SM-DP+
ProvisioningSubscription Manager - Data Preparation Plus is the server-side component in the GSMA RSP architecture responsible for securely generating, storing, and delivering operator profiles to eUICC devices. SM-DP+ establishes a secure channel with the target eUICC using ECKA key agreement before transmitting encrypted profile data.
SM-DP+ (Subscription Manager - Data Preparation Plus)
SM-DP+ is the server-side component in the GSMA consumer RSP architecture (SGP.22) responsible for securely preparing, storing, and delivering operator profiles to eUICC devices. It replaces the earlier SM-DP/SM-SR split used in M2M deployments with a unified, consumer-friendly server that communicates directly with the target SIM chip supporting remote profile switching." data-category="Provisioning">eUICC.
How SM-DP+ Works
The profile delivery process follows a strict cryptographic protocol:
- Profile ordering — The mobile operator submits a profile order to SM-DP+, including IMSI, Ki, OPc, and network access configuration
- Profile packaging — SM-DP+ encrypts the profile data into a bound profile package (BPP) targeted at a specific eUICC EID
- Secure channel — When the device's LPA initiates download, SM-DP+ and eUICC perform mutual authentication using ECC certificates
- Key agreement — ECKA (Elliptic Curve Key Agreement) establishes session keys for profile encryption
- Delivery — The encrypted profile segments are transmitted and installed into an ISD-P on the eUICC
Security Model
SM-DP+ maintains a certificate chain rooted at the GSMA CI (Certificate Issuer). Each SM-DP+ must be certified by the GSMA to operate in the global eSIM ecosystem. The server never transmits profile credentials (Ki, OPc) in plaintext — all sensitive data is encrypted end-to-end between SM-DP+ and the target eUICC's ECASD.
Architecture Comparison
| Feature | SM-DP+ (Consumer) | SM-DP (M2M) |
|---|---|---|
| Standard | GSMA SGP.22 | GSMA SGP.02 |
| Communication | Direct to eUICC via LPA | Via SM-SR |
| User interaction | Required (consent) | Automated |
| Profile binding | Per-EID or generic | Per-EID |
| Deployment scale | Billions of consumer devices | IoT/automotive fleets |
Major SM-DP+ platform vendors include Thales, Idemia, Giesecke+Devrient, and Valid, each operating globally redundant infrastructure to support real-time profile delivery.
Sıkça Sorulan Sorular
The smart card glossary is a comprehensive reference of technical terms, acronyms, and concepts used in smart card technology. It covers protocols (APDU, T=0, T=1), security (Common Criteria, EAL, HSM), hardware (SE, EEPROM, contact pad), and applications (EMV, ePassport, eSIM). It serves developers, product managers, and engineers.
Yes. SmartCardFYI provides glossary definitions in 15 languages including English, Korean, Japanese, Chinese, Spanish, Portuguese, Hindi, Arabic, French, Russian, German, Turkish, Vietnamese, Indonesian, and Thai.