See it work
Recordings of the deployed services.
Independent remote SIM provisioning laboratory
SM-DP+, eIM, SM-DP and SM-SR, a TS.43 entitlement server with CAMARA network APIs, IMS calls, SMS and online charging, an OTA platform, an LPA and a software eUICC — deployed, interoperating, and installing real profiles onto emulated and physical cards.
For engineers working with remote SIM provisioning and OTA: watch it run, sign in and use it, or read the specifications behind it.
An independent laboratory on the GSMA SGP.26 test PKI and TS.48 test profiles.
Start here
Recordings of the deployed services.
One sign-in for every console. New accounts get read access to the ASN.1 Editor; other consoles on request.
Protocol flows and console guides are public, and every specification used is named below.
What you can check
Every leg, from the ES2+ order to the signed install notification, runs in this implementation. The recordings are of the deployed services.
Each capability traces to a published GSMA, ETSI, 3GPP, TCA or GlobalPlatform document, named on this page.
Profile packages decode to typed trees mapped to their bytes; APDUs and secured packets are shown field by field in both directions.
A software eUICC stands in for the card. Unmodified LPA and IPA software drives it over the real protocol, and it runs real CAP files.
SGP.22 — Consumer
A profile ordered over ES2+ reaches the eUICC over ES9+ and ES10, installs, and returns a signed notification the SM-DP+ accepts. Every leg runs in this implementation.
ES2+ DownloadOrder and ConfirmOrder reserve an ICCID and produce an activation code.
Common mutual authentication between eUICC and SM-DP+ over the SGP.26 test PKI.
The SM-DP+ builds the Bound Profile Package: key agreement, metadata and the profile under SCP03t.
The LPA segments the package into ES10b STORE DATA commands.
The signed ProfileInstallationResult is returned and the order closes.
An SGP.22 download from the lab SM-DP+ onto an emulated eUICC.
SGP.32 — IoT
A device without a user interface cannot take an activation code. The eIM keeps a package queue per eUICC; the IPA polls over ESipa and executes each package as an ordinary SGP.22 download against the same SM-DP+.
The eIM console queueing a download, a profile list and an eUICC data request; the IPA on Android executing each and reporting back.
The eIM associates the eUICC by EID with a replay counter, so each package runs once.
An eUICC Package, here a profile download, is queued for the device.
The IPA requests pending work over ESipa. Nothing is pushed; the device chooses when to ask.
The package becomes an SGP.22 download over ES9+ and ES10. The SM-DP+ sees no difference.
The signed result goes back to the eIM and the counter is consumed.
SGP.02 — M2M
SGP.02 has no device-side agent. The SM-SR is the only party that reaches the eUICC: it creates the ISD-P, routes the profile into it as secured packets, and holds the authoritative profile state.
The SM-DP and SM-SR consoles downloading and enabling a profile on an emulated M2M eUICC; a relay stands in for the SMS bearer. Notification redacted.
ES2 DownloadProfile names the EID, profile type and SM-SR. The SM-DP reserves an ICCID.
Over ES3 and ES5, the SM-SR sends INSTALL to the ISD-R and the ISD-P is created.
Key establishment against the ECASD key from the EIS; the profile becomes an ES8 script under SCP03t.
The script reaches the ISD-P as SCP80 secured packets addressed to its TAR.
ES4 then ES5 to the ISD-R. The SM-SR's EIS records the resulting profile state.
TS.43 — Entitlement
After install, the device asks the operator's entitlement server what the line may use — VoWiFi, 5G, satellite, a companion eSIM — and the same server moves the line to a new eSIM on a device change. GSMA TS.43, authenticated with EAP-AKA. The same line then answers an application's CAMARA questions through a TS.43 operator token, and reports its data usage from the lab's charging function.
The entitlement console and a TS.43 client on Android: a line's services, then its transfer to a new eSIM.
EAP-AKA against the lab AAA and HSS; the SIM answers the challenge and the device gets a token.
The device requests its entitlements; each service returns a state set per line.
Transfer rules per line: old-device attestation, terms acceptance or a one-time code.
An ES2+ order to the SM-DP+, an SGP.22 download to the new eSIM, and the old profile retired.
TS 102 226 — OTA
The OTA platform builds ETSI secured packets under the card's own keys and delivers them over SMS-PP, or has the card open an SCP81 session over HTTPS. RFM edits the file system; RAM loads, installs and removes applets through the Issuer Security Domain.
The OTA console sending RFM and RAM scripts to a SIM on an emulated card over SMS-PP and SCP81, with each packet decoded.
KIc, KID and an SCP81 PSK are generated per SIM and written to its security domain. Only check values leave the service.
Each Command Packet carries SPI, TAR and a replay counter, ciphered and MAC'd per TS 102 225, then concatenated over SMS.
RFM reads and updates EFs such as EF(SMSP) and EF(SMS). RAM sends INSTALL [for load], LOAD and INSTALL [for install] to the ISD.
The Proof of Receipt returns the security status and last status word; GET STATUS confirms the registry.
An SCP81 trigger has the card open a TLS-PSK session and pull the same script: no SPI, no counter, no segmentation.
Instruments
When a download fails, the cause is usually in a DER structure or an applet — neither of which a provisioning console shows. Both tools run in a browser against the same lab.
Decodes TCA Interoperable Profile Packages against the SAIP schema into typed trees mapped to their bytes, re-encodes edits to DER, and flags inconsistencies. An edited package can be installed on an emulated device through the lab SM-DP+. Also decodes the 184 SGP.22 v3.0 message types.
Decoding and editing a TS.48 test profile, then installing it on an emulated device.
UICC toolkit applets written in Java in the browser, converted to CAP and loaded onto an interpreted card with standard GlobalPlatform commands. An emulated handset drives proactive commands and envelopes, with every APDU shown in both directions.
Building and installing toolkit applets, then driving them from an emulated handset.
Try it
Every console sits behind one identity issuer, sso.rsplab.click, with Google or email sign-in. New accounts get read access to the ASN.1 Editor; other consoles answer No access until a grant is added.
Profile inventory, packages and StoreMetadata content for the consumer SM-DP+.
The administrative plane over the IoT eSIM manager: devices, associations and profile state.
Operator view over the M2M data-preparation service.
Operator view over secure routing and eUICC profile state.
Operator view over subscribers, devices and the entitlements each one holds, and the lab's emulated phones: their texts, calls, data usage and CAMARA developer clients.
Build, send and decode ETSI secured packets: RFM and RAM over SMS-PP and SCP81, with proof of receipt.
Web editor for TCA Interoperable Profile Packages and SGP.22 structures, decoding and re-encoding real DER.
Write a UICC applet in the browser, compile it and run it against an interpreted card.
Say which console you want to try, and why.
What is running
Grouped by architecture: server, console and device-side client together. Clients run on a handset or bench and are marked as such. Repositories are private.
SGP.22 end to end: the SM-DP+, its inventory and console, and the LPA that installs the profile.
Consumer remote SIM provisioning: prepares, binds and delivers a profile to an eUICC.
smdpplus.rsplab.click
Profile inventory, lifecycle and ES2+ order management behind the SM-DP+.
Profile inventory, packages and StoreMetadata content for the consumer SM-DP+.
Java Local Profile Assistant: the device-side half of a consumer profile download.
not hosted — runs on the device
SGP.32 for devices without a user interface. The eIM decides what a device should do; the IPA executes it.
Remote SIM management for IoT devices: per-eUICC package queues collected by the IPA over ESipa.
eim.rsplab.click
The administrative plane over the IoT eSIM manager: devices, associations and profile state.
IoT Profile Assistant: the on-device agent for constrained devices under SGP.32.
not hosted — runs on the device
SGP.02: SOAP over ES2 and ES3, and platform management of the eUICC over ES5.
Data preparation in the older M2M provisioning architecture.
smdp.rsplab.click
Operator view over the M2M data-preparation service.
Secure routing and eUICC platform management for M2M.
smsr.rsplab.click
Operator view over secure routing and eUICC profile state.
TS.43: service entitlement per line, and companion or primary eSIM activation ordered from the SM-DP+ over ES2+.
Tells a device which services it may switch on, and activates companion and primary eSIMs over ODSA.
entitlement-server.rsplab.click
Operator view over subscribers, devices and the entitlements each one holds, and the lab's emulated phones: their texts, calls, data usage and CAMARA developer clients.
entitlement-server.rsplab.click/console
What the network knows and carries, offered to applications and counted: CAMARA APIs authorized with TS.43 operator tokens, IMS calls and SMS between lab phones, and online charging over Nchf, Gy and Ro for data and minutes.
Answers applications' questions about a line: SIM Swap, Number Verification and Device Reachability, with event subscriptions, and texts one-time codes to it; authorized by TS.43 operator tokens.
api.rsplab.click/camara
Registers lab phones for calls with IMS AKA, calls between them charged by the second, and keeps their forwarding, barring and caller ID; a bridge lets a local IMS use the same HSS.
Holds each lab message as a real SMS until the phone collects it, lets phones text each other on their plan, holds texts while a phone is in airplane mode, delivers OTA packets to a card, and takes SMS over IP from the IMS.
Online charging for data, minutes and messages: grants quota in slices, charges each text as one event, and stops or redirects a session, or cuts a call, when the allowance runs out.
Every integration API documented in one place and callable from the browser: get a token, then try a request against the live services.
OpenAPI documents for the integration APIs of the SM-DP+, eIM, SM-DP, SM-SR, entitlement server and CAMARA network APIs, callable live through the integration gateway with an estate token.
Managing an issued card: RFM and RAM in ETSI secured packets over SMS-PP, CAT_TP and BIP, or SCP81 over HTTPS. Driven from the console or from a phone against a real reader.
ETSI secured packets over SMS-PP, CAT_TP and BIP, and SCP81 sessions over HTTPS.
ota.rsplab.click
Build, send and decode ETSI secured packets: RFM and RAM over SMS-PP and SCP81, with proof of receipt.
Android toolkit that drives the lab from a phone — OTA, SGP.32 relay and card access.
not hosted — runs on the device
A software eUICC all three architectures provision, the editor for the packages they install, and the toolchain for the applets that run on it.
A software eUICC speaking SGP.22 and SGP.32, with a GlobalPlatform card manager that loads real applets.
simulator.rsplab.click
Web editor for TCA Interoperable Profile Packages and SGP.22 structures, decoding and re-encoding real DER.
Write a UICC applet in the browser, compile it and run it against an interpreted card.
A Java Card converter: class files in, CAP files out.
not hosted — runs on the device
The core the rest of the lab authenticates against, and the signalling of a card attaching: EAP-AKA over SWm and SWx, and pcaps dissected into reports.
Authenticates a SIM for the entitlement server and for Wi-Fi calling, and is the IMS home subscriber server: registration over Cx, call settings over Sh, and where each phone is attached for SMS (S6c).
A pcap lands in S3, a Lambda dissects the EPC signalling and the result is served as a static report.
Where the detail is
Every system above is owned by a private repository, so none is linked — a link that resolves to a 404 for every reader is worse than plain text. The architecture, the protocol flows and the console manuals are documented in the open instead, at docs.rsplab.click — with the request and response of every call taken from the code rather than described. The integration APIs can be tried from the browser at swagger.rsplab.click .
Provenance
Each component was written from the published specification. Nothing derives from a proprietary or third-party implementation.
About
I build secure infrastructure for connectivity and digital identity — from the applet inside a secure element to the cloud platform that provisions it. This laboratory is where I work through the specifications properly: on my own time, on my own account, from public documents.
A standard is not understood until something you wrote makes a real card answer. Everything here exists because reading the document was not enough.
Built by
Amin Bakhtvar
Telecommunications & Cloud Engineer
Madrid, Spain
Next step
Questions on remote SIM provisioning, OTA and secure elements are welcome, as are requests for console access.
or write to aminbakhtvar62@gmail.com