ENTERPRISE IDENTITY

One identity. Secured in the eSIM.

SaferSIM turns the eUICC already inside the employee’s phone into a personal, hardware-backed trust anchor – for SSO and VPN, certificate login and high-security physical access.

3 pages · English · PDF

Illuminated eSIM chip inside a smartphone
USER-HELD IDENTITY The trust anchor travels with the employee – inside the phone.
01One profile across access paths
02Non-exportable private key
03Local approval on the phone
04Central provisioning and revocation

THE IDENTITY MODEL

Enterprise access without centralising the key.

Passwords, PC certificates, VPN tokens and access credentials often live in separate systems. SaferSIM brings the trust anchor into the employee’s phone. Enterprise policy stays exactly where it belongs: with the enterprise.

01 / PROFILE

User-held identity

Profile, private key and approval remain hardware-protected with the person who uses them.

02 / KEY

Non-exportable

The P-256 key signs inside the eSIM. It is not stored on the PC or in a cloud service.

03 / DECISION

Approved locally

Service and purpose appear on the phone. The request proceeds only after local SaferSIM PIN approval.

04 / LIFECYCLE

Managed at enterprise scale

Profiles can be provisioned, rotated, suspended and revoked across multiple access paths.

THREE USE CASES

Start with one access path. Extend later.

SaferSIM does not replace your identity or physical-access platform. It adds a hardware-bound approval layer that stays with the employee.

01 / WORKFORCE ACCESS

SSO and optional VPN

The employee sees the service and purpose, approves locally and returns an eSIM-signed proof. The existing identity platform decides whether access is granted.

OIDCSAMLoptional RADIUSAndroid & iOS

Outcome: one auditable approval path for office, home and mobile work.

SaferSIM approval for enterprise access on a smartphone
Employee accessing enterprise systems securely
02 / CERTIFICATE LOGIN

Entra ID and managed PCs

The SaferSIM PC Connector routes the certificate challenge to the phone. The signature is produced by the non-exportable key inside the eSIM.

Microsoft Entra IDX.509Managed PCsPC Connector

Outcome: no private key stored on the PC – not even as an exportable file.

03 / HIGH-SECURITY ACCESS

Digital proof for physical doors

A badge or app, local PIN and optional independent face and liveness verification are bound to one access request. The existing PACS still makes the final decision.

PACS adapterPINFace & livenessTransaction binding

Outcome: identity, intent and presence can be combined in one verifiable assertion.

Employee approving access at a secured building entrance

END-TO-END TRUST CHAIN

Four stages. Clear responsibility.

SaferSIM routes the request to the right profile, protects local approval and returns the signed proof. The connected enterprise system remains the final authorisation point.

01
RELYING PARTY

A fresh request

SSO, VPN, Entra ID, a PC Connector or PACS creates a challenge with service, purpose and policy context.

02
SAFERSIM SERVER

Validate and route

The server validates the customer and request, routes the challenge to the right profile and retains audit evidence.

03
PHONE + eUICC

Approve locally

The user sees the context. After local approval, the non-exportable key signs the bound response.

04
ENTERPRISE DECISION

Evaluate the proof

The identity provider, application, VPN gateway or PACS verifies the assertion and remains the final decision point.

TECHNOLOGY & BOUNDARIES

Built into your existing infrastructure.

The core path works without an additional authenticator app. Where a richer interface or biometrics are required, an app can be added while the private key remains inside the eSIM.

TLS 1.3P-256HMAC-SHA-256SCP03X.509OIDCSAMLRADIUSSGP.07TS 102 223
ENTERPRISE WEB / API

HTTPS with TLS 1.3

Protects web and API endpoints with confidentiality, server authentication and transport integrity.

eUICC RUNTIME

BIP/TCP, HMAC-SHA-256 and P-256

Provides message integrity, replay protection and device proof. The final confidentiality profile is qualified for the selected eUICC and MNO combination.

PROFILE PROVISIONING

SCP03/AES or equivalent

Protects profile and key loading plus lifecycle operations. This provisioning path is separate from the runtime channel.

ENTERPRISE FEDERATION

X.509, OIDC, SAML and adapters

Connects SaferSIM to the existing identity and access estate. Enterprise policy remains authoritative.

RECOMMENDED PAID PILOT

One workflow. Eight weeks. Clear acceptance criteria.

We start with the highest-value access path and qualify the exact eUICC, MNO, device, firmware and provisioning combination selected for it.

Request a pilot
8weeks from scope to decision
50users in a clearly bounded pilot
1primary integration with selected devices
5 daysto a fixed-price proposal after workflow selection
01 / SCOPESelect the workflow

Define users, devices, partners and acceptance criteria.

02 / INTEGRATEConnect

Implement one identity, VPN, PC or physical-access integration.

03 / VALIDATEMeasure

Check completion, response time, lifecycle, audit evidence and feedback.

04 / DECIDEScale

Document results, remaining items and the next production scope.

ENTERPRISE 3-PAGER

The solution, ready to share with your team.

The 3-pager covers the identity model, three use cases, technical architecture, explicit security boundaries, standards and the recommended pilot scope.

Download the PDF

3 pages · English · approx. 640 KB

NEXT STEP

Which access path should we secure first?

Select one workflow. We will align the target system, devices and acceptance criteria and turn them into a pilot scope.

kratz@safersim.com · wulf@safersim.com