eSIM & eUICC engineering

The eUICC itself: architecture, remote SIM provisioning, and how the standards fit together.

Applet development for SIM & eSIM

Writing and deploying applets that live inside the eUICC — Java Card, GlobalPlatform, Security Domains.

SIM-based authentication

Authentication rooted in the SIM/eSIM credential rather than a code in transit.

SMS OTP & authentication security

Why SMS one-time passcodes fail, and what regulators and banks are moving toward.

Hardware trust anchors & embedded PKI

Choosing where keys live, and making certificate hierarchies survive embedded constraints.

Supporting IoT & device-identity engineering

Fleet-scale work that sits alongside the eSIM stack. Broader IoT security is an AmbiSecure capability.

Capability documents

Whitepaper & capability briefs

Documentation made available on request to operator and ecosystem reviewers under appropriate terms.

D1

eSIM / eUICC capability brief

Architecture, applet scope, identity workflows, and assumptions. Available on request under NDA.

Request brief →
D2

IoT identity reference

End-to-end identity reference: silicon RoT, Secure Element, embedded PKI, attestation, lifecycle.

Request reference →
D3

Sandbox collaboration scope

What we can validate, what we will not claim, and proposed shape of an engagement.

Request scope →

Frequently asked questions

What kind of material is in the AmbiSecure resource library?

It is a concept-first library of engineering and architecture articles spanning eSIM and eUICC provisioning, Secure Elements, embedded PKI, attestation, OTA security, and IoT identity. The writing reflects how the team reasons about these problems rather than marketing collateral.

Where should someone new to eSIM start reading?

Begin with the foundations piece distinguishing eSIM, eUICC, and iSIM, then move to the eUICC RSP provisioning architecture and the trust chain article that runs from the manufacturing HSM to the deployed device. From there the hardware-trust section goes deeper on Secure Element, TEE, and TPM trade-offs.

Are capability documents available beyond the articles?

Yes. The eSIM and eUICC capability brief, the IoT identity reference, and the sandbox collaboration scope are available on request to operator and ecosystem reviewers under appropriate terms.

Are the resource articles product marketing?

No — they are concept-first engineering and architecture notes on eSIM, eUICC, Secure Elements, embedded PKI, and IoT identity, written to explain mechanism rather than to sell.

How is the resource library organised?

By theme — SMS-OTP and SIM-based authentication, trust-chain and manufacturing, eSIM/eUICC and telecom integration, and hardware trust and PKI for embedded systems.