摘要
Java卡3.0平台相较于2.x平台有巨大革新,尤其是其连接版,支持多线程、动态类加载、Web应用和垃圾回收机制等。但在带来更强大功能的同时,新特性也为攻击者提供更广的攻击面。文中将针对Java卡3.0平台,结合故障注入和逻辑篡改进行攻击以伪造引用,并以此分析研究其连接版新特性带来的安全隐患,最后将提出相应对策。
Compared with 2.x,Java card 3.0 experiences significant breakthroughs,particularly in its connected edition. This latest release offers myriads of new features such as multithreading,dynamic loading,web services,garbage collection and so on,and these al-so provide even broader attack dimension as well as advanced functionality. Aiming at Java card 3.0,attacks combined with fault injec-tion and logical tampering are fabricated and conducted. By so doing,the corresponding countermeasures are proposed,and the compre-hensive consideration of new threats brought by Java card 3.0 features.
出处
《信息安全与通信保密》
2014年第9期125-128,共4页
Information Security and Communications Privacy