PIN

Personal Identification Number

Security →
Introduced in Rel-2 Also in: Core Network, User Equipment, Security, Radio Access Network

PIN is a numeric password used in 3GPP to authenticate a user and secure SIM/USIM cards, device access, and network services, preventing unauthorized use.

Category
Security
Introduced
Rel-2
Where
Services › Codecs
Also touches
4 segments
Specifications
35 specs
PIN Description Purpose Related Classification Detected Changes Specifications

Description

The Personal Identification Number (PIN) is a core security concept in 3GPP systems, serving as a secret numeric code used for authentication and access control. Primarily, it is associated with the Subscriber Identity Module (SIM) or Universal SIM (USIM) card inserted into a mobile device. The PIN locks the SIM/USIM itself; if enabled, the user must enter the correct PIN to unlock the card and allow the mobile equipment to access the network services stored on it. This prevents unauthorized use of the SIM if the device is lost or stolen. There are typically two PINs: PIN1 (the standard PIN) and PIN2 (used for certain advanced functions like fixed dialing numbers). The PIN is stored securely on the SIM/USIM and is verified locally by the card; it is not transmitted over the network, enhancing security. Beyond SIM locking, PIN concepts extend to service access, such as PIN authentication for value-added services or as part of two-factor authentication schemes. The management of PINs includes capabilities to enable/disable PIN checking, change the PIN, and handle PIN unblocking using a PUK (PIN Unblocking Key) if the PIN is entered incorrectly too many times. Architecturally, the PIN verification is handled between the Mobile Equipment (ME) and the SIM/USIM via standardized commands (e.g., ENTER PIN). The network operator can set initial PIN values and PUKs. PINs are a critical element in the 3GPP security framework, protecting subscriber identity and subscription data at the physical card level.

Purpose & Motivation

The PIN was introduced from the earliest GSM releases (Rel-2) to address the fundamental security problem of protecting the physical SIM card and the subscriber's identity. Without a PIN, a SIM card could be used freely in any device, leading to fraud and unauthorized access to network services. The PIN provides a simple, user-managed layer of protection for the subscription. It solves the issue of device theft or loss by ensuring the SIM itself is locked. Over releases, the PIN concept evolved to support more complex services and management capabilities, reflecting its role as a basic but vital authentication element. Its persistence across all releases underscores its enduring importance in mobile security, even as more advanced authentication like biometrics emerge. The extensive list of specifications referencing PIN highlights its integration into subscription management, service access, device management, and security procedures.

Classification

Specific typesDPPEMCPEGCPUK
Related approachesSIMUSIMPUK

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (79 CRs across 3 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-18 73 changes

In Release 18, the PIN function was significantly expanded beyond the traditional USIM access control to become a core network-managed capability for 5G. The release introduced support for PIN within the 5G Core (5GC), including specific procedures for PIN communication and policy configuration, traffic routing, and QoS management. Furthermore, it defined PIN identifiers and integrated PIN support into network policies, such as supporting PIN ID in URSP rules, to enable new secure group communication and service provisioning use cases.

  • Addition of PIN requirement for credentials provisioning TS 22.101CR0578
  • Adding leftover PIN requirement to normative spec TS 22.261CR0622
  • Requirements on PIN element discovery restriction TS 22.859CR0001
  • Addition of consolidated requirements for use case on PIN element discovery restriction TS 22.859CR0017
  • UE requesting to be added to a PIN TS 22.859CR0018
  • PIN support in 5GC TS 23.501CR3854

+ 67 more changes

Rel-19 5 changes

In Release 19, the new work focused on the Personal IoT Network (PIN) as a network function, introducing Stage 2 architecture work and capabilities like PIN element discovery. The release also addressed configuration and rule management through corrections to the PIN service switch configure procedure and its associated XML schema, alongside defining limitations for URSP rules when interacting with a PIN.

  • PIN element discovery TS 23.542CR0061
  • Stage 2 on Personal IoT Network (PIN) TS 33.127CR0278
  • URSP rule limitations with PIN. TS 29.525CR0375
  • Correction for PIN service switch configure procedure TS 23.542CR0066
  • Correction on XML schema and structure for <pin-configuration-service-switch-configure-request> element TS 24.583CR0013
Rel-20 1 change

In Release 20, the PIN function was enhanced to provide support for complex tethered device scenarios. This update built upon the existing framework where the USIM manages a numeric PIN, an unblocking key, and associated error counters to control access to protected data and functions. The specific enhancements addressed the operational complexities introduced when devices are tethered together.

  • PIN enhance to support for complex tethered device scenarios TS 23.542CR0068

Explore further

Broader topics and technologies where PIN plays a role.

Defining Specifications

3GPP specifications that define or reference PIN, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 21.111 vj00 USIM and UICC Requirements for 3G Rel-19
TS 21.133 v1400 3G Security Requirements Rel-5
TR 21.905 vj00 3GPP Technical Terms and Definitions Rel-19
TS 22.101 vk00 Service Principles for PLMNs Rel-20
TS 22.105 vj00 Telecommunication Services Framework Rel-19
TS 22.153 vk00 Multimedia Priority Service (MPS) requirements Rel-20
TS 22.261 vk30 5G System Service Requirements Rel-20
TR 22.854 vh10 Feasibility Study on Multimedia Priority Service - Phase 2 Rel-17
TR 22.859 vi20 Technical Report Rel-18
TR 22.950 vj00 Feasibility Study on Priority Service Rel-19
TR 22.953 vj00 Multimedia Priority Service Feasibility Study Rel-19
TS 23.501 vk00 5G System Architecture Stage 2 Rel-20
TS 23.542 vk10 Application layer support for Personal IoT Network Rel-20
TS 23.700 vk00 XR Services Application Enablement Layer Rel-20
TS 24.501 vj50 5G NAS Protocols Specification Rel-19
TS 24.583 vj00 Application Layer Support for Personal IoT Network Rel-19
TS 25.123 vj00 Radio Resource Management for TDD Rel-19
TS 25.133 vj00 UTRAN RRM Requirements for FDD Rel-19
TR 26.806 vi00 Technical Report on Smartly Tethering AR Glasses Rel-18
TS 27.007 vj40 AT Command Set for UE Rel-19
TS 29.244 vj40 PFCP Specification for Control/User Plane Separation Rel-19
TS 29.502 vj50 5G System; Nsmf Service Based Interface; Stage 3 Rel-19
TS 29.503 vj50 UDM Service Based Interface Stage 3 Rel-19
TS 29.525 vj40 5G UE Policy Control Service Stage 3 Rel-19
TS 29.583 vj00 PINAPP Stage 3 Protocol for PIN-9 Interface Rel-19
TS 31.102 vj40 USIM Application Specification Rel-19
TS 31.103 vj00 ISIM Application Specification Rel-19
TS 31.105 vj10 Slice Subscriber Identity Module (SSIM) Application Rel-19
TS 31.113 v1800 USAT Interpreter Byte Code Specification Rel-8
TS 31.121 vi50 UICC-terminal interface test specification Rel-18
TS 31.220 vj00 Contact Manager for UICC Applications Rel-19
TR 31.900 vj00 3GPP TS 31.900: Security Interworking Guidance Rel-19
TS 32.808 v1800 Common User Profile Storage Framework Rel-8
TS 33.127 vj50 Lawful Interception Architecture and Functions Rel-19
TR 33.882 vi01 Technical Report on 5G Security for Personal IoT Networks Rel-18
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.