📖 eUICC.tech ← All Stories 🏠 Home
Page 1 of 7
SECRET 🔑 🤖 Encrypted delivery through glowing tubes 🤖 Robot #8721 Mission received! Profile installed ✓

📦 Mission Orders Delivered

How Robots Get New Network Keys

A story of secret handshakes, triple-locked boxes, and missions that arrive through thin air

Page 2 of 7
Page 3 of 7
📡 Fleet Owner 🔑 Key Factory 🦾 Commander 1. Owner: "New profile for robot #8721!" 2. Factory: asks Commander about robot #8721 (EIS) 3. Commander: radios robot: "Build new ISD-P room!" 🤖 Room ready!

🏗️ Phase 1: The Commander Prepares a Mission

The Fleet Owner calls the Key Factory: "New profile for Robot #8721!" The Key Factory asks the Commander about the robot (checks its records in the EIS database). The Commander radios the robot: "Build a new ISD-P room!" The room is created: empty, waiting, in SELECTABLE state.

Page 4 of 7
🔑 🤖 ISD-R 1. Send ID badge 2. Check CI root ✅ Valid! 3. Random challenge 4. Sign challenge 5. SHARED SECRET! 6. SCP03 ready ECKA-EG key agreement: magic math!

🤝 Phase 2: The Secret Handshake

Now comes the cleverest part. The Key Factory sends its ID badge; the robot checks it traces to the CI. The robot generates a random challenge: the Factory must sign it, proving it's the real deal. Then both sides each compute the same Shared Secret using ECKA-EG math: without ever sending it!

Page 5 of 7
📦 SCP03t Encrypted Box MNO-SD (operator office) 🔑 NAA (network keys) 📁 File System + Apps 📜 POL1 Rulebook 🔒 🔒 🔒 ✅ Delivered Chunked through Commander's radio channel

📦 Phase 3: The Triple-Locked Box

The profile is a triple-locked encrypted package containing network keys (NAA), an operator mini-office (MNO-SD), file system, apps, and a POL1 rulebook. It's wrapped in SCP03t encryption and sent in chunks through the Commander's radio. The Commander relays the chunks but sees only scrambled data!

Page 6 of 7
🔍 Check 1 Robot genuine? 🔍 Check 2 Enough memory? 🔍 Check 3 Certificate OK? 🔍 Check 4 POL1 allows? 🔍 Check 5 Receipt match? ❌ If ANY check fails → download stops Cleanup deletes half-built room

🔍 Checking the Box at Every Step

At every phase, the Key Factory checks: is the robot genuine? Enough memory? Certificate valid? If any check fails, the download stops immediately. If a connection drops mid-download, a cleanup routine deletes the half-built room and starts fresh: unless the POL1 rulebook says "never delete me!"

Page 7 of 7
🤖 Robot #8721 Net A Net B ✅ 🔄 REFRESH! Network B CONNECTED! After download, profile sits in DISABLED Commander sends ENABLE → robot goes live!

The random challenge in Phase 2 is a clever anti-replay trick. Every time, the robot generates a fresh random number. The Key Factory must sign it. Even if an attacker recorded yesterday's entire conversation, they can't replay it: yesterday's challenge won't match today's! That's forward secrecy in action.

📚 Read the Next Story!

▶️ Next: Turning Missions On and Off →

📖 Back to All Stories