The Adoption Rate of Java']JavaCard Features by Certified Products and Open-Source Projects

被引:0
|
作者
Zaoral, Lukas [1 ]
Dufka, Antonin [2 ]
Svenda, Petr [2 ]
机构
[1] Red Hat, Raleigh, NC 27601 USA
[2] Masaryk Univ, Brno, Czech Republic
来源
SMART CARD RESEARCH AND ADVANCED APPLICATIONS, CARDIS 2023 | 2024年 / 14530卷
关键词
Smartcard; !text type='Java']Java[!/text]Card; Security certification; Open-source;
D O I
10.1007/978-3-031-54409-5_9
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
JavaCard is the most prevalent platform for cryptographic smartcards nowadays. Despite having more than 20 billion smartcards shipped with it and thirteen revisions since the JavaCard API specification was first published more than two decades ago, uptake of newly added features, cryptographic algorithms or their parameterizations, and systematic analysis of overall activity is missing. We fill this gap by mapping the activity of the JavaCard ecosystem from publicly available sources with a focus on 1) security certification documents available under Common Criteria and FIPS140 schemes and 2) activity and resources required by JavaCard applets released in an open-source domain (Paper supplementary materials, full results of analysis and open tools are available at https://crocs.fi.muni.cz/papers/cardis2023). The analysis performed on all certificates issued between the years 1997-2023 and on more than 200 public JavaCard applets shows that new features from JavaCard specification are adopted slowly, typically taking six or more years. Open-source applets utilize new features even later, likely due to the unavailability of recent performant smartcards in smaller quantities. Additionally, almost 70% of constants defined in JavaCard API specification are completely unused in open-source applets. The applet portability improves with recent cards, and transient memory requirements (scarce resource on smartcards) are typically small. While twenty or more products have been consistently certified every year since 2009, the open-source ecosystem became more active around 2013 but seemed to decline in the past two years. As a result, the whole smartcard ecosystem might be negatively impacted by limited exposure to new ideas and usage scenarios, serving only well-established domains and potentially harming its long-term competitiveness.
引用
收藏
页码:169 / 189
页数:21
相关论文
共 50 条
  • [41] Ecosystem-Level Determinants of Sustained Activity in Open-Source Projects: A Case Study of the PyPI Ecosystem
    Valiev, Marat
    Vasilescu, Bogdan
    Herbsleb, James
    ESEC/FSE'18: PROCEEDINGS OF THE 2018 26TH ACM JOINT MEETING ON EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING, 2018, : 644 - 655
  • [42] Open-Source Framework for Reduced-Complexity Multi-Rate HEVC Encoding
    Matheswaran, Aruna
    Karadugattu, Praveen Kumar
    Ramachandran, Pradeep
    Giladi, Alex
    Grois, Dan
    Venkatesan, Pooj A.
    Balk, Alex
    APPLICATIONS OF DIGITAL IMAGE PROCESSING XLIII, 2020, 11510
  • [43] "We do not appreciate being experimented on": Developer and researcher views on the ethics of experiments on open-source projects
    Feitelson, Dror G.
    JOURNAL OF SYSTEMS AND SOFTWARE, 2023, 204
  • [44] Wind turbine vibration management: An integrated analysis of existing solutions, products, and Open-source developments
    Machado, M. R.
    Dutkiewicz, M.
    ENERGY REPORTS, 2024, 11 : 3756 - 3791
  • [45] A review of open-source image analysis tools for mammalian cell culture: algorithms, features and implementations
    Malik, Hafizi
    Idris, Ahmad Syahrin
    Toha, Siti Fauziah
    Idris, Izyan Mohd
    Daud, Muhammad Fauzi
    Azmi, Nur Liyana
    PEERJ COMPUTER SCIENCE, 2023, 9
  • [46] Matching Skills, Past Collaboration, and Limited Competition: Modeling When Open-Source Projects A.ract Contributors
    Fang, Hongbo
    Herbsleb, James
    Vasilescu, Bogdan
    PROCEEDINGS OF THE 31ST ACM JOINT MEETING EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING, ESEC/FSE 2023, 2023, : 42 - 54
  • [47] A Densely-Deployed, High Sampling Rate, Open-Source Air Pollution Monitoring WSN
    Montrucchio, Bartolomeo
    Giusto, Edoardo
    Vakili, Mohammad Ghazi
    Quer, Stefano
    Ferrero, Renato
    Fornaro, Claudio
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2020, 69 (12) : 15786 - 15799
  • [48] Application note: An open-source Java']JavaScript library to simulate dairy cows and young stock, their growth, requirements and diets
    Vaillant, J.
    Baldinger, L.
    COMPUTERS AND ELECTRONICS IN AGRICULTURE, 2016, 120 : 7 - 9
  • [49] How the founders' social capital affects the success of open-source projects: A resource-based view of project teams
    Wang, Lu
    Huang, Minxue
    Liu, Maohong
    ELECTRONIC COMMERCE RESEARCH AND APPLICATIONS, 2018, 28 : 114 - 126
  • [50] Open-Source Physiological Computing Framework using Heart Rate Variability in Mobile Virtual Reality Applications
    Quintero, Luis
    Papapetrou, Panagiotis
    Munoz, John E.
    2019 IEEE INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND VIRTUAL REALITY (AIVR), 2019, : 126 - 133