An Observe-and-Detect methodology for the security and functional testing of smart card applications - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2016

An Observe-and-Detect methodology for the security and functional testing of smart card applications

Résumé

Smart cards are tamper resistant devices but vulnerabilities are sometimes discovered. We address in this paper the security and the functional testing of embedded applications in smart cards. We propose an original methodology for the evaluation of applications and we show its benefit by comparing it to a classical certification process. The proposed method is based on the observation of the APDU (Application Protocol Data unit) communication with the smart card. Some specific properties are verified as a complementary method in the evaluation process and allows the on-the-fly detection of an anomaly and the reasons that triggered this anomaly during the test. Here are presented two uses of this method: a simple use to illustrate the use of properties to verify an implementation of an application and a more complex illustration by applying the fuzzing method to show what we can obtain with the proposed approach, i.e. an analysis of an anomaly.
Fichier principal
Vignette du fichier
Jolly35.pdf (247.44 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01286831 , version 1 (20-03-2016)

Identifiants

  • HAL Id : hal-01286831 , version 1

Citer

Germain Jolly, Sylvain Vernois, Christophe Rosenberger. An Observe-and-Detect methodology for the security and functional testing of smart card applications. International Conference on Information Systems Security and Privacy (ICISSP), Feb 2016, Rome, Italy. ⟨hal-01286831⟩
119 Consultations
203 Téléchargements

Partager

Gmail Facebook X LinkedIn More