The invention relates to a method for exporting a
telecommunications profile from a source secure element (10) to a target secure element (13) by an LPA of a device comprising the source secure element and the target secure element (10, 13), the method comprising:-sending its
certificate and at least a signed profile ID from the source secure element (10) to the target secure element (13); -verifying, at the target secure element (13), the validity of the
certificate on the basis of the source
certificate and the signature profile ID; if the
verification is positive, sending a signed download request of the configuration file and a certificate of the target secure element (13) from the target secure element (13) to the source secure element (10); -at the source secure element (10), verifying the authenticity of the certificate of the target secure element (13), generating a profile
encryption key PEK and a credential
encryption key CEK; encrypting credentials of the profile with the CEK; -encrypting a profile comprising the encrypted credentials with the PEK; -encrypting the CEK and the PEK as a CEK and a PEK, respectively, with the public key of the target secure element (13); -sending the encrypted profile and PEK from the source secure element (10) to the target secure element (13); -at the target secure element (13), decrypting the received PEK with its private key to obtain a PEK, decrypting the configuration file with the PEK, and installing the configuration file; -sending a first signature message from the target secure element (13) to the source secure element (10) indicating that the configuration file has been successfully installed; -at the source secure element (10), when a first signature message indicating that the configuration file has been successfully installed is received, removing the configuration file and sending to the target secure element (13) a CEK and a second signature message with a private key of the source secure element (10) indicating that the configuration file in the source secure element (10) has been successfully removed; -at the target secure element (13), verifying the validity of the second signature message, decrypting the CEK to obtain the CEK, and decrypting the credential with the CEK.