks
Chris J. Mitchell, Fred Piper |
Comput. Secur. | 1 |