Praveen Gupta <[email protected]> wrote: > The WSIM-AS is not enterprise-built software with an API call to the > MNO. It is MNO-provisioned hardware deployed at the enterprise edge — > conceptually equivalent to what the MNO's SIM personalization > infrastructure does at the factory, but placed on-premises.
Okay. Let's call this the "SIM-proxy", unless you have a better term.
I would seperate that from WSIM for two reasons:
1. There is a protocol from Enterprise AAA to SIM-proxy. It's probably
RADIUS. It might need further details/normalization of the trust model.
Like, it's 2026, so it's gonna be RADIUS over (D?)TLS, and it's gonna
use...?? for authentication. Probably certificates. PrivatePKI?
Whose? The MNO or the Enterprise?
2. There is a protocol from SIM-proxy to MNO. It's just one MNO?
So, (in Canada), I, as an Enterprise, lease this box from (e.g.,) Rogers,
I still want to accept identities from Bell and Videotron, but that
SIM-proxy takes care of that.
Now the Enterprise can do EAP-SIM/EAP-AKA using unmodified existing clients.
(Assuming that they can do that). That shortens your time to MVP.
Getting WSIM deployed to smartphones is gonna be ~5years, assuming the
vendors want to play.
> The trust chain works as follows:
> 1. The MNO operates a MASTER KEY that underlies all subscriber SIM
> provisioning — the same root from which per-subscriber Ki values are
> derived when SIM cards are manufactured.
> 2. The MNO provisions this MASTER KEY material into the WSIM-AS
> security hardware (a tamper-resistant HSM or SIM-card-equivalent
> hardware module) out-of-band, using the same key provisioning
> infrastructure used for SIM card personalization. This is a one-time
> per-venue provisioning event, operationally equivalent to how MNOs
> provision eSIM profiles via GSMA Remote SIM Provisioning (SGP.02).
As an MNO, I would NEVER EVER do that. And I do Remote Attestation and have
lot of interaction with HSM vendors, and I don't see this as being even
remotely feasible.
Further, my *Rogers* managed SIM-proxy is NEVER gonna be trusted by *Videotron*
> So to directly answer your question: the enterprise's AAA server (the
> WSIM-AS) gets access to MNO subscriber credentials the same way a SIM
> card factory gets access to them — because the MNO provisions it. The
> difference from existing EAP-AKA is that the MNO provisions key
> material to hardware at the enterprise edge rather than responding to
> per-authentication queries from the enterprise over a live Diameter
> interface.
I suggest you have a conversation with a few MNO about this.
I doubt it will work that way.
--
Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting )
Sandelman Software Works Inc, Ottawa and Worldwide
** My working hours and your working hours may be different. **
** Please do not feel obligated to reply outside your normal working hours **
signature.asc
Description: PGP signature
_______________________________________________ Emu mailing list -- [email protected] To unsubscribe send an email to [email protected]
