Skip to content

Independent remote SIM provisioning laboratory

Remote SIM Provisioning, built from the public specifications.

SM-DP+, eIM, SM-DP and SM-SR, a TS.43 entitlement server with CAMARA network APIs, IMS calls, SMS and online charging, an OTA platform, an LPA and a software eUICC — deployed, interoperating, and installing real profiles onto emulated and physical cards.

For engineers working with remote SIM provisioning and OTA: watch it run, sign in and use it, or read the specifications behind it.

An independent laboratory on the GSMA SGP.26 test PKI and TS.48 test profiles.

23
Deployed services
12
Public hostnames under one apex
1
Identity issuer for every service

Start here

Three ways in

What you can check

Four properties you can verify

  • Nothing simulated in the middle

    Every leg, from the ES2+ order to the signed install notification, runs in this implementation. The recordings are of the deployed services.

  • Every claim names its specification

    Each capability traces to a published GSMA, ETSI, 3GPP, TCA or GlobalPlatform document, named on this page.

  • Every octet inspectable

    Profile packages decode to typed trees mapped to their bytes; APDUs and secured packets are shown field by field in both directions.

  • No card reader required

    A software eUICC stands in for the card. Unmodified LPA and IPA software drives it over the real protocol, and it runs real CAP files.

SGP.22 — Consumer

One profile, from ES2+ order to install notification

A profile ordered over ES2+ reaches the eUICC over ES9+ and ES10, installs, and returns a signed notification the SM-DP+ accepts. Every leg runs in this implementation.

  1. 01 Order

    ES2+ DownloadOrder and ConfirmOrder reserve an ICCID and produce an activation code.

  2. 02 Authenticate

    Common mutual authentication between eUICC and SM-DP+ over the SGP.26 test PKI.

  3. 03 Bind

    The SM-DP+ builds the Bound Profile Package: key agreement, metadata and the profile under SCP03t.

  4. 04 Install

    The LPA segments the package into ES10b STORE DATA commands.

  5. 05 Notify

    The signed ProfileInstallationResult is returned and the order closes.

An SGP.22 download from the lab SM-DP+ onto an emulated eUICC.

SGP.32 — IoT

The same download, requested by an eIM

A device without a user interface cannot take an activation code. The eIM keeps a package queue per eUICC; the IPA polls over ESipa and executes each package as an ordinary SGP.22 download against the same SM-DP+.

The eIM console queueing a download, a profile list and an eUICC data request; the IPA on Android executing each and reporting back.

  1. 01 Register

    The eIM associates the eUICC by EID with a replay counter, so each package runs once.

  2. 02 Queue

    An eUICC Package, here a profile download, is queued for the device.

  3. 03 Poll

    The IPA requests pending work over ESipa. Nothing is pushed; the device chooses when to ask.

  4. 04 Execute

    The package becomes an SGP.22 download over ES9+ and ES10. The SM-DP+ sees no difference.

  5. 05 Report

    The signed result goes back to the eIM and the counter is consumed.

SGP.02 — M2M

Provisioned entirely from the network

SGP.02 has no device-side agent. The SM-SR is the only party that reaches the eUICC: it creates the ISD-P, routes the profile into it as secured packets, and holds the authoritative profile state.

The SM-DP and SM-SR consoles downloading and enabling a profile on an emulated M2M eUICC; a relay stands in for the SMS bearer. Notification redacted.

  1. 01 Order

    ES2 DownloadProfile names the EID, profile type and SM-SR. The SM-DP reserves an ICCID.

  2. 02 Create

    Over ES3 and ES5, the SM-SR sends INSTALL to the ISD-R and the ISD-P is created.

  3. 03 Bind

    Key establishment against the ECASD key from the EIS; the profile becomes an ES8 script under SCP03t.

  4. 04 Deliver

    The script reaches the ISD-P as SCP80 secured packets addressed to its TAR.

  5. 05 Enable

    ES4 then ES5 to the ISD-R. The SM-SR's EIS records the resulting profile state.

TS.43 — Entitlement

What a line may use, and moving it to a new phone

After install, the device asks the operator's entitlement server what the line may use — VoWiFi, 5G, satellite, a companion eSIM — and the same server moves the line to a new eSIM on a device change. GSMA TS.43, authenticated with EAP-AKA. The same line then answers an application's CAMARA questions through a TS.43 operator token, and reports its data usage from the lab's charging function.

The entitlement console and a TS.43 client on Android: a line's services, then its transfer to a new eSIM.

  1. 01 Authenticate

    EAP-AKA against the lab AAA and HSS; the SIM answers the challenge and the device gets a token.

  2. 02 Ask

    The device requests its entitlements; each service returns a state set per line.

  3. 03 Agree

    Transfer rules per line: old-device attestation, terms acceptance or a one-time code.

  4. 04 Move

    An ES2+ order to the SM-DP+, an SGP.22 download to the new eSIM, and the old profile retired.

TS 102 226 — OTA

Remote file and applet management on an issued card

The OTA platform builds ETSI secured packets under the card's own keys and delivers them over SMS-PP, or has the card open an SCP81 session over HTTPS. RFM edits the file system; RAM loads, installs and removes applets through the Issuer Security Domain.

The OTA console sending RFM and RAM scripts to a SIM on an emulated card over SMS-PP and SCP81, with each packet decoded.

  1. 01 Provision

    KIc, KID and an SCP81 PSK are generated per SIM and written to its security domain. Only check values leave the service.

  2. 02 Secure

    Each Command Packet carries SPI, TAR and a replay counter, ciphered and MAC'd per TS 102 225, then concatenated over SMS.

  3. 03 Execute

    RFM reads and updates EFs such as EF(SMSP) and EF(SMS). RAM sends INSTALL [for load], LOAD and INSTALL [for install] to the ISD.

  4. 04 Prove

    The Proof of Receipt returns the security status and last status word; GET STATUS confirms the registry.

  5. 05 HTTPS

    An SCP81 trigger has the card open a TLS-PSK session and pull the same script: no SPI, no counter, no segmentation.

Instruments

The layers under the protocol, made inspectable

When a download fails, the cause is usually in a DER structure or an applet — neither of which a provisioning console shows. Both tools run in a browser against the same lab.

ASN.1 Editor

asn1-editor.rsplab.click

Decodes TCA Interoperable Profile Packages against the SAIP schema into typed trees mapped to their bytes, re-encodes edits to DER, and flags inconsistencies. An edited package can be installed on an emulated device through the lab SM-DP+. Also decodes the 184 SGP.22 v3.0 message types.

Decoding and editing a TS.48 test profile, then installing it on an emulated device.

AppletLab

appletlab.rsplab.click

UICC toolkit applets written in Java in the browser, converted to CAP and loaded onto an interpreted card with standard GlobalPlatform commands. An emulated handset drives proactive commands and envelopes, with every APDU shown in both directions.

Building and installing toolkit applets, then driving them from an emulated handset.

Try it

Sign in once, then open a console

Every console sits behind one identity issuer, sso.rsplab.click, with Google or email sign-in. New accounts get read access to the ASN.1 Editor; other consoles answer No access until a grant is added.

Ask for access

Say which console you want to try, and why.

What is running

Named by their role in the standards

Grouped by architecture: server, console and device-side client together. Clients run on a handset or bench and are marked as such. Repositories are private.

Consumer provisioning

4

SGP.22 end to end: the SM-DP+, its inventory and console, and the LPA that installs the profile.

  • SM-DP+

    Consumer remote SIM provisioning: prepares, binds and delivers a profile to an eUICC.

    smdpplus.rsplab.click

    • GSMA SGP.22
    • ES2+
    • ES8+
    • ES9+
  • SM-DP+ administration service

    Profile inventory, lifecycle and ES2+ order management behind the SM-DP+.

    • GSMA SGP.22
    • ES2+
  • LPA

    Java Local Profile Assistant: the device-side half of a consumer profile download.

    not hosted — runs on the device

    • GSMA SGP.22 v3.0
    • ES9+
    • ES10a/b/c

IoT provisioning

3

SGP.32 for devices without a user interface. The eIM decides what a device should do; the IPA executes it.

  • eIM

    Remote SIM management for IoT devices: per-eUICC package queues collected by the IPA over ESipa.

    eim.rsplab.click

    • GSMA SGP.32
    • ESipa
    • ES9+
  • eIM console

    The administrative plane over the IoT eSIM manager: devices, associations and profile state.

    eim.rsplab.click/console

    • GSMA SGP.32
  • IPA

    IoT Profile Assistant: the on-device agent for constrained devices under SGP.32.

    not hosted — runs on the device

    • GSMA SGP.32
    • ESipa
    • ES10b

M2M provisioning

4

SGP.02: SOAP over ES2 and ES3, and platform management of the eUICC over ES5.

  • SM-DP (M2M)

    Data preparation in the older M2M provisioning architecture.

    smdp.rsplab.click

    • GSMA SGP.02 v4.3
    • ES2
    • ES3
  • SM-SR (M2M)

    Secure routing and eUICC platform management for M2M.

    smsr.rsplab.click

    • GSMA SGP.02 v4.3
    • ES3
    • ES5

Device entitlement

2

TS.43: service entitlement per line, and companion or primary eSIM activation ordered from the SM-DP+ over ES2+.

  • Entitlement server

    Tells a device which services it may switch on, and activates companion and primary eSIMs over ODSA.

    entitlement-server.rsplab.click

    • GSMA TS.43 v13.0
    • ODSA
    • ES2+
  • Entitlement console

    Operator view over subscribers, devices and the entitlements each one holds, and the lab's emulated phones: their texts, calls, data usage and CAMARA developer clients.

    entitlement-server.rsplab.click/console

    • GSMA TS.43

Network APIs, voice, SMS & charging

4

What the network knows and carries, offered to applications and counted: CAMARA APIs authorized with TS.43 operator tokens, IMS calls and SMS between lab phones, and online charging over Nchf, Gy and Ro for data and minutes.

  • Network APIs (CAMARA)

    Answers applications' questions about a line: SIM Swap, Number Verification and Device Reachability, with event subscriptions, and texts one-time codes to it; authorized by TS.43 operator tokens.

    api.rsplab.click/camara

    • CAMARA ICM r4.2
    • SIM Swap
    • Number Verification
    • Device Reachability Status
    • One Time Password SMS
    • OIDC CIBA
  • IMS core

    Registers lab phones for calls with IMS AKA, calls between them charged by the second, and keeps their forwarding, barring and caller ID; a bridge lets a local IMS use the same HSS.

    • 3GPP TS 24.229
    • TS 33.203 (IMS AKA)
    • TS 24.623 (Ut)
    • TS 24.604/24.607/24.611
    • TS 23.204 (SMS over IP)
  • SMS service (SMSC)

    Holds each lab message as a real SMS until the phone collects it, lets phones text each other on their plan, holds texts while a phone is in airplane mode, delivers OTA packets to a card, and takes SMS over IP from the IMS.

    • 3GPP TS 23.040
    • TS 23.038
    • TS 24.011
    • TS 29.338 (S6c)
    • TS 32.274
    • TS 31.111 (SMS-PP DOWNLOAD)
  • Charging function (CHF)

    Online charging for data, minutes and messages: grants quota in slices, charges each text as one event, and stops or redirects a session, or cuts a call, when the allowance runs out.

    • 3GPP TS 32.291 (Nchf)
    • TS 32.299 (Gy, Ro)
    • TS 32.260
    • TS 32.274 (SMS)
    • RFC 8506

Integration

1

Every integration API documented in one place and callable from the browser: get a token, then try a request against the live services.

  • API reference (Swagger)

    OpenAPI documents for the integration APIs of the SM-DP+, eIM, SM-DP, SM-SR, entitlement server and CAMARA network APIs, callable live through the integration gateway with an estate token.

    swagger.rsplab.click

    • OpenAPI 3
    • OAuth 2.0 client credentials

Over the air

3

Managing an issued card: RFM and RAM in ETSI secured packets over SMS-PP, CAT_TP and BIP, or SCP81 over HTTPS. Driven from the console or from a phone against a real reader.

  • OTA platform

    ETSI secured packets over SMS-PP, CAT_TP and BIP, and SCP81 sessions over HTTPS.

    ota.rsplab.click

    • ETSI TS 102 225
    • TS 102 226
    • SCP80
    • SCP81
  • OTA console

    Build, send and decode ETSI secured packets: RFM and RAM over SMS-PP and SCP81, with proof of receipt.

    ota.rsplab.click/console

    • ETSI TS 102 225
    • TS 102 226
  • Telecom toolkit

    Android toolkit that drives the lab from a phone — OTA, SGP.32 relay and card access.

    not hosted — runs on the device

    • ISO 7816
    • CCID
    • APDU relay

eUICC, IPP & applets

4

A software eUICC all three architectures provision, the editor for the packages they install, and the toolchain for the applets that run on it.

  • eUICC emulator

    A software eUICC speaking SGP.22 and SGP.32, with a GlobalPlatform card manager that loads real applets.

    simulator.rsplab.click

    • GSMA SGP.22
    • SGP.32
    • GlobalPlatform
  • ASN.1 Editor

    Web editor for TCA Interoperable Profile Packages and SGP.22 structures, decoding and re-encoding real DER.

    asn1-editor.rsplab.click

    • ASN.1 DER
    • TCA IPP
    • GSMA SGP.22
  • AppletLab

    Write a UICC applet in the browser, compile it and run it against an interpreted card.

    appletlab.rsplab.click

    • Java Card
    • GlobalPlatform
    • ISO 7816
  • CAP converter

    A Java Card converter: class files in, CAP files out.

    not hosted — runs on the device

    • Java Card
    • CAP
    • JCA export

Mobile core

2

The core the rest of the lab authenticates against, and the signalling of a card attaching: EAP-AKA over SWm and SWx, and pcaps dissected into reports.

  • AAA and HSS

    Authenticates a SIM for the entitlement server and for Wi-Fi calling, and is the IMS home subscriber server: registration over Cx, call settings over Sh, and where each phone is attached for SMS (S6c).

    • 3GPP TS 29.273 (SWm, SWx)
    • TS 29.228/29.229 (Cx)
    • TS 29.328/29.329 (Sh)
    • TS 29.338 (S6c)
    • RFC 4187 EAP-AKA
    • Diameter
  • EPC signalling analysis

    A pcap lands in S3, a Lambda dissects the EPC signalling and the result is served as a static report.

    open5gs.rsplab.click

    • 3GPP NAS
    • S1AP
    • Diameter
    • GTP

Where the detail is

Every system above is owned by a private repository, so none is linked — a link that resolves to a 404 for every reader is worse than plain text. The architecture, the protocol flows and the console manuals are documented in the open instead, at docs.rsplab.click — with the request and response of every call taken from the code rather than described. The integration APIs can be tried from the browser at swagger.rsplab.click .

Provenance

Everything here comes from a document anyone can download

Each component was written from the published specification. Nothing derives from a proprietary or third-party implementation.

About

Why this exists

I build secure infrastructure for connectivity and digital identity — from the applet inside a secure element to the cloud platform that provisions it. This laboratory is where I work through the specifications properly: on my own time, on my own account, from public documents.

A standard is not understood until something you wrote makes a real card answer. Everything here exists because reading the document was not enough.

Built by

Amin Bakhtvar

Telecommunications & Cloud Engineer

Madrid, Spain

Next step

Try the lab, or ask about any of it.

Questions on remote SIM provisioning, OTA and secure elements are welcome, as are requests for console access.