eSIM and Lawful Interception: What the RSP Architecture Means for Compliance

eSIM lawful interception - lawful interception compliance illustration

eSIM lawful interception presents unique technical challenges compared to traditional SIM-based interception. The transition from physical SIM cards to embedded SIM (eSIM) technology is reshaping the mobile telecommunications landscape. Driven by the GSMA’s Remote SIM Provisioning (RSP) architecture, eSIM enables subscribers to switch operators, activate profiles, and manage multiple subscriptions without physically replacing a SIM card. For consumers, this means greater flexibility and convenience. For operators — and particularly for those responsible for lawful interception compliance — eSIM introduces new complexities that must be understood and addressed.

This article examines how the RSP architecture affects lawful interception, identifies the specific challenges that eSIM creates for target identification and interception management, and provides practical guidance for operators seeking to maintain compliance in an eSIM-enabled environment.

How eSIM Lawful Interception Works

The GSMA RSP architecture defines the ecosystem for managing eSIM profiles. The key components include the Subscription Manager — Data Preparation (SM-DP+), which prepares and securely delivers operator profiles to eSIM devices; the Subscription Manager — Discovery Server (SM-DS), which facilitates the discovery of available profiles; the eUICC (embedded Universal Integrated Circuit Card), which is the secure element within the device that hosts one or more operator profiles; and the Local Profile Assistant (LPA), which is the software on the device that manages profile download, installation, and switching.

Under the RSP model, an operator’s profile — containing the IMSI, authentication credentials, network access configuration, and other parameters — is downloaded and installed onto the eUICC remotely. Multiple profiles can coexist on a single eUICC, though typically only one is active at a time. Subscribers can switch between profiles — and effectively between operators — through a software operation on the device, without any physical intervention.

This dynamic, software-driven provisioning model is fundamentally different from the traditional physical SIM model, where the IMSI and operator association are fixed at the time of SIM manufacture and distribution. The implications for lawful interception are significant.

Target Identification Challenges

Lawful interception orders typically identify the target by one or more identifiers: MSISDN (phone number), IMSI (subscriber identity), IMEI (device identity), or IP address. The eSIM model complicates each of these identification methods in different ways.

MSISDN-based targeting is affected by the ease with which subscribers can change operators — and by extension change their MSISDN — through a simple profile switch. A target who suspects surveillance may switch to a different profile and MSISDN without leaving any physical trace. The operator that was performing the interception may lose visibility of the target entirely if the target activates a profile from a different operator.

IMSI-based targeting faces similar challenges. Each operator profile on the eUICC has its own IMSI. When the target switches profiles, a different IMSI becomes active, and the original IMSI is no longer visible on the network. The operator intercepting based on the original IMSI will see the target apparently disappear from the network.

IMEI-based targeting is more stable in the eSIM context, as the IMEI is associated with the device rather than the SIM profile. However, IMEI-based interception has its own limitations — it may capture communications from other users who share the device, and it does not help if the target uses multiple devices.

IP address-based targeting is inherently dynamic and is not specifically affected by eSIM, but the overall complexity of targeting in an eSIM environment may lead law enforcement to rely more heavily on IP-based identification, with its own challenges of dynamic allocation and network address translation.

Profile Switching and Interception Continuity

One of the most significant challenges that eSIM creates for lawful interception is the potential for interception discontinuity during profile switches. When a target switches from one operator profile to another on the same device, the interception that was active on the first operator’s network must be coordinated with a new interception on the second operator’s network. In practice, this coordination requires communication between law enforcement, the issuing authority, and both operators — a process that may take hours or days, during which the target’s communications go unmonitored.

The speed and ease of profile switching in the eSIM model — which can be accomplished in seconds on many devices — contrasts sharply with the time required to establish a new interception on a different operator’s network. This temporal gap represents a significant operational challenge for law enforcement and a compliance risk for operators that cannot provide timely interception of subscribers who switch profiles.

Addressing this challenge requires enhanced coordination mechanisms between operators and law enforcement, potentially including automated notifications when a target’s profile is deactivated and standardised procedures for rapidly establishing interceptions on the target’s new operator. Some regulators have begun to explore these mechanisms, but standardised solutions are not yet widely available.

Multi-Profile and Multi-Device Scenarios

eSIM technology enables scenarios that are difficult to address with traditional interception approaches. A single device may host multiple operator profiles, potentially from operators in different countries. A single subscriber may have eSIM profiles on multiple devices — a smartphone, a tablet, a smartwatch, and a laptop. Each combination of profile and device creates a potential communication channel that may need to be intercepted.

For operators, this means that the scope of an interception may extend beyond the traditional single-subscriber, single-device model. The operator must be able to identify all profiles and devices associated with a target — or at least those that are active on their network — and to apply interception across all of them. This requires integration between the LI system and the operator’s eSIM management platform to track profile activations, deactivations, and switches in real time.

For law enforcement, the multi-profile model means that a single interception order may not be sufficient. If the target has profiles on multiple operators’ networks, separate orders may need to be issued to each operator. The coordination of these multiple orders — ensuring complete coverage without gaps — adds complexity to the investigative process.

Implications for the LI System

To maintain effective lawful interception in an eSIM environment, operators must ensure that their LI systems address several specific requirements. First, the LI system must integrate with the eSIM management platform (specifically the SM-DP+ and the operator’s provisioning systems) to receive real-time notifications of profile activations, deactivations, and switches. This integration enables the LI system to detect when a target activates or deactivates a profile and to adjust the interception accordingly.

Second, the LI system must support the correlation of multiple identifiers associated with the same subscriber. A target may be known by different MSISDNs, IMSIs, and IP addresses depending on which profile is active. The LI system must maintain a mapping between these identifiers and the target’s interception order, ensuring that communications are intercepted regardless of which profile or identifier is in use.

Third, the LI system should generate IRI events that capture profile management activities — such as profile activation and deactivation — as intercept-related information. This information can be valuable to law enforcement in understanding the target’s behavior and in coordinating interceptions across multiple operators.

Fourth, the operator’s warrant management system must be capable of handling the additional complexity introduced by eSIM. This includes the ability to modify interception parameters when a target’s profile changes, to coordinate with law enforcement when a target switches to a different operator, and to maintain complete audit trails of all profile-related events and their impact on active interceptions.

Regulatory and Standards Developments

The LI standards community is actively working on addressing the challenges that eSIM creates. ETSI TC LI has published work items related to eSIM and lawful interception, and 3GPP has incorporated eSIM considerations into its 5G LI architecture. However, the pace of standards development has not fully kept up with the pace of eSIM adoption, and operators may need to implement interim solutions while waiting for fully standardised approaches.

Some national regulators have issued specific guidance on eSIM and LI compliance. In Germany, the BNetzA has addressed eSIM in the context of the TKÜV, requiring operators to maintain interception capabilities regardless of the SIM technology used. Other regulators are expected to follow with their own guidance as eSIM adoption accelerates.

Conclusion

eSIM technology and the RSP architecture introduce significant new challenges for lawful interception, primarily related to target identification, interception continuity, and multi-profile scenarios. These challenges are not insurmountable, but they require operators to invest in enhanced LI capabilities, deeper integration with eSIM management systems, and more sophisticated identity resolution and correlation mechanisms. Operators that proactively address these challenges will be well positioned to maintain compliance as eSIM adoption grows, while those that wait for the challenges to become acute risk falling behind their regulatory obligations.

Practical Steps for Operators

Operators should begin by assessing their current eSIM deployment and its impact on their existing LI capabilities. This assessment should identify any gaps in target identification, interception continuity, or multi-profile handling. Based on the assessment, operators should develop a roadmap for enhancing their LI systems to address eSIM-specific challenges, prioritising the highest-risk gaps first. Integration with the eSIM management platform should be a top priority, as real-time visibility into profile lifecycle events is the foundation for effective interception in an eSIM environment. Operators should also engage with their national regulatory authority to understand any specific guidance or requirements related to eSIM and LI compliance, and should participate in industry forums and standards development activities to help shape the emerging solutions.

As eSIM adoption accelerates, eSIM lawful interception challenges will become more pressing. Operators should proactively address eSIM lawful interception requirements in their compliance roadmaps.

Related Articles

For further reading on related topics, explore these articles:

External Resources

The following external resources provide additional context and official documentation:

Scroll to Top