IPPR

Internet Protocol Packet Reporting

Security →
Introduced in Rel-18

IPPR is a Lawful Interception mechanism for reporting specific IP packet flows, including metadata and content, to authorized Law Enforcement Agencies for security and investigative purposes.

Category
Security
Introduced
Rel-18
Where
Core Network › 5G Core
Specifications
3 specs
IPPR Description Purpose Related Classification Detected Changes Specifications

Description

Internet Protocol Packet Reporting (IPPR) is a standardized function within the 3GPP Lawful Interception (LI) architecture, defined to facilitate the interception and reporting of Internet Protocol (IP) packet-based communications. It operates as a specific type of Intercept Related Information (IRI) and Content of Communication (CC) reporting, focusing on the granular details of IP data flows associated with a target of interception. The IPPR function is implemented within network nodes that handle user plane traffic, such as the Packet Data Network Gateway (PGW), User Plane Function (UPF), or dedicated mediation devices. When activated by a lawful authorization, these nodes are configured to identify the IP traffic belonging to the specified target—using identifiers like IP address, subscription identifier, or other packet filters—and to duplicate and forward this traffic along with rich metadata to the Law Enforcement Monitoring Facility (LEMF).

The technical operation of IPPR involves several key components and interfaces. First, the Administration Function (ADMF) receives the lawful authorization and target identity from the LEA and distributes the interception commands securely to the relevant Intercepting Control Elements (ICEs) in the network, such as the gateway handling the target's session. The ICE, upon activation, performs deep packet inspection and filtering on the user plane to isolate the target's IP packets. For each intercepted flow, IPPR generates structured reports that include both the CC (the actual payload of the IP packets) and associated IRI, which contains metadata like source and destination IP addresses, port numbers, protocol type (TCP/UDP), timestamps, and packet sizes. This data is formatted according to 3GPP-specified encoding standards (e.g., using IPDR or ETSI HI standards) and is transported over secure, dedicated interfaces (the HI2 and HI3 interfaces) to the Mediation Function (MF), which adapts and delivers it to the LEMF.

IPPR's role is critical in modern networks where virtually all communication is IP-based. It provides law enforcement with the technical capability to monitor targeted internet activities, including web browsing, email, messaging over IP, and Voice over IP (VoIP) calls, in a standardized and reliable manner. The specification ensures that the interception is performed without degrading the quality of service for the target or other users and maintains strict access controls and logging to prevent abuse. The detailed packet-level reporting allows investigators to reconstruct communication sessions, analyze data exchange patterns, and gather digital evidence, making it a powerful tool for lawful surveillance in the digital age.

Purpose & Motivation

IPPR was developed to address the evolving requirements for lawful interception in all-IP telecommunications networks. As mobile networks transitioned from circuit-switched voice to packet-switched data services (culminating in 4G LTE and 5G which are fully IP-based), traditional interception methods designed for voice calls became inadequate. Law Enforcement Agencies (LEAs) worldwide have legal mandates requiring telecommunications operators to provide access to targeted communications for criminal investigations and national security. The purpose of IPPR is to fulfill these legal obligations by providing a standardized, scalable, and technically robust mechanism to intercept and report IP packet flows.

Its creation was motivated by the need for a consistent, vendor-interoperable standard that could handle the complexity and volume of IP traffic. Prior to such standardization, interception capabilities were often proprietary, making it difficult for operators to deploy multi-vendor networks and for LEAs to interface with different operators. IPPR, as part of the broader 3GPP LI framework (TS 33.107 series), defines the precise procedures, interfaces, and data formats for IP packet reporting, ensuring that evidence collected is admissible and that operator implementations comply with regional regulations. It solves the critical problem of how to efficiently filter, capture, and report specific data streams from the high-speed, multiplexed IP traffic in modern core networks without compromising network performance or user privacy for non-targeted individuals.

Classification

Part ofIRI

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (2 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Studied in Rel-18, normative work from Rel-19.

Rel-19 2 changes

In Release 19, the IPPR (Internet Protocol Packet Reporting) mechanism was formally introduced into the 3GPP security architecture specifications TS 33.108 and TS 33.128. This provides capabilities for packet header and packet summary IRI (Interception-Related Information) reporting as a defined alternative to existing Packet Data Header and Packet Data Summary mechanisms. The introduction aligns IP packet reporting procedures across relevant 3GPP and referenced ETSI technical specifications.

  • Support for IPPR mechanism in TS 33.108 TS 33.108CR0434
  • Support for IPPR mechanism in TS 33.128 TS 33.128CR0665

Explore further

Broader topics and technologies where IPPR plays a role.

Defining Specifications

3GPP specifications that define or reference IPPR, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 33.108 vj00 LI Handover Interface Specification Rel-19
TS 33.127 vj50 Lawful Interception Architecture and Functions Rel-19
TS 33.128 vj50 3GPP TS 33.128: Lawful Interception Protocols Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.