Section: Bilateral Contracts and Grants with Industry

Bilateral Project with FIME

Participants : Thomas Jensen, Frédéric Besson, David Pichardie, Delphine Demange, Pierre Vittet.

Static program analysis, Javacard, Certification, AFSCM

The FIME contract consists in an industrial transfer of the Sawja platform 5.2 adapted to analyse Javacard programs according to AFSCM (Association Française du Sans Contact Mobile) security guidelines. The rules specify syntactic constraints but also more semantics properties such as the absence of certain runtime exceptions. FIME aims at automating the process of validating that Javacard applications are conformant to the rules. The outcome of the project is the Jacal (JAvaCard AnaLyser) ( 5.3 which takes a binary Javacard application; performs static analysis and output statuses for the different rules. Pierre Vittet has recently been recruited by FIME and the operational deployment of Jacal is in progress.