loading
  • Login
  • Sign-Up

Research.Publish.Connect.

Paper

Authors: Germain Jolly ; Sylvain Vernois and Christophe Rosenberger

Affiliation: Universite de Caen Basse Normandie; ENSICAEN; UMR 6072 GREYC, France

ISBN: 978-989-758-167-0

Keyword(s): Security, Analysis, Smart Card application, Observation, Detection, Evaluation, WSCT Framework.

Related Ontology Subjects/Areas/Topics: Computer-Supported Education ; Enterprise Information Systems ; Information Systems Analysis and Specification ; Information Technologies Supporting Learning ; Security ; Security and Privacy

Abstract: Smart cards are tamper resistant devices but vulnerabilities are sometimes discovered. We address in this paper the security and the functional testing of embedded applications in smart cards. We propose an original methodology for the evaluation of applications and we show its benefit by comparing it to a classical certification process. The proposed method is based on the observation of the APDU (Application Protocol Data Unit) communication with the smart card. Some specific properties are verified as a complementary method in the evaluation process and allows the on-the-fly detection of an anomaly and the reasons that triggered this anomaly during the test. Here are presented two uses of this method: a simple use to illustrate the use of properties to verify an implementation of an application and a more complex illustration by applying the fuzzing method to show what we can obtain with the proposed approach, i.e. an analysis of an anomaly.

PDF ImageFull Text

Download
Sign In Guest: Register as new SCITEPRESS user or Join INSTICC now for free.

Sign In SCITEPRESS user: please login.

Sign In INSTICC Members: please login. If not a member yet, Join INSTICC now for free.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 54.161.217.24. INSTICC members have higher download limits (free membership now)

In the current month:
Recent papers: 1 available of 1 total
2+ years older papers: 2 available of 2 total

Paper citation in several formats:
Jolly G., Vernois S. and Rosenberger C. (2016). An Observe-and-Detect Methodology for the Security and Functional Testing of Smart Card Applications.In Proceedings of the 2nd International Conference on Information Systems Security and Privacy ISBN 978-989-758-167-0, pages 282-289. DOI: 10.5220/0005682202820289

@conference{icissp16,
author={Germain Jolly and Sylvain Vernois and Christophe Rosenberger},
title={An Observe-and-Detect Methodology for the Security and Functional Testing of Smart Card Applications},
booktitle={Proceedings of the 2nd International Conference on Information Systems Security and Privacy },
year={2016},
pages={282-289},
doi={10.5220/0005682202820289},
isbn={978-989-758-167-0},
}

TY - CONF

JO - Proceedings of the 2nd International Conference on Information Systems Security and Privacy
TI - An Observe-and-Detect Methodology for the Security and Functional Testing of Smart Card Applications
SN - 978-989-758-167-0
AU - Jolly G.
AU - Vernois S.
AU - Rosenberger C.
PY - 2016
SP - 282
EP - 289
DO - 10.5220/0005682202820289

Sorted by: Show papers

Note: The preferred Subjects/Areas/Topics, listed below for each paper, are those that match the selected paper topics and their ontology superclasses.
More...

Login or register to post comments.

Comments on this Paper: Be the first to review this paper.

Show authors

Note: The preferred Subjects/Areas/Topics, listed below for each author, are those that more frequently used in the author's papers.
More...