PEMC

PIN Elements with Management Capability

Management →
Introduced in Rel-18 Also in: Services

PEMC is a framework for managing PIN elements and their attributes on a UICC or eSIM to enable remote security management.

Category
Management
Introduced
Rel-18
Where
Core Network › 5G Core
Also touches
1 segments
Specifications
7 specs
PEMC Description Purpose Related Classification Detected Changes Specifications

Description

PIN Elements with Management Capability (PEMC) is a management framework standardized in 3GPP Release 18, primarily within the context of enhanced SIM/UICC management. It defines a structured data model and remote management procedures for PIN-related security elements stored on a UICC. A 'PIN Element' refers to a PIN, its associated PIN Unblocking Key (PUK), and all related attributes such as the PIN value, retry counter, enabled/disabled status, and usage rules (e.g., which operations require PIN verification). The 'Management Capability' signifies that these elements can be created, modified, enabled, disabled, or deleted through remote management protocols, such as those defined by the Remote SIM Provisioning (RSP) architecture for eSIM. The framework is specified across multiple 3GPP specifications: the system architecture (23.501, 23.542), the service requirements for PEMC (23.700), the Non-Access Stratum (NAS) protocols for conveying PIN management messages between UE and network (24.501, 24.583), the management protocol details (26.806), and the security procedures (33.127). Architecturally, PEMC involves the UE, the UICC/eSIM, and network functions like the Subscription Manager - Data Preparation (SM-DP+) or other management servers. The management commands are securely transported to the UICC, which then applies the changes to the specified PIN Element. This allows, for example, an enterprise IT department to remotely reset a device PIN or a mobile operator to initialize PINs during eSIM provisioning without physical access to the device.

Purpose & Motivation

PEMC was developed to overcome the limitations of static, hard-coded PIN management in traditional SIM cards. In legacy systems, PINs and PUKs were pre-programmed by the SIM vendor and could only be changed locally by the user via the device menu, if allowed at all. This posed significant operational challenges for large-scale IoT deployments, enterprise device fleets, and standard consumer eSIM provisioning. If a user forgot a PIN or exhausted retry attempts, physical intervention was often required. PEMC addresses these problems by enabling remote, over-the-air management of PIN security elements. This is crucial for the eSIM ecosystem, where profiles are downloaded remotely; PEMC allows the associated PINs to be configured dynamically as part of the profile provisioning process. It solves logistical headaches in IoT by allowing fleet managers to remotely reset PINs on thousands of sensors. For consumers, it enables self-service PIN recovery through operator portals. The motivation stems from the industry's shift towards fully remote device and subscription lifecycle management, demanding the same flexibility for security features (PINs) as for other subscription data. It enhances both security posture through centralized policy control and user experience by simplifying PIN recovery.

Classification

Part ofPIN
Related approachesPUK

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (7 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-18 7 changes

In Release 18, the specifications introduced clarifications and enhancements for the PIN Element with Management Capability (PEMC) function, including enabling the PEMC to manage the PIN via UPF local switch and resolving issues related to PIN modification after a local PEMC failure. The release also provided clarifications on scenarios where a PEMC represents multiple PIN Elements (PINEs) or PEGCs to register and on PIN management operations performed by a secondary PEMC. Furthermore, it addressed authorization procedures for PEGC and PEMC entities within the 5G Core network.

  • Solve the EN about handling of the PEMC in 5GC in relation with PIN TS 23.501CR4326
  • Enabling PEMC manage PIN via UPF local switch TS 23.501CR4760
  • PEMC represents the PINE to register TS 23.542CR0014
  • Resolve issues related to PIN modification after local PEMC failure TS 23.542CR0019
  • Clarification of PEMC represents multiple PINEs or PEGCs to register TS 23.542CR0036
  • Clarification on PIN management operations by secondary PEMC TS 23.542CR0037

+ 1 more changes

Explore further

Broader topics and technologies where PEMC plays a role.

Defining Specifications

3GPP specifications that define or reference PEMC, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.501 vk00 5G System Architecture Stage 2 Rel-20
TS 23.542 vk10 Application layer support for Personal IoT Network Rel-20
TS 23.700 vk00 XR Services Application Enablement Layer Rel-20
TS 24.501 vj50 5G NAS Protocols Specification Rel-19
TS 24.583 vj00 Application Layer Support for Personal IoT Network Rel-19
TR 26.806 vi00 Technical Report on Smartly Tethering AR Glasses Rel-18
TS 33.127 vj50 Lawful Interception Architecture and Functions Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.