Embedded Eavesdropping on Java Card - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2012

Embedded Eavesdropping on Java Card

Résumé

In this article we present the first Combined Attack on a Java Card targeting the APDU buffer itself, thus threatening both the security of the platform and of the hosted applications as well as the privacy of the cardholder. We show that such an attack, which combines malicious application and fault injection, is achievable in practice on the latest release of the Java Card specifications by presenting several case studies taking advantage for instance of the well-known GlobalPlatform and (U)SIM Application ToolKit.
Fichier principal
Vignette du fichier
main.pdf (128.84 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00706186 , version 1 (09-06-2012)

Licence

Paternité

Identifiants

Citer

Guillaume Barbu, Christophe Giraud, Vincent Guerin. Embedded Eavesdropping on Java Card. 27th Information Security and Privacy Conference (SEC), Jun 2012, Heraklion, Greece. pp.37-48, ⟨10.1007/978-3-642-30436-1_4⟩. ⟨hal-00706186⟩
252 Consultations
3627 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More