Reversing Obfuscated Code of a Java Card Through Code Reconstruction

Abstract

In secure devices like Java Cards, several attacks have been developed to dump memory and reverse its contents, thereby gaining access to sensitive stored assets. Many manufacturers have proposed various countermeasures to protect this data from malicious code. Obfuscation is one of these techniques; it consists of converting part or all of the code into another form that is much harder to understand in order to make the reverse engineering of memory dumps more difficult. This conversion occurs instantly during downloading. In this paper, we propose an automatic approach to reverse engineer obfuscated intermediate bytecode based on a backtracking search algorithm. We then introduce heuristics to optimize the search process and accelerate convergence toward realistic solutions. We implement this approach in a prototype, and, to improve it, we integrate it into the Java Card Disassembler and Analyzer (JCDA) tool. We also explain the new tricks used by our tool to recover some secure assets. Our tool successfully reversed 92% of illegal opcodes and all secure assets.

References

[1] Oracle (2023), Java Card™ Platform, Virtual Machine Specification, Classic Edition, ed., vol. 3.0.5 Classic, O. America, Ed.

[2] J. Gemalto (2006), Java Card and STK Applet Development Guidelines, Version 2.0, Gemalto.

[3] Oracle (2012), Java Card System - Open Configuration Protection Profile, Version 3.0, Oracle.

[4] EMVCo, LLC (2013) EMV Testing and Certification White Paper, Version 1.0, EMVCo, LLC, Aug. 2013. [Online]. Available:

http://www.emvconnection.com/downloads/2013/05/EM-Testing-Certification-V1.0-080213.pdf

[5] A. Mesbah, J.-L. Lanet, and M. Mezghiche (2019) Reverse engineering Java Card and vulnerability exploitation: a shortcut to

ROM, International Journal of Information Security, vol. 18, no. 3, pp. 367-385. DOI: https://doi.org/10.1007/s10207-018-0401-9

[6] S. Volokitin and E. Poll (2016), Logical attacks on secured containers of the Java Card platform, in Smart Card Research and Advanced Applications, Berlin.

[7] T. Razafindralambo, G. Bouffard, B. Thampi and J.L. Lanet (2012), A dynamic syntax interpretation for Java-based smart cards to mitigate logical attacks, in International Conference on Security in Computer Networks and Distributed Systems, Berlin, Allemagne. DOI:

https://doi.org/10.1007/978-3-642-35416-0-13

[8] A. Mosbah, L. Regnaud, j. L. Lanet and M. Mezguiche,(2016), The hell forgery, polymorphic codes shoot again, in 15th Smart Card

Research and Advanced Application Conference.

[9] A. Mesbah, J.-L. Lanet, and M. Mezghiche (2017), Reverse engineering a Java Card memory management algorithm, Comput-

ers and Security, vol. 66, pp. 97-114. DOI: https://doi.org/10.1016/j.cose.2017.01.005

[10] A. A. Azeta, A. Awal, J. I. Azeta, S. L. Hamunyela and A. d. Santos (2024), Designing a Code Obfuscation Scheme for Software Protection, International Conference on Electrical and Computer Engineering Researches (ICECER), Gaborone, Botswana, pp. 1-5, Doi:10.1109/ICE-CER62944.2024.10920373.

[11] Z. Massimiliano and R. Wolfgang (2014), A light-weight compression method for Java Card technology, in EWiLi’14, Lisbon, Portugal.

[12] Farhadi, M., Lanet, JL. (2017), Chronicle of a Java Card death, J Comput Virol Hack Tech 13, 109–123 (2017). DOI: https://doi.org/10.1007/s11416-016-0276-0

[13] J. Lancia (2012), ”Java Card combined attacks with localization-agnostic fault injection,” in International Conference on Smart Card Research and Advanced Applications.

[14] J. Iguchi-Cartigny, J., Lanet, JL. (2010) Developing a Trojan applets in a smart card, J Comput Virol 6, 343–351 (2010). DOI: https://doi.org/10.1007/s11416-009-0135-3

[15] DApro,”HexRays”,[Online].Available: http://www.datarescue.com/idabase/overview.html

[16] E. Hubbers, E. Poll (2004), Transactions and non-atomic API calls in Java Card: specification ambiguity and strange implementation

behaviors, University of Nijmegen.

[17] S. Hamadouche, J. L. Lanet and M. Mezguiche (2020), Hiding a fault-enabled virus through code construction, Journal of Computer Virology and Hacking Techniques. DOI:https:doi 10.1007/s11416-019-00340-z

[18] GLobalPlatform, Java Card Specification, (2006).

[19] C. Florence and G. Arnaud (2010), ”Constraint-based test input generation for Java bytecode, in 21st International Symposium on Software Reliability Engineering (ISSRE).

[20] J. Dubreuil and G. Bouffard (2021) ”PhiAttack: Rewriting the Java Card Class Hierarchy,” in Proceedings of the 20th International Conference on Smart Card Research and Advanced Application Design (CARDIS 2021), L¨ubeck, Germany.

21] E. Faugeron (2011), Manipulating the frame information with an underflow attack, in International Conference on Smart Card Re-

search and Advanced Applications.

[22] E. Faugeron and S. Valette (2010), How to hoax an off-card verifier, in e-smart.

[23] Lars Ræder Clausen, Ulrik Pagh Schultz, Charles Consel, and Gilles Muller (May 2000), Java bytecode compression for low-end embedded systems, ACM Trans. Program, Lang. Syst. 22, 3 (May 2000), 471–489. DOI: https://doi.org/10.1145/353926.353933

[24] G. Bouffard, J. Iguchi-Cartingny, and J.-L.Lanet (2011), Combined Software and Hardware Attacks on the Java Card Control flow,

in CARDIS, E. Prouff.

[25] Bizzotto , Grimaud. G. (2002). Practical Java Card bytecode compression. In Proceedings of RENPAR14/ASF/SYMPA (Citeseer).

[26] G. Bauffard and J. L. Lanet (2014), Reversing the operating system of a java based smart card, Comput. Virol. Hack. Tech, vol.

4, no. 239–253, p. 10.

[27] G. Barbu, On the security of Java Card platforms against hardware attack, Telecom ParisTech, sept. 2012.

[28] Leo Song, Steven H. H. Ding, Yuan Tian, LiTao Li, Weihan Ou, Philippe Charland, Andrew Walenstein (2025), Obfuscated Clone Search in JavaScript based on Reinforcement Subsequence Learning, ACM Transactions on Software Engineering and Methodology.

Authors

  • Yasmina Berrou University of Batna 2 image/svg+xml
  • Mohamed Benmohamed Laboratoire d’Informatique R´epartie (LIRE), University of Constantine 2, Algeria
  • Fatima Bourabaa Laboratoire d’Informatique R´epartie (LIRE), University of Constantine 2, Algeria
  • Billel Kenidra Laboratoire d’Informatique R´epartie (LIRE), University of Constantine 2, Algeria
  • Mohamed Badeche Laboratoire d’Informatique R´epartie (LIRE), University of Constantine 2, Algeria

DOI:

https://doi.org/10.31449/inf.v50i15.14622

Keywords:

Java Card security, Reverse Ingeneering, Obfuscated code

Downloads

Published

09/25/2026

How to Cite

Berrou, Y., Benmohamed, M., Bourabaa, F., Kenidra, B., & Badeche, M. (2026). Reversing Obfuscated Code of a Java Card Through Code Reconstruction. Informatica, 50(15). https://doi.org/10.31449/inf.v50i15.14622