Závěrečná práce: Bc. Veronika Hanulíková, učo 492760: Improving side-channel resistance of Java Card implementations
Diplomová práce
Improving side-channel resistance of Java Card implementations
Anotace
Technologie Java Card umožňuje běh appletů implementovaných v jazyce Java v zabezpečeném prostředí čipových karet. Navzdory zabudovaným bezpečnostním prvkům však tyto karty zůstávají zranitelné vůči útokům postranními kanály. Tato práce se konkrétně zabývá časovými odchylkami, které mohou způsobit únik citlivých informací prostřednictvím postranního kanálu založeného na čase. V této diplomové práci …více
Abstract
Java Card technology allows Java-based applications to run in a secure environment on smart card devices. Despite their built-in security features, these cards remain vulnerable to side-channel attacks. Specifically, this thesis addresses the time variations that can cause sensitive information leakage through a time side-channel. We introduce a comprehensive methodology for detecting and evaluating …více
Zadání práce
This thesis aims to analyze existing timing side-channel attack concepts targeting software cryptographic implementations, focusing on those applicable to the Java Card platform. The theoretical part of the thesis will explore typical patterns of side-channel leakage found in Java Card implementations and options for leakage mitigation.
The practical part of the work will:
- Examine methods available in the JCMathLib library, assess their data-time dependency, and propose code changes to fix detected leakages.
- Evaluate the impact of fixes on detectable time leakage and performance overhead with the JCProfilerNext tool using PC Timing Analysis and Simple Power Analysis (SPA).
- Demonstrate an attack concept against a secret handled by the JCMathLib library based on a timing leak.
- Enhance the JCProfilerNext tool with support for SPA-based time measuring.
References:
-
JCMathLib library, https://github.com/OpenCryptoProject/JCMathLib
-
L. Zaoral, Automatic Performance Profiler for Security Analysis of Cryptographic Smart Cards, https://is.muni.cz/auth/th/v7l30/
-
JCFROST, https://github.com/crocs-muni/JCFROST
23. 5. 2025 12:01, doc. RNDr. Petr Švenda, Ph.D., učo 4085
Práce na příbuzné téma
Seznam prací, které mají shodná klíčová slova.
-
Detection of undocumented JavaCard API using power side-channels
Mgr. Petr Hanák, učo 524742 -
Analysis of open-source JavaCard applets
Bc. Jakub Merta, učo 525302 -
Distribution portal for applications for cryptographic smartcards
Mgr. Hitesh Lilhare -
Analysis of implementations of ECC libraries
Mgr. David Hofman -
Algoritmy pro differenciální odběrovou analýzu kryptografických čipových karet (DPA)
RNDr. Jiří Kůr, Ph.D. -
Security considerations for elliptic curve domain parameters selection
RNDr. Ján Jančár, Ph.D., učo 445358 -
Odběrová analýza průběhu ověřování PINu na kryptografické čipové kartě
Mgr. Jakub Ferenc, učo 98993 -
Reverzní inženýrství JavaCard appletu prováděného na čipové kartě
Mgr. Martin Prpič, učo 256137




