{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2012:XT4QLHP5EANET3FD57TDRAEEVP","short_pith_number":"pith:XT4QLHP5","canonical_record":{"source":{"id":"1209.2531","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CY","submitted_at":"2012-09-12T09:16:13Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"cbed66871c1ea45365fbcbc0ea37ab738b34000be91fa3a4853ffe68bd431b57","abstract_canon_sha256":"b70265047cfe7b406debc9000eabfb5f1e78d61945d32a6ab194c657223c54aa"},"schema_version":"1.0"},"canonical_sha256":"bcf9059dfd201a49eca3efe6388084abe33aedf1304f1c1fab79845401af29f4","source":{"kind":"arxiv","id":"1209.2531","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1209.2531","created_at":"2026-05-18T03:45:41Z"},{"alias_kind":"arxiv_version","alias_value":"1209.2531v1","created_at":"2026-05-18T03:45:41Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1209.2531","created_at":"2026-05-18T03:45:41Z"},{"alias_kind":"pith_short_12","alias_value":"XT4QLHP5EANE","created_at":"2026-05-18T12:27:27Z"},{"alias_kind":"pith_short_16","alias_value":"XT4QLHP5EANET3FD","created_at":"2026-05-18T12:27:27Z"},{"alias_kind":"pith_short_8","alias_value":"XT4QLHP5","created_at":"2026-05-18T12:27:27Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2012:XT4QLHP5EANET3FD57TDRAEEVP","target":"record","payload":{"canonical_record":{"source":{"id":"1209.2531","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CY","submitted_at":"2012-09-12T09:16:13Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"cbed66871c1ea45365fbcbc0ea37ab738b34000be91fa3a4853ffe68bd431b57","abstract_canon_sha256":"b70265047cfe7b406debc9000eabfb5f1e78d61945d32a6ab194c657223c54aa"},"schema_version":"1.0"},"canonical_sha256":"bcf9059dfd201a49eca3efe6388084abe33aedf1304f1c1fab79845401af29f4","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T03:45:41.243664Z","signature_b64":"aeqeREsROVWABxbKgITVGdrzUZz9HpoN9Rp08UFMZJIZsIhQWSQ4pLeeIeWYFWOxTSkATyUr5aTnz8J0lyjhDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"bcf9059dfd201a49eca3efe6388084abe33aedf1304f1c1fab79845401af29f4","last_reissued_at":"2026-05-18T03:45:41.242810Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T03:45:41.242810Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1209.2531","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T03:45:41Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"eBufHgaFxkJuZzAQtkPnPgQfpPqCocPhSfZWJT33XNFIoS6l10wauaanvyPcp6XiZUYiiWzxDWjD+Ak3HVydAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T08:38:52.139879Z"},"content_sha256":"184b1e1249c2813be6f14aa3ef9d6011303fb0904a8b0f5a763fa32e41f8af1c","schema_version":"1.0","event_id":"sha256:184b1e1249c2813be6f14aa3ef9d6011303fb0904a8b0f5a763fa32e41f8af1c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2012:XT4QLHP5EANET3FD57TDRAEEVP","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Chip and Skim: cloning EMV cards with the pre-play attack","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.CY","authors_text":"Mike Bond, Omar Choudary, Ross Anderson, Sergei Skorobogatov, Steven J. Murdoch","submitted_at":"2012-09-12T09:16:13Z","abstract_excerpt":"EMV, also known as \"Chip and PIN\", is the leading system for card payments worldwide. It is used throughout Europe and much of Asia, and is starting to be introduced in North America too. Payment cards contain a chip so they can execute an authentication protocol. This protocol requires point-of-sale (POS) terminals or ATMs to generate a nonce, called the unpredictable number, for each transaction to ensure it is fresh. We have discovered that some EMV implementers have merely used counters, timestamps or home-grown algorithms to supply this number. This exposes them to a \"pre-play\" attack whi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1209.2531","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T03:45:41Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"5XZyDg86TKBFSmKE9uC8aj8o2/MyKBz15No2zC5mebEWCBqy06KBr6iH/KGD3U4AaOxrs8KrT1NTmuV8/PwXDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-31T08:38:52.140546Z"},"content_sha256":"3b69ac2a32019af5352836a10010eab9572fe56845477e179840711415b5fbec","schema_version":"1.0","event_id":"sha256:3b69ac2a32019af5352836a10010eab9572fe56845477e179840711415b5fbec"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/XT4QLHP5EANET3FD57TDRAEEVP/bundle.json","state_url":"https://pith.science/pith/XT4QLHP5EANET3FD57TDRAEEVP/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/XT4QLHP5EANET3FD57TDRAEEVP/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-31T08:38:52Z","links":{"resolver":"https://pith.science/pith/XT4QLHP5EANET3FD57TDRAEEVP","bundle":"https://pith.science/pith/XT4QLHP5EANET3FD57TDRAEEVP/bundle.json","state":"https://pith.science/pith/XT4QLHP5EANET3FD57TDRAEEVP/state.json","well_known_bundle":"https://pith.science/.well-known/pith/XT4QLHP5EANET3FD57TDRAEEVP/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2012:XT4QLHP5EANET3FD57TDRAEEVP","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"b70265047cfe7b406debc9000eabfb5f1e78d61945d32a6ab194c657223c54aa","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CY","submitted_at":"2012-09-12T09:16:13Z","title_canon_sha256":"cbed66871c1ea45365fbcbc0ea37ab738b34000be91fa3a4853ffe68bd431b57"},"schema_version":"1.0","source":{"id":"1209.2531","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1209.2531","created_at":"2026-05-18T03:45:41Z"},{"alias_kind":"arxiv_version","alias_value":"1209.2531v1","created_at":"2026-05-18T03:45:41Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1209.2531","created_at":"2026-05-18T03:45:41Z"},{"alias_kind":"pith_short_12","alias_value":"XT4QLHP5EANE","created_at":"2026-05-18T12:27:27Z"},{"alias_kind":"pith_short_16","alias_value":"XT4QLHP5EANET3FD","created_at":"2026-05-18T12:27:27Z"},{"alias_kind":"pith_short_8","alias_value":"XT4QLHP5","created_at":"2026-05-18T12:27:27Z"}],"graph_snapshots":[{"event_id":"sha256:3b69ac2a32019af5352836a10010eab9572fe56845477e179840711415b5fbec","target":"graph","created_at":"2026-05-18T03:45:41Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"EMV, also known as \"Chip and PIN\", is the leading system for card payments worldwide. It is used throughout Europe and much of Asia, and is starting to be introduced in North America too. Payment cards contain a chip so they can execute an authentication protocol. This protocol requires point-of-sale (POS) terminals or ATMs to generate a nonce, called the unpredictable number, for each transaction to ensure it is fresh. We have discovered that some EMV implementers have merely used counters, timestamps or home-grown algorithms to supply this number. This exposes them to a \"pre-play\" attack whi","authors_text":"Mike Bond, Omar Choudary, Ross Anderson, Sergei Skorobogatov, Steven J. Murdoch","cross_cats":["cs.CR"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CY","submitted_at":"2012-09-12T09:16:13Z","title":"Chip and Skim: cloning EMV cards with the pre-play attack"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1209.2531","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:184b1e1249c2813be6f14aa3ef9d6011303fb0904a8b0f5a763fa32e41f8af1c","target":"record","created_at":"2026-05-18T03:45:41Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"b70265047cfe7b406debc9000eabfb5f1e78d61945d32a6ab194c657223c54aa","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CY","submitted_at":"2012-09-12T09:16:13Z","title_canon_sha256":"cbed66871c1ea45365fbcbc0ea37ab738b34000be91fa3a4853ffe68bd431b57"},"schema_version":"1.0","source":{"id":"1209.2531","kind":"arxiv","version":1}},"canonical_sha256":"bcf9059dfd201a49eca3efe6388084abe33aedf1304f1c1fab79845401af29f4","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"bcf9059dfd201a49eca3efe6388084abe33aedf1304f1c1fab79845401af29f4","first_computed_at":"2026-05-18T03:45:41.242810Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T03:45:41.242810Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"aeqeREsROVWABxbKgITVGdrzUZz9HpoN9Rp08UFMZJIZsIhQWSQ4pLeeIeWYFWOxTSkATyUr5aTnz8J0lyjhDQ==","signature_status":"signed_v1","signed_at":"2026-05-18T03:45:41.243664Z","signed_message":"canonical_sha256_bytes"},"source_id":"1209.2531","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:184b1e1249c2813be6f14aa3ef9d6011303fb0904a8b0f5a763fa32e41f8af1c","sha256:3b69ac2a32019af5352836a10010eab9572fe56845477e179840711415b5fbec"],"state_sha256":"9b3204c117f8ed00180b5685fcc2b8a98a6c60dbbda29ec86c1e7ed5be8f1eae"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8ZXPDacHoTOup5ufVDRGiiS95pR/cYY6f6AhNGaLmmzSZ7I//CHpttEHs1AwwagriwaqGTr4X95rj3/9MGy5CA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-31T08:38:52.144249Z","bundle_sha256":"cfd600df8f4af5a67811a12104ef9eab5eb9591884dd1d840d0a74c5169d7e5f"}}