SecureSIM: rethinking authentication and access control for SIM/eSIM
Jinghao Zhao, Boyan Ding, Yunqi Guo, Zhaowei Tan, Songwu Lu
Abstract
The SIM/eSIM card stores critical information for a mobile user to access the 4G/5G network. In this work, we uncover three vulnerabilities of the current SIM practice. We show that the PIN-based access control may expose the in-SIM data to an adversary through both hardware and software. Once exposed, such in-SIM information can be used to reconstruct various keys used for device authentication, data encryption, etc. They thus enable a number of attacks, including traffic eavesdropping, man-in-the-middle attack, impersonation, etc. The fundamental problem is that, the current SIM design does not offer proper authentication and fine-grained access control to hundreds of in-SIM files for various in-card applets and off-card units. We next propose a new solution that offers both authentication and fine-grained access control. Our implementation and evaluation have confirmed the viability of our proposal.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get b90f3f16-386e-4c8f-ad3f-309229a492abCited by top-tier papers5
- CellDAM: User-Space, Rootless Detection and Mitigation for 5G Data PlaneZhaowei Tan, Jinghao Zhao, Boyan Ding, Songwu LuNSDI 2023 · 13 citations
- SIMurai: Slicing Through the Complexity of SIM Card Security ResearchTomasz Piotr Lisowski, Merlin Chlosta, Jinjin Wang, Marius MuenchUSENIX Security 2024 · 10 citations
- SEED: a SIM-based solution to 5G failuresJinghao Zhao, Zhaowei Tan, Yifei Xu, Zhehui Zhang et al.SIGCOMM 2022 · 5 citations
- Invade the Walled Garden: Evaluating GTP Security in Cellular NetworksYiming Zhang, Tao Wan, Yaru Yang, Haixin Duan et al.S&P 2025
- eSIMplicity or eSIMplification? Privacy and Security Risks in the eSIM EcosystemMaryam Motallebighomi, Jason Veara, Evangelos Bitsikas, Aanjhan RanganathanUSENIX Security 2025
Related papers
- IMS is Not That Secure on Your 5G/4G PhonesJingwen Shi, Sihan Wang, Min-Yue Chen, Guan-Hua Tu et al.MobiCom 2024 · 5 citations
- IMP4GT: IMPersonation Attacks in 4G NeTworksDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperNDSS 2020
- Touching the Untouchables: Dynamic Security Analysis of the LTE Control PlaneHongil Kim, Jiho Lee, Eunkyu Lee, Yongdae KimS&P 2019 · 174 citations
- Trust Dies in Darkness: Shedding Light on Samsung's TrustZone Keymaster DesignAlon Shakevsky, Eyal Ronen, Avishai WoolUSENIX Security 2022
- ZK-eSIM: A Privacy-Centric Zero-Knowledge Approach for eSIM ProvisioningLiza Ahmad, Quan Shi, Joshua Haworth, Yilu Dong et al.CCS 2026
