ZK-eSIM: A Privacy-Centric Zero-Knowledge Approach for eSIM Provisioning
Liza Ahmad, Quan Shi, Joshua Haworth, Yilu Dong, Prosanta Gope, Behzad Abdolmaleki, Syed Rafiul Hussain
摘要
GSMA Remote SIM Provisioning (RSP) enables over-the-air delivery of eSIM profiles, but it exposes long-lived identifiers during profile ordering and download. In particular, stable device identifiers (e.g., EID), profile identifiers, and long-lived certificate material enable mobile operators and profile-delivery infrastructure to link provisioning events to the same eUICC and, when combined with account records, to the same subscriber. This undermines subscriber anonymity and enables cross-session tracking. We present ZK-eSIM, a privacy-preserving redesign that achieves subscriber anonymity and provisioning-session unlinkability while retaining accountable traceability by exception. ZK-eSIM (i) replaces direct disclosure of device identifiers with a zero-knowledge proof of device validity and eligibility; (ii) enforces session unlinkability through short-lived, one-time pseudonymous credentials and per-session identifiers to prevent cross-session tracking; and (iii) provides privacy-preserving accountable traceability through a jointly authorised escrow mechanism, so that no single entity can unilaterally deanonymise a user. We formalise a multi-entity, honest-but-curious threat model and prove subscriber anonymity and the unlinkability of provisioning sessions under standard cryptographic assumptions. We implement a Java Card applet on a test eUICC to evaluate performance on commodity hardware with a modified LPA and SM-DP+ server. Our experiments quantify end-to-end cryptographic overhead relative to conventional RSP, confirming that ZK-eSIM adds only practical overhead, closing a critical privacy gap while preserving deployability within existing GSMA roles and interfaces.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic 等CCS 2018 · 被引用 428 次
- Sonic: Zero-Knowledge SNARKs from Linear-Size Universal and Updatable Structured Reference StringsMary Maller, Sean Bowe, Markulf Kohlweiss, Sarah MeiklejohnCCS 2019 · 被引用 412 次
- Pretty Good Phone PrivacyPaul Schmitt, Barath RaghavanUSENIX Security 2021 · 被引用 24 次
- LOCA: A Location-Oblivious Cellular ArchitectureZhihong Luo, Silvery Fu, Natacha Crooks, Shaddi Hasan 等NSDI 2023
- PGUS: Pretty Good User Security for Thick MVNOs with a Novel Sanitizable Blind SignatureYang Yang, Quan Shi, Prosanta Gope, Behzad Abdolmaleki 等S&P 2025
相关 Paper
- eSIMplicity or eSIMplification? Privacy and Security Risks in the eSIM EcosystemMaryam Motallebighomi, Jason Veara, Evangelos Bitsikas, Aanjhan RanganathanUSENIX Security 2025
- Privacy-Preserving and Standard-Compatible AKA Protocol for 5GYuchen Wang, Zhenfeng Zhang, Yongquan XieUSENIX Security 2021 · 被引用 58 次
- SecureSIM: rethinking authentication and access control for SIM/eSIMJinghao Zhao, Boyan Ding, Yunqi Guo, Zhaowei Tan 等MobiCom 2021 · 被引用 18 次
- Device-Bound Anonymous Credentials With(out) Trusted HardwareKarla Friedrichs, Franklin Harding, Anja Lehmann, Anna LysyanskayaEUROCRYPT 2026 · 被引用 1 次
- AAKA: An Anti-Tracking Cellular Authentication Scheme Leveraging Anonymous CredentialsHexuan Yu, Changlai Du, Yang Xiao, Angelos D. Keromytis 等NDSS 2024
