首页> 外文期刊>Annals of telecommunications >Transparency of SIM profiles for the consumer remote SIM provisioning protocol
【24h】

Transparency of SIM profiles for the consumer remote SIM provisioning protocol

机译:消费者远程SIM SIM配置协议的SIM简档的透明度

获取原文
获取原文并翻译 | 示例
           

摘要

In mobile communication, User Equipment (UE) authenticates a subscriber to a Mobile Network Operator (MNO) using credentials from the MNO specified SIM profile that is securely stored inside the SIM card. Traditionally, a change in a subscriber's SIM profile, such as a change in a subscription, requires replacement of the physical SIM card. To address this shortcoming, the GSM Association (GSMA) has specified the consumer Remote SIM Provisioning (RSP) protocol. The protocol enables remote provisioning of SIM profiles from a server to SIM cards, also known as the embedded Universal Integrated Circuit Card (eUICC). In RSP, any GSMA-certified server is trusted by all eUICCs, and consequently any server can provision SIM profiles to all eUICCs, even those not originating from the MNO associated with the GSMA-certified RSP server. Consequently, an attacker, by compromising a server, can clone a genuine SIM profile and provision it to other eUICCs. To address this security problem, we present SIM Profile Transparency Protocol (SPTP) to detect malicious provisioning of SIM profiles. SPTP assures to the eUICC and the MNO that all SIM provisioning actions-both approved and unapproved-leave a permanent, non-repudiatable trail. We evaluate security guarantees provided by SPTP using a formal model, implement a prototype for SPTP, and evaluate the prototype against a set of practical requirements.
机译:在移动通信中,用户设备(UE)使用来自SIM卡内的MNO指定的SIM配置文件的凭证对移动网络运营商(MNO)验证到移动网络运营商(MNO)。传统上,订户的SIM简档的变化,例如订阅的变化,需要更换物理SIM卡。为了解决此缺点,GSM关联(GSMA)指定了消费者远程SIM配置(RSP)协议。协议使远程从服务器远程配置SIM配置文件到SIM卡,也称为嵌入式通用集成电路卡(EUICC)。在RSP中,所有euiccs都信任任何GSMA认证服务器,因此任何服务器都可以向所有euicc提供SIM配置文件,即使是那些未源自与GSMA认证的RSP服务器相关联的MNO。因此,攻击者通过妥协服务器,可以克隆真正的SIM卡配置文件并将其提供给其他EUICC。为了解决此安全问题,我们呈现SIM配置透明度协议(SPTP)以检测SIM配置文件的恶意配置。 SPTP向EUICC和MNO确保所有SIM拨款行动 - 批准和未经批准 - 留下永久性,不允许的小径。我们使用正式模型评估SPTP提供的安全保证,实现SPTP的原型,并根据一组实际要求评估原型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号