Diplomová práce
Získaná ocenění: Cena děkana FI za vynikající závěrečnou práci

Improving side-channel resistance of Java Card implementations

Bc. Veronika Hanulíková, učo 492760
Anotace

Technologie Java Card umožňuje běh appletů implementovaných v jazyce Java v zabezpečeném prostředí čipových karet. Navzdory zabudovaným bezpečnostním prvkům však tyto karty zůstávají zranitelné vůči útokům postranními kanály. Tato práce se konkrétně zabývá časovými odchylkami, které mohou způsobit únik citlivých informací prostřednictvím postranního kanálu založeného na čase. V této diplomové práci …více

Abstract

Java Card technology allows Java-based applications to run in a secure environment on smart card devices. Despite their built-in security features, these cards remain vulnerable to side-channel attacks. Specifically, this thesis addresses the time variations that can cause sensitive information leakage through a time side-channel. We introduce a comprehensive methodology for detecting and evaluating …více

Zadání práce

This thesis aims to analyze existing timing side-channel attack concepts targeting software cryptographic implementations, focusing on those applicable to the Java Card platform. The theoretical part of the thesis will explore typical patterns of side-channel leakage found in Java Card implementations and options for leakage mitigation.

The practical part of the work will:

  1. Examine methods available in the JCMathLib library, assess their data-time dependency, and propose code changes to fix detected leakages.
  2. Evaluate the impact of fixes on detectable time leakage and performance overhead with the JCProfilerNext tool using PC Timing Analysis and Simple Power Analysis (SPA).
  3. Demonstrate an attack concept against a secret handled by the JCMathLib library based on a timing leak.
  4. Enhance the JCProfilerNext tool with support for SPA-based time measuring.
Results that can be used outside of JCMathLib scope will be the identification of typical problematic constructions causing time inconsistency in Java Card code, the definition of approaches to convert these constructions into constant-time solutions, and the proposal of techniques for leakage detection and testing of time side-channel resistance on a real card.

References:

  • JCMathLib library, https://github.com/OpenCryptoProject/JCMathLib

  • L. Zaoral, Automatic Performance Profiler for Security Analysis of Cryptographic Smart Cards, https://is.muni.cz/auth/th/v7l30/

  • JCFROST, https://github.com/crocs-muni/JCFROST

Práce zkontrolována:
23. 5. 2025 12:01, doc. RNDr. Petr Švenda, Ph.D., učo 4085
Jazyk práce
angličtina angličtina
Termín obhajoby
17. 6. 2025
Práce byla úspěšně obhájena

Vedoucí

doc. RNDr. Petr Švenda, Ph.D., učo 4085
KPSK FI MU

Oponent

Lukasz Michal Chmielewski, PhD, učo 247858
KPSK FI MU

  • Přidání souboru

    Soubor nebo složku lze nahrát pomocí tlačítka Přidat.
  • Další operace se soubory

    Podrobnosti lze zjistit označením příslušného řádku.
  • Pohled pro experty

    Pro častou práci je možné zvolit režim Více možností.
  • Vyhledávání souborů

    Vyhledávaný výraz můžete zadat přímo do adresního řádku.
  • Rychlý přístup k souborům

    Pomocí funkce Nedávné je možné se rychle vrátit k právě prohlíženým souborům. Oblíbené soubory je také možné označit Hvězdičkou.