A Verifiable Conformance Relationship between Smart Card Applets and B security Models

Frédéric Dadeau 1 Julien Lamboley 2 Thierry Moutet 2 Marie-Laure Potet 2
1 CASSIS - Combination of approaches to the security of infinite states systems
FEMTO-ST - Franche-Comté Électronique Mécanique, Thermique et Optique - Sciences et Technologies (UMR 6174), INRIA Lorraine, LORIA - Laboratoire Lorrain de Recherche en Informatique et ses Applications
Abstract : We propose a formal framework based on the B method, that supports the development of secured smart card applications. Accordingly to the Common Criteria methodology, we start from a formal definition and modelling of security policies, as access control policies. At the end of the development process, smart card applications are implemented in a standardized way, based on both the life cycle of smart card applets and the APDU protocol. In this paper, we define a conformance relationship that aims at establishing how smart card applications can be related to security requirement models. This embraces both the notions of security conformance as well as traceability allowing to relate basic events appearing at the level of applications with abstract security policies. This approach has been developed in the RNTL POS´E project1, involving a smart card issuer, Gemalto.
Document type :
Conference papers
Complete list of metadatas

https://hal.inria.fr/inria-00329966
Contributor : Frédéric Dadeau <>
Submitted on : Monday, October 13, 2008 - 5:06:50 PM
Last modification on : Friday, July 6, 2018 - 3:06:09 PM

Identifiers

Citation

Frédéric Dadeau, Julien Lamboley, Thierry Moutet, Marie-Laure Potet. A Verifiable Conformance Relationship between Smart Card Applets and B security Models. First International Conference on ASM, B and Z - ABZ'08, Sep 2008, London, United Kingdom. pp.237-250, ⟨10.1007/978-3-540-87603-8⟩. ⟨inria-00329966⟩

Share

Metrics

Record views

330