Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a21ca36e5fd0bd4a

Jump to content

Remote SIM provisioning

From Wikipedia, the free encyclopedia

Remote SIM provisioning is a GSMA specification that allows consumers to remotely activate the subscriber identity module (SIM) embedded in a portable device such as a smart phone, smart watch, fitness band or tablet computer.[1][2] Originally part of the GSMA's work on eSIM,[3] remote SIM provisioning is just one of the aspects Remote SIM provisioning includes. The other aspects are that the SIM is now structured into "domains" that separate the operator profile from the security and application "domains." In practice, "eSIM upgrade" in the form of a normal SIM card[4] is possible (using the Android 9 eSIM APIs), or eSIM can be included in an SOC.[5] GSMA certification requires that the personalization packet is decoded inside the chip, so there is no way to dump Ki, OPc and 5G keys. Another important aspect is that the eSIM is owned by the enterprise[clarification needed], which means that the enterprise now has full control of the security and applications in the eSIM, and which operator profiles are to be used.

Background to the specification

[edit]

In the background of the technology, the following issues were looked into:

  • The development of non-removable SIM technology - a new generation of SIM cards (like MFF) which are soldered into the device.
  • The appearance and support by mobile operators of the concept of ABC (always best connected) – the opportunity to get quality connections from any mobile operator at any point in time.
  • The explosive growth of Internet of Things (IoT) devices - according to Gartner, about 8.4 billion connections in 2017 (up 31% from 2016).[6]
  • The cost and effort required to swap a SIM in a device that has been deployed in the field.

Origin

[edit]

The GSM Association (GSMA), which brings together about 800 operators and 250 mobile ecosystem companies, became the first to come up with the Consumer Remote SIM Provisioning initiative. The technology was announced in the summer of 2014. The complete version of the specification was released in February, 2016. Initially, the specification was supposed to be used just by M2M devices, but since December, 2015, it has started to spread over various custom wearable devices, and into enterprise applications like authentication and identity management.[7]

"This new specification gives consumers the freedom to remotely connect devices, such as wearables, to a mobile network of their choice and continues to evolve the process of connecting new and innovative devices," Alex Sinclair, Chief Technology Officer, GSMA.[8]

Besides, the right of independent service providers to transmit commands for loading profiles to SIM cards in the device has been amended, and the possibility to store arrays of profiles in independent certified data centers (Subscriptions manager) has appeared.[9]

Functions and benefits

[edit]

The specification that covers the carrier selection aspects aims to allow consumers to choose a mobile network operator from a wide range to activate the SIM embedded in a device via a subscription. It aims to simplify users' lives by connecting their multiple devices through the same subscription. It should also motivate mobile device manufacturers to develop the next generation of mobile-connected devices that will better suit wearable technology applications. The specification that covers the carrier selection for M2M devices is simpler since typically there is no subscriber involved (e.g., changing the operator in an electricity meter).

The language that is used to describe this specification can be confusing since eSIM is not a physical format (or "form factor" - the phrase used to describe the various SIM sizes). The eSIM describes the functionality in the SIM, not the physical size of the SIM - and there are eSIMs in many formats (2FF, 3FF, 4FF, MFF)[10].

GSMA has also developed a compliance framework[11] for eSIM devices, eUICCs, and subscription management products - to help with interoperability and security for products supporting eSIM. This is published by the GSMA as SGP.24.[12] The eSIM compliance process describes common compliance requirements for:

  • Functional interoperability
  • eUICC security
  • eUICC production site security
  • Subscription Management site security

Operation

[edit]

For consumer devices, remote provisioning on the host device is initiated by the Local Profile Assistant (LPA), a software package that follows the consumer eSIM RSP specifications SGP.21/22 [13][14].

When the LPA wants to retrieve a carrier profile, it contacts a subscription manager (SM) service on the internet via HTTPS. The address of the SM can be defined:

  • in a QR code scanned by the user
  • by manually entering the SM's host name/activation code on screen
  • hard-coded by the host device manufacturer in firmware.
  • via a universal discovery service operated by the GSMA.

The LPA is responsible for validating that the X.509 certificate of the SM is valid and issued by the GSMA certificate authority.[15] Once validation is complete, the LPA will coordinate a secure channel between the eUICC and the SM using challenge-response authentication to enter programming mode. The LPA will request carrier profiles available for download, either by submitting the activation code provided by the user or the eSIM ID (EID) of the eUICC. The SM will provide the requested profile encrypted in a way that only the eUICC can decrypt/install to ensure the network authentication key remains secure.

RSP works slightly differently for IoT devices, following GSMA's technical specifications as outlined in SGP.31/32 [16]. The eSIM IoT specification replaces the LPA with IPA (IoT Profile Assistant) that lives either in the eUICC (IPAe) or the device (IPAd). Remote SIM Provisioning in IoT is managed in a new technical component, the eIM (eSIM IoT Manager) – the software that sends the user commands to the IPA [17].

References

[edit]
  1. "eSIM — Что это и как подключить в России" (in Russian). Retrieved 2020-09-22.
  2. GSMA releases remote provisioning specification to help consumers connect mobile devices http://www.gsma.com/rsp/
  3. "The SIM for the next Generation of Connected Consumer Devices - eSIM". eSIM. Retrieved 2018-03-01.
  4. "eSIM.me Store". esim.me. Retrieved 2022-05-28.
  5. "Vodafone, Qualcomm Technologies, and Thales Deliver World-First Smartphone Demonstration of Integrated SIM (iSIM) Technology | Qualcomm". www.qualcomm.com. Retrieved 2022-05-28.
  6. "Gartner Says 8.4 Billion Connected". Retrieved 2018-03-01.
  7. "BTG E-SIM project enters next phase - BTG". BTG (in Dutch). 2016-06-14. Retrieved 2018-03-01.
  8. "GSMA Remote Provisioning Release". 18 February 2016.
  9. Jhon, Jackson. "Esim Global". Retrieved 25 February 2024.
  10. "What are eSIMs? And when to use them for IoT – Onomondo". onomondo.com. 2023-06-27. Retrieved 2026-04-13.
  11. "GSMA eSIM Compliance Process".
  12. "GSMA SGP 24".
  13. "SGP.22 V3.1". eSIM. Retrieved 2026-04-13.
  14. "SGP.02 vs SGP.22 vs SGP.32: eSIM IoT in dialogue with M2M and consumer eSIM - Onomondo". onomondo.com. 2026-02-05. Retrieved 2026-04-13.
  15. "GSMA Certificate Issuer (CI)". eSIM. Retrieved 2022-01-22.
  16. "SGP.32 v1.1". eSIM. Retrieved 2026-04-13.
  17. "What is GSMA SGP.32? Diving into the eSIM IoT standard - Onomondo". onomondo.com. 2025-05-25. Retrieved 2026-04-13.