Description
The IP Multimedia CN subsystem Private Identity (IMPI) is a critical identifier within the 3GPP IMS architecture, defined as a permanent and globally unique credential assigned to a user. It is stored securely in the Home Subscriber Server (HSS) and within the IP Multimedia Services Identity Module (ISIM) application on the user's Universal Integrated Circuit Card (UICC). The IMPI is used exclusively for authentication and registration procedures, never for routing SIP messages or public communication. It typically follows the format of a Network Access Identifier (NAI), such as user@realm. During IMS registration, the User Equipment (UE) presents the IMPI along with authentication vectors derived from a shared secret key to the Serving-Call Session Control Function (S-CSCF) via the Proxy-CSCF (P-CSCF). The S-CSCF verifies the credentials with the HSS using authentication protocols like Digest AKAv1-MD5 or later, more secure methods. This process establishes a secure registration binding between the IMPI and the user's IP address, enabling subsequent service authorization. The IMPI's separation from public identities ensures that the user's private authentication key is never exposed on the network, providing a foundational layer of security. It is intrinsically linked to a user's subscription and remains constant, unlike temporary identifiers, forming the anchor for the user's IMS service profile and associated public identities (IMPUs).
Purpose & Motivation
The IMPI was created to provide a secure, subscription-based authentication mechanism for the IMS, which was introduced in 3GPP Release 5 to enable IP-based multimedia services over packet-switched networks. Prior to IMS, circuit-switched mobile networks used the International Mobile Subscriber Identity (IMSI) for authentication, but a new identity was needed for the SIP-based, all-IP service layer that is independent of the underlying access network (e.g., GPRS, WLAN, fixed broadband). The IMPI solves the problem of securely identifying and authenticating a user to the IMS core without revealing permanent credentials during service invocation. It enables a single user with multiple devices or service profiles to have a consistent private identity for authentication, while maintaining multiple public identities for communication. Its creation was motivated by the need for a robust security model that separates authentication (private) from addressing (public), a principle borrowed from Internet security architectures, to prevent impersonation and ensure that only authorized subscribers can access and use IMS services like VoLTE, ViLTE, and RCS.
Classification
Evolution Across Releases
Introduced as the foundational private identity for IMS authentication, initially defined in the IMS stage 1, 2, and 3 specifications (22.228, 23.228, 24.229). It was specified to use the Digest AKAv1-MD5 authentication protocol, with the IMPI stored on the ISIM and in the HSS, establishing the basic registration and security procedures for early IMS deployments.
Explore further
Broader topics and technologies where IMPI plays a role.
Defining Specifications
3GPP specifications that define or reference IMPI, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TR 21.905 vj00 | 3GPP Technical Terms and Definitions | Rel-19 |
| TS 22.066 vj00 | Mobile Number Portability Stage 1 | Rel-19 |
| TS 23.179 vd50 | MCPTT Functional Architecture | Rel-13 |
| TS 23.280 vk10 | Common Architecture for Mission Critical Services | Rel-20 |
| TS 23.379 vk00 | MCPTT Functional Architecture | Rel-20 |
| TS 23.700 vk00 | XR Services Application Enablement Layer | Rel-20 |
| TS 24.109 vj00 | HTTP Digest AKA & GAA Stage 3 | Rel-19 |
| TS 26.237 vj00 | IMS for PSS and MBMS Control | Rel-19 |
| TS 29.109 vj00 | GAA Bootstrapping Interfaces (Zh, Dz, Zn, Zpn) | Rel-19 |
| TS 31.103 vj00 | ISIM Application Specification | Rel-19 |
| TS 31.829 vd00 | ISIM Conformance Requirements Technical Report | Rel-13 |
| TS 32.182 vj00 | UDC Common Baseline Information Model (CBIM) | Rel-19 |
| TS 33.107 vj00 | Lawful Interception Architecture & Functions | Rel-19 |
| TS 33.141 vj00 | Security for Presence Service (Ut reference point) | Rel-19 |
| TS 33.203 vj10 | IMS Security Specification | Rel-19 |
| TS 33.222 vj00 | Secure HTTP Access in GAA | Rel-19 |
| TS 33.804 vc00 | Non-UICC SSO using SIP Digest credentials | Rel-12 |
| TR 33.978 v1800 | Interim Security for Early IMS | Rel-8 |