eSIM PKI Trust Chain

GSMA SGP.22 — Certificate Hierarchy, Mutual Authentication, and Session Keys

GSMA Certificate Issuer (CI) Root CA — SK.CI.ECDSA / PK.CI.ECDSA CERT.EUM.ECDSA EUM Certificate (SAS-UP) signs CERT.DPauth.ECDSA SM-DP+ Auth (SAS-SM) CERT.DPpb.ECDSA (Profile Binding) CERT.DP.TLS (Transport) signs CERT.DSauth.ECDSA SM-DS Auth (SAS-SM) CERT.EUICC.ECDSA eUICC Certificate (per chip) signs Mutual Authentication Flow (ECDSA P-256 + SHA-256) 1. SM-DP+ signs challenge 2. eUICC verifies with PK.CI.ECDSA 3. eUICC signs with SK.EUICC.ECDSA 4. SM-DP+ verifies Session keys (S-ENC, S-MAC) derived via ECDH key agreement — Perfect Forward Secrecy • LPA is pass-through, cryptographically untrusted SGP.32 IoT Extension CERT.EIM.ECDSA (eIM Signing) CERT.EIM.TLS (eIM Transport) eIM TLS cert NOT signed by GSMA CI