Current research interests
  • Vulnerabilities in the current EMV payments architecture caused by the weak partitioning between Chip & PIN, contactless and mobile payment technologies.
  • Investigating the security of EMV Next Generation.
  • Distributed ledger as a disruptive enabling technology in payment systems e.g. peer-to-peer micro loans, mortgages and international money transfer. This would include a focus on the security issues created by the new technologies.
  • Multi-modal user authentication combining IoT, wearable technologies, biometric identification techniques and smart data analysis of user activity / habits.

This research is supported by my extensive industry knowledge gained in my previous role, as a Solutions Architect, in retail banking / financial sectors in the UK, USA and Australia.in this role I was responsible for both design and implementation of large projects.

PhD Research

My PhD research investigates the question “Contactless payments; has security been sacrificed for usability?” specifically do the features which make contactless and mobile payments more convenient and user friendly negatively impact the security of the EMV payment system.  This research combines abstract formal modelling, software emulation and practical demonstrations.  This links the research theory, which identifies vulnerabilities in the payment system, to demonstrating the practical impact in a way that is relevant to both the payment industry and the public.  Publications from this research include Financial Cryptography and Data Security 2013 and Computer and Communications Security 2014.  In this research I have collaborated, prior to publication, with the UK Cards Association, the FCA, Visa, MasterCard and a number of major UK banks to ensure responsible disclosure of my research results.

I am principle investigator on the Access Control Live Lab.  In this project I have designed and built an environment for the investigation of multimodal user authentication.  The Access Control Lab combines IoT, wearable technologies and biometric identification techniques to create a physical space where multiple users are continuously identified without having to constantly enter PINs or passwords.

Research into the use of pervasive technologies in the protection of individuals such as survivors of domestic violence.  For example; (1) smart-phone technologies which allow survivors of domestic violence to access support services without leaving any evidence in their phone or browsing history (2) technologies which allow survivors to send a discrete emergency call for help when they are under duress (3) user authentication which can identify an invalid user trying to access the device using the correct password.  These projects were inspired and informed by collaboration with Northumbria Police, Metropolitan Police, Criminal Justice Board, National Crime Agency (NCA) and other government security agencies.

My research focuses on real-world impact of cyber security, as such I have been invited to present my work on TV news, BBC radio, in various UK newspapers and in computer security magazines.

Teaching Activities

Recently I have played a central role providing the content for one of the three weeks in Newcastle University's Cyber Security MOOC,

My teaching activities include mentoring MSc and BSc student's dissertation projects, giving guest lectures and teaching in computing practical sessions.

