📖 eUICC.tech ← All Stories 🏠 Home
Page 1 of 14
SECRET CLUB TREEHOUSE

📇 The Trusted Friends List

Adding Remote Managers to Your Chip's Contacts

A story of secret clubhouses, contact cards, and the chicken-and-egg problem

Page 2 of 14
Page 3 of 14
📇 TRUSTED CONTACTS ✅ eIM Manager A: key: 7F3A... ✅ eIM Manager B: key: B2E1... ✅ Factory Manager: key: 9C4D... ❌ Not on list! Orders from strangers ignored

🤝 Why Do We Need a Contact List?

Phones don't remember who managed them. But IoT devices are deployed on remote mountains and ocean turbines: they need to know instantly if a command is from a trusted source. So they store a contact list right on the chip: only trusted managers can give orders!

Page 4 of 14
Page 5 of 14
📋 CONTACT CARD 📛 Name: eIM-Manager-42 🔑 Public Key: k7f3a2b1... 🧮 Counter: #42 🗣️ Language: HTTPS + CoAPS 🔒 Trust Anchor: cert-xyz APPROVED

📋 What's on the Contact Card?

Each trusted manager gets a digital contact card stored right on the chip. It includes their name, public key (for signature verification), a counter (against replay attacks), their language (HTTPS, CoAPS, etc.), and a trust anchor for encrypting the connection.

Page 6 of 14
Page 7 of 14
➕ addEim Add a new trusted manager 🔄 updateEim Change a manager's details ❌ deleteEim Remove a friend from the list 📜 listEim Show all trusted managers 🥚→🐔 First manager added at the factory: bootstrap!

✏️ Four Ways to Manage the List

Four operations: addEim (add a new friend), updateEim (change their details), deleteEim (remove a friend), and listEim (who's on my list?). The very first manager solves a chicken-and-egg problem: it's added at the factory with a special bootstrap command!

Page 8 of 14
Page 9 of 14
🧮 TICKET COUNTER #42 → #43 → #44 ❌ Ticket #41 REJECTED ✅ Ticket #45 ACCEPTED When counter nears max, manager is re-added fresh!

🧮 The Ticket Counter

Every command includes a ticket number that only goes up. The chip remembers the last number seen. Old numbers get rejected: "sorry, already saw that one!" When the counter nears its max of 8,388,607, the manager is removed and re-added with a fresh counter. Simple and bulletproof!

Page 10 of 14
Page 11 of 14
🧠 🏭 Manufacturer Trusted Slot #1 👤 Customer Trusted Slot #2 Both can manage the same device!

A single eSIM chip can trust multiple managers at once: so the company that made the device and the customer who bought it can both manage it, each with their own trusted spot on the contact list!

Page 12 of 14
Page 13 of 14

📚 Ready for the Next Story?

Discover how devices send report cards and undo mistakes!

📖 Next: Report Cards & Undo →

📚 Back to All Stories

Page 14 of 14
📖 Back Cover