The Adoption Rate of Java']JavaCard Features by Certified Products and Open-Source Projects

被引:0
|
作者
Zaoral, Lukas [1 ]
Dufka, Antonin [2 ]
Svenda, Petr [2 ]
机构
[1] Red Hat, Raleigh, NC 27601 USA
[2] Masaryk Univ, Brno, Czech Republic
来源
SMART CARD RESEARCH AND ADVANCED APPLICATIONS, CARDIS 2023 | 2024年 / 14530卷
关键词
Smartcard; !text type='Java']Java[!/text]Card; Security certification; Open-source;
D O I
10.1007/978-3-031-54409-5_9
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
JavaCard is the most prevalent platform for cryptographic smartcards nowadays. Despite having more than 20 billion smartcards shipped with it and thirteen revisions since the JavaCard API specification was first published more than two decades ago, uptake of newly added features, cryptographic algorithms or their parameterizations, and systematic analysis of overall activity is missing. We fill this gap by mapping the activity of the JavaCard ecosystem from publicly available sources with a focus on 1) security certification documents available under Common Criteria and FIPS140 schemes and 2) activity and resources required by JavaCard applets released in an open-source domain (Paper supplementary materials, full results of analysis and open tools are available at https://crocs.fi.muni.cz/papers/cardis2023). The analysis performed on all certificates issued between the years 1997-2023 and on more than 200 public JavaCard applets shows that new features from JavaCard specification are adopted slowly, typically taking six or more years. Open-source applets utilize new features even later, likely due to the unavailability of recent performant smartcards in smaller quantities. Additionally, almost 70% of constants defined in JavaCard API specification are completely unused in open-source applets. The applet portability improves with recent cards, and transient memory requirements (scarce resource on smartcards) are typically small. While twenty or more products have been consistently certified every year since 2009, the open-source ecosystem became more active around 2013 but seemed to decline in the past two years. As a result, the whole smartcard ecosystem might be negatively impacted by limited exposure to new ideas and usage scenarios, serving only well-established domains and potentially harming its long-term competitiveness.
引用
收藏
页码:169 / 189
页数:21
相关论文
共 50 条
  • [1] Security Analysis of Web Open-Source Projects Based on Java']Java and PHP
    Yin, Zhen
    Lee, Scott Uk-Jin
    ELECTRONICS, 2023, 12 (12)
  • [2] SPMF: A Java']Java Open-Source Pattern Mining Library
    Fournier-Viger, Philippe
    Gomariz, Antonio
    Gueniche, Ted
    Soltani, Azadeh
    Wu, Cheng-Wei
    Tseng, Vincent S.
    JOURNAL OF MACHINE LEARNING RESEARCH, 2014, 15 : 3389 - 3393
  • [3] On Understanding the Release Patterns of Open Source Java']Java Projects
    Kaur, Arvinder
    Vig, Vidhi
    COMPUTATIONAL INTELLIGENCE IN DATA MINING, 2019, 711 : 9 - 18
  • [4] Insights into Female Contributions in Open-Source Projects
    Champa, Arifa I.
    Rabbi, Md Fazle
    Zibran, Minhaz F.
    Islam, Md Rakibul
    2023 IEEE/ACM 20TH INTERNATIONAL CONFERENCE ON MINING SOFTWARE REPOSITORIES, MSR, 2023, : 357 - 361
  • [5] An Empirical Investigation of the Security Weaknesses in Open-Source Projects
    Al-Shammare, Haifa A.
    Al-Otaiby, Nehal F.
    Al-Otabi, Muradi M.
    Alshayeb, Mohammad R.
    PROCEEDINGS OF 2024 28TH INTERNATION CONFERENCE ON EVALUATION AND ASSESSMENT IN SOFTWARE ENGINEERING, EASE 2024, 2024, : 634 - 642
  • [6] The emergence of openness in open-source projects: the case of openEHR
    Curto-Millet, Daniel
    Shaikh, Maha
    JOURNAL OF INFORMATION TECHNOLOGY, 2017, 32 (04) : 361 - 379
  • [7] Evolution Impact on Architecture Stability in Open-Source Projects
    Alenezi, Mamdouh
    Khellah, Fakhry
    INTERNATIONAL JOURNAL OF CLOUD APPLICATIONS AND COMPUTING, 2015, 5 (04) : 24 - 35
  • [8] Risk Management in Projects Based on Open-Source Software
    Nguyen Duc Linh
    Phan Duy Hung
    Vu Thu Diep
    Ta Duc Tung
    2019 8TH INTERNATIONAL CONFERENCE ON SOFTWARE AND COMPUTER APPLICATIONS (ICSCA 2019), 2019, : 178 - 183
  • [9] Open-source products for a lighting experiment device
    Gildea, Kevin M.
    Milburn, Nelda
    BEHAVIOR RESEARCH METHODS, 2014, 46 (04) : 960 - 983
  • [10] Open-source products for a lighting experiment device
    Kevin M. Gildea
    Nelda Milburn
    Behavior Research Methods, 2014, 46 : 960 - 983