How Does an eSIM Work? Technology, Security, and Benefits Explained
You've probably heard that eSIMs make travel easier. But what actually happens, technically, when you scan a QR code and suddenly have signal? In this article, we'll look at exactly that: the chip, the data transfer, the security mechanisms — and what it all means for you day to day.
If you're still at the very beginning and want to know what an eSIM even is first, it's worth starting with our introductory article What Is an eSIM?. Here, we go deeper.
1. What Is an eSIM — and How Is It Different from a Physical SIM Card?
A traditional SIM card is a small, removable chip you physically insert into your device. It stores your identity on the mobile network: your phone number, your authentication data, your network parameters.
An eSIM (embedded SIM) does exactly the same job — except the chip is no longer removable. It's permanently soldered onto the device's circuit board. You never insert anything and never take anything out. Instead, you load a digital profile onto that chip, usually via a QR code.
Here's the key distinction: "eSIM" describes the hardware. What actually connects you to a specific carrier is a profile. A single eSIM chip can store multiple profiles at once — that's the basis for what's known as Dual SIM, where you might run your home number and a local travel eSIM on the same device at the same time.
2. The Technology in Detail: eUICC, Profiles, and the GSMA Standard SGP.22
The eUICC Chip — Permanently Built In, but Carrier-Neutral
The technical term for the eSIM chip is eUICC, short for embedded Universal Integrated Circuit Card. Straight from the factory, this chip is blank and neutral — it doesn't belong to any carrier yet. That's an important difference from a physical SIM, which usually ships already loaded with a specific carrier's data.
What Exactly Is an eSIM Profile?
A profile is an encrypted file containing all the information that used to live on the plastic card: your subscriber identity (IMSI), the cryptographic keys used for authentication, and your carrier's network parameters. Only once a profile is installed and activated on the eUICC does your device actually connect to that network.
SGP.22 — the Official GSMA Specification
So that manufacturers and carriers don't each build their own incompatible version of this, the GSMA — the global trade body for the mobile industry — defined a single, unified standard. For consumer devices like smartphones, tablets, and smartwatches, that's the SGP.22 specification. It defines exactly how a profile is created, transferred, installed, and deleted — consistently, across manufacturers, worldwide.
3. How Activation Actually Works: From QR Code to Live Connection
The Three Building Blocks: SM-DP+, LPA, eUICC
Three components work together every time an eSIM is activated:
- SM-DP+ (Subscription Manager Data Preparation) — your carrier's server, where your encrypted profile sits ready for delivery
- LPA (Local Profile Assistant) — the software on your device that you see in settings when you add an eSIM
- eUICC — the chip that ultimately stores the profile
Step by Step: Activating an eSIM
- You purchase an eSIM and receive a QR code.
- The QR code doesn't contain any personal data — just the SM-DP+ server address and an activation code.
- The LPA on your device reads that code, opens an encrypted connection to the server, and authenticates itself.
- The server delivers the profile, encrypted.
- Only on the eUICC itself is the profile decrypted, installed, and activated.
At no point does your profile sit unencrypted anywhere on the network. For a full breakdown of the process, see the official GSMA page on how it works.
4. Security First: How Well Protected Is Your Data on an eSIM?
Encryption During Profile Transfer
The connection between the SM-DP+ server and the eUICC is encrypted throughout. The profile is only ever decrypted on the certified eUICC chip itself — never on an intermediate server or inside an app. This server-to-chip principle is built directly into the GSMA specification.
GSMA Certification and the eSA Process
Before a chip manufacturer or carrier can even use the eSIM specification, they have to go through a certification process known as eSIM Security Assurance (eSA). This confirms that both the hardware and the profile-creation processes meet the required security standards. The GSMA publishes the details in its specification overview.
5. eSIMs While Traveling: Real Benefits for Frequent Travelers and Families
Dual SIM — Your Home Number and Local Data, Side by Side
Because an eUICC can store several profiles at once, you can keep your home number active while running a local data eSIM for your destination at the same time. Important calls and texts still come through, while your data runs over the cheaper local plan.
Saving on Roaming Costs — A Quick Example
Traditional roaming outside the EU can quickly cost several euros per megabyte. A local travel eSIM connects directly to a carrier's network in your destination country, which usually comes in well below home-carrier roaming rates — often a fraction of the cost, depending on the destination and data volume.
For families especially, it's worth planning data volume carefully ahead of time. We've run the numbers in detail in What data package does a family with kids need for summer vacation 2026?. You can browse plans for 150+ countries directly in the Horisim shop.
6. eSIM Beyond the Smartphone: SGP.32 and the Internet of Things
eIM and IPA — the New Components for IoT
A smartphone can scan a QR code. A sensor out in a field, or a smart meter, can't. For devices like that, the GSMA developed the SGP.32 specification. Instead of the user triggering the download, a central management platform — the eIM (eSIM IoT Remote Manager) — handles it. In place of the LPA, an IPA (IoT Profile Assistant) runs either on the device or directly on the eUICC.
Use Cases: Wearables, Smart Meters, Connected Cars
This makes it possible to manufacture thousands of identical devices and only assign them a carrier profile once they're out in the field — automatically, with no physical intervention needed. Think connected vehicles, smart power meters, or wearables, where there's simply no room (or no need) for a traditional SIM slot.
7. Frequently Asked Questions About eSIM
Is an eSIM as secure as a physical SIM card? Yes. The GSMA specification requires the same level of security for eSIM chips and profile transfer as for traditional SIM cards, including end-to-end encryption throughout.
Can I store multiple eSIM profiles at the same time? Yes, an eUICC chip can hold multiple profiles. Typically one profile can be actively used per cellular connection at a time, or two in parallel on devices that support Dual SIM.
What happens to my eSIM profile if I switch phones? An eSIM profile can't simply be moved like a physical card. You'll need to request it again from your carrier and reactivate it on the new device.
How do I know if my device supports eSIM? Most manufacturers list this in the technical specs. Alternatively, dialing *#06# on many devices will display an EID number if an eUICC chip is present.
Does an eSIM work in every country? Technically, yes — though some countries restrict the use of certain foreign profiles or data services. It's worth a quick check before you travel.
Who sets the technical standards for eSIMs? The GSMA, the global mobile industry association, defines the specifications — both for consumer devices (SGP.22) and for IoT applications (SGP.32).
Ready to set up an eSIM for your next trip? The Horisim shop has plans for 150+ countries, and every profile can be managed directly from the app.