首页> 外文会议>IFIP WG 11.2 International workshop on information security theory and practice >New Countermeasures against Fault and Software Type Confusion Attacks on Java Cards
【24h】

New Countermeasures against Fault and Software Type Confusion Attacks on Java Cards

机译:Java卡故障和软件类型混淆攻击的新对策

获取原文

摘要

Attacks based on type confusion against Java Card platforms have been widely studied in the literature over the past few years. Until now, no generic countermeasure has ever been proposed to cover simultaneously and efficiently direct and indirect type confusions. In this article we bridge this gap by introducing two different schemes which cover both type confusions. First, we show that an adequate random transformation of all the manipulated data on the platform according to their type can bring a very good resistance against type confusion exploits. Secondly, we describe how a so-called Java Card Virtual Machine Abstract Companion can allow one to detect all type confusions between integers and Objects all across the platform. While the second solution stands as a strong but resource-demanding mechanism, we show that the first one is a particularly efficient memory/security trade-off solution to secure the whole platform.
机译:在过去的几年中,针对Java Card平台的基于类型混淆的攻击已得到广泛研究。迄今为止,还没有提出通用的对策来涵盖同时和有效地解决直接和间接类型混淆的问题。在本文中,我们通过介绍两种涵盖两种类型混淆的不同方案来弥合这种差距。首先,我们证明,根据平台上所有被操纵数据的类型进行适当的随机转换可以带来很好的抵抗类型混淆攻击的能力。其次,我们描述一种所谓的Java Card虚拟机抽象伴侣如何允许人们检测整个平台上整数和对象之间的所有类型混淆。尽管第二种解决方案是一种强大的资源需求机制,但我们证明了第一种解决方案是一种特别有效的内存/安全性折衷解决方案,可确保整个平台的安全。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号