GPI

GBA Push Information

Security →
Introduced in Rel-8 Also in: Services

GPI is a GBA security mechanism that enables a network application server to securely push bootstrap information to a UE to initiate communication setup.

Category
Security
Introduced
Rel-8
Where
Security
Also touches
1 segments
Specifications
9 specs
GPI Description Purpose Related Classification Detected Changes Specifications

Description

GBA Push Information (GPI) is a component of the 3GPP Generic Bootstrapping Architecture (GBA), which provides a standardized method for mutual authentication and key agreement between a User Equipment (UE) and a Network Application Function (NAF). While standard GBA relies on the UE initiating the bootstrapping procedure, GPI enables a 'push' model. In this model, a NAF (e.g., a service provider's server) can proactively send essential bootstrapping information to the UE, allowing the UE to subsequently establish a secure connection with that NAF. This information is contained within a GPI message, which is itself a secure object.

Architecturally, GPI involves several key entities defined in GBA: the UE, the Bootstrapping Server Function (BSF), the NAF, and the Home Subscriber Server (HSS). The process begins when a NAF determines it needs to push information to a specific UE. The NAF requests a GPI from the BSF. The BSF, which shares a trust relationship with the HSS, generates the GPI. This GPI contains critical data such as a Bootstrapping Transaction Identifier (B-TID), the NAF's identity, key lifetime information, and potentially other parameters. Crucially, this GPI is cryptographically protected using keys derived from the subscriber's long-term credentials stored in the HSS, ensuring its integrity and authenticity. The BSF sends the GPI to the NAF, which then delivers it to the UE via a push channel, which could be an IP-based push mechanism like SIP Push or an SMS bearer.

Upon receiving the GPI, the UE processes it. The UE can verify the GPI's authenticity because it can derive the same cryptographic keys from its own identity module (USIM/ISIM) and the parameters in the GPI. Once verified, the UE extracts the B-TID and other information. The UE can then contact the BSF using this B-TID to perform a standard GBA bootstrapping run, resulting in the establishment of shared session keys (Ks_NAF) specifically for use with that NAF. Finally, the UE establishes a secure connection (e.g., using TLS) with the NAF using these keys. This mechanism allows services like firmware updates over-the-air (FOTA), instant messaging service activation, or emergency alert systems to securely initiate contact with a device that has not previously interacted with the service server.

Purpose & Motivation

GPI was created to address a limitation in the original GBA model, which was purely 'pull'-based, requiring the UE to always initiate contact with the BSF. Many emerging mobile services, however, are server-initiated (push services). For example, a service provider may need to send a configuration update or an alert to a device. Without a pre-established security context, initiating such communication securely is challenging. GPI solves this by allowing the server to securely push the initial bootstrap 'invitation' to the UE.

Historically, before standardized push security mechanisms, services used less secure methods like plain SMS for activation or relied on pre-provisioned keys, which were difficult to manage at scale. Introduced in 3GPP Release 8 alongside GBA enhancements, GPI leveraged the existing, robust security of the GBA infrastructure (rooted in the USIM) to enable secure server-initiated services. It filled a critical gap in the service enablement ecosystem, allowing for secure, scalable, and standardised push-based service delivery without requiring modifications to the UE's SIM card for each new service.

Classification

Part ofGBA
Related approachesBSFNAFUSIM

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (2 CRs across 2 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 1 change

In Release 15, the specification introduced the detailed procedure for delivering GBA Push Information (GPI) using WAP Push over SMS, including the structure of the GPI envelope and the specific use of WDP port 2948. It defined the interfaces Zpn for the Push-NAF to retrieve GPI from the BSF and Upa for transferring the GPI from the Push-NAF to the UE. Furthermore, this release provided the technical specifications for constructing the push message, including the use of the MIME media type 'application/vnd.3gpp.gpi' and corresponding short codes.

Rel-17 1 change

In Release 17, the GBA Push Information (GPI) function was newly introduced to enable a Push-NAF to establish a shared NAF SA with a UE for push services, using a disposable Ks model. This was specified for use in procedures like the 5G ProSe direct link security mode control, defining the bootstrapping interfaces Zpn and Upa for GPI retrieval and transport. The release also detailed the GPI envelope structure and its delivery mechanisms, such as via WAP Push within an SMS using the specific content type `application/vnd.3gpp.gpi`.

  • Introducing the GBA Push Info (GPI) in the 5G ProSe direct link security mode control procedure TS 24.554CR0067

Explore further

Broader topics and technologies where GPI plays a role.

Defining Specifications

3GPP specifications that define or reference GPI, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 24.109 vj00 HTTP Digest AKA & GAA Stage 3 Rel-19
TS 24.334 vj00 ProSe Protocols and Procedures Rel-19
TS 24.554 vj40 5G Proximity Services (ProSe) Protocols Rel-19
TS 29.109 vj00 GAA Bootstrapping Interfaces (Zh, Dz, Zn, Zpn) Rel-19
TS 33.223 vj00 GBA Push Function Specification Rel-19
TS 33.224 vj00 Generic Push Layer (GPL) Specification Rel-19
TS 33.503 vj20 Security for Proximity Services (ProSe) in 5G Rel-19
TS 33.843 vf10 Security Study for ProSe UE-to-Network Relay Rel-15
TR 33.924 vj00 GBA-OpenID Interworking Specification Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.