Overview
Explore the vulnerabilities in GSMA's embedded SIM card with remote provisioning (eUICC) in this 30-minute Black Hat conference talk. Delve into the security mechanisms of remote provisioning and uncover potential attacks that could hinder network operators from providing service. Learn about SIM card functionality, the evolution of embedded UICCs, and the role of subscription managers. Examine technical details, including profile container creation and the Error Unlink Protocol. Discover other potential attacks, GSMA's response, and preventive measures against SMS-based vulnerabilities. Gain valuable insights into the challenges facing the mobile-phone subscription model and the security implications of over-the-air installation of subscription data.
Syllabus
Introduction
Agenda
How SIM Cards Work
Problems With SIM Cards
Embedded UICC
Evolution
Subscription Manager
Technical Details
How It Works
Creating a Profile Container
Error Unlink Protocol
Error Unlink Protocol Simplified
Other Attacks
GSMA Response
Summary
What would prevent SMS
Taught by
Black Hat