SIM and eSIM Architecture: Where Subscriber Identity Lives
Subscriber identity management is the chain from a credential in a device to a record in your core. The SIM, eSIM or iSIM holds the IMSI and the key; the HLR, HSS or UDM holds what that identity is allowed to do; and the AuC or AUSF proves the two belong together. When the credential becomes software, the problem moves from logistics to access control.
Every mobile subscriber on your network has an identity. That identity is anchored in a SIM, an eSIM, or an iSIM, and it connects to a set of records in your core network that determine who can access your service, what they are permitted to do, and how they are charged. Understanding the architecture behind subscriber identity management is not just a technical matter. It directly influences how you provision subscribers, how quickly you can onboard customers, how you manage roaming, and how you prepare your MVNO for an eSIM-first future.
This guide explains the complete architecture of subscriber identity management for MVNOs, from the physical SIM card through to the core network records that authenticate and authorize every call, message, and data session your subscribers generate.
On this page
- What is Subscriber Identity and Why It Matters for MVNOs
- The SIM Card: Foundation of Subscriber Identity
- How SIM Cards Work in an MVNO Context
- SIM Provisioning and Personalization Workflows
- eSIM and iSIM Architecture
- How eSIM Changes the Subscriber Identity Model
- Remote SIM Provisioning and SGP.32
- Core Network Identity: HLR, HSS, and UDM
What is Subscriber Identity and Why It Matters for MVNOs
Subscriber identity is the mechanism by which your network knows who is connecting, confirms they are authorized to use your service, and applies the correct plan, policy, and charging rules to their session. Every interaction between a subscriber's device and your network begins with an identity check.
For MVNOs, subscriber identity management touches every part of the business. The SIM or eSIM your subscriber uses must be provisioned with the correct IMSI and authentication keys. Your core network must hold accurate, up-to-date subscriber records. Your BSS must synchronize subscriber state with your network in real time. When any of these elements falls out of sync, subscribers experience service failures, and your operations team spends time resolving provisioning incidents instead of growing the business.
Getting subscriber identity architecture right from the start saves enormous operational cost and creates a foundation for the services you will want to deliver as your business grows, including eSIM provisioning, roaming, and advanced value-added services.
The SIM Card: Foundation of Subscriber Identity
SIM, eSIM and iSIM compared
| Feature | SIM | eSIM (eUICC) | iSIM |
|---|---|---|---|
| Form | Removable card | Chip soldered into the device | Inside the device chipset |
| Profile | Written before shipping | Downloaded over the air | Downloaded over the air |
| Changing operator | Swap the card | Download another profile | Download another profile |
| Logistics | Stock, shipping, returns | None after manufacture | None after manufacture |
| The hard part | Warehouse and distribution | Who may download, and who may remove | The same, plus device dependency |
| Specified in | ETSI TS 102 221, 3GPP TS 31.102 | GSMA SGP.21 / SGP.22 | Same series, in-chipset implementation |
How SIM Cards Work in an MVNO Context
The Subscriber Identity Module (SIM) card is a secure element that stores three critical pieces of information: the International Mobile Subscriber Identity (IMSI), the authentication key (Ki), and the network access application. When a subscriber powers on their device, the SIM and the network perform a mutual authentication exchange using these credentials to verify identity before granting service access.
For MVNOs, the IMSI is particularly important because it identifies both the subscriber and the home network. The Mobile Country Code (MCC) and Mobile Network Code (MNC) embedded in the IMSI must match the network your MVNO operates on or has been allocated by your MNO or MVNE partner. If you operate as a Light MVNO, you typically use your host MNO's MCC/MNC. If you operate as a Full MVNO, you may hold your own MNC and issue SIMs under your own identity.
The SIM card also stores the Mobile Station International Subscriber Directory Number (MSISDN), which is the subscriber's phone number. Your BSS manages the relationship between MSISDN, IMSI, and the subscriber's account record.
SIM Provisioning and Personalization Workflows
SIM provisioning is the process of writing subscriber-specific data onto a SIM card and creating the corresponding records in your core network and BSS. This process must complete correctly before a subscriber can use your service.
The physical SIM provisioning workflow involves three stages. First, a SIM manufacturer personalizes blank SIM cards with your IMSI range, authentication keys, and network access profiles. Second, your OSS system activates the SIM record in your HLR or HSS, creating the network-level subscriber record. Third, your BSS creates the commercial subscriber record, linking the IMSI to the customer account, plan, and charging profile.
Automation of this provisioning workflow is critical at scale. Manual provisioning steps create errors and delay customer onboarding. Design your provisioning architecture to trigger BSS, OSS, and core network updates atomically, so that all three systems stay synchronized from the moment a SIM is activated.
eSIM and iSIM Architecture
How eSIM Changes the Subscriber Identity Model
The embedded SIM (eSIM) fundamentally changes the subscriber identity model by separating the secure element (the hardware) from the operator profile (the subscriber identity data). A physical SIM card carries exactly one operator's credentials. An eSIM can carry multiple operator profiles and switch between them over the air, without the subscriber needing to physically change a card.
For MVNOs, this creates both opportunity and architectural complexity. The opportunity is significant: eSIM enables frictionless digital onboarding, eliminates SIM logistics costs, and opens markets where physical SIM distribution is impractical, such as IoT deployments with millions of remote devices or roaming MVNOs targeting travelers who need instant connectivity on arrival.
The architectural complexity comes from the need to manage operator profiles remotely. Your MVNO platform must include or integrate with a Subscription Manager Data Preparation server (SM-DP+), which creates and delivers encrypted operator profiles to eSIM-enabled devices. This requires new interfaces, new security infrastructure, and new provisioning workflows that do not exist in a physical SIM-only architecture.
The iSIM (integrated SIM) takes this further by embedding the secure element directly into the device's main processor. For IoT MVNOs in particular, iSIM reduces device size and cost significantly. Review the comparison of SIM, eSIM, and iSIM features to understand the architectural implications of each.
Remote SIM Provisioning and SGP.32
Remote SIM Provisioning (RSP) is the set of standards and protocols that govern how operator profiles are downloaded, installed, and managed on eSIM-enabled devices. The GSMA defines these standards, with different specifications for consumer devices and IoT devices.
SGP.32 is the GSMA's specification for IoT remote SIM provisioning. It introduces an eIM (eSIM IoT Remote Manager) architecture that allows operators to manage eSIM profiles on IoT devices at massive scale, including devices that are battery-constrained, intermittently connected, or deployed in remote locations.
For MVNOs building an eSIM-capable architecture, the key infrastructure components are the SM-DP+ server (which prepares and delivers profiles), the SM-DS (Subscription Manager Discovery Server, which helps devices find their profile), and the eIM for IoT use cases. These components must integrate with your OSS for provisioning orchestration and with your BSS for subscription management and charging.
Core Network Identity: HLR, HSS, and UDM
The same identity, three generations of register
| Generation | Register | Authentication | What it holds |
|---|---|---|---|
| 2G and 3G | HLR | AuC | IMSI, MSISDN, service profile, location |
| 4G and IMS | HSS | AuC inside the HSS | The same, plus IMS identities (IMPI, IMPU) |
| 5G | UDM, with data in the UDR | AUSF | The same, split between the function and the data layer |
| Across all three | The subscription itself | Proof the credential holds the right key | What an MVNO actually owns, or does not |
The Role of HLR and HSS in Subscriber Management
The Home Location Register (HLR) is the core database that stores subscriber identity and service information in 2G and 3G networks. The Home Subscriber Server (HSS) serves the same function in 4G/LTE networks, with additional capabilities for IMS (IP Multimedia Subsystem) services. Both hold the master record of every subscriber on your network.
Subscriber identity from the credential to the core, and what multi-IMSI changes.

The HLR and HSS store the subscriber's IMSI, their current location (which network node they are registered to), their service profile (what services they are authorized to use), and their authentication data. When a subscriber attempts to register on the network, the network queries the HLR or HSS to authenticate the subscriber and retrieve their service profile.
For MVNOs operating their own core network, the HLR or HSS is one of the most critical and sensitive components of the platform. Any corruption or outage of subscriber records directly causes service failures. Design your HLR and HSS deployments with geographic redundancy and real-time replication from the start. For MVNOs using an MVNE or host MNO platform, the HLR or HSS is managed by the host, but you should understand how subscriber record updates flow between your BSS and the host's core network.
Unified Data Management in 5G
The 5G Core replaces the HLR and HSS with the Unified Data Management (UDM) function, working alongside the Unified Data Repository (UDR) for data storage. The UDM handles authentication, subscriber data management, and access authorization using a service-based architecture where other network functions query it through HTTP/2 APIs.
This architectural change has practical implications for MVNOs. The UDM's API-based interface makes it easier to integrate with BSS systems and external identity management platforms than legacy HLR and HSS systems, which used proprietary protocols. It also enables more granular and real-time subscriber policy management, supporting advanced use cases such as network slicing and dynamic service authorization.
IMSI Management and Number Portability
IMSI management is an operational discipline that many new MVNOs underestimate. Your IMSI range is a finite resource allocated by your MNO or national regulator. Managing IMSI assignment, recycling of IMSIs from churned subscribers, and tracking IMSI-to-MSISDN-to-account mappings across your BSS and core network requires disciplined processes and tooling.
Number portability adds further complexity. When a subscriber ports their number into your MVNO from another operator, or ports out to a competitor, your platform must execute a coordinated update across your HLR or HSS, your BSS, and the national number portability database. Failures in this process result in misdirected calls and messages, which generate regulatory complaints and customer churn.
Ensure your BSS and OSS platforms include robust number portability management capabilities, and test your porting workflows thoroughly before launch. Number porting failures are among the most visible and damaging operational issues an MVNO can experience in its early months.
Multi-IMSI Architecture for MVNOs
Multi-IMSI connectivity allows a single SIM to carry multiple IMSIs from different networks. This architecture is particularly valuable for roaming MVNOs and IoT MVNOs that need their subscribers or devices to connect to the best available network in any location.
In a multi-IMSI architecture, the SIM stores multiple IMSI and authentication key pairs, each associated with a different network. The SIM's applet logic selects the appropriate IMSI based on the available networks in the current location, enabling seamless connectivity without manual profile switching.
For MVNOs targeting international travelers or deploying IoT devices across multiple countries, multi-IMSI architecture removes the roaming dependency that creates both cost and reliability risks. The trade-off is increased SIM management complexity and the need to maintain commercial relationships and technical integrations with multiple network partners.
Security in Subscriber Identity Management
Subscriber identity data is among the most sensitive data your MVNO manages. IMSI values and authentication keys, if compromised, enable identity fraud, call interception, and unauthorized network access. Protecting this data requires security measures at every layer of your subscriber identity architecture.
SIM manufacturing security is the foundation. Authentication keys must be generated and written to SIM cards in a certified secure manufacturing environment, and the keys must never be transmitted in plaintext outside that environment. Your SIM vendor's security credentials matter as much as their pricing.
At the core network level, protect your HLR, HSS, and UDM from unauthorized access through network segmentation, strict access controls, and signaling firewall protection. SS7 and Diameter protocol vulnerabilities remain active attack vectors against subscriber identity systems, and MVNOs with exposed signaling interfaces are targets. A Session Border Controller provides important protection at the signaling boundary.
For eSIM deployments, the SM-DP+ server must operate in a certified security environment meeting GSMA SAS (Security Accreditation Scheme) standards. Profile delivery to devices uses end-to-end encryption, ensuring that operator credentials cannot be intercepted in transit.
Frequently Asked Questions
What is the difference between IMSI and MSISDN?
The IMSI (International Mobile Subscriber Identity) is the unique identifier stored on the SIM card that identifies the subscriber to the network. It is used for authentication and routing within the mobile network infrastructure. The MSISDN is the subscriber's phone number, the address used to route calls and messages to the subscriber. An MVNO manages the mapping between these two identifiers in its BSS and core network.
Does an MVNO need its own HLR or HSS?
Not necessarily. Light MVNOs and those operating through an MVNE use the host network's HLR or HSS. Only Full MVNOs that operate their own core network need to deploy and manage their own HLR or HSS. The decision depends on your MVNO architecture model and your need for direct control over subscriber records.
What infrastructure does an MVNO need to support eSIM?
At minimum, an MVNO needs access to an SM-DP+ server for consumer eSIM, and an eIM for IoT eSIM under SGP.32. These can be operated in-house or accessed as a managed service from a specialist provider. The SM-DP+ must integrate with your OSS for provisioning and with your BSS for subscription lifecycle management. Learn more about eSIM and SGP.32.
How does number portability work for MVNOs?
When a subscriber ports their number to your MVNO, your platform receives a porting request, validates it, and triggers updates to your HLR or HSS to route calls and messages for that number to your network. Simultaneously, the national number portability database is updated so that other networks know to route traffic for that number to your network. Your BSS manages the commercial aspects of the port, linking the ported number to the subscriber's account.
What is the risk of IMSI exposure?
IMSI exposure allows attackers to track a subscriber's location, intercept calls and messages, and potentially clone their identity. This is why signaling security and SIM manufacturing security are critical. Modern 5G networks introduce SUPI (Subscription Permanent Identifier) and SUCI (Subscription Concealed Identifier) mechanisms that encrypt the IMSI equivalent over the air interface, significantly reducing IMSI exposure risk compared to 4G and earlier generations.
Summary
Subscriber identity management is the technical core of your MVNO's ability to serve customers. From the SIM or eSIM in the subscriber's device, through the authentication protocols of your core network, to the subscriber records in your HLR, HSS, or UDM, every element of this architecture must work correctly and stay synchronized for your network to function reliably.
Invest in understanding your subscriber identity architecture before you launch. Design your provisioning workflows for automation and reliability. Plan your eSIM readiness now, even if your initial launch uses physical SIMs. Protect your subscriber identity data with appropriate security measures at every layer.
Explore the full range of SIM, eSIM, and iSIM resources on MVNO Index, review the core network elements that manage subscriber identity, and use the solution provider directory to identify vendors that deliver the subscriber identity management capabilities your MVNO needs.








