Showing posts with label UICC. Show all posts
Showing posts with label UICC. Show all posts

Friday, December 06, 2019

eSIM - Observing Possible Outcomes Part 1

Back in 2012 I wrote about the introduction of a new form factor for SIM Cards (4FF). The outline and a potted history of SIM Card form factors were illustrated and in a separate post the first ETSI standard defining this new form factor (4FF) - (R1) and (R2).

Seven years down the line in (2019) ARM Limited produced a useful graphics of where eSIM is placed in the evolutionary chain of form factors - (R3).



eSIM has already established a presence in the digital tech marketplace. SIMalliance published SIM Market Insights in June 2019 giving the following stats '2018 Shipment Volumes (SIM Units)'. Here again it is easier to show the graphics than simply record word-for-word the stats - (R4).


Recorded in in Arm's presentation are more stats 4.4 billion cellular devices by 2025 – Source: Machina 2017; $1.8 trillion operator revenue opportunity for LPWAN by 2026 – Source: GSMA 2017 to support the vision of eSIMs integration into future devices and market size - (R3).

There are, of course, numerous market reports predicting how eSIM will fair in the marketplace; this blog post is giving a potted history just to bring the discussion up to speed.

Specifications and standards for eSIM/eUICC are available from 3GPP, GSMA and SIMalliance. These will be discussed in another Part to this blog discussion. For now, what is required to know is how eSIM will actual operate in practice. The SIMalliance produced a helpful graphic (R4) showing eSIM profile (a package), delivered to a physical product (eUICC), when deployed in the field. So let us look at that first.
For the download (update) system architecture to work requires both network and device to operate and function according to the Remote SIM Provisioning Service (RSP) Architecture'. This has been designed into the RSP Architecture. The following graphics helpfully illustrate two important element: the network side and the device side (eUICC) - (R5).


Once the eUICC has been deployed in the field [it], when inserted into a compatible smartphone, will be able to download one or more mobile operator profiles and then subscribed services. An eSIM user can then switch between operator profiles or download profiles and services on the fly - time, place and location, and so on. This enables the eSIM/eUICC to excel in connectivity. This approach to connectivity is exciting and yet remarkable, for logically the SIM Card issued previously was issued and controlled by the subscriber's mobile operator. eSIM/eUICC in essence removes sovereignty which was jealously guarded by each operator prior to the intro of this technology handover. That is even to the extent where virtual mobile operators (VMOs) only functioned based upon piggy-backing off primary operators' core network but issued their own SIM Cards.

It should be understood that the envisaged usage for eSIM focussed on M2M, so candidates would be industry devices, automobiles, metering and so on. But the concept of eSIM has recently engaged operators and handset manufacturers to look at how 5G can help with profiling and service downloads. Recently, GSMA ran seminars with hands-on training for eSIM profiling and services download, which apparently was very successful.

Moreover, Samsung, Google and Apple have devices with eSIM capability.Android framework provides standard APIs for accessing eSIM and managing subscription profiles on the eSIM (Android 9). Importantly, Devices running Android 10 or higher can support devices with multiple eSIMs. So these factors alone are investigative elements for cyber security oversight, pentesters and forensic examiners to be aware.

In Part 2 the discussion will refine and define observations that have been generally stated in this post; examine more closely eSIM and eUICC aspects and then more in Parts 3 and 4 looking at potential implications for cyber security, law enforcement, forensic examiners and ICT specialists.

REFERENCES
(R1) SIM Card new 4FF form factor size - https://trewmte.blogspot.com/2012/06/sim-card-new-4ff-form-factor-size.html
(R2) ETSI release details of new 4FF UICC  - https://trewmte.blogspot.com/2012/06/etsi-release-details-of-new-4ff-uicc.html
(R3) The Challenges Deploying IoT eSIM M2M enabling Secure Communications Scaled for 1 trillion devices. Jean-Philippe Betoin Marketing Director, Secure Identity Confidential © 2019 Arm Limited.
(R4) SIMs, eSIMs and Secure Elements: Providing a roadmap to dynamic security and flexible control for connected devices. Remy Cricco Chair of the Board, SIMalliance ETSI Security Week June 2019.
(R5) GSMA SGP.21 - RSP Architecture, V2.2, 1 Sep 2017

Sunday, October 06, 2013

(U)ICC/(U)SIM Script Commands and Responses

(U)ICC/(U)SIM Script Commands and Responses

The discussion under (U)ICC/(U)SIM Script Commands and Responses is one of a number that will appear to assist Diploma students with their course work.

http://sim2usim.blogspot.co.uk/2013/10/uiccusim-script-commands-and-responses.html

(U)ICC/(U)SIM Script Commands and Responses

(U)ICC/(U)SIM 3F00 7F10 6F4A

3GPP UICC/USIM script selecting Master File, Dedicated File and Elementary File





















GSM ICC/SIM script selecting Master File, Dedicated File and Elementary File






























Reason for script test : defining an examination procedure to isolate and test a single elementary file; determine the EF's status, file structure, coding etc; conrroborate the ability of the (U)ICC/(U)SIM to action responses from commands sent to card; provide corroborating evidence of commands sent to the card to demonstrate evidential integrity (transparency of practices and procedures); testing the examination card reader is functioning correctly; QA procedures. 

Script examination tool used : USIM Commander - http://www.quantaq.com/usimcommander.htm

Relevant Core Diplomas:-

Aims : MTEB Diploma for Mobile Evidence QA and Evidence Handling - Mobile Telephone Diploma Core CQAE1

Objectives : Device Maintenance and Calibration; Examination Procedure

Aims :  MTEB Diploma for SIM and USIM Technology Examination - Mobile Telephone
Diploma Core CSUT2

Objectives : Your understanding of roles and responsibilities and the importance of
appropriate practices and procedures for SIM and USIM Technology
Examination for acquiring evidence.

Reference Standards :
GSM11.11/3GPP TS51.011/3GPP TS31.102,
GSM11.12,
GSM11.17/3GPP TS51.017/3GPP TS31.120/3GPP TS31.121/3GPP TS31.122,
GSM11.18/3GPP31.101,

EU MTEB Diploma Student Note : Remember to check with ETSI Standards e.g. TS102.221 etc

US MTEB Diploma Student Note : Diploma Students remember to check e.g. C.S0065-0 v1.0, C.S0074-0 v1.0, C.S0074-A v1.0, N.S0009-0 v1.0, S.R0095-0 v1.0 etc

Generically speaking, apart from GSMA and 3GPP, there is also 3GPP2 which also includes ARIB, CCSA, TIA TTA, TTC that all have conditions that can impact/influence results on (U)ICC/(U)SIM.

The discussion under (U)ICC/(U)SIM Script Commands and Responses is one of a number that will appear here to assist Diploma students with their course work.

The latest MTEB Diploma Modules Guide MTEdipl 2.2 can be downloaded here:
https://dl.dropboxusercontent.com/u/84491783/MTEdipl%202.2.pdf


Saturday, September 14, 2013

Blocked SIM

A regular question that arises, "is it possible to bypass a PIN blocked SIM card?"

For a quick solution it is best to go to the operator to obtain a PUK code where there has been 3 CHV1 attempts and access is now blocked.

If it is 10 CHV1 attempts and blocked ([unless you know and have the test tools to e.g. slow the card]) then the operator may request that you send it to them and they in turn (depending upon their security level) may need to send it to the (U)ICC producer / manufacturer.

Today's UICC (using improved silicon and security techniques) have significant security improvements within each operator's card where there are various levels of electronic counter-measures (traps doors/dead-man's trap etc). Many of us (including me) simply cannot access certain areas of the UICC unless a flaw in the security is discovered. Unless you are confident of what you know and what you are doing, my observation is take the safest route.


None of the opinions I express originate based upon my gut feeling about a particular matter. I research, like others, to establish the industry security protocols, practices and procedures and then consider the position from there. It is important to bare in mind that forensics and evidence is not about hacking everything in sight or writing a program to extract data but to be aware and comprehend how industry standard bodies intended security should be implement, which norms the manufacturer and operator follow and whether following implementation security flaws occur.


sim2usim


Examination and Evidence from SIM and USIM Cards. Now an open blog. 

http://sim2usim.blogspot.co.uk/


(U)SIM Examination (Physical) Pt2

(U)SIM Examination (Physical) Pt2

Before we can progress to consider various methods of (U)SIM physical examination there are more standards we need to be aware and there are reasons for that. Transitioning from GSM to 3GPP (*wcdma) standards required rewriting existing GSM standards to make the standards technology neutral to integrate GSM into future mobile developments under 3GPP global standards. Technology-wise, we know that GSM is a defined circuit-switched voice mobile communications system that has evolved with value-added data services (GPRS, HSCSD and EDGE). 3GPP (wcdma) as we know is a defined packet-switched technology and thus would be a pointless exercise to re-invent the wheel, so to speak, and introduce a new voice circuit-switched system and the matured installation base that went with it. That needs to be understood on many levels when dealing with mobile communications. Three examples of GSM and 3GPP working together:

(i) generally, we refer to Release 99 (R99) as a reference point whereby 3GPP could transition and re-write mobile communication technology standards with birthing-periods: GSM only before 3GPP Release 4 (Rel-4); GSM only (Rel-4 and later); 3GPP and beyond / GSM (R99 and later).  This enabled manufacturers, developers and operators and service providers to conintue with GSM standards in a pure GSM environment or evolve to a 3GPP environment but in the knowledge access and inter-connectivity to GSM would continue:

(ii) introduction of 3GPP (*wcdma) would take time and thus should avoid, as best possible, disruption to existing moble services;

(iii) GSM user/subscriber base was still growing at that time and has now reached over 3-billion users, from which we can draw a conclusion that GSM's importance in its relationship with 3GPP should not be under-estimated.GSM is by no means the junior partner.

In the mobile examination environment, we, as examiners, are exposed to multitude and multiple-layers of technical and technology standards many of which impact on (U)SIM, and particuarly so if the technical and technology generates a mobile communication outcome associated to/with a user/subscriber. 

(*) wcdma is one of a family of mobile technology standards under 3GPP and has been used for easy of reference. 

The scope of the tests and the requirements set down in GSM1117 were reproduced under the approved and adopted standard 3GPP TS51.017. In Pt1( usim-examination-physical-pt1.html ) reference was made to GSM11.11, however the approved and adopted standard (and the counterpart to GSM11.11) is 3GPP TS51.011:

PHY:    Physical characteristics - 3GPP TS 51.011 [1], clause 4.
ELEC:    Electronic signals and transmission protocols - 3GPP TS 51.011 [1], clause 5.
AFS:    Application and File structure - 3GPP TS 51.011 [1], clause 6.
SEC:    Security features - 3GPP TS 51.011 [1], clause 7.
CMD:    Description of the commands - 3GPP TS 51.011 [1], clause 9.
CEF:    Contents of the elementary files - 3GPP TS 51.011 [1], clause 10.
APP:    Application Protocol - 3GPP TS 51.011 [1], clause 11.

Whilst GSM11.17 standard is the starting point for ICC/SIM and 3GPP TS51.011 moved the technology to neutral ground to enable 3GPP to evolve 3G environment standards incorportating interconnectivity to and backward compatibility for ICC/UICC, the 3GPP evolution hasn't stopped there. There is, of course, 3GPP TS 31.120 the aim of which is to ensure interoperability between an UICC and a Terminal independently of the respective manufacturer, card issuer or operator. This is the expansion of the 3GPP domain going beyond specific limitations encumbent with a particular proprietory technology.

The run of standards doesn't end there. Attention and consideration should be given to:

ETSI standards
TS 102 230
TS 102 221

International standards
ISO/IEC 7816-pt1 to pt4

The standards referred to above are merely a starting point to identify the complexities involved in dealing with (U)SIM card and tasks involved in considering examination techniques that may not simply relate to recovery of data but other aspects and attributes of a card which may point to evidence. Readers should be prepared to delve into the standards above and release the huge number that haven't been mentioned. There are various analogies that may be used to imagine what I have in mind for this physical series, but I quite like the analogy about forensic vehicle tyre analysis. Evidentially, consideration is given to tyre size, tread, pressure, rubber, moulding, any wheel balacing and so on to assess a skid mark or tracks at the scene of a crime. It is equally possible to use an investigative and examination approach to SIM/USIM card materials, contacts, gold content, embossing etc to identify potential evidence.

Monday, May 06, 2013

(U)SIM Examination (Physical) Pt2

(U)SIM Examination (Physical) Pt2

Before we can progress to consider various methods of (U)SIM physical examination there are more standards we need to be aware and there are reasons for that. Transitioning from GSM to 3GPP (*wcdma) standards required rewriting existing GSM standards to make the standards technology neutral to integrate GSM into future mobile developments under 3GPP global standards. Technology-wise, we know that GSM is a defined circuit-switched voice mobile communications system that has evolved with value-added data services (GPRS, HSCSD and EDGE). 3GPP (wcdma) as we know is a defined packet-switched technology and thus would be a pointless exercise to re-invent the wheel, so to speak, and introduce a new voice circuit-switched system and the matured installation base that went with it. That needs to be understood on many levels when dealing with mobile communications. Three examples of GSM and 3GPP working together:

(i) generally, we refer to Release 99 (R99) as a reference point whereby 3GPP could transition and re-write mobile communication technology standards with birthing-periods: GSM only before 3GPP Release 4 (Rel-4); GSM only (Rel-4 and later); 3GPP and beyond / GSM (R99 and later).  This enabled manufacturers, developers and operators and service providers to conintue with GSM standards in a pure GSM environment or evolve to a 3GPP environment but in the knowledge access and inter-connectivity to GSM would continue:

(ii) introduction of 3GPP (*wcdma) would take time and thus should avoid, as best possible, disruption to existing moble services;

(iii) GSM user/subscriber base was still growing at that time and has now reached over 3-billion users, from which we can draw a conclusion that GSM's importance in its relationship with 3GPP should not be under-estimated.GSM is by no means the junior partner.

In the mobile examination environment, we, as examiners, are exposed to multitude and multiple-layers of technical and technology standards many of which impact on (U)SIM, and particuarly so if the technical and technology generates a mobile communication outcome associated to/with a user/subscriber. 

(*) wcdma is one of a family of mobile technology standards under 3GPP and has been used for easy of reference. 

The scope of the tests and the requirements set down in GSM1117 were reproduced under the approved and adopted standard 3GPP TS51.017. In Pt1( usim-examination-physical-pt1.html ) reference was made to GSM11.11, however the approved and adopted standard (and the counterpart to GSM11.11) is 3GPP TS51.011:

PHY:    Physical characteristics - 3GPP TS 51.011 [1], clause 4.
ELEC:    Electronic signals and transmission protocols - 3GPP TS 51.011 [1], clause 5.
AFS:    Application and File structure - 3GPP TS 51.011 [1], clause 6.
SEC:    Security features - 3GPP TS 51.011 [1], clause 7.
CMD:    Description of the commands - 3GPP TS 51.011 [1], clause 9.
CEF:    Contents of the elementary files - 3GPP TS 51.011 [1], clause 10.
APP:    Application Protocol - 3GPP TS 51.011 [1], clause 11.

Whilst GSM11.17 standard is the starting point for ICC/SIM and 3GPP TS51.011 moved the technology to neutral ground to enable 3GPP to evolve 3G environment standards incorportating interconnectivity to and backward compatibility for ICC/UICC, the 3GPP evolution hasn't stopped there. There is, of course, 3GPP TS 31.120 the aim of which is to ensure interoperability between an UICC and a Terminal independently of the respective manufacturer, card issuer or operator. This is the expansion of the 3GPP domain going beyond specific limitations encumbent with a particular proprietory technology.

The run of standards doesn't end there. Attention and consideration should be given to:

ETSI standards
TS 102 230
TS 102 221

International standards
ISO/IEC 7816-pt1 to pt4

The standards referred to above are merely a starting point to identify the complexities involved in dealing with (U)SIM card and tasks involved in considering examination techniques that may not simply relate to recovery of data but other aspects and attributes of a card which may point to evidence. Readers should be prepared to delve into the standards above and release the huge number that haven't been mentioned. There are various analogies that may be used to imagine what I have in mind for this physical series, but I quite like the analogy about forensic vehicle tyre analysis. Evidentially, consideration is given to tyre size, tread, pressure, rubber, moulding, any wheel balacing and so on to assess a skid mark or tracks at the scene of a crime. It is equally possible to use an investigative and examination approach to SIM/USIM card materials, contacts, gold content, embossing etc to identify potential evidence.

Friday, June 22, 2012

iPhone changing to 19-pin port?

iPhone changing to 19-pin port?

Screen Shot 2012-06-20 at 5.13.55 PM
Image courtesy of Tech Crunch

This could be an interesting twist in the marketplace relating to Apple's campaign to continue separating iPhone innovation from other handsets in the marketplace, not only through the use of distinctive design, but distinctive access to the phone. According to Tech Crunch  (the popular online tech gadget news website) they have verified that iPhone is to have changes made to the pin port swapping out the 30-pin port for a 19-pin port - http://techcrunch.com/2012/06/20/confirmed-the-new-iphone-will-have-a-19-pin-mini-connector/?goback=.gde_1794802_member_126527789

Some handset manufacturers have taken the route adopting the miniUSB. See USB research reference materials (below), but other handset manufacturers still retain specialists plugs in order to gain access.

http://en.wikipedia.org/wiki/USB
http://en.wikipedia.org/wiki/Enhanced_mini-USB
http://en.wikipedia.org/wiki/File:Types-usb_new.svg

Tech Crunch's news suggests Apple are not yet ready to take the USB route. I am more intrigued though whether there is any connection between the 19-pin port intro and Apple's adoption of the 4FF-uicc size which they have been successful in gaining agreement and approval for inclusion into the ETSI standard?

4FF-uicc research reference material
http://trewmte.blogspot.co.uk/2012/06/etsi-release-details-of-new-4ff-uicc.html
http://trewmte.blogspot.co.uk/2012/06/sim-card-new-4ff-form-factor-size.html

The implications could be wider for the handset examination market as new standards, and tools ranging from plugs to STKs to newer software upgardes, should be expected from such a development.

Saturday, June 09, 2012

ETSI release details of new 4FF UICC

ETSI release details of new 4FF UICC




Following on from the discussion ( http://www.trewmte.blogspot.co.uk/2012/06/sim-card-new-4ff-form-factor-size.html ) relating to SIM Card icc/uicc sizes, ETSI has now released the updated standard TS.102221 Release 11 that identifies that the new uicc size as '4FF'.

Tuesday, June 05, 2012

SIM Card new 4FF form factor size

On 1st June 2012 ETSI announced a new SIM Card size has been agreed and approved for inclusion in the standard TS.102221 and the new inclusion will be in the updated standard in due course:

http://www.etsi.org/WebSite/NewsandEvents/2012_06_New_SIM_Card_Format.aspx

There are now four physical sizes for SIM Card. In the TS standard the physical card is referred to by its correct technical name an UICC (universal integrated circuit card), the UICC thus cover the transmission technologies of for GSM and 3G. Interestingly, although TS.102221 makes no reference to SIM but USIM, the generic use if the term SIM Card is still applied   

1FF: ID-1 uicc size (the size of a credit card)
2FF: Plug-in uicc (the size of a postage stamp)
3FF: Mini-uicc (the size of a finger-nail)
4FF: XXXX-uicc (12.3mm wide by 8.8mm high, and 0.67mm thick) A titled suggested for this new uicc size is nano-size. It is my suggestion that a fair representation of its size is **eye contact lense size, which might be of useful assistance to a Court or Jury.

Image courtesy of http://en.wikipedia.org/wiki/Contact_lens

* Diameter
The diameter of a contact is the distance across the lens in millimeters. Average eye measurement for diameter yields a size between 12 and 14 millimeters. Diameter is important for proper fit of the lens. If the lens is too small or too big, it can cause irritation or damage to the eye.
Quick reference source: http://www.ehow.com/facts_6163786_average-eye-measurement-contact-lenses_.html

Currently TS10221 displays the characteristics for plug-in uicc and mini-uicc as:



 

 Regarding ID-1 uicc the ETSI TS records:

4.1 ID-1 UICC
The physical characteristics of the ID-1 UICC shall conform to ISO/IEC 7816-1 [9] and ISO/IEC 7816-2 [10].

The terminal shall accept embossed ID-1 UICCs. The embossing shall be in accordance with ISO/IEC 7811-1 [8] and ISO/IEC 7811-3 [i.1]. The contacts of the ID-1 UICC shall be located on the front (embossed face, see ISO/IEC 7810 [7]) of the card.

Discussion Updated 08-06-2012

ETSI release details of new 4FF UICC