📖 eUICC.tech ← All Stories 🏠 Home
Page 1 of 16
🔐

🔐 Secret Handshakes for Robots

eIM Certificates, DTLS, and Device Trust

A story of digital ID cards, emergency parachutes, and security that survives sleep

Page 2 of 16
Page 3 of 16
✍️ Signing Certificate Proves commands are genuinely from eIM 🔒 Transport Certificate Encrypts the connection nobody can eavesdrop 🏠 Front door lock 📔 Diary lock Two keys for two different jobs!

👑 The New Guardian: eIM Certificates

IoT adds a brand new digital ID card: the eIM Certificate: for the remote control centre. It comes in two flavours: a Signing Certificate (proves commands are genuine) and a Transport Certificate (encrypts the connection). Two separate keys: like a lock for your front door and a different lock for your diary!

Page 4 of 16
Page 5 of 16
🦾 Full PKI Linux gateways Validates entire certificate chains 📌 Pinning Most IoT devices Stores one trusted certificate only 🔑 Raw Key Ultra-tiny sensors Just the raw secret code! 🐻 Goldilocks Style Big, medium, and tiny: everyone fits! 🐻 🐻 🐻

🐻 Three Trust Levels: Goldilocks Style

Not all devices have the same power. Full PKI for powerful gateways, Certificate Pinning for most devices (trust one specific ID), and Raw Public Key for ultra-tiny sensors: just the raw secret code, no fancy parsing. Something for everyone!

Page 6 of 16
Page 7 of 16
Zzz Sleeping 🧥 Jacket on chair Awake! Resumes 🌊 DTLS Security that survives sleeping & waking!

🌊 DTLS: Security That Survives Sleep

Your phone uses TLS, but IoT devices use DTLS: a lightweight version that works even when the device falls asleep and wakes up. The magic trick? Connection ID. Like leaving your jacket on a chair to save your spot, it lets a device resume its secure connection after a nap: even with a new IP address!

Page 8 of 16
Page 9 of 16
LOST CONN! SAFE! 🪂 Fallback Profile Automatic emergency parachute: no server needed!

🪂 The Emergency Parachute

If a profile switch goes wrong and the device loses all connectivity, the eSIM chip automatically switches to a Fallback Profile: a backup that's always there. This happens without any server involvement. The chip just does it on its own: like an automatic parachute that opens when it detects you're falling!

Page 10 of 16
Page 11 of 16
No imposters No replays No fakes No snooping 🔒 SAFE Everything is signed and encrypted!

🛡️ Defence Against the Dark Arts

The system protects against four threats: imposter commands (digital signatures), replay attacks (counters), fake control centres (only trusted eIMs), and snooping (everything encrypted). Four layers of protection: no dark arts getting through!

Page 12 of 16
Page 13 of 16
🧠 📶 WiFi A 📶 WiFi B DTLS Connection ID means the conversation keeps going without restarting!

DTLS with Connection ID means a device could change IP addresses: like moving to a different WiFi network: and still keep its secure conversation going without starting over. It's a truly uninterrupted encrypted tunnel!

Page 14 of 16
Page 15 of 16

📚 Ready for the Next Story?

Learn how eSIM chips keep a trusted friends list!

📖 Next: The Trusted Friends List →

📚 Back to All Stories

Page 16 of 16
📖 Back Cover