Checking secure interactions of smart card applets: extended version

  • Authors:
  • P. Bieber;J. Cazin;P. Girard;J.-L. Lanet;V. Wiels;G. Zanon

  • Affiliations:
  • ONERA-CERT/DTIM, BP 4025, 2 avenue E. Belin, F-31055 Toulouse Cedex 4, France;ONERA-CERT/DTIM, BP 4025, 2 avenue E. Belin, F-31055 Toulouse Cedex 4, France;GEMPLUS, avenue du pic de Bertagne, 13881 Gémenos cedex, France;GEMPLUS, avenue du pic de Bertagne, 13881 Gémenos cedex, France;ONERA-CERT/DTIM, BP 4025, 2 avenue E. Belin, F-31055 Toulouse Cedex 4, France;ONERA-CERT/DTIM, BP 4025, 2 avenue E. Belin, F-31055 Toulouse Cedex 4, France

  • Venue:
  • Journal of Computer Security - Special issue on ESORICS 2000
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents an approach enabling a smart card issuer to verify that a new applet securely interacts with already downloaded applets. A security policy has been defined that associates levels to applet attributes and methods and defines authorized flows between levels. We propose a technique based on model checking to verify that actual information flows between applets are authorized. We illustrate our approach on applets involved in an electronic purse running on Java enabled smart cards.