Tech Behind ThingsHow the ordinary machinery actually works

Networks

A SIM card is a small computer that proves who you are

It does not store your phone number and it never hands over its secret. It answers a puzzle the network sets, and that is the whole job.

A modern server room featuring network equipment with blue illumination. Ideal for technology themes.
Photograph by panumas nikhomkhai via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

The options around subscriber identity modules are set out side by side below, with the conditions that genuinely favour one over the other.

The difference in one place

  • The card holds a key that is never transmitted anywhere.
  • Authentication works by answering a challenge, not by sending a password.
  • An embedded SIM is the same secure chip with a downloadable profile.

The card is a processor, not a memory stick

A SIM contains a small processor, a little storage and a secure element designed to resist attempts to read what is inside it. The critical item is a secret key written during manufacture and shared only with the operator that issued the card.

That key never leaves the chip, is never transmitted over the air and cannot be read out through the contacts. Everything else on the card, including the identifier that names your subscription, is comparatively unimportant and largely public in effect. Treating the card as a container for a phone number misses the point entirely; it is a credential holder that performs calculations.

Authentication is a puzzle, not a password

When a phone attaches to a network, the network sends a random challenge rather than asking for anything the card is storing. The card combines that challenge with its secret key using an agreed algorithm and returns only the result of the calculation.

The operator performs the same calculation independently and compares answers, which proves the card holds the key without revealing it. Because the challenge is different every time, an intercepted answer is useless for attaching to the network later on. The same exchange also produces keys used to encrypt the radio link, so authentication and encryption are set up in one step.

Your number is not on the card

The number people dial is a routing label held in the operator's systems and mapped to your subscription, not written into the chip. That separation is why a number can be moved between operators and between cards without physically altering anything you hold.

It is also why a stolen card cannot simply be read to discover the number, and why a replacement card keeps the number. Older cards did store contacts and short messages, which is why the contacts of a decade ago sometimes travelled with the card. Modern phones keep that data in their own storage or in an account, so moving a card now moves the subscription and nothing else.

The card shrank until it disappeared

Successive form factors removed plastic from around the same chip, since the working part was always a small rectangle of silicon. The final step soldered the secure element permanently into the device and made the subscription itself a downloadable file. An embedded subscription is a profile containing the same kind of key material, written into the chip over a secured channel.

At the protocol level, the chip can hold several profiles and activate one or more at a time, which is why one device can carry several subscriptions.

Nothing about the underlying authentication changed; only the way the credential arrives inside the secure element is different.

What changes when the card is embedded

Transferring a subscription now requires the operator's cooperation, because the profile must be issued again rather than physically moved. That is convenient when travelling and awkward when a device fails, since the credential cannot be pulled out and put elsewhere. Losing the ability to swap a card into a borrowed handset removes a genuinely useful fallback that physical cards always provided.

Mechanically, it also concentrates control, because the process of moving a profile is defined by the operator rather than by your fingers. Regulations in some countries require operators to support transfers, so the practical experience varies considerably by jurisdiction.

Firmware updates change this behaviour more often than hardware does.

The weak point is the shop, not the chip

The cryptography protecting a subscription is strong, and attacks overwhelmingly target the process for issuing a replacement instead. Persuading an operator to move a number to a new card is a customer service problem rather than a technical one. Because so many services send confirmation codes by text, control of a number can become control of unrelated accounts entirely.

Many operators now offer a separate passcode or a lock that blocks transfers, and it is usually not enabled by default. Where a service allows an authentication method that does not depend on the number, that method removes the operator from the risk.

Side by side

ConsiderationWhat it means in practice
The card is a processor, not a memory stickThe card holds a key that is never transmitted anywhere.
Authentication is a puzzle, not a passwordAuthentication works by answering a challenge, not by sending a password.
Your number is not on the cardAn embedded SIM is the same secure chip with a downloadable profile.

The takeaway

The card proves something without ever saying it, which is the whole of its design.

Once you know what it is trading away, the design stops looking arbitrary.

Questions readers ask

Can somebody clone my SIM by copying it?

Not by copying the storage, because the key cannot be read out. Historic attacks targeted weak older algorithms that are no longer used.

Does removing the card stop tracking?

It stops the cellular network identifying that subscription, but the device itself has its own identifiers and other radios remain active.

Networksmobilesecurityidentitynetworking
Grigor Petrov
Hardware writer, Tech Behind Things

Grigor writes about silicon, thermals and the physical limits designers keep bumping into.

Also by Grigor Petrov