IMPI

IP Multimedia CN subsystem Private Identity

Identifier →
Introduced in Rel-6 Also in: Security, Core Network

IMPI is a permanent, globally unique private user identifier used for authentication and registration within the IMS, stored securely in the HSS and ISIM, and is fundamental for secure service access.

Category
Identifier
Introduced
Rel-6
Where
Services › Codecs
Also touches
2 segments
Specifications
18 specs
IMPI Description Purpose Related Classification Specifications

Description

The IP Multimedia CN subsystem Private Identity (IMPI) is a critical identifier within the 3GPP IMS architecture, defined as a permanent and globally unique credential assigned to a user. It is stored securely in the Home Subscriber Server (HSS) and within the IP Multimedia Services Identity Module (ISIM) application on the user's Universal Integrated Circuit Card (UICC). The IMPI is used exclusively for authentication and registration procedures, never for routing SIP messages or public communication. It typically follows the format of a Network Access Identifier (NAI), such as user@realm. During IMS registration, the User Equipment (UE) presents the IMPI along with authentication vectors derived from a shared secret key to the Serving-Call Session Control Function (S-CSCF) via the Proxy-CSCF (P-CSCF). The S-CSCF verifies the credentials with the HSS using authentication protocols like Digest AKAv1-MD5 or later, more secure methods. This process establishes a secure registration binding between the IMPI and the user's IP address, enabling subsequent service authorization. The IMPI's separation from public identities ensures that the user's private authentication key is never exposed on the network, providing a foundational layer of security. It is intrinsically linked to a user's subscription and remains constant, unlike temporary identifiers, forming the anchor for the user's IMS service profile and associated public identities (IMPUs).

Purpose & Motivation

The IMPI was created to provide a secure, subscription-based authentication mechanism for the IMS, which was introduced in 3GPP Release 5 to enable IP-based multimedia services over packet-switched networks. Prior to IMS, circuit-switched mobile networks used the International Mobile Subscriber Identity (IMSI) for authentication, but a new identity was needed for the SIP-based, all-IP service layer that is independent of the underlying access network (e.g., GPRS, WLAN, fixed broadband). The IMPI solves the problem of securely identifying and authenticating a user to the IMS core without revealing permanent credentials during service invocation. It enables a single user with multiple devices or service profiles to have a consistent private identity for authentication, while maintaining multiple public identities for communication. Its creation was motivated by the need for a robust security model that separates authentication (private) from addressing (public), a principle borrowed from Internet security architectures, to prevent impersonation and ensure that only authorized subscribers can access and use IMS services like VoLTE, ViLTE, and RCS.

Classification

Part ofIMS
Specific typesISIMTMPI
Related approachesIMSIIMPUHSS

Evolution Across Releases

Rel-6 Initial

Introduced as the foundational private identity for IMS authentication, initially defined in the IMS stage 1, 2, and 3 specifications (22.228, 23.228, 24.229). It was specified to use the Digest AKAv1-MD5 authentication protocol, with the IMPI stored on the ISIM and in the HSS, establishing the basic registration and security procedures for early IMS deployments.

Explore further

Broader topics and technologies where IMPI plays a role.

Defining Specifications

3GPP specifications that define or reference IMPI, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TR 21.905 vj00 3GPP Technical Terms and Definitions Rel-19
TS 22.066 vj00 Mobile Number Portability Stage 1 Rel-19
TS 23.179 vd50 MCPTT Functional Architecture Rel-13
TS 23.280 vk10 Common Architecture for Mission Critical Services Rel-20
TS 23.379 vk00 MCPTT Functional Architecture Rel-20
TS 23.700 vk00 XR Services Application Enablement Layer Rel-20
TS 24.109 vj00 HTTP Digest AKA & GAA Stage 3 Rel-19
TS 26.237 vj00 IMS for PSS and MBMS Control Rel-19
TS 29.109 vj00 GAA Bootstrapping Interfaces (Zh, Dz, Zn, Zpn) Rel-19
TS 31.103 vj00 ISIM Application Specification Rel-19
TS 31.829 vd00 ISIM Conformance Requirements Technical Report Rel-13
TS 32.182 vj00 UDC Common Baseline Information Model (CBIM) Rel-19
TS 33.107 vj00 Lawful Interception Architecture & Functions Rel-19
TS 33.141 vj00 Security for Presence Service (Ut reference point) Rel-19
TS 33.203 vj10 IMS Security Specification Rel-19
TS 33.222 vj00 Secure HTTP Access in GAA Rel-19
TS 33.804 vc00 Non-UICC SSO using SIP Digest credentials Rel-12
TR 33.978 v1800 Interim Security for Early IMS Rel-8
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.