5th Benelux Workshop on
Information and System Security
November 29-30, 2010, Nijmegen, the Netherlands
University of Twente Radboud Universiteit Nijmegen

PROGRAM

November 29
9:00 - 9:30Registration and welcome coffee
9:30 - 10:30Session I: Side Channel Attacks and RFID
  • Jasper van Woudenberg, Marc Witteman and Bram Bakker - Improving Differential Power Analysis by Elastic Alignment
  • Mayla Bruso, Konstantinos Chatzikokolakis, Sandro Etalle and Jerry den Hartog - Trace-based formalization of unlinkability for RFID systems
  • Timo Kasper, Ingo von Maurich and David Oswald - Cloning Cryptographic RFID Cards for 25$
10:30 - 10:45Coffee break
10:45 - 11:30Invited talk: Srdjan Capkun - 'Wireless Security gets Physical'
11:30 - 12:30Session II: Public Key Cryptography
  • Saeed Sedghi, Peter van Liesdonk, Svetla Nikova, Pieter Hartel and Willem Jonker - Searching Keywords with Wildcards on Encrypted Data
  • Sophie Mawet and Olivier Pereira - Equitable cake cutting without mediator
  • Alfredo Rial and Bart Preneel - Blind Attribute-Based Encryption and Oblivious Transfer with Fine-Grained Access Control
12:30 - 13:30Lunch
13:30 - 14:30Session III: Software Security and Applications
  • Willem De Groef, Nick Nikiforakis, Yves Younan and Frank Piessens - JITSec: Just-in-time Security for Code Injection Attacks
  • Yoni De Mulder, Nessim Kisserli, Jan Cappaert, Nikos Mavrogiannopoulos and Bart Preneel - Perturbated Functions: a new approach to Obfuscation and Diversity
  • Fabian van den Broek - Eavesdropping on GSM: state-of-affairs
14:30 - 14:40Short break
14:40 - 15:25Invited talk: Ronald Leenes - Who needs Facebook anyway: Privacy and Sociability in social network sites
15:25 - 15:45Coffee break
15:45 - 17:45Session of Short Talks
  • Roel Verdult - Practical attacks on NFC enabled cell phones
  • Somanath Tripathy - Authentication in Securing Wireless Mesh Network
  • Qiang Tang - Public Key Encryption Supporting Plaintext Equality Test and its Applications
  • Joeri de Ruiter - Formal analysis of the EMV protocol suite
  • Alfredo Rial - Privacy-Preserving Smart Metering
  • Eva van Niekerk - DPA on contactless cards
  • Matt Smart - True Trustworthy Elections: Remote Electronic Voting Using Trusted Computing
  • Pieter Burghouwt - Detection of Botnet Collusion by Degree Distribution of Domains
  • Koen Decroix - Reconfigurable security in home monitoring systems
  • Mainack Mondal - TweLEX: A Tweaked Version of the LEX Stream Cipher
  • Chunhua Chen - Ubiquitous One-Time Password Service Using Generic Authentication Architecture
  • Dave Singelee - ECC-based grouping proof protocols
19:00Dinner
November 30
8:30 - 9:00Welcome coffee
9:00 - 10:00Session IV: Secret Key Cryptography and Watermarking
  • Antonino Simone and Boris Skoric - Accusation probabilities in Tardos codes
  • Gerhard de Koning Gans and Eric R. Verheul - Best Effort and Practice Activation Codes
  • Vesselin Velichkov, Vincent Rijmen and Bart Preneel - Analysis of the Hash Function BMW
10:00 - 10:45Invited talk: Lars Knudsen - Present Block Ciphers Erik Poll - EMV - the end of skimming? Formal analysis of the EMV protocol suite
10:45 - 11:00Coffee break
11:00 - 12:20Session V: Hardware Security and Privacy
  • Georgios Selimis, Mario Konijnenburg, Maryam Ashouei, Jos Huisken, Harmke de Groot, Vincent van der Leest, Geert-Jan Schrijen, Marten van Hulst and Pim Tuyls - Evaluation of use of 90nm 6T-SRAM as a PUF for secure key generation in a wireless communication system
  • Vincent van der Leest, Geert-Jan Schrijen and Helena Handschuh - Hardware Intrinsic Security from D flip-flops
  • Amitabh Das, Miroslav Knezevic, Stefaan Seys and Ingrid Verbauwhede - Challenge-response based secure test wrapper for testing cryptographic circuits
  • Josep Balasch, Alfredo Rial, Carmela Troncoso, Christophe Geuens, Bart Preneel and Ingrid Verbauwhede - PrETP: Privacy-Preserving Electronic Toll Pricing
12:20 - 12:30Closing
12:30Lunch

INVITED TALKS

Prof. Dr. Srdjan Capkun - 'Wireless Security gets Physical'

This talk is concerned with the impact of the physical layer and physical locations on the security of wireless networks and their applications. We discuss the problem of secure location verification, and show applications of proximity verification protocols in medical and automotive domains. We further look at the problem of anti-jamming broadcast communication and show how the limitations of the wireless channel introduce a key-establishment/anti-jamming dependency cycle; we then describe a solution that breaks this cycle that is based on novel Uncoordinated Spread Spectrum techniques.

Prof. Dr. Lars Knudsen - Present Block Ciphers

For most block cipher applications the AES is a good and preferred choice. However, AES it not well suited for extremely constrained environments such as RFID tags. Therefore, one trend in block cipher design is to find ultra-lightweight block ciphers with good security and hardware efficiency. We present the ciphers Present (from CHES 2007) and PrintCipher (from CHES 2010). Another trend in block cipher design is try to increase the efficiency by making certain components part of the secret key, e.g., to be able to reduce the number of rounds of a cipher. We outline attacks on two such proposals, C2 (presented at Crypto 2009) and the cipher Maya from Princeton.

Prof. Dr. Ronald Leenes - Who needs Facebook anyway: Privacy and Sociability in social network sites

SNSs pose a plethora of privacy issues that are reasonably well known and understood. Many issues boil down to the same problem: information makes it to the wrong audience. This problem is inherent to the design and business model of many current social network sites. How to cope with this? Two approaches seem obvious: address user behaviour and/or address the architecture of social network sites. In this presentation I will argue that the options for changing users' behaviour are limited by highlighting some of the social dynamics of SNS. Next I will focus on three areas of privacy issues: those caused by individual SNS users, those used by the SNS platform providers and those caused by the non subscribers. I will show how these issues are addressed within the EU FP7 project PrimeLife in the Clique prototype.