科研速览 · Science Skim继续刷下去 · Keep skimming →
◆ Alexandria Engineering Journal2026-01-01· Computer science

Revisiting the M2M remote SIM provisioning protocol: A comprehensive security and performance analysis

Yongho Ko, Jhury Kevin Lastre, Hoseok Kwon, Ilsun You

原始摘要(英文原文)· Original abstract
The Remote SIM Provisioning (RSP) protocol, standardized by the Global System for Mobile Communications Association (GSMA), facilitates the secure download of Subscriber Identity Module (SIM) profiles onto device equipment and is widely recognized under the term embedded-SIM (eSIM). By enabling greater physical flexibility, RSP replaces traditional Universal SIM (USIM) cards and supports automated profile provisioning in Machine-to-Machine (M2M) scenarios. Through these benefits, the technology is increasingly regarded as a key enabler in emerging private 5G network environments. Since the SIM profile includes credentials required for authentication, ensuring the security, performance, and effectiveness of the RSP protocol is of paramount importance, particularly as M2M deployments must balance cryptographic robustness with computational efficiency. While Ahmed et al. have conducted formal verification of the Consumer RSP variant, their studies were confined to foundational analyses and did not consider performance-related aspects. Moreover, to the best of our knowledge, no formal security analysis or performance evaluation has been conducted on the M2M RSP protocol, despite its growing relevance in industrial environments. In this paper, we present the first integrated analysis of the M2M RSP protocol that combines formal security verification and implementation-based performance evaluation. Using ProVerif under the Dolev–Yao model, we uncover critical vulnerabilities, most notably the absence of Perfect Forward Secrecy (PFS), and show how reliance on intermediaries such as the SM-SR can enable man-in-the-middle attacks. Complementary performance modeling demonstrates predictable memory scaling but volatile CPU utilization during cryptographic operations, highlighting the tight coupling between security weaknesses and computational inefficiency. Based on these findings, we introduce concrete enhancements, including (i) replacing TLS 1.2 with TLS 1.3 to reduce handshake latency, (ii) migrating from symmetric SCP03t to asymmetric SCP11b for stronger key establishment, and (iii) incorporating hybrid post-quantum key agreement schemes to ensure long-term resilience. These proposals directly address the identified vulnerabilities while providing pathways to improved scalability and efficiency in future large-scale M2M deployments.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

Revisiting the M2M remote SIM provisioning protocol: A comprehensive security and performance analysis — 科研速览 Science Skim