Resources — eSIM, eUICC & SIM authentication engineering
This is the AmbiSecure technical library: concept-first articles on eSIM and eUICC provisioning, Secure Element and Java Card engineering, embedded PKI, and IoT device identity — written for engineering and architecture readers who want the mechanism rather than the brochure. The pieces are grouped by theme below, from SMS-OTP fraud and the case for SIM-based authentication through trust-chain manufacturing, telecom integration, and hardware-backed PKI for constrained devices.
eSIM & eUICC engineering
The eUICC itself: architecture, remote SIM provisioning, and how the standards fit together.
Applet development for SIM & eSIM
Writing and deploying applets that live inside the eUICC — Java Card, GlobalPlatform, Security Domains.
SIM-based authentication
Authentication rooted in the SIM/eSIM credential rather than a code in transit.
SMS OTP & authentication security
Why SMS one-time passcodes fail, and what regulators and banks are moving toward.
Hardware trust anchors & embedded PKI
Choosing where keys live, and making certificate hierarchies survive embedded constraints.
Supporting IoT & device-identity engineering
Fleet-scale work that sits alongside the eSIM stack. Broader IoT security is an AmbiSecure capability.
Whitepaper & capability briefs
Documentation made available on request to operator and ecosystem reviewers under appropriate terms.
eSIM / eUICC capability brief
Architecture, applet scope, identity workflows, and assumptions. Available on request under NDA.
Request brief →IoT identity reference
End-to-end identity reference: silicon RoT, Secure Element, embedded PKI, attestation, lifecycle.
Request reference →Sandbox collaboration scope
What we can validate, what we will not claim, and proposed shape of an engagement.
Request scope →Frequently asked questions
What kind of material is in the AmbiSecure resource library?
It is a concept-first library of engineering and architecture articles spanning eSIM and eUICC provisioning, Secure Elements, embedded PKI, attestation, OTA security, and IoT identity. The writing reflects how the team reasons about these problems rather than marketing collateral.
Where should someone new to eSIM start reading?
Begin with the foundations piece distinguishing eSIM, eUICC, and iSIM, then move to the eUICC RSP provisioning architecture and the trust chain article that runs from the manufacturing HSM to the deployed device. From there the hardware-trust section goes deeper on Secure Element, TEE, and TPM trade-offs.
Are capability documents available beyond the articles?
Yes. The eSIM and eUICC capability brief, the IoT identity reference, and the sandbox collaboration scope are available on request to operator and ecosystem reviewers under appropriate terms.
Are the resource articles product marketing?
No — they are concept-first engineering and architecture notes on eSIM, eUICC, Secure Elements, embedded PKI, and IoT identity, written to explain mechanism rather than to sell.
How is the resource library organised?
By theme — SMS-OTP and SIM-based authentication, trust-chain and manufacturing, eSIM/eUICC and telecom integration, and hardware trust and PKI for embedded systems.