eSIM technology works by storing carrier profiles digitally on an eUICC chip, a permanent, soldered component inside your device, and downloading those profiles over the air with no physical swap needed. That is the core of how eSIM works, and this page explains the technology layer behind it: the chip architecture, the remote SIM provisioning (RSP) protocol, what a QR code actually encodes, the eSIM profile lifecycle, push and QR provisioning, multi-profile storage, network authentication, profile transfers, and expiry mechanics.
Understanding how eSIM technology works and how does eSIM work at a technical level is what makes every other eSIM decision clearer, from choosing a carrier profile to troubleshooting an eSIM profile download. If you are starting from scratch and need to understand what an eSIM is before diving into the mechanics, visit our What Is an eSIM guide first.
What Is an eSIM in Simple Terms?
An eSIM is a digital SIM embedded permanently in your device. There is no plastic card to insert or remove, the eSIM chip is soldered onto the motherboard at manufacture, and carrier profiles are written to it electronically.
With the basics in place, it is worth understanding exactly what is inside the chip that makes all of this possible.
What Is Inside an eSIM Chip?
The eUICC chip (embedded Universal Integrated Circuit Card) contains three main components: a secure operating system, encrypted profile storage memory, and a hardware security processor. Together, these allow the chip to receive, store, and run carrier profiles without exposing sensitive credentials to the rest of the device.
The eSIM chip is soldered directly to the motherboard at manufacture and cannot be removed. This is a deliberate design: because the chip never leaves the device, the credentials stored on it are harder to steal or clone than those on a removable physical SIM card.
The GSMA specification (specifically GSMA SGP.22) defines the standards that all eUICC chips must meet, covering everything from the operating system interface to how profiles are encrypted and stored. Any device marketed as eSIM compatible has a chip that conforms to this specification.
Knowing what the chip contains makes it easier to understand what actually lives on it in the form of a carrier profile.
What Is an eSIM Profile?
An eSIM profile contains four key data elements: an IMSI number (International Mobile Subscriber Identity, the unique number that identifies your subscription on the network), network authentication keys, access point settings, and carrier branding. Every eSIM profile that downloads to your device is a complete package of these four elements.
Every eSIM profile moves through five defined lifecycle states:
- Downloaded: the profile data has arrived on the eUICC but has not yet been installed.
- Installed: the profile is written into the chip’s storage and ready to be enabled.
- Enabled: the profile is active and your device is connected to that carrier’s network.
- Disabled: the profile remains on the chip but is not active. You can re-enable it at any time without re-downloading.
- Deleted: the profile has been permanently removed from the eUICC storage.
Only one carrier profile can be in the Enabled state per SIM slot at a time. If you store multiple eSIM profiles on a device, only one is active at any given moment, switching between them changes the state from Enabled to Disabled on the current profile and from Disabled to Enabled on the new one.
Understanding the profile structure is what makes the activation process make sense, here is exactly how that process runs.
How Does eSIM Activation Work? (The Technical Process)
eSIM activation follows a 6-step RSP (Remote SIM Provisioning) protocol between your device’s LPA and the SM-DP+ server. Here is what each of those terms means:
LPA (Local Profile Assistant) is the software built into your device that manages the entire provisioning conversation on your behalf. SM-DP+ (Subscription Manager Data Preparation Plus) is the secure server operated by the carrier or eSIM provider where your carrier profile is stored and prepared. EID (eUICC Identifier) is the unique hardware ID of your specific eUICC chip, think of it as your chip’s serial number.
The six steps of eSIM activation:
- You purchase a plan and receive an activation code (delivered via QR code or app).
- Your device’s LPA sends a connection request to the SM-DP+ server using the address encoded in the activation code.
- The LPA and SM-DP+ server perform mutual certificate authentication, each side verifies the other is legitimate before any data transfers.
- The SM-DP+ server encrypts the eSIM profile specifically to your device’s EID, so the profile can only be decrypted by your chip and no other.
- The encrypted carrier profile downloads over the air to your eUICC chip via the LPA.
- Your device attaches to the mobile network using the credentials in the newly installed and enabled profile.
This entire sequence happens in the background when you scan a QR code or tap through an app. What feels like a simple eSIM setup process is, technically, a cryptographically secured provisioning handshake between your device and a remote server.
One piece of this process deserves its own explanation: the QR code itself.
What Does the QR Code Actually Contain?
An eSIM QR code encodes exactly two pieces of data: the SM-DP+ server address (the URL of the server where your carrier profile is stored) and an activation code (the credential that unlocks your specific profile on that server).
When you scan the QR code, your device’s LPA reads those two values and knows precisely where to go (the SM-DP+ address) and what to request (the activation code matching your profile). The QR code is not the profile itself, it is the address and key that tell the LPA how to retrieve the profile.
Push provisioning delivers the same two pieces of data without requiring you to scan anything. Instead of a QR code, the provider’s app passes the SM-DP+ address and activation code directly to the LPA in the background.
This distinction between QR and push provisioning is worth understanding in more detail, because the underlying process is identical.
What Is the Difference Between QR Code and Push Provisioning?
QR code provisioning requires manually scanning a code containing the SM-DP+ server address. Push provisioning delivers the profile automatically via the provider’s app without any QR code. The RSP protocol running underneath is identical in both cases, the only difference is how the SM-DP+ address and activation code reach your device’s LPA.
In QR code provisioning, the SM-DP+ address is encoded in a printed or on-screen code that you scan manually. In push provisioning, the provider’s app delivers that same address directly to the LPA over the internet. The profile download, mutual authentication, encryption, and network attach steps are the same either way.
iOS 17 automatic eSIM transfer between iPhones uses push provisioning: when you set up a new iPhone, the LPA on the new device contacts the carrier’s SM-DP+ server to re-download the profile without any QR code involved.
Once a profile is on your device, switching between stored profiles is a separate and much simpler operation than a full provisioning event.
How Do You Switch Between eSIM Profiles?
eSIM profile switching changes the active profile state from Enabled to Disabled for the current profile, then from Disabled to Enabled for the chosen profile, all within your phone’s SIM settings, with no hardware change and no re-download required.
Because eSIM profile data stays on the eUICC chip in storage, switching is instantaneous. Your device is not contacting the SM-DP+ server, re-authenticating with a certificate chain, or downloading any new data. The profiles already exist on the chip in Disabled state, the switch simply promotes one to Enabled.
Profile switching in eSIM management takes seconds. This is one of the core technical advantages of eSIM technology over a physical SIM: changing networks requires a settings tap, not a hardware swap.
Before you can switch between profiles, you need to have multiple profiles stored on the device. Storage limits vary by hardware.
How Many eSIM Profiles Can Your Phone Store?
iPhone (iOS 16 and later) stores up to 8 eSIM profiles, with a maximum of 2 active simultaneously on Dual SIM models. Android devices typically store 5 to 10 profiles depending on the manufacturer, with 1 to 2 active at once, the exact limit varies by make and model.
Storing a profile is different from activating it. A profile in Downloaded, Installed, or Disabled state occupies storage on the eUICC chip but uses no network resources and does not affect your active connection. You can accumulate eSIM profiles from multiple providers and switch between them without deleting old ones, up to your device’s storage limit.
iPhone 14 models sold in the United States and all later iPhone models are eSIM-only, they have no physical SIM tray. These devices support multiple eSIM profiles and two active simultaneously, but there is no fallback to a physical card.
With the core mechanics covered, the sections below address related technical questions that come up frequently for travelers and new eSIM users.
How Does eSIM Authenticate With a Mobile Network?
eSIM authenticates with a mobile network using the AKA (Authentication and Key Agreement) algorithm. During authentication, the network and the eSIM chip exchange encrypted credentials derived from the Ki key, a secret authentication key stored inside the carrier profile, confirming device identity without ever transmitting the Ki key itself across the network.
In plain terms: the network sends your device a challenge (a random number). The eSIM chip runs the AKA algorithm against that challenge using the Ki key stored in the eUICC and sends back a computed response. The network runs the same calculation on its end using the Ki key it holds for your IMSI (your subscriber identity number). If both results match, authentication succeeds and your device is admitted to the network. The Ki key never travels over the air at any point.
This is the same authentication mechanism used by physical SIM cards. eSIM technology changes how credentials get onto the device in the first place (over-the-air provisioning via RSP), but it does not change how the network verifies the device once the profile is installed.
This authentication architecture is directly relevant to how eSIM performs when you cross an international border.
How Does eSIM Work When You Travel Internationally?
A travel eSIM activates before departure. RSP provisioning runs over any internet connection including Wi-Fi, so the carrier profile downloads at home and is ready the moment the plane lands. Your device does not need access to your destination country’s cellular network to complete the provisioning.
The technical reason this works is that RSP is an internet protocol, not a cellular-dependent process. The SM-DP+ server that delivers your carrier profile is reachable via any data connection. You could download a travel eSIM profile on a hotel Wi-Fi network, a home broadband connection, or your existing cellular data.
The difference between a travel eSIM and international roaming is a difference in which carrier profile is active. Roaming keeps your home carrier profile in the Enabled state and routes your traffic through the home network at a premium rate. A travel eSIM adds a local carrier profile from a provider in the destination country, connecting your device directly to that country’s networks at local data rates.
For country-specific recommendations and plan comparisons, see our Best eSIM for Travel buying guide.
Once you have used a travel eSIM on a trip, you may need to move it to a new device. The mechanics of that transfer are different from a simple profile switch.
What Happens When You Transfer an eSIM to a New Phone?
eSIM profile transfer to a new phone requires a new profile download. An eSIM profile cannot be physically moved from one eUICC chip to another because the profile was encrypted specifically to the original device’s EID at provisioning time. The provider must issue a new activation QR code or transfer authorization, and the profile re-downloads to the new device via the SM-DP+ server.
iPhone QuickStart on iOS 16 and later is an exception to the manual re-request process. When setting up a new iPhone next to an existing one, QuickStart uses peer-to-peer transfer to pass the SM-DP+ address and re-download the profile automatically, bypassing the QR code step.
Most travel eSIM providers including Airalo and Saily allow one re-download after identity verification. Check your specific provider policy before initiating a transfer.
Important caution: deleting a profile from your old device before confirming your provider supports re-issuance may forfeit any remaining data on that plan. Always verify the provider’s transfer policy first, and ideally complete the transfer before deleting the old profile.
A related concern for travelers is what happens when a plan runs out, which is different from what happens when you delete a profile.
What Happens When an eSIM Plan Expires?
An expired eSIM plan disables the active profile, moving it from Enabled to Disabled state on your eUICC chip. The profile is not deleted. It remains in storage on the chip until you manually remove it.
This means an expired eSIM profile does not disappear from your device. If your provider offers a top-up or data refill option for that profile, re-enabling the profile after purchase resumes connectivity without any re-download. The credentials and network authentication keys are still on the eUICC chip, still valid, and can be reactivated by moving the profile back to Enabled state.
If you no longer need the profile, you can delete it from your SIM settings to free up storage space on the chip. Deletion is permanent and cannot be undone without the provider issuing a new activation code.
The security architecture underlying all of these operations is worth understanding, especially for anyone evaluating eSIM against a traditional SIM on security grounds.
How Secure Is eSIM Technology?
eSIM uses GSMA-standardized end-to-end encrypted provisioning, with mutual certificate authentication ensuring that the carrier profile can only be decrypted by the specific eUICC chip it was prepared for. According to the GSMA SGP.22 specification (Consumer eSIM Architecture), the security architecture rests on three layers working together.
Layer 1: EID binding. During provisioning, the SM-DP+ server encrypts the carrier profile to your device’s specific EID. No other eUICC chip, regardless of manufacturer or model, can decrypt a profile prepared for a different EID.
Layer 2: CI root certificate chain. CI (Certificate Issuer) root certificates are pre-installed on the eUICC chip at manufacture. When the LPA connects to an SM-DP+ server, both sides verify each other’s certificates against this root chain before any data transfers. This mutual authentication prevents both rogue server attacks and unauthorized device connections.
Layer 3: Ki key non-transmission. The Ki authentication key stored inside the carrier profile never leaves the eUICC chip. During network authentication, the AKA algorithm computes a response derived from the Ki key, and only that computed response travels over the network. The key itself is never transmitted and cannot be intercepted in transit.
The “What Is an eSIM?” article on this site covers user-facing security practices such as 2FA, lock screen settings, and what to do if a device is lost. This section covers the underlying cryptographic architecture that governs how eSIM provisioning and network authentication work at a protocol level.
eSIM security is built into the provisioning protocol and the chip hardware itself, not added on top after the fact.
How eSIM Works: The Core Mechanism, in Plain English
Understanding how eSIM works comes down to one central idea: a carrier profile is a digital package of network credentials that lives on an eUICC chip inside your device, and the RSP protocol delivers that carrier profile over any internet connection using end-to-end encrypted provisioning. How does eSIM work when you scan a QR code? The code gives your device’s LPA an address and a key, the LPA contacts the SM-DP+ server, mutual authentication confirms legitimacy on both sides, and the eSIM profile downloads encrypted to your specific chip. eSIM technology replaces the physical logistics of SIM swapping with a cryptographically secured software process.
The eSIM profile lifecycle (Downloaded, Installed, Enabled, Disabled, Deleted), the difference between QR code and push provisioning, the AKA network authentication algorithm, the EID binding that secures each profile download, and the expiry and transfer mechanics covered on this page are the technical layer that sits beneath every eSIM activation, profile switch, and plan top-up.
Now that you understand how eSIM works, the logical next step is finding the right travel eSIM plan for your destination. Our Best eSIM for Travel Page compares data-only eSIM plans by country, price, and coverage so you can put the technology to work on your next trip.
Frequently Asked Questions
What is an eUICC chip?
An eUICC (embedded Universal Integrated Circuit Card) is the eSIM chip soldered permanently to your device’s motherboard. It contains a secure operating system, encrypted storage for carrier profiles, and a hardware security processor. The GSMA SGP.22 specification defines the standards all eUICC chips must meet.
What is remote SIM provisioning?
Remote SIM provisioning (RSP) is the protocol that delivers a carrier profile from a provider’s SM-DP+ server to the eUICC chip in your device over the internet. RSP handles mutual certificate authentication, profile encryption to your specific EID, and the over-the-air download. It works over any internet connection, including Wi-Fi.
Can I have two eSIM profiles active at the same time?
Yes, on Dual SIM capable devices. iPhone models from iPhone XS onward support two active eSIM profiles simultaneously (or one eSIM and one physical SIM on models with a SIM tray). iPhone 14 US models and later support two active eSIM profiles with no physical SIM tray. Android Dual SIM support varies by manufacturer and model.
Does eSIM work without Wi-Fi?
eSIM activation (the initial profile download) requires an internet connection, which can be Wi-Fi or existing cellular data. Once the carrier profile is installed and enabled on the eUICC chip, the eSIM operates on the cellular network independently of Wi-Fi, exactly like a physical SIM card.
Is eSIM more secure than a physical SIM?
eSIM provisioning uses end-to-end encryption with EID binding (the profile is encrypted to one specific chip), mutual certificate authentication (both device and server verify each other), and Ki key non-transmission (the authentication key never leaves the chip). These are architectural security properties built into the GSMA SGP.22 specification. For user-facing security practices, see the What Is an eSIM? article.