On the implementation of cryptographic algorithms in Java
Rui Miguel da Silva, Abreu, José Bacelar Almeida · 2008
Cryptography software has a critical nature because any failure can compromise the system’s security. Therefore, its implementation must follow strict rules. These rules are defined by cryptography standards, which must serve as guidelines to programmers that implement the algorithms in the different programming languages. The emergence of Java as one of the most popular programming languages makes it a natural choice for encoding cryptographic algorithms. The aim of this thesis is to analyse that particular use of Java. More concretely, we are interested in the following perspectives: • functional correctnessjudge how close actual implementations are with respect to funcional descriptions made available by cryptography standards. • efficiency considerationsthe appropriateness of pure Java implementations for computationally demanding cryptographic techniques, such as those based in elliptic curves over finite fields. This work evaluates selected cryptographic algorithms from publicly available libraries. Their implementations were matched against relevant cryptography standards and efficiency compared with state-of-art C++ implementations. A solution based on extending JVM with selected operations was proposed and tested to obviate Java efficiency limitations. Applications Areas: Cryptography.