PCK

Personalisation Control Key

Security →
Introduced in Rel-4 Also in: Security

PCK is a secret key used in a UICC or USIM to lock a mobile device to a specific network, brand, or service provider, enforcing commercial agreements.

Category
Security
Introduced
Rel-4
Where
Services
Also touches
1 segments
Specifications
12 specs
PCK Description Purpose Related Classification Detected Changes Specifications

Description

The Personalisation Control Key (PCK) is a security feature defined within the 3GPP UICC (Universal Integrated Circuit Card) and USIM (Universal Subscriber Identity Module) application toolkit. It is a secret cryptographic key, typically 128 bits long, stored securely in a protected file (EF_PCK) on the UICC. The primary function of the PCK is to facilitate network, service provider, or corporate personalisation of the Mobile Equipment (ME). Personalisation refers to the ability to restrict the ME's operation to work only with a specific UICC, network, or set of services. The mechanism is invoked via the "PERSONALISE" command from the UICC to the ME, which includes a challenge-response authentication protocol using the PCK.

The technical process works as follows: When a personalised ME is powered on with a UICC, the ME reads the personalisation data from the UICC. If personalisation is active, the ME sends a random challenge (RAND) to the UICC. The UICC uses the stored PCK and a cryptographic algorithm (like MILENAGE) to compute a response (RES) and an expected response (XRES). The RES is sent back to the ME. The ME, which also possesses the PCK (programmed into its non-volatile memory during the personalisation process), independently computes the XRES using the same RAND and algorithm. If RES matches XRES, the personalisation check passes, and the ME operates normally. If the check fails, the ME may deny service, restrict functionality, or display a message, depending on the personalisation category (e.g., network, service provider, corporate).

The architecture involves several components: the ME's personalisation framework, the UICC's USIM application with the PCK file, and the over-the-air (OTA) platform used to provision or update the PCK on the UICC. The PCK is distinct from the authentication keys (Ki/K) used for network access; it is solely for device locking. Its role is critical for enforcing commercial policies. For example, a subsidised phone sold by Operator A is personalised with Operator A's PCK, preventing its use with a competitor's SIM until unlocked. The specifications detail multiple personalisation categories (Network, Network Subset, Service Provider, Corporate) each potentially with its own PCK, allowing for granular control. Management commands allow for disabling personalisation (unlocking) if the correct PCK is provided.

Purpose & Motivation

The PCK was introduced to address the commercial need for network operators and handset manufacturers to control the usage environment of mobile devices, particularly in markets where handsets are heavily subsidised. Without such a mechanism, a subsidised device could be immediately used with a competitor's SIM card, undermining the business model of recouping subsidy costs through service revenue. Prior to standardised personalisation, proprietary locking solutions existed, leading to fragmentation and interoperability issues. The PCK, standardised from Release 4 onwards, provided a universal, secure method for personalisation across all 3GPP-compliant devices and UICCs. It solves the problem of device locking in a cryptographically secure manner, preventing easy circumvention. Its creation was motivated by the desire to protect operator investments, manage device fleets for corporate customers, and enable branded service offerings, while maintaining a standardised security framework that is interoperable between different ME and UICC vendors.

Classification

Part ofUSIM
Related approachesOTA

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (1 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-16 1 change

In Release 16, the PCK (Personalisation Control Key) function was newly introduced for the MCData (Mission Critical Data) service. Specifically, this release established the procedures for the creation and management of the PCK within the MCData system architecture.

  • [33.180] R16 Establishment of PCK for MCData TS 33.180CR0112

Explore further

Broader topics and technologies where PCK plays a role.

Defining Specifications

3GPP specifications that define or reference PCK, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TR 21.905 vj00 3GPP Technical Terms and Definitions Rel-19
TS 22.022 vj00 ME Personalisation Features for GSM/3G Rel-19
TS 24.380 vj10 MCPTT Media Plane Control Protocol Rel-19
TS 24.581 vj00 MCVideo Media Plane Control Protocol Specification Rel-19
TS 24.582 vj00 MCData Media Plane Control Protocols Rel-19
TS 29.380 vj00 MCPTT-LMR Interworking Media Plane Control Rel-19
TS 29.582 vj00 MCData Interworking with LMR Systems Rel-19
TS 33.179 vdc0 MCPTT Security Architecture and Procedures Rel-13
TS 33.180 vk00 Security of Mission Critical (MC) Service Rel-20
TS 33.879 vd10 MCPTT Security Study Rel-13
TS 33.880 vf10 Security Study for Enhanced Mission Critical Services Rel-15
TR 33.938 vj10 3GPP Cryptographic Inventory for 5G Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.