The Adoption Rate of Java']JavaCard Features by Certified Products and Open-Source Projects

被引:0
|
作者
Zaoral, Lukas [1 ]
Dufka, Antonin [2 ]
Svenda, Petr [2 ]
机构
[1] Red Hat, Raleigh, NC 27601 USA
[2] Masaryk Univ, Brno, Czech Republic
来源
SMART CARD RESEARCH AND ADVANCED APPLICATIONS, CARDIS 2023 | 2024年 / 14530卷
关键词
Smartcard; !text type='Java']Java[!/text]Card; Security certification; Open-source;
D O I
10.1007/978-3-031-54409-5_9
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
JavaCard is the most prevalent platform for cryptographic smartcards nowadays. Despite having more than 20 billion smartcards shipped with it and thirteen revisions since the JavaCard API specification was first published more than two decades ago, uptake of newly added features, cryptographic algorithms or their parameterizations, and systematic analysis of overall activity is missing. We fill this gap by mapping the activity of the JavaCard ecosystem from publicly available sources with a focus on 1) security certification documents available under Common Criteria and FIPS140 schemes and 2) activity and resources required by JavaCard applets released in an open-source domain (Paper supplementary materials, full results of analysis and open tools are available at https://crocs.fi.muni.cz/papers/cardis2023). The analysis performed on all certificates issued between the years 1997-2023 and on more than 200 public JavaCard applets shows that new features from JavaCard specification are adopted slowly, typically taking six or more years. Open-source applets utilize new features even later, likely due to the unavailability of recent performant smartcards in smaller quantities. Additionally, almost 70% of constants defined in JavaCard API specification are completely unused in open-source applets. The applet portability improves with recent cards, and transient memory requirements (scarce resource on smartcards) are typically small. While twenty or more products have been consistently certified every year since 2009, the open-source ecosystem became more active around 2013 but seemed to decline in the past two years. As a result, the whole smartcard ecosystem might be negatively impacted by limited exposure to new ideas and usage scenarios, serving only well-established domains and potentially harming its long-term competitiveness.
引用
收藏
页码:169 / 189
页数:21
相关论文
共 50 条
  • [31] Productivity, Turnover, and Team Stability of Agile Teams in Open-Source Software Projects
    Scott, Ezequiel
    Charkie, Khaled Nimr
    Pfahl, Dietmar
    2020 46TH EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA 2020), 2020, : 124 - 131
  • [32] Open-source software projects in music education: Stakeholders, structure and the development cycle
    Myllykoski, Mikko
    JOURNAL OF MUSIC TECHNOLOGY & EDUCATION, 2012, 5 (02) : 159 - 170
  • [33] Open source tools for measuring the Internal Quality of Java']Java software products. A survey
    Tomas, P.
    Escalona, M. J.
    Mejias, M.
    COMPUTER STANDARDS & INTERFACES, 2013, 36 (01) : 244 - 255
  • [34] Poster: Communication in Open-Source Projects-End of the E-mail Era?
    Kaefer, Verena
    Graziotin, Daniel
    Bogicevic, Ivan
    Wagner, Stefan
    Ramadani, Jasmin
    PROCEEDINGS 2018 IEEE/ACM 40TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING - COMPANION (ICSE-COMPANION, 2018, : 242 - 243
  • [35] HelloArduBot: A DSL For Teaching Programming To Incoming Students With Open-source Robotic (OSR) Projects
    Slomski, Gustavo
    Rohling, Adair Jose
    Varela, Paulo
    Albonico, Michel
    PROCEEDINGS OF THE 18TH INTERNATIONAL SYMPOSIUM ON OPEN COLLABORATION, OPENSYM 2022, 2022,
  • [36] O3-RWS: a Java']Java-based, IHE-compliant open-source radiology workstation
    Faustini, G.
    Inchingolo, P.
    11TH MEDITERRANEAN CONFERENCE ON MEDICAL AND BIOLOGICAL ENGINEERING AND COMPUTING 2007, VOLS 1 AND 2, 2007, 16 (1-2): : 727 - +
  • [37] An Open-Source Tool-set for Meaningful Monitoring and Visualisation of Rural ICT Projects
    Gush, Kim
    2018 IST-AFRICA WEEK CONFERENCE (IST-AFRICA), 2018,
  • [38] Open-source projects as incubators of innovation: From niche phenomenon to integral part of the industry
    Schrape, Jan-Felix
    CONVERGENCE-THE INTERNATIONAL JOURNAL OF RESEARCH INTO NEW MEDIA TECHNOLOGIES, 2019, 25 (03): : 409 - 427
  • [39] O3-DPACS: a Java']Java-based, IHE compliant open-source data and image manager and archiver
    Beltrame, M.
    Bosazzi, P.
    Poli, A.
    Inchingolo, P.
    11TH MEDITERRANEAN CONFERENCE ON MEDICAL AND BIOLOGICAL ENGINEERING AND COMPUTING 2007, VOLS 1 AND 2, 2007, 16 (1-2): : 732 - +
  • [40] Adoption of Third-party Libraries in Mobile Apps: A Case Study on Open-source Android Applications
    Polese, Aidan
    Hassan, Safwat
    Tian, Yuan
    9TH IEEE/ACM INTERNATIONAL CONFERENCE ON MOBILE SOFTWARE ENGINEERING AND SYSTEMS, MOBILESOFT 2022, 2022, : 125 - 135