<?xml version="1.0" encoding="utf-8"?>
<journal>
<title>Biannual Journal Monadi for Cyberspace Security (AFTA)</title>
<title_fa>امنیت فضای تولید و تبادل اطلاعات (منادی)</title_fa>
<short_title>منادی</short_title>
<subject>Engineering &amp; Technology</subject>
<web_url>http://monadi.isc.org.ir</web_url>
<journal_hbi_system_id>1</journal_hbi_system_id>
<journal_hbi_system_user>admin</journal_hbi_system_user>
<journal_id_issn>2476-3047</journal_id_issn>
<journal_id_issn_online>2476-3047</journal_id_issn_online>
<journal_id_pii>8</journal_id_pii>
<journal_id_doi>7</journal_id_doi>
<journal_id_iranmedex></journal_id_iranmedex>
<journal_id_magiran></journal_id_magiran>
<journal_id_sid>14</journal_id_sid>
<journal_id_nlai>8888</journal_id_nlai>
<journal_id_science>13</journal_id_science>
<language>fa</language>
<pubdate>
	<type>jalali</type>
	<year>1404</year>
	<month>12</month>
	<day>1</day>
</pubdate>
<pubdate>
	<type>gregorian</type>
	<year>2026</year>
	<month>3</month>
	<day>1</day>
</pubdate>
<volume>14</volume>
<number>2</number>
<publish_type>online</publish_type>
<publish_edition>1</publish_edition>
<article_type>fulltext</article_type>
<articleset>
	<article>


	<language>fa</language>
	<article_id_doi></article_id_doi>
	<title_fa>طراحی و توسعه سامانه یکپارچه مدیریت کلیدهای امنیتی اپراتور تلفن همراه (سیم کات)</title_fa>
	<title>Design and Development of a Secure and Integrated Cryptographic Key Management System for Mobile Network Operators (SIMKAT)</title>
	<subject_fa>رمز و امنیت اطلاعات</subject_fa>
	<subject>Cryptology and Information Security</subject>
	<content_type_fa>پژوهشی</content_type_fa>
	<content_type> Research Article</content_type>
	<abstract_fa>&lt;div style=&quot;text-align: justify;&quot;&gt;مدیریت امن کلیدهای رمزنگاری سیم&#8204;کارت در اپراتورهای تلفن همراه، به&#8204;ویژه در چرخه عمر کلیدها شامل تولید، ذخیره&#8204;سازی، توزیع و بهره&#8204;برداری، از چالش&#8204;های اصلی امنیت سایبری به شمار می&#8204;رود. این مقاله به بررسی موانع موجود در مدیریت کلیدهای سیم&#8204;کارت در اپراتورهای تلفن همراه می&#8204;پردازد و مسائلی نظیر تولید و انتقال غیرامن کلیدها، ذخیره&#8204;سازی ناامن، نبود زیرساخت یکپارچه برای ارتباط با سامانه&#8204;های مرتبط، فقدان سوابق جامع و متمرکز و ریسک تبانی یا سوءاستفاده را مورد توجه قرار می&#8204;دهد. برای رفع این مشکلات، سامانه یکپارچه مدیریت کلیدهای امنیتی اپراتور تلفن همراه (سیم&#8204;کات) طراحی و پیاده&#8204;سازی شده است. این سامانه با بهره&#8204;گیری از افزاره&#8204;های امنیتی سخت&#8204;افزاری بومی، الگوریتم&#8204;های رمزنگاری پیشرفته و روش&#8204;های تسهیم راز، امکان تولید، نگهداری و انتقال امن کلیدهای سیم&#8204;کارت را فراهم می&#8204;کند. همچنین با ارائه قابلیت&#8204;هایی مانند احراز هویت دو عاملی، مدیریت متمرکز سوابق و پشتیبانی از مهاجرت به پیمانکاران جدید بدون ایجاد محدودیت، امنیت و کارایی فرایندهای مرتبط با کلیدهای سیم&#8204;کارت را به&#8204;طور چشمگیری ارتقا داده است. این راهکار به&#8204;عنوان یک نوآوری جامع، نیازهای امنیتی اپراتورهای تلفن همراه را به&#8204;صورت مؤثر برآورده می&#8204;سازد.&lt;br&gt;
&amp;nbsp;&lt;/div&gt;</abstract_fa>
	<abstract>&lt;div style=&quot;text-align: justify;&quot;&gt;Cryptography is the foundation of modern information security and is extensively used to protect communications, digital services, and critical infrastructures. The effectiveness of any cryptographic system depends heavily on the secure management of cryptographic keys throughout their lifecycle. Key lifecycle management includes key generation, storage, distribution, usage, backup, recovery, and destruction. Any weakness in these processes can compromise the security of the entire system. In mobile network operators, SIM card cryptographic keys represent one of the most sensitive assets because they are responsible for subscriber authentication, secure communication, and the protection of SIM-based applications.&lt;br&gt;
A copy of each SIM card key is stored within the SIM card, while another copy is maintained in the operator&amp;rsquo;s core systems and subscriber databases. Consequently, protecting these keys is essential for ensuring network security. However, in many telecommunications environments, especially within developing regions, the management of SIM card keys still relies on manual procedures. Human involvement in key generation, transfer, and storage increases the risk of key exposure, insider threats, and operational errors. In some cases, keys may be temporarily stored on insecure media such as files, laptops, removable storage devices, or even printed documents, creating opportunities for unauthorized disclosure.&lt;br&gt;
Beyond secure generation and transfer, operators face additional challenges related to key storage and access control. Different cryptographic keys require different levels of protection based on their security attributes. Confidential keys should only be accessible to authorized users or applications, sensitive keys should never be extracted in plaintext form, and non-extractable keys must remain protected inside secure cryptographic hardware. Managing these requirements for millions of SIM cards creates significant technical and operational complexity.&lt;br&gt;
Another important challenge is the secure exchange of cryptographic keys between different systems. Existing infrastructures often lack standardized mechanisms for automated key distribution, forcing organizations to depend on manual processes and vendor-specific solutions. Furthermore, operators require comprehensive historical records associated with SIM cards and their keys for operational and auditing purposes. The large volume of data involved makes centralized management and rapid retrieval difficult without a dedicated platform.&lt;br&gt;
Insider threats and collusion among personnel also represent a serious concern. Since multiple individuals may participate in key management operations, there must be mechanisms that prevent any single person&amp;mdash;or even a small group&amp;mdash;from gaining unauthorized access to critical cryptographic assets. In addition, operators often encounter difficulties when migrating from one equipment vendor to another. Existing approaches frequently require the insecure transfer of cryptographic keys, increasing security risks and limiting operational flexibility.&lt;br&gt;
To address these challenges, an integrated solution called SIMKAT was designed and developed. The objective of SIMKAT is to provide a secure and centralized infrastructure for the complete lifecycle management of SIM card cryptographic keys while minimizing human intervention and improving security throughout the key lifecycle.&lt;br&gt;
The proposed solution combines dedicated Hardware Security Modules (HSMs) with a centralized software platform. SIMKAT is responsible for receiving SIM card keys from SIM personalization facilities, securely storing them, managing key-related operations, and distributing authorized keys to subscriber databases and other operator systems. By integrating hardware-based security with software-controlled workflows, the system provides comprehensive protection for cryptographic assets throughout their lifecycle.&lt;br&gt;
The architecture employs multiple categories of keys, including SIM card keys, transport keys, and root keys. Root keys are generated within trusted HSM devices and are used to secure the encrypted transfer of SIM card keys between HSMs. To ensure maximum protection, root key distribution is performed offline using an M-of-N secret-sharing mechanism based on Shamir&amp;rsquo;s Secret Sharing Scheme. Under this approach, no individual participant possesses sufficient information to reconstruct the root key independently. The key can only be recovered when a predefined minimum number of authorized participants collaborate. This mechanism significantly reduces the risks associated with insider threats and unauthorized disclosure.&lt;br&gt;
Transport keys are generated and stored within HSM devices using hardware-based true random number generators compliant with FIPS 140-2 Level 3 security requirements. Standard cryptographic algorithms such as AES-256, RSA, and Elliptic Curve Cryptography (ECC) are employed to provide strong protection for key management operations. Key management functions are implemented through standardized interfaces, ensuring interoperability between different systems and vendors.&lt;br&gt;
After generation, SIM card keys are encrypted using transport keys and securely transferred to the SIMKAT platform. The keys remain protected throughout their lifecycle and are only accessible through controlled and authorized processes. Any request for key transfer or operational use must pass through predefined approval workflows involving authorized personnel. All activities are recorded in immutable audit logs, ensuring accountability, traceability, and compliance with security policies.&lt;br&gt;
One of the most important innovations of the proposed solution is its ability to securely exchange encrypted SIM card keys with systems developed by different vendors. Unlike traditional approaches that require exposing keys during migration processes, SIMKAT enables secure interoperability without compromising confidentiality. As a result, mobile network operators can replace infrastructure vendors while preserving existing subscriber information and cryptographic assets. This capability supports secure migration between vendors and eliminates the need to replace existing SIM cards during infrastructure upgrades.&lt;br&gt;
The platform also incorporates advanced authentication and access-control mechanisms. For sensitive operations, two-factor authentication based on USB security tokens is supported. Furthermore, operations performed on HSM devices require multi-person authorization through M-of-N authentication policies. Critical operations involving cryptographic keys can only be executed when the required number of authorized representatives are simultaneously present and authenticated. These controls provide an additional layer of protection against insider misuse and unauthorized actions.&lt;br&gt;
To support operational requirements, SIMKAT includes a centralized repository capable of maintaining complete historical records associated with SIM cards and their cryptographic keys. Efficient indexing and search mechanisms enable rapid retrieval of information even in environments containing millions of records. This functionality improves operational visibility and supports auditing and reporting activities.&lt;br&gt;
In conclusion, SIM card cryptographic keys are among the most critical security assets of mobile network operators. Traditional key management approaches suffer from significant limitations, including manual processes, inadequate protection mechanisms, interoperability challenges, insider threats, and vendor dependency. The SIMKAT platform addresses these issues through the integration of hardware-based security, centralized lifecycle management, secure key distribution, secret-sharing mechanisms, and advanced authentication controls. The resulting solution provides a secure framework for managing SIM card cryptographic keys while supporting interoperability and secure migration between different vendors.&lt;br&gt;
&amp;nbsp;&lt;/div&gt;</abstract>
	<keyword_fa>سیم‌کارت, کلید امنیتی, رمزنگاری, اپراتور, تلفن همراه</keyword_fa>
	<keyword>SIM card, Security Key, Cryptography, Mobile Network Operator, Mobile Phone</keyword>
	<start_page>125</start_page>
	<end_page>130</end_page>
	<web_url>http://monadi.isc.org.ir/browse.php?a_code=A-10-407-24&amp;slc_lang=fa&amp;sid=1</web_url>


<author_list>
	<author>
	<first_name>Amirhossein</first_name>
	<middle_name></middle_name>
	<last_name>Pourshams</last_name>
	<suffix></suffix>
	<first_name_fa>امیرحسین</first_name_fa>
	<middle_name_fa></middle_name_fa>
	<last_name_fa>پورشمس</last_name_fa>
	<suffix_fa></suffix_fa>
	<email>ah.pourshams@mci.ir</email>
	<code>10031947532846002225</code>
	<orcid>10031947532846002225</orcid>
	<coreauthor>Yes
</coreauthor>
	<affiliation>Mobile Communications Company of Iran (MCI), Iran</affiliation>
	<affiliation_fa>شرکت ارتباطات سیار ایران ، تهران، ایران</affiliation_fa>
	 </author>


	<author>
	<first_name>Ali</first_name>
	<middle_name></middle_name>
	<last_name>Ahmadi Beni</last_name>
	<suffix></suffix>
	<first_name_fa>علی</first_name_fa>
	<middle_name_fa></middle_name_fa>
	<last_name_fa>احمدی بنی</last_name_fa>
	<suffix_fa></suffix_fa>
	<email>a.ahmadibeni@mci.ir</email>
	<code>10031947532846002226</code>
	<orcid>10031947532846002226</orcid>
	<coreauthor>No</coreauthor>
	<affiliation>Mobile Communications Company of Iran (MCI), Iran</affiliation>
	<affiliation_fa>شرکت ارتباطات سیار ایران ، تهران، ایران</affiliation_fa>
	 </author>


</author_list>


	</article>
</articleset>
</journal>
