Related Experiment Video
Updated: Aug 14, 2026

10:53
Utilization of Microscale Silicon Cantilevers to Assess Cellular Contractile Function In Vitro
Published on: October 3, 2014
Closing the HNDL Window in Consumer eSIM Provisioning: Hybrid Post-Quantum Migration, Formal Verification, and
Jhury Kevin Lastre1, Yongho Ko1, Hoseok Kwon1
1Department of Information Security, Cryptology, and Mathematics, Kookmin University, Seoul 02707, Republic of Korea.
Sensors (Basel, Switzerland)
|August 13, 2026
Summary
To counter the Harvest-Now-Decrypt-Later threat to eSIMs, a post-quantum cryptography (PQC) migration framework is proposed. Hybrid PQC key exchange is the minimum configuration to resist threats, with RAM being the key deployment constraint.
Area of Science:
- Cryptography and Network Security
- Embedded Systems Security
- Quantum Computing Impact
Background:
- Embedded Subscriber Identity Modules (eSIMs) use GSMA SGP.22 for remote SIM provisioning (RSP).
- RSP relies on classical cryptography, posing a Harvest-Now-Decrypt-Later (HNDL) risk to long-lived eSIM profiles.
- Transport Layer Security (TLS) upgrades alone are insufficient due to key exchange occurring below the transport layer.
Purpose of the Study:
- To develop a systematic post-quantum cryptography (PQC) migration framework for consumer RSP.
- To analyze PQC configurations for SGP.22 key agreement against quantum adversaries.
- To identify resource constraints for PQC deployment on eSIMs.
Main Methods:
- Modeling four SGP.22 on-card key-agreement configurations.
- Symbolic verification using ProVerif.
- Device-grounded evaluation using an eUICC and PQC measurements on an ARM Cortex-M4F core.
Main Results:
- Hybrid classical and PQC key exchange is the minimal configuration resisting HNDL.
- Fully PQC configurations offer additional protection against signature forgery.
- Volatile Random Access Memory (RAM) is identified as the primary deployment constraint, not computation.
Conclusions:
- A hybrid PQC approach is necessary for HNDL resistance in consumer RSP.
- Future PQC migration must consider memory constraints on embedded devices.
- A capability-negotiation mechanism is proposed to match configurations to available card memory.
Keywords:
ML-DSAML-KEMProVerifSGP.22eSIMformal verificationharvest-now–decrypt-laterhybrid key exchangepost-quantum cryptographyremote SIM provisioning
