> For the complete documentation index, see [llms.txt](https://docs.eseye.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.eseye.com/anynet-sim/esim-and-remote-provisioning/understanding-the-gsma-rsp-m2m-general-architecture.md).

# Understanding the GSMA RSP M2M general architecture

Remote SIM Provisioning (RSP) is governed by GSMA (Global System for Mobile Communications) standards, ensuring that it works across different networks globally, and adheres to regulatory and security requirements. The GSMA provides the following general architecture for the roles and interfaces associated with RSP:

![](https://2995386447-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzlTL8FVu6GaQkB5i1TRY%2Fuploads%2F7rMS04AOLBLEtLAopn33%2FeSIM_RSPArchitecture.png?alt=media)

## Key RSP components

RSP relies on secure communications between servers and devices to download, install, enable, update, disable, and delete network profiles on eUICC SIMs.

The following core elements are required to support these processes:

### Subscription Manager - Data Preparation (SM-DP)

The SM-DP is a server-based network component that securely prepares subscription data, including subscriber profiles and security keys, for delivery to eUICC SIMs. The SM-DP enforces security measures to protect the confidentiality and integrity of the data, including encryption and authentication.

The SM-DP communicates with devices via an SM-SR. MNOs have their own SM-DP servers that can send SIM profiles directly to SM-SRs, or donate the SIM profiles directly to Eseye. Eseye has two SM-DPs, hosted by Thales and Kigen.

The available functions depend on how the SM-DP is uniquely configured for a specific MNO. The MNO can use the SM-DP to enable a profile on the eUICC, after it is downloaded and installed. Eseye manages this process on behalf of customers and the MNOs.

### Subscription Manager - Secure Routing (SM-SR)

The SM-SR is a server-based network component that ensures the subscription data is securely and reliably routed from the SM-DP to the target eUICC SIMs. The SM-SR manages the end-to-end security of the data transfer, validating the legitimacy of requests, ensuring the correct profile is sent for the module type, and securely delivering the subscription data to the eSIMs.

The SM-SR plays a crucial role in ensuring the overall security of RSP, preventing unauthorized access to subscriber profiles during the data transfer. Eseye has two SM-SRs, hosted by Thales and Kigen. Eseye manages this process on behalf of customers and the MNOs.

### eUICC

eUICC is the eSIM software component that runs on a UICC. For more information, see [eUICC overview](/anynet-sim/esim-and-remote-provisioning/euicc-overview.md).

During RSP, the eUICC securely stores the prepared subscription data (subscriber profiles and cryptographic keys), enabling subscribers to access mobile networks and services. eSIMs are designed with strong security features to protect stored data and resist tampering.

### Mobile Network Operators (MNOs)

The MNO interacts with the SM-DP and SM-SR to manage and deliver subscriber profiles to eUICC SIMs. MNOs use RSP to remotely provision, update, and personalise eUICCs for their subscribers. Eseye manage the profile stock to ensure near 100% availability for customer needs.

## Further RSP components and interfaces

### Entity and User Module Manager (EUM Manager)

The EUM Manager manages the entity and user modules with an eUICC SIM, ensuring their security and integrity. The entity module stores device manufacturer data, and the user module stores subscriber-specific data. The EUM Manager assists with securely loading and managing eUICC profiles, and is managed indirectly through the SM-DP and SM-SR by the MNO that owns or operates the eUICC.

### GSMA Certificate Issuer (CI)

The CI is responsible for issuing digital certificates used for various RSP and eSIM security and authentication purposes. The digital certificates are vital for maintaining the security and integrity of communication between different entities and components within the mobile network, including the eUICC, SM-DP, and SM-SR. The certificates are used for authentication, encryption, and the establishment of secure connections to protect sensitive information, such as subscriber profiles and encryption keys.

### Interfaces

The GSMA RSP M2M general architecture components communicate via a number of different interfaces. The table below briefly describes each interface. For more in-depth understanding, refer to the latest GSMA specifications.

| Interface | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| --------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| ES1       | eUICC Manufacturer (EUM)-to-SM-SR interface. Enables the eUICC Manufacturer to register the eUICC based on its eUICC Information Set (EIS). The EIS contains initial information provided at registration time, such as the eid, which remains unchanged during the eUICC lifetime.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ES2       | <p>MNO-to-SM-DP interface. Enables the caller MNO to:</p><ul><li>Securely retrieve EIS information and instruct the SM-DP to download a profile, identified by its ICCID, to the eUICC, identified by its EID, through the SM-SR.</li><li>Update the current profile's policy rules.</li><li>Replace the profile subscription address, such as the MSISDN or IMSI, through which the eUICC is accessible from the SM-SR through the mobile network when the profile is enabled.</li><li>Request that the SM-DP enable or disable a target profile in a specified eUICC, identified by its EID. The caller MNO owns the target profile.</li><li>Request that the SM-DP delete a target profile. The SM-DP passes this request to the SM-SR.</li></ul><p>Enables the SM-DP to:</p><ul><li>Notify the MNO when the target profile is enabled, disabled, or deleted.</li><li>Notify all MNOs with profiles on the eUICC when the SM-SR changes.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ES3       | <p>SM-DP-to-SM-SR interface. Enables the SM-DP to download and install a target profile, specifically to:</p><ul><li>Establish a link with an SM-SR that is previously unknown to the SM-DP.</li><li>Retrieve the target profile EIS from the SM-SR. The target profile is identified using the EID. Only EIS data that is applicable for the specific SM-DP is retrieved. The information verifies the eligibility of the eUICC for storing the profile, for example, type, certificate, and memory.</li><li>Retrieve up-to-date EIS information.</li><li>Use secure commands to request that the SM-SR creates a new Issuer Security Domain Profile, the ISD-P that hosts a unique profile, in the eUICC. If the data is too large for the eUICC to handle at once, the SM-SR may send commands in several steps.</li><li>Inform the SM-SR that the profile download is complete. The subscription address may be set at this point, or updated later.</li><li>Replace the profile's subscription address in the EIS. The subscription address is the identifier, such as the MSISDN and/or IMSI, through which the eUICC is accessible from the SM-SR via the mobile network when the profile is enabled.</li><li>Request the SM-SR to enable or disable a profile.</li><li>Request the SM-SR to delete a target ISD-P containing a specific profile.</li><li>Update the Connectivity Parameters store on instruction by the MNO, for enabling or disabling the target profile.</li><li>Send notifications to the MNO when the target profile is enabled, disabled, or deleted.</li><li>Send a notification to all MNOs with profiles on the eUICC when the SM-SR changes.</li></ul> |
| ES4       | <p>MNO-to-SM-SR interface. Enables secure communication for profile delivery, activation, and management. The MNO can:</p><ul><li>Retrieve applicable EIS data and profile information.</li><li>Update profile policy rules and subscription addresses.</li><li>Request that the SM-SR enable, disable, or delete a profile.</li><li>Request an SM-SR change.</li></ul><p>The SM-SR can:</p><ul><li>Notify the MNO when a target profile changes state.</li><li>Notify all MNOs with profiles on the eUICC when the SM-SR changes.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ES5       | <p>SM-SR-to-eUICC interface. The SM-SR handles OTA communication through SMS, CAT\_TP, or HTTPS. This interface enables the ISD-R to:</p><ul><li>Create an ISD-P and enable, disable, or delete a target profile.</li><li>Query eUICC status and assign a fall-back profile.</li><li>Establish and clear SM-SR keys during an SM-SR change.</li><li>Update SM-SR addressing parameters after an SM-SR change.</li><li>Notify and confirm changes in the target profile network attachment state.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| ES6       | <p>MNO-to-eUICC interface. This is the secure interface between the MNO OTA platform and the target profile. It enables the MNO to:</p><ul><li>Update policy rules (POL1) on the eUICC.</li><li>Update Connectivity Parameter rules on the eUICC.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ES7       | SM-SR-to-SM-SR interface. Enables secure communication between SM-SRs when changing or updating the SM-SR. A new SM-SR can request a new ISD-R key set. This enables a secure, authenticated handover of the eUICC.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ES8       | SM-DP-to-eUICC interface. This secure interface is between the SM-DP and ISD-P through the SM-SR. The SM-DP and ISD-P authenticate each other. They sign and encrypt all commands and responses.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.eseye.com/anynet-sim/esim-and-remote-provisioning/understanding-the-gsma-rsp-m2m-general-architecture.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
