biblio-defqa.bib (38120B)
1 2 3 @Misc{henning2024netzpolitik, 4 author = {Maximilian Henning}, 5 title = {{EU Council} discusses Digital Euro: And how much privacy should it be?}, 6 howpublished = {\url{https://netzpolitik.org/2024/eu-council-discusses-digital-euro-and-how-much-privacy-should-it-be/}}, 7 month = {July}, 8 year = {2024}, 9 note = {Last accessed December 2024}, 10 } 11 12 @misc{ecDE2023, 13 author = {{European Commission}}, 14 year = {2023}, 15 number = {COM/2023/369 final}, 16 title = {Proposal for a Regulation of the European Parliament and of the Council on the establishment of the digital euro}, 17 month = {June}, 18 url = {https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52023PC0369} 19 } 20 21 @misc{ecDEservices2023, 22 author = {{European Commission}}, 23 year = {2023}, 24 number = {COM/2023/368 final}, 25 title = {Proposal for a Regulation of the European Parliament and of the Council on the provision of digital euro services by payment services providers incorporated in Member States whose currency is not the euro and amending Regulation (EU) 2021/1230 of the European Parliament and the Council}, 26 month = {June}, 27 url = {https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52023PC0368}, 28 } 29 30 @misc{ecCash2023, 31 author = {{European Commission}}, 32 year = {2023}, 33 number = {COM/2023/364 final}, 34 title = {Proposal for a Regulation of the European Parliament and of the Council on the legal tender of euro banknotes and coins}, 35 month = {June}, 36 url = {https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52023PC0364}, 37 } 38 39 @InProceedings{nagel2024, 40 author = {Joachim Nagel}, 41 title = {The digital euro and the protection of privacy (video address)}, 42 note = {\url{https://www.bundesbank.de/en/press/speeches/the-digital-euro-and-the-protection-of-privacy-935192}}, 43 month = {July}, 44 year = {2024}, 45 booktitle = {International Conference on Payments and Securities Settlement}, 46 } 47 48 @Misc{daman2024, 49 author = {{Maarten G.A. Daman (ECB)}}, 50 title = {Making the digital euro truly private}, 51 howpublished = {\url{https://eaccny.com/news/chapternews/ecb-making-the-digital-euro-truly-private/}}, 52 month = {June}, 53 year = {2024}, 54 note = {Last accessed December 2024}, 55 } 56 57 @Misc{maper2008vsuk, 58 key = {30562/04 and 30566/04}, 59 author = {{European Court of Human Rights, Grand Chamber}}, 60 title = {{S. and Maper vs. The United Kingdom}}, 61 howpublished = {\url{https://repository.library.georgetown.edu/handle/10822/513747}}, 62 month = {December}, 63 year = {2008}, 64 } 65 66 @TechReport{effects2023, 67 author = {Helge Sigurd Næss-Schmidt and Charlotta Zienau and Rodrigo Cipriano and Jens Brink}, 68 title = {Effects of a digital euro on financial stability and consumer welfare}, 69 institution = {Copenhagen Economics}, 70 year = {2023}, 71 } 72 73 74 @article{dedollarization2024sovereignty, 75 author = {Theryn D. Arnold}, 76 title ={De-dollarization and global sovereignty: BRICS’ quest for a new financial paradigm}, 77 journal = {Human Geography}, 78 volume = {0}, 79 number = {0}, 80 pages = {19427786241266896}, 81 year = {0}, 82 doi = {10.1177/19427786241266896}, 83 } 84 85 86 87 @Article{knowlimits2023, 88 author = {Barbara Meller and Oscar Soons}, 89 title = {Know Your (Holding) Limits: CBDC, Financial Stability and Central Bank Reliance}, 90 journal = {ECB Occasional Paper}, 91 year = {2023}, 92 number = {326}, 93 pages = {46}, 94 month = {August}, 95 } 96 97 98 99 @Misc{bis2021absolute, 100 author = {Clint Siegner}, 101 title = {Bank of International Settlements Chief Talks “Absolute Control”}, 102 howpublished = {\url{https://www.moneymetals.com/news/2021/07/12/bank-of-international-settlements-chief-talks-absolute-control-002328}}, 103 month = {July}, 104 year = {2021}, 105 } 106 107 @Misc{floss, 108 author = {{Free Software Foundation}}, 109 title = {What is Free Software?}, 110 howpublished = {\url{https://gnu.org/philosophy/free-sw.html}}, 111 year = {1996}, 112 } 113 114 @TechReport{ecb2021survey, 115 title = {Eurosystem report on the public consultation on a digital euro}, 116 author = {{European Central Bank}}, 117 year = {2021}, 118 month = {April}, 119 note = {\url{https://www.ecb.europa.eu/pub/pdf/other/Eurosystem_report_on_the_public_consultation_on_a_digital_euro~539fa8cd8d.en.pdf}}, 120 } 121 122 @TechReport{ecb2024timeline, 123 title = {Project timeline and planning of 2024 ERPB}, 124 institution = {{European Central Bank}}, 125 year = {2024}, 126 month = {April}, 127 note = {\url{https://www.ecb.europa.eu/euro/digital_euro/timeline/profuse/shared/pdf/ecb.degov240411_item6erpb-planning2024.en.pdf}}, 128 } 129 130 @misc{cppfqa, 131 author = {Kreinin, Yossi}, 132 title = {C++ FQA Lite}, 133 howpublished = {\url{https://yosefk.com/c++fqa/}}, 134 year = {2009}, 135 month = {October}, 136 } 137 138 @misc{bdi2022, 139 author = {Sch\"onborn, Sven and Rudelt, Christian}, 140 title = {{BDI: Digitaler Euro. Industriebedarfe bei Etablierung nicht vernachlässigen}}, 141 journal = {Position. Wirtschaftspolitik. Zahlungsverkehr}, 142 publisher = {{Bundesverband der Deutschen Industrie e.V. (BDI)}}, 143 address = {Berlin}, 144 year = {2022}, 145 volume = {D1620}, 146 pages = {1-8}, 147 howpublished = 148 {\url{https://bdi.eu/publikation/news/digitaler-euro-innovation-digitalisierung-waehrung/}}, 149 } 150 151 152 @TechReport{offline2023cbdc, 153 author = {Anonymous}, 154 title = {Project Polaris: A handbook for offline payments with CBDC}, 155 institution = {Bank of International Settlements}, 156 year = {2023}, 157 month = {May}, 158 } 159 160 @journal {ss7, 161 author = {Roger Piqueras Jover}, 162 title = {Security analysis of SMS as a second factor of authentication}, 163 journal = {Communications of the ACM}, 164 volume = 63, 165 Number = 12, 166 year = {2020}, 167 pages = {46-52} 168 } 169 170 @article{bis1993, 171 title = {The Nature and Management of Payment System Risks: An International Perspective}, 172 author = {Borio, C.F.V and {Van den Bergh}, P.}, 173 year = {1993}, 174 month = feb, 175 journal = {BIS Economic Papers}, 176 volume = {36}, 177 urldate = {2024-10-30} 178 } 179 180 @misc{bis2020, 181 author = {Auer, Raphael and Böhme,Rainer}, 182 year = {2020}, 183 title = {The technology of retail central bank digital currency}, 184 journal = {BIS Quarterly Review}, 185 month = {March}, 186 pages = {85--96}, 187 howpublished = {\url{https://www.bis.org/publ/qtrpdf/r_qt2003j.pdf}}, 188 } 189 190 @misc{bis2021, 191 author = {Auer, Raphael and Böhme,Rainer}, 192 year = {2021}, 193 title = {Central bank digital currency: the quest for minimally invasive technology}, 194 journal = {BIS Quarterly Review}, 195 month = {June}, 196 volume = {948}, 197 howpublished = {\url{https://www.bis.org/publ/work948.pdf}}, 198 } 199 200 @misc{ecb2020, 201 author = {{European Central Bank}}, 202 year = {2020}, 203 title = {Report on a digital euro}, 204 month = {October}, 205 howpublished = 206 {\url{https://www.ecb.europa.eu/pub/pdf/other/Report_on_a_digital_euro~4d7268b458.en.pdf}}, 207 } 208 209 @misc{ecb2021a, 210 author = {Bindseil, Ulrich and Panetta, Fabio and Terol, Ignacio}, 211 year = {2021}, 212 title = {Central Bank Digital Currency: functional scope, pricing and controls}, 213 journal = {ECB Occasional Paper Series}, 214 month = {December}, 215 volume = {286}, 216 howpublished = {\url{https://www.ecb.europa.eu/pub/pdf/scpops/ecb.op286~9d472374ea.en.pdf}}, 217 } 218 219 @misc{ecb2021b, 220 author = {{European Central Bank}}, 221 year = {2021}, 222 title = {Eurosystem report on the public consultation on a digital euro}, 223 month = {April}, 224 howpublished = 225 {\url{https://www.ecb.europa.eu/pub/pdf/other/ 226 Eurosystem_report_on_the_public_consultation_on_a_digital_euro~539fa8cd8d.en.pdf}}, 227 } 228 229 @misc{mastercard, 230 author = {Norbert Häring}, 231 title = {How Mastercard invented the health hazard of cash}, 232 year = {2021}, 233 month = {March}, 234 howpublished = {\url{https://norberthaering.de/en/war-on-cash/mastercard-holsten/}}, 235 } 236 237 @misc{ecbTender0078480, 238 author = {{European Central Bank}}, 239 title = {Tender ID: PRO-007480}, 240 year = {2022}, 241 howpublished = {per Email, \url{https://www.ecb.europa.eu/ecb/jobsproc/proc/pdf/2022-ojs040-099799-en.pdf}}, 242 } 243 244 @misc{ecbTender009488, 245 author = {{European Central Bank}}, 246 title = {Tender ID: PRO-009488}, 247 year = {2024}, 248 howpublished = {not public, available upon request} 249 } 250 251 @misc{paymenthabits2022, 252 author = {{European Central Bank}}, 253 year = {2022}, 254 title = {Study on the payment attitudes of consumers in the euro area (SPACE) -- 2022}, 255 month = {November}, 256 howpublished = 257 {\url{https://www.ecb.europa.eu/stats/ecb_surveys/space/shared/pdf/ecb.spacereport202212~783ffdf46e.en.pdf}}, 258 } 259 @misc{paymenthabits2024, 260 author = {{European Central Bank}}, 261 year = {2024}, 262 title = {Study on the payment attitudes of consumers in the euro area (SPACE) -- 2024}, 263 month = {December}, 264 howpublished = 265 {\url{https://www.ecb.europa.eu/stats/ecb_surveys/space/shared/pdf/ecb.space2024~19d46f0f17.en.pdf}}, 266 } 267 268 @misc{masProgrammable2023, 269 author = {{Monetary Authority of Singapore}}, 270 year = {2023}, 271 title = {Purpose Bound Money (PBM) Technical Whitepaper}, 272 month = {June}, 273 howpublished = 274 {\url{https://www.mas.gov.sg/-/media/mas-media-library/development/fintech/pbm/pbm-technical-whitepaper.pdf}}, 275 } 276 277 @misc{ecbHoldingLimit2023, 278 author = {{European Central Bank}}, 279 year = {2023}, 280 title = {Financial Stability Review}, 281 month = {November}, 282 howpublished = 283 {\url{https://www.ecb.europa.eu/press/financial-stability-publications/fsr/html/ecb.fsr202311~bfe9d7c565.en.html}}, 284 } 285 286 287 288 @Article{suerf2021moser, 289 author = {Christian Grothoff and Thomas Moser}, 290 title = {How to issue a privacy-preserving central bank digital currency}, 291 journal = {SUERF Policy Briefs}, 292 year = {2021}, 293 number = {114}, 294 month = {June}, 295 } 296 297 @article{suerf2022aligny, 298 title={Who comes after us? The correct mindset for designing a Central Bank Digital Currency}, 299 author={d’Aligny, Antoine and Benoist, Emmanuel and Dold, Florian and Grothoff, Christian and Kesim, {\"O}zg{\"u}r and Schanzenbach, Martin}, 300 journal={SUERF Policy Note}, 301 number={279}, 302 pages={1--9}, 303 year={2022}, 304 month={June}, 305 publisher={Soci{\'e}t{\'e} Universitaire Europ{\'e}enne de Recherches Financi{\`e}res} 306 } 307 308 @article{uhlig2023privacy, 309 title={Privacy in Digital Payments—Escaping the Panopticon}, 310 author={Uhlig, Harald and Alonso, Mike and Frost, Jon}, 311 journal={Georgetown Journal of International Affairs}, 312 volume={24}, 313 number={2}, 314 pages={174--180}, 315 year={2023}, 316 publisher={Johns Hopkins University Press} 317 } 318 319 @book{white1999, 320 author = {Lawrence H. White}, 321 title = {The Theory of Monetary Institutions}, 322 publisher = {Blackwell Publishers}, 323 year = {1999}, 324 address = {Malden, MA}, 325 } 326 327 @inproceedings{platypus, 328 author = {W\"{u}st, Karl and Kostiainen, Kari and Delius, Noah and Capkun, Srdjan}, 329 title = {Platypus: A Central Bank Digital Currency with Unlinkable Transactions and Privacy-Preserving Regulation}, 330 year = {2022}, 331 isbn = {9781450394505}, 332 publisher = {Association for Computing Machinery}, 333 address = {New York, NY, USA}, 334 url = {https://doi.org/10.1145/3548606.3560617}, 335 doi = {10.1145/3548606.3560617}, 336 booktitle = {Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security}, 337 pages = {2947–2960}, 338 numpages = {14}, 339 keywords = {zero-knowledge proof, regulation, privacy, e-cash, digital currency, compliance, cbdc, anonymity}, 340 location = {Los Angeles, CA, USA}, 341 series = {CCS '22} 342 } 343 344 @article{kerckhoffs1883, 345 author = {Auguste Kerckhoffs}, 346 title = {La cryptographie militaire}, 347 journal = {Journal des sciences militaires}, 348 volume = {IX}, 349 pages = {5--38, 161--191}, 350 year = {1883}, 351 month = {January, February}, 352 language = {French} 353 } 354 355 @book{schneier2015secrets, 356 title={Secrets and lies: digital security in a networked world}, 357 author={Schneier, Bruce}, 358 year={2015}, 359 publisher={John Wiley \& Sons} 360 } 361 362 @article{raymond1999cathedral, 363 title={The cathedral and the bazaar}, 364 author={Raymond, Eric}, 365 journal={Knowledge, Technology \& Policy}, 366 volume={12}, 367 number={3}, 368 pages={23--49}, 369 year={1999}, 370 publisher={Springer} 371 } 372 373 374 375 @Misc{onlinefirst2021, 376 author = {Christian Grothoff and Florian Dold}, 377 title = {Why a Digital Euro should be Online-first and Bearer-based}, 378 howpublished = {\url{https://taler.net/en/news/2021-03.html}}, 379 month = {March}, 380 year = {2021}, 381 } 382 383 @misc{gerKWG, 384 author = {Deutscher Bundestag}, 385 title = {{Gesetz über das Kreditwesen (KWG): § 25i Allgemeine Sorgfaltspflichten in Bezug auf E-Geld}}, 386 year = {2023}, 387 month = {December}, 388 howpublished = {\url{https://www.gesetze-im-internet.de/kredwg/__25i.html}}, 389 } 390 391 @Misc{tsys, 392 author = {{Taler Systems SA}}, 393 title = {{GNU Taler}}, 394 howpublished = {\url{https://taler-systems.com/}}, 395 year = {2024}, 396 } 397 398 @misc{ecDeFunding2023, 399 author = {Sandali Handagama}, 400 title = {European Central Bank Shows It’s Serious About Enabling Digital Euro Offline Use}, 401 year = {2024}, 402 month = {January}, 403 howpublished = {\url{https://www.coindesk.com/policy/2024/01/11/european-central-bank-shows-its-serious-about-enabling-digital-euro-offline-use/}}, 404 } 405 406 @misc{KandarStudy2023, 407 author = {{Kantar Public}}, 408 year = {2023}, 409 month = {March}, 410 title = {Study on Digital Wallet Features}, 411 howpublished = {\url{https://www.ecb.europa.eu/press/pr/date/2023/html/ecb.pr230424_1_annex~93abdb80da.en.pdf}}, 412 } 413 414 @misc{ecbFinalInv2023, 415 author = {{European Central Bank}}, 416 title = {A stocktake on the digital euro - Summary report on the investigation phase and outlook on the next phase}, 417 year = {2023}, 418 month = {August}, 419 howpublished = {\url{https://www.ecb.europa.eu/euro/digital_euro/timeline/profuse/shared/pdf//ecb.dedocs231018.en.pdf}}, 420 } 421 422 @misc{ecbProgInv2023, 423 author = {{European Central Bank}}, 424 title = {Progress on the investigation phase of a digital euro – fourth report}, 425 year = {2023}, 426 month = {July}, 427 howpublished = {\url{https://www.ecb.europa.eu/euro/digital_euro/progress/shared/pdf/ 428 ecb.degov230713-fourth-progress-report-digital-euro-investigation-phase.en.pdf}}, 429 } 430 431 @misc{ecbBlog2024, 432 author = {Daman, Maarten G.A.}, 433 journal = {THE ECB BLOG}, 434 year = {2024}, 435 month = {June}, 436 title = {Making the digital euro truly private}, 437 howpublished = {\url{https://www.ecb.europa.eu/press/blog/date/2024/html/ecb.blog240613~47c255bdd4.en.html}}, 438 } 439 440 @misc{ecbProgPrepFirst2024, 441 author = {{European Central Bank}}, 442 year = {2024}, 443 month = {June}, 444 title = {Progress on the preparation phase of a digital euro - First progress report}, 445 howpublished = {\url{https://www.ecb.europa.eu/euro/digital_euro/progress/html/ecb.deprp202406.en.html}}, 446 } 447 448 @misc{ecbRulebookUpdate, 449 author = {{European Central Bank}}, 450 year = {2024}, 451 month = {January}, 452 title = {Update on the work of the digital euro scheme's Rulebook Development Group}, 453 howpublished = {\url{https://www.ecb.europa.eu/euro/digital_euro/timeline/profuse/shared/pdf/ecb.degov240103_RDG_digital_euro_schemes_update.en.pdf}}, 454 } 455 456 @Misc{defaq2024, 457 author = {{European Central Bank}}, 458 title = {{FAQs on the Digital Euro}}, 459 howpublished = {\url{https://www.ecb.europa.eu/paym/digital_euro/faqs/html/ecb.faq_digital_euro.en.html}}, 460 year = {2024}, 461 month = {December}, 462 note = {Accessed: December 2, 2024}, 463 } 464 465 @misc{ecbDEoffline2024, 466 author = {{European Central Bank}}, 467 year = {2024}, 468 month = {April}, 469 date = {11}, 470 title = {State of play on offline digital euro---11th ERPB technical session on digital euro}, 471 howpublished = {\url{https://www.ecb.europa.eu/euro/digital_euro/timeline/profuse/shared/pdf/ecb.degov240411_item3updateofflinedigitaleuro.en.pdf}}, 472 } 473 474 @Misc{fdroid2023totp, 475 author = {{RedHat}}, 476 title = {{FreeOTP}}, 477 howpublished = {\url{https://freeotp.github.io/}}, 478 year = {2023}, 479 } 480 481 @techreport{m2011totp, 482 title={Totp: Time-based one-time password algorithm}, 483 author={M'Raihi, David and Machani, Salah and Pei, Mingliang and Rydell, Johan}, 484 year={2011}, 485 institution = {{IETF}}, 486 howpublished = {\url{https://datatracker.ietf.org/doc/html/rfc6238}} 487 } 488 @phdthesis{dold2019gnu, 489 title={The {GNU} Taler system: practical and provably secure electronic payments}, 490 author={Dold, Florian}, 491 year={2019}, 492 school={Universit{\'e} Rennes 1} 493 } 494 @inproceedings{kesim2022zero, 495 title={Zero-Knowledge Age Restriction for GNU Taler}, 496 author={Kesim, {\"O}zg{\"u}r and Grothoff, Christian and Dold, Florian and Schanzenbach, Martin}, 497 booktitle={Computer Security--ESORICS 2022: 27th European Symposium on Research in Computer Security, Copenhagen, Denmark, September 26--30, 2022, Proceedings, Part I}, 498 pages={110--129}, 499 year={2022}, 500 organization={Springer} 501 } 502 @inproceedings{d2022project, 503 title={Project Depolymerization: Tokenization of Blockchains}, 504 author={d’Aligny, Antoine and Benoist, Emmanuel and Grothoff, Christian}, 505 booktitle={2022 4th Conference on Blockchain Research \& Applications for Innovative Networks and Services (BRAINS)}, 506 pages={51--54}, 507 year={2022}, 508 organization={IEEE} 509 } 510 @misc{sumup2023, 511 title = {Business made simple}, 512 author = {{Sumup Inc.}}, 513 year = 2023, 514 note = {Accessed: March 3rd, 2023}, 515 howpublished = {\url{https://www.sumup.com/en-us/}} 516 } 517 518 @article{cap, 519 author = {Gilbert, Seth and Lynch, Nancy}, 520 title = {Brewer's Conjecture and the Feasibility of Consistent, Available, Partition-Tolerant Web Services}, 521 year = {2002}, 522 issue_date = {June 2002}, 523 publisher = {Association for Computing Machinery}, 524 address = {New York, NY, USA}, 525 volume = {33}, 526 number = {2}, 527 issn = {0163-5700}, 528 url = {https://doi.org/10.1145/564585.564601}, 529 doi = {10.1145/564585.564601}, 530 abstract = {When designing distributed web services, there are three properties that are commonly desired: consistency, availability, and partition tolerance. It is impossible to achieve all three. In this note, we prove this conjecture in the asynchronous network model, and then discuss solutions to this dilemma in the partially synchronous model.}, 531 journal = {SIGACT News}, 532 month = {jun}, 533 pages = {51–59}, 534 numpages = {9} 535 } 536 537 @misc{worldlineDE2023, 538 title = {{Worldline helps the {ECB} to shape future digital euro by successfully delivering a front-end prototype}}, 539 author = {{Worldline}}, 540 year = 2023, 541 note = {Accessed: October 15th, 2024}, 542 howpublished = {\url{https://worldline.com/en/home/top-navigation/media-relations/press-release/worldline-helps-the-ecb-to-shape-future-digital-euro-by-successfully-delivering-a-front-end-prototype}} 543 } 544 545 @misc{gdOffline2024, 546 title = {{New survey indicates digital euro must also work offline}}, 547 author = {{Giesecke+Devrient}}, 548 year = 2024, 549 note = {Accessed: October 15th, 2024}, 550 howpublished = {\url{https://www.gi-de.com/en/group/press/press-releases/new-survey-indicates-digital-euro-must-also-work-offline}} 551 } 552 553 @misc{snbCBDC2024, 554 title = {{Swiss National Bank's Jordan against issuing retail cenbank digital currency}}, 555 author = {{Reuters}}, 556 year = 2024, 557 note = {Accessed: October 15th, 2024}, 558 howpublished = {\url{https://www.reuters.com/markets/currencies/swiss-national-banks-jordan-against-issuing-retail-cenbank-digital-currency-2024-04-08/}} 559 } 560 561 @misc{fedCBDC2024, 562 title = {{Implications of a U.S. CBDC for International Payments and the Role of the Dollar}}, 563 author = {{Jean Flemming and Ruth Judson}}, 564 year = 2024, 565 note = {Accessed: October 15th, 2024}, 566 howpublished = {\url{https://www.federalreserve.gov/econres/notes/feds-notes/implications-of-a-u-s-cbdc-for-international-payments-and-the-role-of-the-dollar-20240216.html}} 567 } 568 569 @misc{eurojustCrypto2024, 570 title = {{Successful operation against cryptocurrency scam coordinated by Eurojust }}, 571 author = {{Eurojust}}, 572 year = 2024, 573 note = {Accessed: October 15th, 2024}, 574 howpublished = {\url{https://www.eurojust.europa.eu/news/successful-operation-against-cryptocurrency-scam-coordinated-eurojust}} 575 } 576 577 @misc{libra2021, 578 title = {White Paper}, 579 author = {{Diem Association}}, 580 year = 2020, 581 note = {Accessed: January 10th, 2021}, 582 howpublished = {\url{https://www.diem.com/en-us/white-paper/}} 583 } 584 585 586 @misc{twint2023, 587 title = {Simply {TWINT} it.}, 588 author = {{Twint AG}}, 589 year = 2023, 590 note = {Accessed: March 3rd, 2023}, 591 howpublished = {\url{https://www.twint.ch/en/}} 592 } 593 594 @misc{paypal2023, 595 title = {Pay in a flash with {QR}}, 596 author = {{PayPal Inc.}}, 597 year = 2023, 598 note = {Accessed: March 13th, 2023}, 599 howpublished = {\url{https://www.paypal.com/us/digital-wallet/ways-to-pay/pay-with-qr-code}} 600 } 601 602 @misc{twint2023-2, 603 title = {Collect payments simply – even without any infrastructure}, 604 author = {{Twint AG}}, 605 year = 2023, 606 note = {Accessed: March 3rd, 2023}, 607 howpublished = {\url{https://www.twint.ch/en/bausiness-customers/our-solutions/qr-code-sticker/}} 608 } 609 610 @misc{safenet-otp-110, 611 title = {{SafeNet OTP 110}}, 612 author = {{Thales}}, 613 year = 2023, 614 note = {Accessed: March 3rd, 2023}, 615 howpublished = {\url{https://cpl.thalesgroup.com/en-gb/access-management/authenticators/safenet-otp-110}} 616 } 617 @misc{wechat, 618 title = {{Offline Store without {POS} Devices}}, 619 author = {{Tenpay}}, 620 year = 2023, 621 note = {Accessed: March 14th, 2023}, 622 howpublished = {\url{https://pay.weixin.qq.com/wiki/doc/api/wxpay/en/guide/OfflineStoresWithoutPOS.shtml}} 623 } 624 625 @misc{wirecard, 626 author = {Wikipedia}, 627 title = {Wirecard scandal}, 628 howpublished = {\url{https://en.wikipedia.org/wiki/Wirecard_scandal}}, 629 note = {Accessed: September 15, 2024}, 630 } 631 632 @misc{crowdstrike, 633 author = {Wikipedia}, 634 title = {2024 CrowdStrike incident}, 635 howpublished = {\url{https://en.wikipedia.org/wiki/2024_CrowdStrike_incident}}, 636 note = {Accessed: September 15, 2024}, 637 } 638 639 @misc{ecbStatsInflation, 640 author = {{European Central Bank}}, 641 title ={Inflation and consumer prices}, 642 howpublished = {\url{https://www.ecb.europa.eu/stats/macroeconomic_and_sectoral/hicp/html/index.en.html}}, 643 note = {Accessed: September 15, 2024}, 644 } 645 646 @book{ibmandholocaust, 647 author = {Black, Edwin}, 648 title = {IBM and the Holocaust: The Strategic Alliance Between Nazi Germany and America's Most Powerful Corporation}, 649 year = {2001}, 650 isbn = {0375431241}, 651 publisher = {Random House Large Print}, 652 } 653 654 @misc{canada2022, 655 author = {Tasker, John Paul}, 656 jounal = {CBC}, 657 title = {Banks have started to freeze accounts linked to the protests, Freeland says}, 658 year = {2022}, 659 month = {February}, 660 howpublished = {https://www.cbc.ca/news/politics/ottawa-protests-frozen-bank-accounts-1.6355396}, 661 note = {Accessed: September 15, 2024}, 662 } 663 664 @TechReport{chavanette2024, 665 author = {{Chavanette Advisors}}, 666 title = {Galactic Grid: Your Guide to the Complex Landscape of Retail Central Bank Digital Currency Technology Providers}, 667 institution = {Chavanette Advisors}, 668 year = {2024}, 669 } 670 671 @Misc{italy2022cardforce, 672 author = {{AFP/The Local}}, 673 title = {Italy abandons plan to elt shops refuse card payments in budget U-turn}, 674 howpublished = {\url{https://www.thelocal.it/20221219/italy-abandons-plan-to-let-shops-refuse-card-payments-in-budget-u-turn}}, 675 month = {December}, 676 year = {2022}, 677 } 678 679 @TechReport{digitaleuro2020, 680 author = {Christine Lagarde and Fabio Panetta}, 681 title = {Report on a digital euro}, 682 institution = {European Central Bank}, 683 year = {2020}, 684 month = {October}, 685 } 686 687 @Misc{markpersonal, 688 author = {Alessandro Giovannini and Marc Stibane}, 689 title = {Euro 2.0 -- Der Euro wird (auch) digital - Oesterreichische Nationalbank}, 690 howpublished = {Statement on stage in discussion with audience, \url{https://x.com/taler/status/1767621751825907879}}, 691 month = {March}, 692 year = {2024}, 693 } 694 695 @Misc{offlinedebit2020kagan, 696 author = {Julia Kagan}, 697 title = {Offline Debit Card: What They Are and How They Work}, 698 howpublished = {\url{https://www.investopedia.com/terms/o/offlinedebitcard.asp}}, 699 month = {August}, 700 year = {2020}, 701 } 702 703 @Misc{dea2024members, 704 author = {{Digital Euro Association}}, 705 title = {Members}, 706 howpublished = {https://home.digital-euro-association.de/members}, 707 month = {September}, 708 year = {2024}, 709 } 710 711 @Misc{ezb2024duve, 712 author = {{Ledger Insights}}, 713 title = {ex-{BNY} Mellon tokenization lead joins European Central Bank}, 714 howpublished = {\url{https://www.ledgerinsights.com/ex-bny-mellon-tokenization-lead-joins-european-central-bank/}}, 715 month = {March}, 716 year = {2024}, 717 } 718 719 720 @inproceedings{arm2016alias, 721 author={R. {Guanciale} and H. {Nemati} and C. {Baumann} and M. {Dam}}, 722 booktitle={2016 IEEE Symposium on Security and Privacy (SP)}, 723 title={Cache Storage Channels: Alias-Driven Attacks and Verified Countermeasures}, 724 year={2016}, 725 volume={}, 726 number={}, 727 pages={38-55}, 728 keywords={Security;Cache storage;Timing;Monitoring;Program processors;Virtual machine monitors;side channels;hypervisor;cache storage channels;verification}, 729 doi={10.1109/SP.2016.11}, 730 ISSN={2375-1207}, 731 month={May}, 732 } 733 734 @inproceedings{arm2016cache, 735 author = {Lipp, Moritz and Gruss, Daniel and Spreitzer, Raphael and Maurice, Cl\'{e}mentine and Mangard, Stefan}, 736 title = {ARMageddon: Cache Attacks on Mobile Devices}, 737 year = {2016}, 738 isbn = {9781931971324}, 739 publisher = {USENIX Association}, 740 address = {USA}, 741 abstract = {In the last 10 years, cache attacks on Intel x86 CPUs have gained increasing attention among the scientific community and powerful techniques to exploit cache side channels have been developed. However, modern smartphones use one or more multi-core ARM CPUs that have a different cache organization and instruction set than Intel x86 CPUs. So far, no cross-core cache attacks have been demonstrated on non-rooted Android smartphones. In this work, we demonstrate how to solve key challenges to perform the most powerful cross-core cache attacks Prime+Probe, Flush+Reload, Evict+Reload, and Flush+Flush on non-rooted ARM-based devices without any privileges. Based on our techniques, we demonstrate covert channels that outperform state-of-the-art covert channels on Android by several orders of magnitude. Moreover, we present attacks to monitor tap and swipe events as well as keystrokes, and even derive the lengths of words entered on the touchscreen. Eventually, we are the first to attack cryptographic primitives implemented in Java. Our attacks work across CPUs and can even monitor cache activity in the ARM TrustZone from the normal world. The techniques we present can be used to attack hundreds of millions of Android devices.}, 742 booktitle = {Proceedings of the 25th USENIX Conference on Security Symposium}, 743 pages = {549–564}, 744 numpages = {16}, 745 location = {Austin, TX, USA}, 746 series = {SEC'16} 747 } 748 749 @article{zhang2016truspy, 750 title={TruSpy: Cache Side-Channel Information Leakage from the Secure World on ARM Devices.}, 751 author={Zhang, Ning and Sun, Kun and Shands, Deborah and Lou, Wenjing and Hou, Y Thomas}, 752 journal={IACR Cryptol. ePrint Arch.}, 753 volume={2016}, 754 pages={980}, 755 year={2016} 756 } 757 758 @inproceedings{arm2017boomerang, 759 title={BOOMERANG: Exploiting the Semantic Gap in Trusted Execution Environments.}, 760 author={Machiry, Aravind and Gustafson, Eric and Spensky, Chad and Salls, Christopher and Stephens, Nick and Wang, Ruoyu and Bianchi, Antonio and Choe, Yung Ryn and Kruegel, Christopher and Vigna, Giovanni}, 761 booktitle={NDSS}, 762 year={2017} 763 } 764 765 @inproceedings{arm2017clkscrew, 766 author = {Tang, Adrian and Sethumadhavan, Simha and Stolfo, Salvatore}, 767 title = {CLKSCREW: Exposing the Perils of Security-Oblivious Energy Management}, 768 year = {2017}, 769 isbn = {9781931971409}, 770 publisher = {USENIX Association}, 771 address = {USA}, 772 abstract = {The need for power- and energy-efficient computing has resulted in aggressive cooperative hardware-software energy management mechanisms on modern commodity devices. Most systems today, for example, allow software to control the frequency and voltage of the underlying hardware at a very fine granularity to extend battery life. Despite their benefits, these software-exposed energy management mechanisms pose grave security implications that have not been studied before.In this work, we present the CLKSCREW attack, a new class of fault attacks that exploit the security-obliviousness of energy management mechanisms to break security. A novel benefit for the attackers is that these fault attacks become more accessible since they can now be conducted without the need for physical access to the devices or fault injection equipment. We demonstrate CLKSCREW on commodity ARM/Android devices. We show that a malicious kernel driver (1) can extract secret cryptographic keys from Trustzone, and (2) can escalate its privileges by loading self-signed code into Trustzone. As the first work to show the security ramifications of energy management mechanisms, we urge the community to re-examine these security-oblivious designs.}, 773 booktitle = {Proceedings of the 26th USENIX Conference on Security Symposium}, 774 pages = {1057–1074}, 775 numpages = {18}, 776 location = {Vancouver, BC, Canada}, 777 series = {SEC'17} 778 } 779 780 @inproceedings{samsung2017knox, 781 author={M. {Dorjmyagmar} and M. {Kim} and H. {Kim}}, 782 booktitle={2017 19th International Conference on Advanced Communication Technology (ICACT)}, 783 title={Security analysis of Samsung Knox}, 784 year={2017}, 785 volume={}, 786 number={}, 787 pages={550-553}, 788 doi={10.23919/ICACT.2017.7890150}} 789 790 @InProceedings{amd2019, 791 author = {Mengyuan Li and Yinqian Zhang and Zhiqiang Lin and Yan Solihin}, 792 title = {Exploiting Unprotected I/O Operations in AMD’s Secure Encrypted Virtualization}, 793 booktitle = {USENIX Security Symposium}, 794 year = {2019}, 795 } 796 797 @Misc{sim2019, 798 author = {Adaptive Mobile Security Limited}, 799 title = {Simjacker Technical Report}, 800 howpublished = {\url{https://www.enea.com/info/simjacker/}}, 801 year = {2019}, 802 } 803 804 @inproceedings{intel2020lvi, 805 title = {{LVI: Hijacking Transient Execution through Microarchitectural Load Value Injection}}, 806 author = {Van Bulck, Jo and Moghimi, Daniel and Schwarz, Michael and Lipp, Moritz and Minkin, Marina and Genkin, Daniel and Yuval, Yarom and Sunar, Berk and Gruss, Daniel and Piessens, Frank}, 807 booktitle = {41th IEEE Symposium on Security and Privacy (S\&P'20)}, 808 month={March}, 809 year = {2020}, 810 } 811 812 @misc{intel2020sgaxe, 813 title={{SGAxe}: How {SGX} Fails in Practice}, 814 author={van Schaik, Stephan and Kwong, Andrew and Genkin, Daniel and Yarom, Yuval}, 815 howpublished = {\url{https://sgaxeattack.com/}}, 816 month={June}, 817 year={2020}, 818 } 819 820 @article{smartcard2020, 821 author = {Jan Jancar and Vladimir Sedlacek and Petr Svenda and Marek Sys}, 822 title = {Minerva: The curse of {ECDSA} nonces (Systematic analysis of lattice 823 attacks on noisy leakage of bit-length of {ECDSA} nonces)}, 824 journal = {IACR Transactions on Cryptographic Hardware and Embedded Systems}, 825 volume = {2020}, 826 number = {4}, 827 pages = {281--308}, 828 year = {2020}, 829 doi = {10.13154/tches.v2020.i4.281-308} 830 } 831 832 @inproceedings{atecc2022, 833 author={Hériveaux, Olivier}, 834 booktitle={2022 Workshop on Fault Detection and Tolerance in Cryptography (FDTC)}, 835 title={Triple Exploit Chain with Laser Fault Injection on a Secure Element}, 836 year={2022}, 837 pages={9-17}, 838 keywords={Semiconductor lasers;Fault detection;EPROM;Memory management;Lighting;Silicon;Circuit faults;Laser Fault Injection;Secure Element;Reverse Engineering}, 839 doi={10.1109/FDTC57191.2022.00011} 840 } 841 842 @inproceedings{amd2023, 843 title={faulTPM: Exposing AMD fTPMs’ Deepest Secrets}, 844 author={Jacob, Hans Niklas and Werling, Christian and Buhren, Robert and Seifert, Jean-Pierre}, 845 booktitle={2023 IEEE 8th European Symposium on Security and Privacy (EuroS\&P)}, 846 pages={1128--1142}, 847 year={2023}, 848 organization={IEEE} 849 } 850 851 @inproceedings{arm2023, 852 title={Oops..! I Glitched It Again! How to {Multi-Glitch} the {Glitching-Protections} on {ARM} {TrustZone-M}}, 853 author={Sa{\ss}, Xhani Marvin and Mitev, Richard and Sadeghi, Ahmad-Reza}, 854 booktitle={32nd USENIX Security Symposium (USENIX Security 23)}, 855 pages={6239--6256}, 856 year={2023} 857 } 858 859 @Misc{tpm2023, 860 author = {Francisco Falcon}, 861 title = {Vulnerabilities in the TPM 2.0 reference implementation code}, 862 howpublished = {\url{https://blog.quarkslab.com/vulnerabilities-in-the-tpm-20-reference-implementation-code.html}}, 863 month = {March}, 864 year = {2023}, 865 } 866 867 @Misc{intel2023sgx, 868 author = {Joseph Nuzman}, 869 title = {CVE-2022-38090: Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.}, 870 howpublished = {\url{https://www.cve.org/CVERecord?id=CVE-2022-38090}}, 871 month = {February}, 872 year = {2023}, 873 } 874 875 @Misc{infineon2024, 876 author = {Thomas Roche}, 877 title = {EUCLEAK: Side-Channel Attack on the YubiKey 5 Series---Revealing and Breaking Infineon ECDSA Implementation on the Way}, 878 howpublished = {\url{https://ninjalab.io/eucleak/}}, 879 month = {September}, 880 year = {2024}, 881 } 882 883 @inproceedings{intel2024, 884 title={TDXdown: Single-Stepping and Instruction Counting Attacks against Intel TDX}, 885 author={Wilke, Luca and Sieck, Florian and Eisenbarth, Thomas}, 886 booktitle={ACM CCS 2024}, 887 year={2024} 888 } 889 890 @inproceedings{powerled2024, 891 title={Video-Based Cryptanalysis: Extracting Cryptographic Keys from Video Footage of a Device’s Power LED Captured by Standard Video Cameras}, 892 author={Nassi, Ben and Iluz, Etay and Cohen, Or and Vayner, Ofek and Nassi, Dudi and Zadov, Boris and Elovici, Yuval}, 893 booktitle={2024 IEEE Symposium on Security and Privacy (SP)}, 894 pages={163--163}, 895 year={2024}, 896 organization={IEEE Computer Society} 897 } 898 899 @inproceedings{amd2025, 900 title = {CounterSEVeillance: Performance-Counter Attacks on AMD SEV-SNP}, 901 abstract = {Confidential virtual machines (VMs) promise higher security by running the VM inside a trusted execution environment (TEE). Recent AMD server processors support confidential VMs with the SEV-SNP processor extension. SEV-SNP provides guarantees for integrity and confidentiality for confidential VMs despite running them in a shared hosting environment.In this paper, we introduce CounterSEVeillance, a new side-channel attack leaking secret-dependent control flow and operand properties from performance counter data. Our attack is the first to exploit performance counter side-channel leakage with single-instruction resolution from SEV-SNP VMs and works on fully patched systems. We systematically analyze performance counter events in SEV-SNP VMs and find that 228 are exposed to a potentially malicious hypervisor. CounterSEVeillance builds on this analysis and records performance counter traces with an instruction-level resolution by single-stepping the victim VM using APIC interrupts in combination with page faults. We match CounterSEVeillance traces against binaries, precisely recovering the outcome of any secret-dependent conditional branch and inferring operand properties. We present four attack case studies, in which we exemplarily showcase concrete exploitable leakage with 6 of the exposed performance counters. First, we use CounterSEVeillance to extract a full RSA-4096 key from a single Mbed TLS signature process in less than 8 minutes. Second, we present the first side-channel attack on TOTP verification running in an AMD SEV-SNP VM, recovering a 6-digit TOTP with only 31.1 guesses on average. Third, we show that CounterSEVeillance can leak the secret key from which the TOTPs are derived from the underlying base32 decoder. Fourth and finally, we show that CounterSEVeillance can also be used to construct a plaintext-checking oracle in a divide-and-surrender-style attack. We conclude that moving an entire VM into a setting with a privileged adversary increases the attack surface, given the vast amounts of code not vetted for this specific security setting.}, 902 keywords = {Performance Counter, Confidential Virtual Machines, AMD SEV}, 903 author = {Stefan Gast and Hannes Weissteiner and Schr{\"o}der, {Robin Leander} and Daniel Gruss}, 904 year = {2025}, 905 month = feb, 906 language = {English}, 907 booktitle = {Network and Distributed System Security (NDSS) Symposium 2025}, 908 note = {Network and Distributed System Security Symposium 2025 : NDSS 2025, NDSS 2025 ; Conference date: 23-02-2025 Through 28-02-2025}, 909 } 910 @misc{letemps2020refusDeCash, 911 author = {{Mathilde Farine}}, 912 year = {2020}, 913 month = {April}, 914 date = {02}, 915 journal={{Le Temps}}, 916 title = {Les commerces peuvent refuser les achats en cash}, 917 howpublished = {\url{https://www.letemps.ch/economie/finance/commerces-peuvent-refuser-achats-cash}}, 918 } 919 @misc{freedom2024gnu, 920 author = {{GNU}}, 921 title = {What is Free Software?}, 922 howpublished = {\url{https://www.gnu.org/home.en.html}}, 923 } 924 @article{deyoung2004banks, 925 title={How do banks make money? The fallacies of fee income}, 926 author={DeYoung, Robert and Rice, Tara and others}, 927 journal={Economic Perspectives-Federal Reserve Bank of Chicago}, 928 volume={28}, 929 number={4}, 930 pages={34}, 931 year={2004}, 932 publisher={THE FEDERAL RESERVE BANK OF CHICAGO} 933 }