PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 3, 2026Future Internet2 citationsOpen Access

Hardware-Anchored ES-SPA: A Dynamic Zero-Trust Architecture for Secure eSIM Provisioning in 6G IoT via Moving Target Defense

View Full Paper
HNHari N. NKJKurunandan JainPPPrabu P.

Key Points

  • The research aims to develop a secure architecture for eSIM provisioning amid rising threats in 6G IoT environments.
  • Developed MTD-SDP-eSIM framework integrating eUICC with Zero Trust principles.
  • Implemented Software-Defined Networking and Moving Target Defense techniques.
  • Conducted experiments on a 6G testbed using ns-3 and Open5GS.
  • Achieved a 90% survival rate against DoS attacks during provisioning.
  • Improved scalability by 35% compared to traditional VPN approaches.
  • Reduced profile lock-in failures by 75% through runtime verification methods.

Abstract

The rapid evolution of 6G networks and large-scale Internet of Things (IoT) deployments intensifies security and privacy challenges in embedded SIM (eSIM) Remote SIM Provisioning (RSP), particularly during the bootstrap and profile delivery phases. Traditional perimeter-based and VPN-centric approaches expose static attack surfaces, making provisioning workflows vulnerable to denial-of-service (DoS) attacks, reconnaissance, and profile lock-in risks. This paper presents MTD-SDP-eSIM, a hardware-anchored Zero Trust Architecture that secures eSIM provisioning by integrating the embedded Universal Integrated Circuit Card (eUICC) as a root of trust with Software-Defined Perimeter (SDP), Software-Defined Networking (SDN), and Moving Target Defense (MTD). The framework introduces Hardware-Anchored Single Packet Authorization (ES-SPA), which cryptographically binds initial access to tamper-resistant eUICC credentials and enforces an authenticate-before-connect model. A unified Zero Trust controller dynamically orchestrates SDP access control, SDN-based micro-segmentation, and MTD-driven Network Address Shuffling during high-risk provisioning phases. This framework is validated on a high-fidelity 6G testbed built using ns-3, Open5GS, and P4-programmable switches. Experimental results demonstrate a 90% DoS survival rate during provisioning, a 35% scalability improvement over VPN-based baselines, and a 75% reduction in profile lock-in failures through runtime deletion verification. These findings confirm that anchoring dynamic network defenses in hardware-rooted identity significantly enhances the resilience, scalability, and privacy of eSIM provisioning for massive 6G IoT deployments.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

N et al. (2026) studied this question.

synapsesocial.com/papers/69cf5e5f5a333a821460cb8bhttps://doi.org/10.3390/fi18040187
Ask AI
Helpful
Bookmark
Share
View Full Paper