Published in

Springer Verlag (Germany), IFIP Advances in Information and Communication Technology , p. 37-48, 2012

DOI: 10.1007/978-3-642-30436-1_4

Links

Tools

Export citation

Search in Google Scholar

Embedded Eavesdropping on Java Card

Journal article published in 2012 by Guillaume Barbu, Christophe Giraud, Vincent Guerin
This paper is made freely available by the publisher.
This paper is made freely available by the publisher.

Full text: Download

Green circle
Preprint: archiving allowed
Green circle
Postprint: archiving allowed
Red circle
Published version: archiving forbidden
Data provided by SHERPA/RoMEO

Abstract

In this article we present the first Combined Attack on a Java Card targeting the APDU buffer itself, thus threatening both the security of the platform and of the hosted applications as well as the privacy of the cardholder. We show that such an attack, which combines malicious application and fault injection, is achievable in practice on the latest release of the Java Card specifications by presenting several case studies taking advantage for instance of the well-known GlobalPlatform and (U)SIM Application ToolKit.