发表机构
University of Sheffield; National University of Singapore; Pennsylvania State University(谢菲尔德大学; 新加坡国立大学; 宾夕法尼亚州立大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
ZK-eSIM利用零知识证明和一次性假名凭证,在保留可问责追溯的前提下,实现eSIM配置中的用户匿名与会话不可链接,仅增加实际开销。
AI 中文摘要
GSMA远程SIM配置(RSP)支持eSIM配置文件的空中传送,但在配置文件订购和下载过程中会暴露长期标识符。特别是,稳定的设备标识符(如EID)、配置文件标识符以及长期证书材料使移动运营商和配置文件交付基础设施能够将配置事件关联到同一eUICC,并且当与账户记录结合时,能够关联到同一用户。这破坏了用户匿名性并导致跨会话跟踪。我们提出ZK-eSIM,一种隐私保护的重设计,在保留可问责的例外追溯能力的同时,实现用户匿名性和配置会话的不可链接性。ZK-eSIM(i)用设备有效性和资格的零知识证明取代设备标识符的直接披露;(ii)通过短期、一次性假名凭证和每会话标识符强制会话不可链接性,以防止跨会话跟踪;(iii)通过联合授权的托管机制提供隐私保护的可问责追溯,使得任何单一实体都不能单方面对用户去匿名化。我们形式化了一个多实体、诚实但好奇的威胁模型,并在标准密码学假设下证明了用户匿名性和配置会话的不可链接性。我们在测试eUICC上实现了一个Java Card小程序,使用修改后的LPA和SM-DP+服务器在商用硬件上评估性能。我们的实验量化了相对于传统RSP的端到端密码学开销,确认ZK-eSIM仅增加实际可行的开销,在现有GSMA角色和接口内保持可部署性的同时,弥补了关键隐私缺口。
英文摘要
GSMA Remote SIM Provisioning (RSP) enables over-the-air delivery of eSIM profiles, but it exposes long-lived identifiers during profile ordering and download. In particular, stable device identifiers (e.g., EID), profile identifiers, and long-lived certificate material enable mobile operators and profile-delivery infrastructure to link provisioning events to the same eUICC and, when combined with account records, to the same subscriber. This undermines subscriber anonymity and enables cross-session tracking. We present ZK-eSIM, a privacy-preserving redesign that achieves subscriber anonymity and provisioning-session unlinkability while retaining accountable traceability by exception. ZK-eSIM (i) replaces direct disclosure of device identifiers with a zero-knowledge proof of device validity and eligibility; (ii) enforces session unlinkability through short-lived, one-time pseudonymous credentials and per-session identifiers to prevent cross-session tracking; and (iii) provides privacy-preserving accountable traceability through a jointly authorised escrow mechanism, so that no single entity can unilaterally deanonymise a user. We formalise a multi-entity, honest-but-curious threat model and prove subscriber anonymity and the unlinkability of provisioning sessions under standard cryptographic assumptions. We implement a Java Card applet on a test eUICC to evaluate performance on commodity hardware with a modified LPA and SM-DP+ server. Our experiments quantify end-to-end cryptographic overhead relative to conventional RSP, confirming that ZK-eSIM adds only practical overhead, closing a critical privacy gap while preserving deployability within existing GSMA roles and interfaces.
Comments22 Pages, Accepted into ACM CCS 2026