eUICC
ProvisioningEmbedded Universal Integrated Circuit Card -- a reprogrammable SIM chip that can securely download and switch between multiple operator profiles without physical SIM swapping. The eUICC contains a secure element with an ISD-R (Issuer Security Domain - Root) that manages profile lifecycle operations through standardized GSMA interfaces.
eUICC (Embedded Universal Integrated Circuit Card)
The eUICCeUICCProvisioningReprogrammable SIMSIMApplicationSmart card for mobile network authentication.Click to view → chip supporting remote profile switching.Click to view → is a secure element designed specifically for remote SIM provisioning. Unlike traditional removable SIM cards that carry a single operator profile soldered or socketed into a device, the eUICC is a reprogrammable chip — typically soldered directly onto the device motherboard — capable of securely downloading, storing, and switching between multiple operator profiles over the air.
Architecture
The eUICC contains an ISD-R (Issuer Security Domain - Root) that serves as the trust anchor for all profile management operations. Each downloaded profile resides in its own ISD-P (Issuer Security Domain - Profile), providing cryptographic isolation between operators. The GlobalPlatform framework manages applet lifecycle within each domain.
Key components inside the eUICC:
- ECASD (eUICC Controlling Authority Security Domain) — holds the eUICC certificate and private key for SM-DP+ authentication
- ISD-R — root domain managing profile installation, enabling, disabling, and deletion
- ISD-P (per profile) — isolated container for each operator profile's NAA, file system, and applets
- LPA services — device-side interface for profile discovery and management
Standards and Specifications
The GSMA defines two RSPRSPApplicationOver-the-air SIM profile management.Click to view → architectures:
| Aspect | Consumer (SGP.22) | M2M (SGP.02) |
|---|---|---|
| Profile delivery | SM-DP+ direct to eUICC | SM-DP via SM-SR |
| Management | User-driven via LPA | Platform-driven remotely |
| Target devices | Smartphones, wearables | IoT modules, automotive |
| Confirmation | User consent required | Automated |
The eUICC chip itself must be Common Criteria certified (typically EAL 4+ with AVA_VAN.5) to ensure tamper resistance of stored profiles and cryptographic operations.
Deployment Considerations
Modern eUICC implementations support 5-15 simultaneous profiles depending on available EEPROM or flash memory. Profile download uses ECKA (Elliptic Curve Key Agreement) to establish a secure channel between the SM-DP+ and eUICC, ensuring that profile data — including IMSI, Ki, and OPc — is never exposed during transit. The RSP specification requires mutual authentication before any profile operation proceeds.
Related Content
TEE vs Secure Element
Security…Depends on threat model SIM / eSIM N/A Yes — eUICC GSMA SESP, separate die Enterprise PIV No Yes NIST SP…
eSIM and Remote SIM Provisioning
Industry Applications…Assistant On-device agent managing profile lifecycle LPA eUICC (eSIM chip) Secure vault storing profiles eUICC The SM-DP+…
Smart Card in IoT
Industry Applications…SE + modem in single package Miniaturised IoT, wearables eUICC (eSIM) Reprogrammable SE for cellular M2M, connected…
SIM to eSIM Migration Guide
Industry Applications…OTA channel to deliver encrypted operator profiles to the eUICC chip. eSIM Ecosystem Readiness Assessment Before…
Sıkça Sorulan Sorular
The smart card glossary is a comprehensive reference of technical terms, acronyms, and concepts used in smart card technology. It covers protocols (APDU, T=0, T=1), security (Common Criteria, EAL, HSM), hardware (SE, EEPROM, contact pad), and applications (EMV, ePassport, eSIM). It serves developers, product managers, and engineers.
Yes. SmartCardFYI provides glossary definitions in 15 languages including English, Korean, Japanese, Chinese, Spanish, Portuguese, Hindi, Arabic, French, Russian, German, Turkish, Vietnamese, Indonesian, and Thai.