Overview of Presentation            Types Of Smart Cards Introduction What is SIM card? History Design Data on SIM Advantages of SIM Threats to SIM Future Evolution Conclusion References V.T. Patel Department of EC CSPIT.CHARUSAT 14/11/2011 SIM 09EC092 2 .

T. Patel Department of EC CSPIT.CHARUSAT Crypto Card USB token SIM Card JAVA Card Memory Card 15/11/2011 SIM 09EC092 3 .Types of Smart Card V.

Introduction V. which can be transferred between different mobile devices.CHARUSAT • A Subscriber Identity Module or Subscriber Identification Module (SIM) is an integrated circuit that securely stores the service-subscriber key (IMSI) used to identify a subscriber on mobile telephony devices (such as mobile phones and computers). 14/11/2011 SIM 09EC092 4 . • A SIM is held on a removable SIM card.T. Patel Department of EC CSPIT.

Serial communication module • These five modules must be integrated into an Integrated Circuit (IC). 14/11/2011 SIM 09EC092 5 . This is because the chip connections may become illegal access and misappropriation of SIM cards important clues.Working memory (RAM) and V.Program memory (ROM) --. Patel Department of EC CSPIT.CPU --.Data memory (EPROM or E2PROM) --.T. otherwise their safety would be threatened.What is SIM Card ? • both programming --. SIM card is a smart card with a microprocessor and it consists of the following modules: --.CHARUSAT The Subscriber Identity Module (SIM) is a small smart card which contains information.

60 mm × 53.76 mm).T. who sold the first 300 SIM cards to Finnish wireless network operator Radiolinja.The development of physically smaller mobile devices prompted the development of a smaller SIM card.CHARUSAT • The first SIM card was made in 1991 by Munich smart card maker Giesecke & Devrient. but their length and width are reduced to 25 mm × 15 mm. the mini-SIM card. Patel Department of EC CSPIT.History V.98 mm × 0. Mini-SIM cards have the same thickness as full-size cards. 14/11/2011 SIM 09EC092 6 . • SIM cards were first made the same size as a credit card (85.

8 V (ISO/IEC 7816-3 classes A.Design • Vcc (C1): Supply voltage V. • Vpp (C6): EEPROM programming voltage. • GND (C5): Ground. B and C. Patel Department of EC CSPIT. respectively).10 MHz) that is used as a system clock for the smart card microcontroller. • AUX2 (C8): Auxiliary contact 14/11/2011 SIM 09EC092 7 . • I/O (C7): Input/Output for serial communication • AUX1 (C4): Auxiliary contact. •CLK (C3):Clock input delivers an external clock signal (1.T.CHARUSAT There are three operating voltages for SIM cards: 5 V. Not used any more since modern cards generate the programming voltage on-chip using a charge pump fed by Vcc. • RST (C2): Reset input. 3 V and 1.

Issuer identification number (IIN) Individual account identification Check digit SIM 09EC092 8 15/11/2011 .Data on SIM • V. ICC-IDs are stored in the SIM cards and are also engraved or printed on the SIM card body during a process called personalization. ICC-ID (Integrated Circuit Card . b.ID) • Each SIM is Internationally identified by its ICC-ID.CHARUSAT SIM cards store network specific information used to authenticate and identify subscribers on the Network. Local Area Identity (LAI) and Operator-Specific Emergency Number. Patel Department of EC CSPIT. Authentication Key (Ki). the most important of these are the ICCID. • The ICC-ID number is composed of the following subparts: a.T. IMSI. 1. c.

is the identity of a subscriber.T.Data on SIM( Contd.CHARUSAT • The IMSI (International mobile subscriber identity) programmed on the SIM card. Each IMSI is mapped to a mobile number and provisioned on the HLR to allow a subscriber to be identified..) 2. 14/11/2011 SIM 09EC092 9 . Patel Department of EC CSPIT. • Mobile operators connect mobile phone calls and communicate with their market SIM cards using their IMSIs. International mobile subscriber identity (IMSI): V.

makes usage of the SIM card mandatory unless the Ki can be extracted from the SIM card. Instead.. by design. or the carrier is willing to reveal the Ki. Authentication key (Ki): V. that allows the phone to pass data to the SIM card to be signed with the Ki.Data on SIM( Contd. Each SIM holds a unique Ki assigned to it by the operator during the personalization process. 14/11/2011 SIM 09EC092 10 .) 3. This. the SIM card provides a function.T. • The SIM card is designed not to allow the Ki to be obtained using the smartcard interface. Patel Department of EC CSPIT. The Ki is also stored in a database (known as Authentication Center or AuC) on the carrier's network.CHARUSAT • The Ki is a 128-bit value used in authenticating the SIMs on the mobile network. Run GSM Algorithm .

each having a unique LAI number.. This saves time by avoiding having to search the whole list of frequencies that the telephone normally would.Data on SIM( Contd. Location Area Identify: • V.T.) 4. Storage: • To store phone numbers and SMS. 15/11/2011 SIM 09EC092 11 . Patel Department of EC CSPIT. 5.CHARUSAT Operator networks are divided into Location Areas. If the handset is turned off and back on again it will take data off the SIM and search for the LAI it was in. When the Mobile changes its location from one Location Area to another it stores its new LAI in SIM and sends it to the operator network to inform network with its new location.

Installation: V. on the order of 128-1024 megabytes. 14/11/2011 SIM 09EC092 12 . 2. Such data storage is used by the phone directly.T. Patel Department of EC CSPIT.CHARUSAT • The SIM card allows users to change phones by simply removing the SIM card from one mobile phone and inserting it into another mobile phone. Cost and Memory: • • • The typical low cost SIM card has little memory. In future we can expect SIM cards having megabytes of capacity. There are also Large Memory SIMs. 2-3 KB as described.Advantages 1.

V. resets PIN and the attempt counter Too many attempts on PUK blocks use permanently 15/11/2011 SIM 09EC092 13 .T..) 3. PIN and PUK: PIN –Personal Identification Number 2 PINs exist (PIN 1 and PIN2) Limited attempts on PIN access PUK –PIN Unblocking Code Resetting PUK.Advantages (Contd. • The other factors which make the SIM secure are…. Patel Department of EC CSPIT. iii) Secure Crypto operation support. Security: • SIM card is very secure and provides: i) the secure loading of the applications .CHARUSAT ii) Secure data storage for the application data and application cryptographic keys.

and what was missing (about 4-6 lines) and was reverse engineered. COMP128 design was completely private.’ 14/11/2011 14 SIM 09EC092 . A leaked document led to publication of COMP128. That document produced the majority of the code. Attacks to COMP128: • • COMP128 is a popular algorithm and a published standard. SIM cloning is also a great concern of security services because of its GSM locationbased service undependable if more than one handset is using the same SIM card. 2.T.Threats to SIM 1.CHARUSAT SIM cloning consists of duplicating the GSM Subscriber Identity Module identification and placing calls or using other charged services using the account of the cloned SIM. SIM Cloning: • • V. Patel Department of EC CSPIT. • It exploits the weakness in diffusion of the second round in the compression function. This is commonly referred to as a ’Narrow Pipe.

CHARUSAT • It is an application for UMTS mobile telephony running on a UICC smart card which is inserted in a 3G mobile phone. There is a common misconception to call the UICC card itself a USIM.Future Evolution 1.T. 14/11/2011 SIM 09EC092 15 . but the USIM is merely a logical entity on the physical card. • For authentication purposes. UNIVERSAL SUBSCRIBER IDENTITY MODULE(USIB): V. which is shared with the Authentication Cente (AuC) in the network. authentication information and provides storage space for text messages and phone book contacts. Patel Department of EC CSPIT. • It stores user subscriber information. the USIM stores a long-term pre-shared secret key K.

14/11/2011 SIM 09EC092 16 .Conclusion V. SIM may be moved from one Mobile Station to another which forms an advantage for the GSM architecture. It stores several user-defined information such as phonebook entries and other subscriber information like IMSI. Patel Department of EC CSPIT.CHARUSAT • SIM is a smart card which forms an unavoidable part in GSM mobile phones. This makes upgrades very simple for the GSM telephone user.T.

2005a. 3rd Generation Partnership Project. Patel Department of EC CSPIT. International 15/11/2011 SIM 09EC092 17 .CHARUSAT 1. [ISO7816] ISO: “Identification Cards . Specification of the Subscriber Identity Module Mobile Equipment (SIM .Integrated circuit cards with 2. http://en. V.T. 3. (2005-06).References contacts”. Parts 1-15. [SIMME] 3GPP. Technical Specification. TS 11.0 (Release 1999).wikipedia.11 V8.ME) interface.13.

