首页> 外文会议>International Conference on Information Systems Security and Privacy >An Observe-and-Detect Methodology for the Security and Functional Testing of Smart Card Applications
【24h】

An Observe-and-Detect Methodology for the Security and Functional Testing of Smart Card Applications

机译:智能卡应用的安全性和功能测试的观察和检测方法

获取原文

摘要

Smart cards are tamper resistant devices but vulnerabilities are sometimes discovered. We address in this paper the security and the functional testing of embedded applications in smart cards. We propose an original methodology for the evaluation of applications and we show its benefit by comparing it to a classical certification process. The proposed method is based on the observation of the APDU (Application Protocol Data unit) communication with the smart card. Some specific properties are verified as a complementary method in the evaluation process and allows the on-the-fly detection of an anomaly and the reasons that triggered this anomaly during the test. Here are presented two uses of this method: a simple use to illustrate the use of properties to verify an implementation of an application and a more complex illustration by applying the fuzzing method to show what we can obtain with the proposed approach, i.e. an analysis of an anomaly.
机译:智能卡是防篡改设备,但有时会发现漏洞。 我们在本文中解决了智能卡中嵌入式应用的安全性和功能测试。 我们提出了一种原始方法,用于评估应用程序,并通过将其与经典认证过程进行比较来表现出福利。 所提出的方法基于与智能卡的APDU(应用协议数据单元)通信的观察。 一些特异性属性被验证为评估过程中的互补方法,并允许在测试期间随机检测发生异常和引发这种异常的原因。 这里呈现了这种方法的两个用途:简单用来说明使用属性来验证应用程序的实现和通过应用模糊方法来展示我们可以通过所提出的方法来获得的应用程序,即分析 一个异常。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号