DIMSIM -- Device Integrity Monitoring through iSIM Applets and Distributed Ledger Technology

Tooba Faisal,Emmanuel Marilly
2024-05-16
Abstract:In the context of industrial environment, devices, such as robots and drones, are vulnerable to malicious activities such device tampering (e.g., hardware and software changes). The problem becomes even worse in a multi-stakeholder environment where multiple players contribute to an ecosystem.
Cryptography and Security
What problem does this paper attempt to address?
This paper attempts to solve the problems of remote device integrity monitoring and trust establishment in a multi - stakeholder environment. Specifically, the paper addresses the following issues: 1. **Devices are vulnerable to malicious activities**: In industrial environments, devices such as robots and drones are vulnerable to malicious tampering (e.g., hardware and software changes). Especially in multi - party - involved ecosystems, this risk is more prominent. 2. **Limitations of existing methods**: Current methods usually rely on additional hardware, such as Trusted Platform Module (TPM), but not all vendors provide this hardware. Moreover, remote authentication relies on a centralized architecture. When multiple stakeholders need to track device integrity, they must rely on a central authority. 3. **Ensuring device integrity and trust**: In the case of remotely deployed devices, ensuring that all stakeholders can trust these devices is a challenge. Especially when device operations may deviate from the expected programming, it is crucial to ensure the integrity of their software and firmware as well as the accuracy and accountability of the generated data. To solve these problems, the paper proposes a solution based on distributed ledger technology and eUICC technology, called DIMSIM (Device Integrity Monitoring with SIM Applets). This solution monitors the integrity of devices by using a secure applet embedded in the eUICC without installing additional hardware. Specifically, DIMSIM utilizes the following technologies: - **eUICC technology**: A standard component for providing cellular connections, which can dynamically switch and re - configure mobile network providers. - **Distributed ledger technology (DLT)**: In particular, Permissioned Distributed Ledger (PDL), which ensures that all stakeholders can transparently view the software and firmware status of devices and that records are immutable. - **Attestation Applet**: A novel security element, embedded in the eUICC, responsible for continuously monitoring the integrity of devices and reporting abnormal situations. Through these technologies, DIMSIM aims to achieve the following goals: - Eliminate the dependence on additional hardware. - Provide a transparent device monitoring mechanism to ensure trust among all stakeholders. - Achieve efficient device integrity verification and management to ensure the reliability and safety of industrial systems. In summary, the main purpose of this paper is to solve the problems of remote device integrity monitoring and trust establishment in industrial environments by introducing the DIMSIM system, thereby ensuring device safety and reliability in a multi - stakeholder environment.