Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hardware Security Module. Basically an embedded device that stores cryptographic keys and performs cryptographic operations (like encrypting/decrypting/signing).

EDIT: HN is throttling me for responding too quickly so I'm responding to the comment below this. eSIM uses UICC hardware, not unlike a cryptographic smartcard (think PIV or OpenPGP smartcards). It's built upon the same kind of cards as physical UICC (SIM) cards are. You have a CPU, some memory, and the ability to store applets usually written in java. Where eSIM/eUICC is different is it is an implementation of downloadable SIM profiles. The standard does allow for, and there are physical removable eSIM's made. The phone controls profiles on them using apdu commands at the low-leve: https://en.wikipedia.org/wiki/Smart_card_application_protoco... . Check my prior comments on the matter.



I was asking the GP kevincox, but anyway:

What kind of physical hardware is an eSIM composed of?


A small, purpose built chip. The GSM Association refers to it variously depending on audience. For example on their landing page for eSIMs they refer to it as a Secure Element: https://www.gsma.com/esim/

You can get from that page to their technical standards which go into much more detail about hardware for eSIMs.

STMicro makes Arm based ones: https://www.st.com/en/secure-mcus/st4sim-201m.html


Show HN: My eSIM runs DOOM at 30FPS

Ask HN: Installed DOOM on my employer's FIPS-certified HSM; why won't it run?


Look, seriously, you didn't answer the question. An eSIM consists of software. To say that eSIM is UICC is like saying that KDE is a Lenovo ThinkPad.

eSIMs are not HSMs and the GP shouldn't be muddying the waters. SIM cards aren't HSMs. They run apps! Smart Cards aren't HSMs. They have cryptographic functions, but they aren't HSMs!

An HSM is a very specific, physical hardware-based cryptographic device. You'll know it when you see it, and they're designed, labeled, and sold as HSMs with a price to match. No mobile provider is going to let you download no HSM for no $40. Crazy talk.


SIM cards can function like HSMs. Even in the niche security product market, the difference between a $20000 HSM and a $1000 HSM is that the former is filled with epoxy.


My ThinkPad is an IBM mainframe! Look, it adds two numbers together!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: