PowerBI Data Analyst - Create visualizations and dashboards from scratch
Get 20% off all career paths from fullstack to AI
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
This conference talk explores vulnerabilities in the consumer Remote SIM Provisioning (RSP) protocol that enables eSIM downloads to mobile devices. Discover how the GSMA-defined protocol works for downloading SIM profiles to secure elements in phones, and understand the critical security implications for mobile authentication and communication. Learn about the formal methods analysis that revealed several security weaknesses, including over-reliance on TLS encapsulation, problematic trust assumptions regarding download servers, and security risks from compromised secure elements in mobile devices. Examine how the lack of pre-established identifiers contributes to these vulnerabilities and how insufficient verification of user intent can lead to SIM swapping-like attacks. The presenters, Dr. Abu Shohel Ahmed and Professor Tuomas Aura from Aalto University, offer practical solutions for mitigating these vulnerabilities in current eSIM deployments and suggest protocol improvements for enhanced security.
Syllabus
Vulnerabilities in the eSIM download protocol
Taught by
Black Hat