Your SIM card guards a secret key it will never hand to your phone
Inside every SIM sits a 128-bit key that the chip is built never to reveal, not even to the handset it lives in. Instead the card signs random challenges from the network, proving who you are without exposing the secret. The first 300 of these cards went to a Finnish operator in 1991.
A subscriber identity module is a small integrated circuit, usually mounted on a plastic smart card, whose main job is to hold your international mobile subscriber identity, or IMSI, plus the key that goes with it. Munich smart-card firm Giesecke+Devrient made the first ones in 1991 and sold them to Radiolinja, which opened the world's first commercial 2G GSM network that same year. Early cards were as big as a bank card; later versions shrank several times while usually keeping the same contacts.
Authentication works like a sealed handshake. At start-up the phone reads the IMSI, sometimes after you enter a PIN, and sends it to the operator. The network looks up the matching key, called Ki, generates a random number and signs it, producing a 32-bit response and a 64-bit encryption key. The card receives the same random number, signs it with its own copy of Ki, and the phone forwards the result so the network can compare. Weaknesses in the original GSM algorithm have nonetheless let attackers extract Ki and clone cards.
Each card also carries an ICCID serial number, up to 19 digits under the ITU standard and ending in a Luhn check digit; telecom ones begin with 89. Storage ranges from 8 KB to at least 256 KB, yet every size tops out at 250 contacts. Operators use spare space to list preferred roaming partners, 33 on a 32 KB card and 80 on a 64 KB one.
The industry is enormous: 5.4 billion cards were made in 2016, earning vendors over 6.5 billion dollars. Since around 2020, eSIM, a software profile on a chip soldered inside the device, has begun replacing the removable card in phones.
Source: SIM card