SIMPATIC (SIM and PAiring Theory for Information and Communications security)


SIMPATIC (SIM and PAiring Theory for Information and Communications security) is a cooperative project funded by ANR (French Research Agency) in the call “Ingénierie Numérique et Sécurité  (INS 2012).

Bilinear pairings are special kinds of functions that map pairs of points on groups to points in a third group. They make it possible to design cryptographic schemes with new properties that seem to be difficult to achieve in a more traditional public key cryptography setting, such as cryptography without Public Key Infrastructure (PKI), shorter signatures, cryptosystems with additional properties, or more secure systems.

The aim of the SIMPATIC (SIM and PAiring Theory for Information and Communications security) project is first to provide the most possible efficient and secure hardware/software implementation of a bilinear pairing in a SIM card.

This implementation will be next used to improve and develop new cryptographic efficient algorithms and protocols in the context of mobile phone and SIM cards. These pairing-­based cryptographic tools will be finally used to develop or improve the security of several mobile phone based services. The project will more precisely focus on e-­ticketing and e-­cash, on cloud storage and on the security of contactless and of remote payment systems.

The partners of the project are:

  • Orange Labs
  • ENS
  • Oberthur Technologies
  • STMicroelectronics
  • Université Bordeaux 1
  • Université de Caen Basse-­Normandie
  • Université de Paris VII

Related projects

Several national, European or international collaborative projects on specific aspects of « Privacy and Identity Management » have been launched in the past five years. PRIME[1], PrimeLife (PRIME’s follow-up project), PICOS (Privacy and Identity Management for Community Services)[2] COPRIM (Contactless Privacy Manager) and ABC4Trust (Attribute-Based Credentials for Trust) [3], are representative projects in this area. In contrast to all of those projects, LYRICS puts a strong emphasis on conceiving and implementing innovative cryptographic primitives, and specifically addresses the computational constraints faced by embedded applications.

Our project bears some similarities with the European FP6 project PRIME (PRivacy and Identity Management for Europe) whose goal was to develop a framework and a number of tools allowing a user to manage his identity and to protect his privacy in the cyberspace. The main difference however is that we are focusing on real-world near-field transactions using low resources devices (NFC-enabled mobile phones) whereas PRIME was focusing exclusively on the on-line setting (Internet transactions performed on powerful devices such as personal computers). Moreover the privacy-enhancing cryptographic tools developed during the course of this project are mainly based on those used in the Idemix system and therefore would not be suitable for resources constrained devices such as SIM cards and mobile phones.


Global Platform: Global Platform (GP) is an important standard coping with the way applications are securely managed on the security element. Together with Java Card, it offers a good basis for industrial development and remote issuance of secure applications in the smartphone context, and consequently these environments will be the target of LYRICS.

GP is broadly used for SIMs which are typical multi-applicative secure elements (SE). Aspects dealt with by GP are secure download, activation, disable and removal of applications with their code, data and their secret material (keys, parameters, etc…) while preserving the right policy for doing these operations which can involve various entities: mobile network operators, the security element issuer, the application provider, and some trusted third party. There are clearly some concerns with privacy in tasks like secure code and keys downloading, since it could result for example in some problems of traceability.  These aspects will be addressed in LYRICS in order to provide an analysis of mechanisms provided by GP2.2 and the work being done on “remote application management” topic to verify adequacy with the goals of LYRICS regarding privacy, describe relevant measures concerning remote management & privacy, and eventually define and propose some technical adaptations of GP protocols, and if necessary contribute to the GP standardization body.

ISO/IEC: Several standardization bodies have been involved over the last ten years in attempts to develop an information privacy protection standard. ISO/IEC JTC1/SC27 has vested interests in standardizing “information technology-security techniques”. This includes standards for privacy-enhancing technologies and especially for credential-based solutions. The subject of anonymous authentication mechanisms intersects with standardization works in two SC27 working groups, WG2 and WG5. WG2 develops standards based on algorithms such as group signatures and WG5 elaborates on requirements and guidelines. An initiative is currently being undertaken by SC27 WG5:

-       The project ISO/IEC 29191 provides a model for partially anonymous unlinkable authentication mechanisms where a designated agent can revoke anonymity, and defines requirements thereof.

The WG5 is responsible for other privacy standards. The most advanced are ISO/IEC 29100 Privacy Framework and ISO/IEC 29101 Privacy Reference Architecture:

-       The Privacy Framework serves as a basis for a technical reference architecture, for the implementation and use of specific privacy technologies and overall privacy management, for privacy controls for outsourced data processes, for privacy risk assessment or for specific engineering specifications.

-       The Privacy Reference Architecture guides the implementation of controls associated with a privacy framework to ensure the proper handling of personally identifiable information within an information and communication technology environment.

NEC and France Telecom are actively involved in these two working groups WG2 and WG5. More precisely, NEC is the editor in charge of the ISO/IEC 29191 project. NEC, France Telecom as well as Microsoft also hold several patents on Privacy-Enhancing Cryptographic (PEC) mechanisms such as blind signatures, DAA and k-TAA and on applications making use of these anonymous signatures schemes such as e-cash, e-voting and e-auctions.