| 2018 | NDSS | Mind Your Keys? A Security Evaluation of Java Keystores. | Riccardo Focardi, Francesco Palmarini, Marco Squarcina, Graham Steel, Mauro Tempesta |
| 2016 | RAID | APDU-Level Attacks in PKCS#11 Devices. | Claudio Bozzato, Riccardo Focardi, Francesco Palmarini, Graham Steel |
| 2015 | ACSAC | Getting to know your Card: Reverse-Engineering the Smart-Card Application Protocol Data Unit. | Andriana Gkaniatsou, Fiona McNeill, Alan Bundy, Graham Steel, Riccardo Focardi, Claudio Bozzato |
| 2013 | ESORICS | Universally Composable Key-Management. | Steve Kremer, Robert Knnemann, Graham Steel |
| 2012 | CCS | Revoke and let live: a secure key revocation api for cryptographic devices. | Vronique Cortier, Graham Steel, Cyrille Wiedling |
| 2012 | CRYPTO | Efficient Padding Oracle Attacks on Cryptographic Hardware. | Romain Bardou, Riccardo Focardi, Yusuke Kawamoto, Lorenzo Simionato, Graham Steel, Joe-Kai Tsay |
| 2010 | CCS | Attacking and fixing PKCS#11 security tokens. | Matteo Bortolozzo, Matteo Centenaro, Riccardo Focardi, Graham Steel |
| 2010 | ESORICS | Formal Analysis of Privacy for Vehicular Mix-Zones. | Morten Dahl, Stphanie Delaune, Graham Steel |
| 2009 | ESORICS | Type-Based Analysis of PIN Processing APIs. | Matteo Centenaro, Riccardo Focardi, Flaminia L. Luccio, Graham Steel |
| 2009 | ESORICS | A Generic Security API for Symmetric Key Management on Cryptographic Devices. | Vronique Cortier, Graham Steel |
| 2007 | TACAS | Automatic Analysis of the Security of XOR-Based Key Management Schemes. | Vronique Cortier, Gavin Keighren, Graham Steel |
| 2005 | CADE | Deduction with XOR Constraints in Security API Modelling. | Graham Steel |
| 2004 | CADE | Attacking a Protocol for Group Key Agreement by Refuting Incorrect Inductive Conjectures. | Graham Steel, Alan Bundy, Monika Maidl |