Formal analysis of PIN block attacks

Graham Steel

Research output: Contribution to journalArticlepeer-review

Abstract

Personal identification number (PIN) blocks are 64-bit strings that encode a PIN ready for encryption and secure transmission in banking networks. These networks employ tamper-proof hardware security modules (HSMs) to perform sensitive cryptographic operations, such as checking the correctness of a PIN typed by a customer. The use of these HSMs is controlled by an API designed to enforce security. PIN block attacks are unanticipated sequences of API commands which allow an attacker to determine the value of a PIN in an encrypted PIN block. This paper describes a framework for formal analysis of such attacks. Our analysis is probabilistic, and is automated using constraint logic programming and probabilistic model checking.
Original languageEnglish
Pages (from-to)257-270
Number of pages14
JournalTheoretical Computer Science
Volume367
Issue number1-2
DOIs
Publication statusPublished - 2006

Fingerprint

Dive into the research topics of 'Formal analysis of PIN block attacks'. Together they form a unique fingerprint.

Cite this