Login
User Agreement & LicensingPrivacy Policy
FIPS 140-3
Common Criteria EAL5+

Products

  • ProvenHSM
  • ProvenBox
  • Native Security Applications
  • Software Developer Kit (SDK)
  • ProvenCore OS and TEE
  • ProvenVisor

Use Cases

  • Data Protection
  • PQC Migration
  • Key Management & Cloud KMS
  • Confidential Computing
  • Finance Innovation
  • Digital Signature (eIDAS 1.0)
  • Wallet & Identity (eIDAS 2.0)
  • Multi-Party Computation (MPC)
  • Enterprise PKI
  • Strengthening HPC Platforms

Resources

  • Blog and Whitepapers
  • Security and Certifications
  • Integrations

Company

  • Careers
  • About
All customer stories

Orange — Telecommunications

Securing Secure Element Provisioning at Carrier Scale

Digital Lock
Orange Logo

Company

Orange

HQ

Paris, France

Industry

Telecommunications

Focus

eSIM provisioning, secure elements, subscriber credentials

Products used

  • ProvenCore
  • Native Security Application
Subscriber credentials are the one asset we cannot afford to get wrong, across hundreds of device models we do not control. A certified base that every model inherits is the only version of that problem we can realistically staff.
Full nameJob title

Key outcome

Certified Isolation for Subscriber Credentials

Subscriber credentials are among the most attacked assets a carrier holds. Running the provisioning path inside a formally verified environment means the code handling those credentials is separated from the rest of the device software by a boundary that has been mathematically proven, not just tested.

More customer stories

Metal Processor
Bull Logo

High-performance computing

Strengthening HPC Platform Integrity with ProvenCore

Digital Cloud
OVH Cloud Logo

Cloud infrastructure

Running Sovereign Key Management on Certified Infrastructure

The challenge

Assurance Requirements That Scale Across Device Generations

The GSMA’s eUICC Protection Profile allows a composite evaluation in which secure hardware and the operating system are certified once, and applications such as USIM or ISIM are evaluated independently on top. Realising that model in practice requires a base platform whose isolation properties hold across every device generation it ships on.

The solution

A Shared Certified Platform for Multiple Trusted Applications

ProvenCore is aligned with GlobalPlatform TEE specifications, so existing Trusted Applications can be reused rather than rewritten. Multiple operators and profiles coexist securely on the same chip, each evaluated independently, without restarting the whole evaluation when one of them changes.

Being able to reuse our existing trusted applications meant the migration was an integration project rather than a rewrite.
— Full name, Orange
Previous storyOVHcloudNext storyRenault
Digital Processor
Renault Logo

Automotive

Hardening Connected Vehicle Gateways and OTA Updates

Explore ProvenHSM
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo
Bull Logo
Safran Logo
BMW Logo
DGA Logo
Atos Logo
Renault Logo
Microsoft Logo
Orange Logo
OVH Cloud Logo
ST Microelectronics Logo