Reversing Obfuscated Code of a Java Card Through Code Reconstruction
Abstract
In secure devices like Java Cards, several attacks have been developed to dump memory and reverse its contents, thereby gaining access to sensitive stored assets. Many manufacturers have proposed various countermeasures to protect this data from malicious code. Obfuscation is one of these techniques; it consists of converting part or all of the code into another form that is much harder to understand in order to make the reverse engineering of memory dumps more difficult. This conversion occurs instantly during downloading. In this paper, we propose an automatic approach to reverse engineer obfuscated intermediate bytecode based on a backtracking search algorithm. We then introduce heuristics to optimize the search process and accelerate convergence toward realistic solutions. We implement this approach in a prototype, and, to improve it, we integrate it into the Java Card Disassembler and Analyzer (JCDA) tool. We also explain the new tricks used by our tool to recover some secure assets. Our tool successfully reversed 92% of illegal opcodes and all secure assets.References
[1] Oracle (2023), Java Card™ Platform, Virtual Machine Specification, Classic Edition, ed., vol. 3.0.5 Classic, O. America, Ed.
[2] J. Gemalto (2006), Java Card and STK Applet Development Guidelines, Version 2.0, Gemalto.
[3] Oracle (2012), Java Card System - Open Configuration Protection Profile, Version 3.0, Oracle.
[4] EMVCo, LLC (2013) EMV Testing and Certification White Paper, Version 1.0, EMVCo, LLC, Aug. 2013. [Online]. Available:
http://www.emvconnection.com/downloads/2013/05/EM-Testing-Certification-V1.0-080213.pdf
[5] A. Mesbah, J.-L. Lanet, and M. Mezghiche (2019) Reverse engineering Java Card and vulnerability exploitation: a shortcut to
ROM, International Journal of Information Security, vol. 18, no. 3, pp. 367-385. DOI: https://doi.org/10.1007/s10207-018-0401-9
[6] S. Volokitin and E. Poll (2016), Logical attacks on secured containers of the Java Card platform, in Smart Card Research and Advanced Applications, Berlin.
[7] T. Razafindralambo, G. Bouffard, B. Thampi and J.L. Lanet (2012), A dynamic syntax interpretation for Java-based smart cards to mitigate logical attacks, in International Conference on Security in Computer Networks and Distributed Systems, Berlin, Allemagne. DOI:
https://doi.org/10.1007/978-3-642-35416-0-13
[8] A. Mosbah, L. Regnaud, j. L. Lanet and M. Mezguiche,(2016), The hell forgery, polymorphic codes shoot again, in 15th Smart Card
Research and Advanced Application Conference.
[9] A. Mesbah, J.-L. Lanet, and M. Mezghiche (2017), Reverse engineering a Java Card memory management algorithm, Comput-
ers and Security, vol. 66, pp. 97-114. DOI: https://doi.org/10.1016/j.cose.2017.01.005
[10] A. A. Azeta, A. Awal, J. I. Azeta, S. L. Hamunyela and A. d. Santos (2024), Designing a Code Obfuscation Scheme for Software Protection, International Conference on Electrical and Computer Engineering Researches (ICECER), Gaborone, Botswana, pp. 1-5, Doi:10.1109/ICE-CER62944.2024.10920373.
[11] Z. Massimiliano and R. Wolfgang (2014), A light-weight compression method for Java Card technology, in EWiLi’14, Lisbon, Portugal.
[12] Farhadi, M., Lanet, JL. (2017), Chronicle of a Java Card death, J Comput Virol Hack Tech 13, 109–123 (2017). DOI: https://doi.org/10.1007/s11416-016-0276-0
[13] J. Lancia (2012), ”Java Card combined attacks with localization-agnostic fault injection,” in International Conference on Smart Card Research and Advanced Applications.
[14] J. Iguchi-Cartigny, J., Lanet, JL. (2010) Developing a Trojan applets in a smart card, J Comput Virol 6, 343–351 (2010). DOI: https://doi.org/10.1007/s11416-009-0135-3
[15] DApro,”HexRays”,[Online].Available: http://www.datarescue.com/idabase/overview.html
[16] E. Hubbers, E. Poll (2004), Transactions and non-atomic API calls in Java Card: specification ambiguity and strange implementation
behaviors, University of Nijmegen.
[17] S. Hamadouche, J. L. Lanet and M. Mezguiche (2020), Hiding a fault-enabled virus through code construction, Journal of Computer Virology and Hacking Techniques. DOI:https:doi 10.1007/s11416-019-00340-z
[18] GLobalPlatform, Java Card Specification, (2006).
[19] C. Florence and G. Arnaud (2010), ”Constraint-based test input generation for Java bytecode, in 21st International Symposium on Software Reliability Engineering (ISSRE).
[20] J. Dubreuil and G. Bouffard (2021) ”PhiAttack: Rewriting the Java Card Class Hierarchy,” in Proceedings of the 20th International Conference on Smart Card Research and Advanced Application Design (CARDIS 2021), L¨ubeck, Germany.
21] E. Faugeron (2011), Manipulating the frame information with an underflow attack, in International Conference on Smart Card Re-
search and Advanced Applications.
[22] E. Faugeron and S. Valette (2010), How to hoax an off-card verifier, in e-smart.
[23] Lars Ræder Clausen, Ulrik Pagh Schultz, Charles Consel, and Gilles Muller (May 2000), Java bytecode compression for low-end embedded systems, ACM Trans. Program, Lang. Syst. 22, 3 (May 2000), 471–489. DOI: https://doi.org/10.1145/353926.353933
[24] G. Bouffard, J. Iguchi-Cartingny, and J.-L.Lanet (2011), Combined Software and Hardware Attacks on the Java Card Control flow,
in CARDIS, E. Prouff.
[25] Bizzotto , Grimaud. G. (2002). Practical Java Card bytecode compression. In Proceedings of RENPAR14/ASF/SYMPA (Citeseer).
[26] G. Bauffard and J. L. Lanet (2014), Reversing the operating system of a java based smart card, Comput. Virol. Hack. Tech, vol.
4, no. 239–253, p. 10.
[27] G. Barbu, On the security of Java Card platforms against hardware attack, Telecom ParisTech, sept. 2012.
[28] Leo Song, Steven H. H. Ding, Yuan Tian, LiTao Li, Weihan Ou, Philippe Charland, Andrew Walenstein (2025), Obfuscated Clone Search in JavaScript based on Reinforcement Subsequence Learning, ACM Transactions on Software Engineering and Methodology.
DOI:
https://doi.org/10.31449/inf.v50i15.14622Keywords:
Java Card security, Reverse Ingeneering, Obfuscated codeDownloads
Published
Issue
Section
License
Authors retain copyright in their work. By submitting to and publishing with Informatica, authors grant the publisher (Slovene Society Informatika) the non-exclusive right to publish, reproduce, and distribute the article and to identify itself as the original publisher.
All articles are published under the Creative Commons Attribution license CC BY 3.0. Under this license, others may share and adapt the work for any purpose, provided appropriate credit is given and changes (if any) are indicated.
Authors may deposit and share the submitted version, accepted manuscript, and published version, provided the original publication in Informatica is properly cited.







