Transparency of SIM profiles for the consumer remote SIM provisioning protocol
| dc.contributor | Aalto-yliopisto | fi |
| dc.contributor | Aalto University | en |
| dc.contributor.author | Ahmed, Abu Shohel | en_US |
| dc.contributor.author | Thakur, Mukesh | en_US |
| dc.contributor.author | Paavolainen, Santeri | en_US |
| dc.contributor.author | Aura, Tuomas | en_US |
| dc.contributor.department | Department of Computer Science | en |
| dc.contributor.department | Department of Communications and Networking | en |
| dc.contributor.groupauthor | Network Security and Trust | en |
| dc.contributor.groupauthor | Professorship Aura Tuomas | en |
| dc.contributor.groupauthor | Helsinki Institute for Information Technology (HIIT) | en |
| dc.contributor.organization | Ericsson Oy | |
| dc.date.accessioned | 2021-02-02T09:12:09Z | |
| dc.date.available | 2021-02-02T09:12:09Z | |
| dc.date.issued | 2020-08-19 | en_US |
| dc.description | | openaire: EC/H2020/779984/EU//SOFIE Lataa oa-artikkeli, kun julkaistu. | |
| dc.description.abstract | In mobile communication, User Equipment (UE) authenticates a subscriber to a Mobile Network Operator (MNO) using credentials from the MNO specified SIM profile that is securely stored inside the SIM card. Traditionally, a change in a subscriber’s SIM profile, such as a change in a subscription, requires replacement of the physical SIM card. To address this shortcoming, the GSM Association (GSMA) has specified the consumer Remote SIM Provisioning (RSP) protocol. The protocol enables remote provisioning of SIM profiles from a server to SIM cards, also known as the embedded Universal Integrated Circuit Card (eUICC). In RSP, any GSMA-certified server is trusted by all eUICCs, and consequently any server can provision SIM profiles to all eUICCs, even those not originating from the MNO associated with the GSMA-certified RSP server. Consequently, an attacker, by compromising a server, can clone a genuine SIM profile and provision it to other eUICCs. To address this security problem, we present SIM Profile Transparency Protocol (SPTP) to detect malicious provisioning of SIM profiles. SPTP assures to the eUICC and the MNO that all SIM provisioning actions—both approved and unapproved—leave a permanent, non-repudiatable trail. We evaluate security guarantees provided by SPTP using a formal model, implement a prototype for SPTP, and evaluate the prototype against a set of practical requirements. | en |
| dc.description.version | Peer reviewed | en |
| dc.format.extent | 16 | |
| dc.format.mimetype | application/pdf | en_US |
| dc.identifier.citation | Ahmed, A S, Thakur, M, Paavolainen, S & Aura, T 2020, 'Transparency of SIM profiles for the consumer remote SIM provisioning protocol', Annals of Telecommunications - Annales des Telecommunications. https://doi.org/10.1007/s12243-020-00791-2 | en |
| dc.identifier.doi | 10.1007/s12243-020-00791-2 | en_US |
| dc.identifier.issn | 0003-4347 | |
| dc.identifier.issn | 1958-9395 | |
| dc.identifier.other | PURE UUID: dea60331-5ee2-491f-a5ac-cab9c1daae3a | en_US |
| dc.identifier.other | PURE ITEMURL: https://research.aalto.fi/en/publications/dea60331-5ee2-491f-a5ac-cab9c1daae3a | en_US |
| dc.identifier.other | PURE FILEURL: https://research.aalto.fi/files/55558677/Ahmed2020_Article_TransparencyOfSIMProfilesForTh.pdf | |
| dc.identifier.uri | https://aaltodoc.aalto.fi/handle/123456789/102606 | |
| dc.identifier.urn | URN:NBN:fi:aalto-202102021908 | |
| dc.language.iso | en | en |
| dc.publisher | Springer | |
| dc.relation | info:eu-repo/grantAgreement/EC/H2020/779984/EU//SOFIE Lataa oa-artikkeli, kun julkaistu. | en_US |
| dc.relation.fundinginfo | Open access funding provided by Aalto University. This work has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement no. 779984. | |
| dc.relation.ispartofseries | Annals of Telecommunications - Annales des Telecommunications | en |
| dc.rights | openAccess | en |
| dc.subject.keyword | Consumer RSP | en_US |
| dc.subject.keyword | eSIM security | en_US |
| dc.subject.keyword | SIM profile cloning | en_US |
| dc.subject.keyword | Transparency | en_US |
| dc.title | Transparency of SIM profiles for the consumer remote SIM provisioning protocol | en |
| dc.type | A1 Alkuperäisartikkeli tieteellisessä aikakauslehdessä | fi |
| dc.type.version | publishedVersion |