PVS

Provisioning Server

Management →
Introduced in Rel-17

PVS is a 5G network function that securely delivers configuration data, policies, and service parameters to User Equipment for remote management and provisioning.

Category
Management
Introduced
Rel-17
Where
Core Network › 5G Core
Specifications
3 specs
PVS Description Purpose Related Classification Detected Changes Specifications

Description

The Provisioning Server (PVS) is a standardized network function introduced in 5G System (5GS) architecture, operating within the management and enabling framework. Its primary role is the secure, reliable, and efficient delivery of provisioning information to User Equipment (UE). This information is diverse and can include initial bootstrap configuration for devices (especially crucial for IoT), policy parameters, service-related configuration data, updates for applications on the UE, and parameters for network slice selection. The PVS interacts with other 5G core network functions and external entities like application servers or device management platforms.

Architecturally, the PVS is defined as an application server that communicates with the UE via the 5G core network. A key protocol for this communication is the Provisioning Protocol, which can be based on HTTPS or CoAP for constrained IoT devices. The UE discovers and connects to the PVS using information that may be pre-configured, derived from the UICC, or provided by the network during registration (e.g., via the UDM or PCF). The 5G core network, specifically the Network Exposure Function (NEF), often acts as an intermediary or enabler, providing a secure API-based interface for external Application Functions (AFs) to request the delivery of provisioning data to specific UEs via the PVS.

The provisioning process typically involves several steps. First, the UE triggers provisioning, often at initial power-on or based on a policy. It establishes a secure connection (e.g., TLS/DTLS) to the PVS, authenticated using 5G credentials. The PVS, which may have received provisioning instructions from an external management system, then delivers a structured data package (e.g., a JSON object) to the UE. The UE's provisioning client processes this data, applying the configuration to the relevant subsystems (e.g., updating connectivity policies, configuring an application, or storing service parameters). The PVS supports both push and pull models of data delivery and can handle acknowledgements and error reporting, ensuring the provisioning transaction is complete and successful.

Purpose & Motivation

The PVS was created to address the critical need for scalable, automated, and secure remote device provisioning in 5G, a system designed to support a massive number of diverse devices, from smartphones to massive IoT sensors. Traditional manual provisioning or device-specific management protocols were insufficient for this scale and heterogeneity. The PVS provides a unified, standards-based mechanism within the 5G architecture.

It solves several key problems. First, it enables zero-touch provisioning for IoT devices, allowing them to be deployed in the field and automatically receive their operational configuration from the network, drastically reducing operational costs. Second, it allows for dynamic updates of policies and service parameters without requiring a full device firmware update or user intervention, enabling flexible service delivery. Third, it provides a secure channel for delivering sensitive configuration data, leveraging 5G's robust authentication and security framework. Its introduction was motivated by the vision of network slicing and service-based architecture, where a device's configuration may need to be tailored for specific network slices or applications on-the-fly. The PVS is a foundational enabler for efficient device lifecycle management in the 5G era.

Classification

Related approachesNEFUDM

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (17 CRs across 2 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-17 16 changes

In Release 17, the PVS (Provisioning Server) function was enhanced to support providing its address (IP or FQDN) to a UE during PDU session establishment for onboarding and for obtaining SNPN credentials via the User Plane. The specifications detailed how the AMF and SMF retrieve and convey PVS information, which can be received from a DCS, locally configured, or included in Onboarding Configuration Data, to enable this remote provisioning. Furthermore, mechanisms were defined to restrict PDU sessions used for onboarding to only allow traffic between the UE and the PVS or a DNS server.

  • PVS information providing in PDU session establishment for onboarding TS 24.008CR3268
  • PVS information providing in PDU session establishment for onboarding TS 24.501CR3323
  • Providing PVS addresses for obtaining SO-SNPN credentials when registered for non-onboarding services in SNPN TS 24.501CR3988
  • DCS providing PVS address to ONN TS 23.501CR3085
  • Interaction between PVS and SO-SNPN TS 23.501CR3084
  • Clarification on the FQDN(s) and IP address(es) of PVS for remote provisioning TS 23.501CR3623

+ 10 more changes

Rel-18 1 change

In Release 18, a specific correction was introduced regarding the maximum number of Provisioning Server (PVS) IP addresses and/or Fully Qualified Domain Names (FQDNs) that are allowed to be provided to the User Equipment (UE) for remote provisioning. This change clarifies a technical limit within the procedures where the network supplies PVS address information, which the UE uses to establish a PDU session for accessing the provisioning server. The update ensures consistency in how multiple PVS contact points are managed during credential provisioning for SNPN access.

  • Correction on maximum number of PVS IP address(es) and/or PVS FQDN(s) allowed to be provided to the UE TS 23.501CR4461

Explore further

Broader topics and technologies where PVS plays a role.

Defining Specifications

3GPP specifications that define or reference PVS, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.501 vk00 5G System Architecture Stage 2 Rel-20
TS 24.008 vj50 3GPP TS 24008: Core Network Protocols Rel-19
TS 24.501 vj50 5G NAS Protocols Specification Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.