Description
PIN Elements with Gateway Capability (PEGC) is a concept introduced in 3GPP Release 18, defined across multiple specifications including TS 23.501 and TS 29.583. It involves enhancing traditional PIN-based authentication elements with gateway capabilities to facilitate secure and efficient access in advanced network architectures like 5G. The architecture integrates PEGC into the authentication and security framework, where it acts as an intermediary between user equipment (UE) and network functions, providing both identity verification and gateway services. This is particularly relevant in scenarios involving network slicing, edge computing, and non-public networks (NPNs), where trusted access is critical.
In operation, PEGC works by leveraging PIN elements—such as those used in SIM cards or embedded secure elements—to authenticate users or devices, while the gateway capability allows it to route traffic, enforce policies, and manage connectivity. For example, in a network slice for industrial IoT, a PEGC might authenticate a sensor using its PIN credentials and then gateway the sensor's data to a specific slice instance, ensuring isolation and security. Key components include the PIN management function, which handles PIN verification, and the gateway function, which provides routing, filtering, and protocol translation. PEGC interfaces with other network functions via service-based interfaces (e.g., Nudm for authentication) or reference points, as detailed in specs like TS 24.501 and TS 33.127.
The role of PEGC in the network is to enhance security and flexibility in access control. It enables fine-grained authentication, where PIN elements are used not just for initial access but for ongoing verification in dynamic environments. By combining gateway capabilities, PEGC can also support traffic steering, for instance, directing authenticated users to localized edge services. This is vital for use cases like mission-critical communications or private 5G networks, where low latency and high reliability are required. PEGC contributes to the overall security architecture by providing a trusted point for identity assertion, reducing the risk of unauthorized access, and enabling seamless mobility across different network domains.
Purpose & Motivation
PEGC was created to address the evolving security and access needs of 5G networks, especially with the proliferation of network slicing, edge computing, and diverse device types (e.g., IoT sensors, AR/VR headsets). Prior approaches relied on separate authentication and gateway functions, which could lead to complexity, latency, and security gaps in dynamic scenarios. Limitations included inefficient handling of PIN-based authentication in gateway contexts, lack of integration with network slicing, and limited support for edge access, making it hard to ensure trusted and efficient connectivity for specialized services.
The motivation for PEGC stems from 3GPP's efforts to enhance network flexibility and security in Release 18 and beyond. It solves problems such as how to securely authenticate devices in edge locations without centralized servers, how to gateway traffic for isolated network slices, and how to simplify access control for non-public networks. Historically, PIN elements were used primarily for subscriber identity in cellular networks, but with PEGC, they are extended to provide gateway services, enabling a more integrated and scalable solution. This addresses the need for lightweight, yet robust, authentication mechanisms in decentralized architectures.
PEGC also supports the trend towards network automation and service-based architectures. By embedding gateway capabilities into PIN elements, it reduces the dependency on external gateways for basic routing, lowering latency and improving efficiency. This is particularly important for time-sensitive applications in industrial IoT or vehicular communications. The inclusion in multiple specs, from core network (23.501) to security (33.127), indicates its cross-cutting role in 5G evolution. PEGC helps operators deploy secure, slice-aware networks while maintaining backward compatibility with existing PIN-based systems, ensuring a smooth transition to more advanced authentication and access paradigms.
Classification
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (6 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.
In Release 18, the PEGC (PIN Element with Gateway Capability) function was enhanced with procedures for handling authorization failures and selecting proper routes for PINE join/leave requests. The specifications also introduced mechanisms for notifying PIN elements about a backup PEGC and for resolving authorization issues for the PEGC and PEMC. Furthermore, corrections were made to descriptions and procedures concerning PIN modification during PEGC unavailability and for enabling PINE communication via the 5GS and a PEGC.
- Correction on description about PEGC TS 23.501CR4733
- Correction of PIN modification due to PEGC unavailability TS 23.542CR0007
- PEGC authorization failure and select proper route for PINE join/leave request TS 23.542CR0013
- PINE Communication via 5GS+PEGC TS 23.542CR0046
- Resolving EN on PEGC/PEMC authorization TS 23.542CR0048
- Notifying the PIN elements about backup PEGC TS 23.542CR0056
Explore further
Broader topics and technologies where PEGC plays a role.
Defining Specifications
3GPP specifications that define or reference PEGC, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 23.501 vk00 | 5G System Architecture Stage 2 | Rel-20 |
| TS 23.542 vk10 | Application layer support for Personal IoT Network | Rel-20 |
| TS 23.700 vk00 | XR Services Application Enablement Layer | Rel-20 |
| TS 24.501 vj50 | 5G NAS Protocols Specification | Rel-19 |
| TS 24.583 vj00 | Application Layer Support for Personal IoT Network | Rel-19 |
| TR 26.806 vi00 | Technical Report on Smartly Tethering AR Glasses | Rel-18 |
| TS 29.583 vj00 | PINAPP Stage 3 Protocol for PIN-9 Interface | Rel-19 |
| TS 33.127 vj50 | Lawful Interception Architecture and Functions | Rel-19 |
| TR 33.882 vi01 | Technical Report on 5G Security for Personal IoT Networks | Rel-18 |