
What Is an eSIM, Really? How eSIM Technology Works
An eSIM is really three things working together: a tiny secure chip called an eUICC soldered inside your phone, on-device software called the LPA that manages what's loaded onto that chip, and a remote server called an SM-DP+ that your provider runs to prepare and deliver your subscription. Understanding what each piece does is what makes the rest of eSIM make sense.
#What Do eUICC, LPA, and SM-DP+ Actually Mean?
eUICC stands for embedded Universal Integrated Circuit Card, and it's the physical hardware side of an eSIM. It's a chip, not a card you can pull out: it's "installed via surface-mount technology at the factory" and "programmed with a permanent eUICC ID" at manufacture, the same way a traditional SIM's chip is manufactured, just soldered to the board instead of housed in a removable tray (Wikipedia). One eUICC can hold several downloaded subscription profiles at once, even if only one or two are active at a time, which is the entire reason a single phone can carry an eSIM from co:sim alongside another provider's eSIM without conflict.
LPA stands for Local Profile Assistant, and it's the software layer that actually does the work of managing those profiles. It's "a standalone, system app" built into the phone's operating system that "serves as a bridge between the SM-DP+ ... and the eUICC chip," handling the download, install, enable, and delete actions you see in your phone's cellular settings screen (Android Open Source Project). "Local" refers to where it runs: on your device, as opposed to the remote server on the other end of the connection.
SM-DP+ stands for Subscription Manager Data Preparation, and it's that remote server, described by one eSIM management vendor as "the digital heart of eSIM management," the system that creates, packages, and delivers your specific subscription profile (Trasna). When you buy a co:sim eSIM for Japan or anywhere else in the catalog, our SM-DP+ infrastructure is what prepares your profile the moment payment clears, and the QR code or activation code emailed to you is simply the address and credentials your phone's LPA needs to go fetch it.
All three pieces are defined by a single GSMA technical standard called SGP.22, the specification for consumer remote SIM provisioning that every major eSIM provider builds against, which is also why an eSIM from one provider behaves the same way, mechanically, as one from any other (Wikipedia).

#How Does a Profile Actually Get Onto Your Phone?
The download itself follows a fixed sequence, and every step maps to one of the three pieces above. First, the eSIM provider's SM-DP+ server prepares your profile and its metadata in advance, tied to the activation code it's about to hand you (Android Open Source Project). Second, when you scan a QR code or enter an activation code, your phone's LPA reads it and opens a connection to that specific SM-DP+ server. Third, the profile data moves across an encrypted channel; one vendor describes this connection as acting "as a protective tunnel through which encrypted profile data is securely transferred" between the SM-DP+ and the LPA, so the data is unreadable to anything intercepting it in transit (Trasna). Fourth, the LPA hands the decrypted profile to the eUICC chip itself, which stores it and can then enable it as your active line.
The security underpinning every step of that handoff is a public key infrastructure "governed by the GSMA" that "secures authentication across the ecosystem," meaning every SM-DP+ server, including the one behind a co:sim eSIM, has to pass GSMA certification before it's allowed to talk to eUICC chips at all (G+D). That's the part that makes "just email me a QR code" trustworthy rather than a security hole: the chip on your phone won't accept a profile from a server that hasn't been vetted into that trust chain.
#FAQ
#Is an eSIM the same thing as an eUICC?
Not quite, though the terms get used loosely. The eUICC is the physical chip itself, soldered into the phone and present whether or not you've ever downloaded anything onto it. "eSIM" more commonly refers to the whole system, the eUICC plus the downloaded profile plus the LPA software managing it, or sometimes just to a specific downloaded profile, like "my co:sim eSIM for Japan." A phone with a functioning eUICC but no profiles downloaded is eSIM-capable but not yet running an eSIM in the everyday sense of the word. The distinction matters mainly when troubleshooting: a "no eSIM support" error means the eUICC chip itself is missing or disabled, while a failed activation means the LPA couldn't complete a download from the SM-DP+.
#Can one eUICC chip store more than one eSIM profile?
Yes, and this is one of the most practically useful facts about the technology. A single eUICC is designed to hold multiple downloaded profiles simultaneously, typically eight or more depending on the phone, even though only one or two can be active for calls and data at any given moment depending on the device. That's the mechanism that lets someone install a co:sim eSIM for an upcoming trip while a home carrier's eSIM sits stored on the same chip, switching which one is active from the phone's settings rather than juggling physical cards. Deleting a profile clears space on the chip; simply switching which profile is active does not delete anything, it just changes which one the LPA currently has enabled.
#What does the SM-DP+ server actually store about me?
It holds the specific subscription profile prepared for your purchase, the cryptographic credentials tied to your eUICC, and enough metadata to authenticate that download request as legitimate, not a general database of your personal browsing or usage history. The "+" in SM-DP+ distinguishes it from an older, machine-to-machine-only version of the standard; the consumer version adds the direct device-to-server download flow that makes scanning a QR code possible at all, rather than requiring a technician to provision the chip by hand. Once a co:sim eSIM profile has been successfully downloaded to your eUICC, the SM-DP+ server's role in that specific transaction is effectively done, it isn't sitting in the middle of your ongoing calls or data sessions, which are handled entirely by the mobile network your profile connects to, not by the server that delivered it.
#Why can't I just copy an eSIM profile to a new phone like a file?
Because the entire security model is built specifically to prevent that. A profile is cryptographically bound to the unique ID of the one eUICC chip it was delivered to during that SM-DP+ handshake, so it can't simply be copied, exported, or dragged onto a different device the way a photo or document can. Moving to a new phone means going through the same download process again, either via your provider's own transfer tool or a fresh activation code, so the new eUICC gets its own independently verified copy of the profile. This is also why losing a phone doesn't hand a thief your active cellular identity the way a physical SIM card, which is physically dependent on the phone in the first place.
#Does the GSMA SGP.22 standard mean every eSIM works the same way?
Mechanically, yes, at least for the download and installation process itself. SGP.22 is the single GSMA specification that defines how a consumer eUICC, LPA, and SM-DP+ are supposed to interact, so an eSIM from co:sim, your home carrier, or any other provider goes through the identical technical handshake to reach your phone: profile prepared on an SM-DP+, requested by the LPA, delivered through an encrypted channel, installed on the eUICC. What differs between providers is everything above that plumbing, the mobile network the profile connects to, the data allowance, the price, and how quickly the profile is emailed to you after purchase, not the underlying delivery mechanism itself. That's also why a phone that's eSIM-compatible with one provider is compatible with essentially any SGP.22-compliant provider.


