@conference { ABDM09, title = {A tool for checking secure interaction in Java Cards}, booktitle = {Proceedings of the 12th European Workshop on Dependable Computing, EWDC 2009 12th European Workshop on Dependable Computing, EWDC 2009}, year = {2009}, month = {May}, pages = {8 pages}, address = {Toulouse, France}, abstract = {

We present an approach based on a multilevel security policy and the theory of abstract interpretation for checking secure interaction between applications in Java Cards. The security policy is defined by the user, which assigns security levels to Java Card applications. Actual values are abstracted into security levels, and an abstract interpreter executes the bytecode of applications in the abstract domain. We show JCSI, a tool that implements the presented approach. JCSI can be used to check the binary code of Java Card.

}, author = {Marco Avvenuti and Cinzia Bernardeschi and Nicoletta De Francesco and Paolo Masci}, editor = {H{\'e}l{\`e}ne Waeselynck} }