A method for preparing content to be provided from a
hardware security module, HSM, to an integrated secure element, iSE, comprising: a) providing in the HSM a pre-shared key PSK derived from a first seed (S1) and a generic key derivation constant KDC permanently stored in the iSEs, where the KDC is identical for a large number of multiple iSEs and the first seed (51) is specific or unique for a specific content provider (CP) of the content; b) in the HSM, providing a second seed (S2) that is specific or unique to the iSE and applying a CEK key derivation scheme based on the PSK and the second seed in order to derive a code
encryption key CEK; c) in the HSM, encrypting the code packet with a code
encryption key CEK and by applying a code
encryption scheme in order to generate an encrypted code packet (OS packet); d) in the HSM, generating a header comprising a second seed (S2) and, if needed, further: information about the code encryption scheme of step c) or / and information about the CEK key derivation scheme of step b); e) in the HMS, encrypting the header using the PSK or a header encryption key derived from the PSK and applying a header encryption scheme to generate an encrypted header (Header), f) in the HSM, merging the encrypted code packet (OS packet) and the encrypted header (Header) in order to create a
binary large object BLOB to be transmitted to the iSE.