IRI

Intercept Related Information

Security →
Introduced in Rel-8 Also in: Security

IRI is the metadata and call-associated information, such as identities, location, and timestamps, collected during lawful interception of telecommunications, separate from the actual communication content.

Category
Security
Introduced
Rel-8
Where
Core Network › 5G Core
Also touches
1 segments
Specifications
7 specs
IRI Description Purpose Detected Changes Specifications

Description

Intercept Related Information (IRI) is a critical component of the Lawful Interception (LI) architecture standardized by 3GPP. It constitutes the set of information or data associated with the telecommunication services of a target subscriber, excluding the actual content of the communication itself. IRI is generated by network functions such as the Mobile Switching Center (MSC), Serving GPRS Support Node (SGSN), or Mobility Management Entity (MME) and is delivered to a Law Enforcement Monitoring Facility (LEMF) via a Mediation Function (MF). The IRI data stream is separate from the Content of Communication (CC) stream, ensuring a clear distinction between call metadata and the actual voice or data payload.

Architecturally, IRI is defined within the Handover Interface (HI) between the network operator's domain and the law enforcement domain. The generation of IRI is triggered by interception warrants and is based on events occurring within the network for the target subscriber. Key network elements involved include the Intercepting Control Element (ICE), which detects the target's activity and generates the raw IRI, and the Mediation Function, which formats and delivers the IRI according to standardized protocols like ETSI standards or the 3GPP-specific ATIS/T1. LI standards. The delivery uses reliable transport mechanisms to ensure the integrity and authenticity of the intercepted data.

The information contained within IRI is extensive and standardized. It typically includes the identity of the intercepted target (e.g., IMSI, MSISDN), the identity of the communicating party, the location of the target (Cell ID, TAI, or more precise location if available), the time and date of the communication event, the type of communication service (e.g., voice call, SMS, packet data session), and the direction of the communication. For data sessions, IRI may include details like PDP context activation, APN used, and IP addresses assigned. This metadata provides the context necessary for law enforcement to understand the 'who, when, where, and how' of a communication without initially accessing the private content, adhering to legal proportionality principles.

IRI plays a fundamental role in ensuring that network operators can comply with national legal requirements for lawful interception in a standardized, secure, and efficient manner. Its strict separation from CC facilitates controlled access and auditing. The standardization of IRI parameters across 3GPP releases ensures interoperability between equipment from different vendors and consistent data presentation to law enforcement agencies globally, which is crucial for multi-national investigations and operator compliance.

Purpose & Motivation

IRI exists to fulfill legal obligations imposed on telecommunications service providers to assist law enforcement and security agencies in criminal investigations and national security matters. Laws in most countries mandate that network operators must have the technical capability to intercept communications upon presentation of a lawful warrant. Before standardization, proprietary and incompatible interception systems created significant challenges for operators with multi-vendor networks and for law enforcement agencies needing to process data from different operators.

The creation of standardized IRI, as part of the broader 3GPP Lawful Interception framework, solves the problem of interoperability and cost. It defines a uniform set of metadata that must be provided, regardless of the underlying network vendor technology. This allows law enforcement to receive information in a consistent format, simplifying their monitoring tools and procedures. It also reduces development and integration costs for network equipment manufacturers and operators, as they can implement a single, well-defined interface.

Furthermore, the separation of IRI from CC addresses privacy and legal concerns by enabling a tiered approach to interception. Authorities can initially receive just the contextual metadata (IRI) to establish facts, and only access the more intrusive communication content (CC) when specifically justified. This architectural principle supports the legal principle of proportionality. The evolution of IRI across 3GPP releases has been driven by new services (VoLTE, VoWiFi, 5G) and the need to include new types of metadata, such as IMS identities, service domain indicators, and enhanced location information, ensuring the interception capability remains effective in modern, IP-based networks.

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (38 CRs across 5 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 5 changes

In Release 15, corrections and clarifications were made to the stage 3 descriptions for IRI messages across several core network elements. This specifically addressed errors and missing fields in the procedures for HLR-triggered IRI for Packet-Switched services and HSS-triggered IRI for both EPS and IMS. These updates ensured the accurate technical reporting of Intercept Related Information for the targeted services.

  • Missing IRI events fields TS 33.108CR0387
  • Errors in stage 3 descriptions of CS related IRI details TS 33.108CR0389
  • Stage 3 Corrections to the HLR triggered IRI messages for PS TS 33.108CR0390
  • Stage 3 Corrections to the HSS triggered IRI messages for EPS TS 33.108CR0391
  • Stage 3 Corrections to the HSS triggered IRI messages for IMS TS 33.108CR0393
Rel-16 12 changes

In Release 16, the IRI function was enhanced with new fields to support ATSSS (Access Traffic Steering, Switching and Splitting) and received clarifications on the IRI Type for records generated by network functions like the SMF, UPF, SMSF, UDM, LALS, and AMF. The release also provided clarifications on the contents of the IRI TargetIdentifiers field and addressed specific procedural gaps, such as ensuring the session establishment time is included in SMF IRI and separating the LI_X1 interface for CC and IRI delivery when handled by the same network function.

  • IRI fields for ATSSS TS 33.128CR0075
  • IMS LI: Alternate option has potentially missing IRI-POI for certain scenarios TS 33.127CR0110
  • IMS LI: Separate LI_X1 to CC-TF and IRI-POI when in the same NF TS 33.127CR0112
  • Clarifying IRI Type for SMF-UPF IRI records TS 33.128CR0101
  • Clarifying IRI Type for SMSF IRI records TS 33.128CR0102
  • Clarifying IRI Type for UDM IRI records TS 33.128CR0103

+ 6 more changes

Rel-17 4 changes

In Release 17, specific clarifications and corrections were made to the Intercept Related Information (IRI) function. These included updating the requirement for IRI types, providing a clarification on LALS triggering with LMISF-IRI, and correcting the normative text for identifier association at the IRI-POI. Additionally, corrections were made to the IRI types table to ensure accurate technical implementation.

  • Wrong stage 2 normative text of identifier association xIRI for the IRI-POI in the AMF and MME TS 33.127CR0152
  • Update requirement for IRI type TS 33.128CR0251
  • A Clarification on LALS Triggering with LMISF-IRI TS 33.128CR0279
  • Correction to IRI types table 7.2.2.4-1 TS 33.128CR0350
Rel-18 12 changes

In Release 18, the IRI function introduced new events for reporting PDN connection events from the combined SMF+PGW-C and added IRI for location acquisition. It also included clarifications and corrections, such as aligning AMF IRI events between specifications, clarifying the provisioning of equivalent 4G and 5G identifiers as targets, and adding a parameter to indicate the xIRI version used for generation. Furthermore, corrections were made to various technical elements including service scoping at the LMISF-IRI and diagrams for the IRI-POI.

  • IRI Events for reporting PDN Connection events from the combined SMF+PGW-C TS 33.128CR0373
  • Corrections to the diagrams – Part II (IRI-POI_CC-POI) TS 33.127CR0195
  • Alignment of 33.127 and 33.128 AMF IRI Events TS 33.127CR0230
  • IRI for Location Acquisition TS 33.128CR0447
  • Addition of parameter indicating the version of xIRI an IRI is generated from TS 33.128CR0632
  • Correction to table 6.2.3.7-1 SMF IRI Types TS 33.128CR0421

+ 6 more changes

Rel-19 5 changes

In Release 19, the IRI function was enhanced with new security protocols for AKMA-based interception by adding TLS 1.3 and DTLS support for IRI delivery. It also introduced modifications for error handling related to provisioning IRI-POI in the 5G DDNMF and enabled IRI generation in the MDF based on AMF and MME service scoping. Furthermore, the release included alignment for provisioning the SMSF specifically for IRI-only interception scenarios.

  • Adding TLS 1.3 IRI for AKMA LI TS 33.128CR0674
  • Modifications on errors related to provisioning of IRI-POI in 5G DDNMF TS 33.128CR0724
  • Adding DTLS IRI for AKMA LI (Rel-19) TS 33.128CR0728
  • IRI generation in the MDF for AMF and MME based on service scoping TS 33.128CR0739
  • Alignment of SMSF provisioning for IRI only TS 33.128CR0767

Explore further

Broader topics and technologies where IRI plays a role.

Defining Specifications

3GPP specifications that define or reference IRI, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 33.106 vj00 Lawful Interception Requirements (Pre-Rel-15) Rel-19
TS 33.107 vj00 Lawful Interception Architecture & Functions Rel-19
TS 33.108 vj00 LI Handover Interface Specification Rel-19
TS 33.126 vj30 Lawful Interception Requirements Rel-19
TS 33.127 vj50 Lawful Interception Architecture and Functions Rel-19
TS 33.128 vj50 3GPP TS 33.128: Lawful Interception Protocols Rel-19
TS 43.033 vd00 Lawful Interception Stage 2 for GSM/GPRS Rel-13
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.