Activating mobile agents from contactless smart cards through a Java bytecode extractor
Jonathan L. C. Lee, Shin-Jie Lee, Hsi‐Min Chen, Jeremy Liang, Chia-Ling Wu, Yao-Chiang Wang
Abstract
Jonathan L. C. Lee, Shin-Jie Lee, Hsi‐Min Chen, Jeremy Liang, Chia-Ling Wu, Yao-Chiang Wang
Abstract
As mobile agents reside on on-board units or mobile devices and act on behalf of drivers, it imposes a strong demand to devise mechanisms for protecting the algorithms that are exclusively coded in mobile agents for different drivers. Although contactless smart cards are widely used as a means to protecting personal information, it is still a challenge to protect the whole code of a mobile agent in a limited storage. In this paper, we propose a tool, called jExtractor, by which the private or sensitive data coded in a Java-based mobile agent can be extracted and moved to a contactless smart card, and can further be read from the card and merged to be the original mobile agent. Moreover, we use 30,000 Java classes as samples to validate jExtractor. In the experimental result, 79.4% of the sample classes can successfully be extracted and moved to Mifare Standard S50 (1K) smart card with our strictest configuration level.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
As mobile agents reside on on-board units or mobile devices and act on behalf of drivers, it imposes a strong demand to devise mechanisms for protecting the algorithms that are exclusively coded in mobile agents for different drivers. Although contactless smart cards are widely used as a means to protecting personal information, it is still a challenge to protect the whole code of a mobile agent in a limited storage. In this paper, we propose a tool, called jExtractor, by which the private or sensitive data coded in a Java-based mobile agent can be extracted and moved to a contactless smart card, and can further be read from the card and merged to be the original mobile agent. Moreover, we use 30,000 Java classes as samples to validate jExtractor. In the experimental result, 79.4% of the sample classes can successfully be extracted and moved to Mifare Standard S50 (1K) smart card with our strictest configuration level.
Key concepts: Bytecode, Java Card, Computer science, Smart card application protocol data unit, Smart card, Java, Open Smart Card Development Platform, OpenPGP card