On Practical Information Flow Policies for Java-Enabled Multiapplication Smart Cards

  • Authors:
  • Dorina Ghindici;Isabelle Simplot-Ryl

  • Affiliations:
  • IRCICA/LIFL, CNRS UMR 8022, Univ. Lille 1, INRIA Lille, Nord Europe, France;IRCICA/LIFL, CNRS UMR 8022, Univ. Lille 1, INRIA Lille, Nord Europe, France

  • Venue:
  • CARDIS '08 Proceedings of the 8th IFIP WG 8.8/11.2 international conference on Smart Card Research and Advanced Applications
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

In the multiapplicative context of smart cards, a strict control of underlying information flow between applications is highly desired. In this paper we propose a model to improve information flow usability in such systems by limiting the overhead for adding information flow security to a Java Virtual Machine. We define a domain specific language for defining security policies describing the allowed information flow inside the card. The applications are certified at loading time with respect to information flow security policies. We illustrate our approach on the LoyaltyCard, a multiapplicative smart card involving four loyalty applications sharing fidelity points.