Description
PIN Elements with Management Capability (PEMC) is a management framework standardized in 3GPP Release 18, primarily within the context of enhanced SIM/UICC management. It defines a structured data model and remote management procedures for PIN-related security elements stored on a UICC. A 'PIN Element' refers to a PIN, its associated PIN Unblocking Key (PUK), and all related attributes such as the PIN value, retry counter, enabled/disabled status, and usage rules (e.g., which operations require PIN verification). The 'Management Capability' signifies that these elements can be created, modified, enabled, disabled, or deleted through remote management protocols, such as those defined by the Remote SIM Provisioning (RSP) architecture for eSIM. The framework is specified across multiple 3GPP specifications: the system architecture (23.501, 23.542), the service requirements for PEMC (23.700), the Non-Access Stratum (NAS) protocols for conveying PIN management messages between UE and network (24.501, 24.583), the management protocol details (26.806), and the security procedures (33.127). Architecturally, PEMC involves the UE, the UICC/eSIM, and network functions like the Subscription Manager - Data Preparation (SM-DP+) or other management servers. The management commands are securely transported to the UICC, which then applies the changes to the specified PIN Element. This allows, for example, an enterprise IT department to remotely reset a device PIN or a mobile operator to initialize PINs during eSIM provisioning without physical access to the device.
Purpose & Motivation
PEMC was developed to overcome the limitations of static, hard-coded PIN management in traditional SIM cards. In legacy systems, PINs and PUKs were pre-programmed by the SIM vendor and could only be changed locally by the user via the device menu, if allowed at all. This posed significant operational challenges for large-scale IoT deployments, enterprise device fleets, and standard consumer eSIM provisioning. If a user forgot a PIN or exhausted retry attempts, physical intervention was often required. PEMC addresses these problems by enabling remote, over-the-air management of PIN security elements. This is crucial for the eSIM ecosystem, where profiles are downloaded remotely; PEMC allows the associated PINs to be configured dynamically as part of the profile provisioning process. It solves logistical headaches in IoT by allowing fleet managers to remotely reset PINs on thousands of sensors. For consumers, it enables self-service PIN recovery through operator portals. The motivation stems from the industry's shift towards fully remote device and subscription lifecycle management, demanding the same flexibility for security features (PINs) as for other subscription data. It enhances both security posture through centralized policy control and user experience by simplifying PIN recovery.
Classification
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (7 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.
- Solve the EN about handling of the PEMC in 5GC in relation with PIN TS 23.501CR4326
- Enabling PEMC manage PIN via UPF local switch TS 23.501CR4760
- PEMC represents the PINE to register TS 23.542CR0014
- Resolve issues related to PIN modification after local PEMC failure TS 23.542CR0019
- Clarification of PEMC represents multiple PINEs or PEGCs to register TS 23.542CR0036
- Clarification on PIN management operations by secondary PEMC TS 23.542CR0037
+ 1 more changes
Explore further
Broader topics and technologies where PEMC plays a role.
Defining Specifications
3GPP specifications that define or reference PEMC, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 23.501 vk20 | 5G System Architecture Stage 2 | Rel-20 |
| TS 23.542 vk20 | Personal IoT Networks (PIN) Application Enabler Layer | Rel-20 |
| TS 23.700 vk10 | AI/ML Application Layer Support Phase 2 | Rel-20 |
| TS 24.501 vk00 | 5G System (5GS) Non-Access Stratum (NAS) Protocol | Rel-20 |
| TS 24.583 vj10 | Application layer support for Personal IoT Network | Rel-19 |
| TR 26.806 vi00 | Technical Report on Smartly Tethering AR Glasses | Rel-18 |
| TS 33.127 vj70 | Lawful Interception Architecture and Functions | Rel-19 |