ISIM

IMS Subscriber Identity Module

Security →
Introduced in Rel-5 Also in: Services, Security, User Equipment

ISIM is an application on a UICC that securely stores a subscriber's IMS identity and credentials to enable authentication and access to services like VoLTE.

Category
Security
Introduced
Rel-5
Where
Core Network › 5G Core
Also touches
3 segments
Specifications
18 specs
ISIM Description Purpose Related Classification Detected Changes Specifications

Description

The IMS Subscriber Identity Module (ISIM) is a specialized software application residing on a Universal Integrated Circuit Card (UICC), commonly known as a SIM card. It is distinct from the classic SIM application used for cellular network access (CS domain) and the USIM application for 3G/4G packet access (PS domain). The ISIM application is dedicated exclusively to the IP Multimedia Subsystem (IMS), which provides multimedia services like Voice over LTE (VoLTE), video calls, and instant messaging over the mobile packet core.

Architecturally, the ISIM contains a set of securely stored files and parameters essential for IMS registration and service invocation. The most critical data is the IMS Private User Identity (IMPI), a unique global identifier for the subscriber in the IMS realm (often formatted like a NAI, e.g., user@domain.com). It also stores the corresponding IMS Public User Identity (IMPU), which is the address used for communication (e.g., a SIP URI). Furthermore, the ISIM holds long-term authentication credentials: a shared secret key and the associated authentication algorithm parameters. These credentials are used in the IMS Authentication and Key Agreement (IMS AKA) procedure.

When a user wishes to access IMS services, the mobile device's IMS client reads the necessary identities from the ISIM. During registration, the device and the network perform the IMS AKA protocol. The device uses the secret key from the ISIM to compute a response to a challenge from the network. This process authenticates the subscriber to the IMS network and establishes secure session keys for protecting SIP signaling. The ISIM thus acts as the root-of-trust for IMS access, analogous to how USIM authenticates the user to the packet core network.

The ISIM application interoperates with other applications on the same UICC. A device may use the USIM for accessing the LTE/5G network (for bearer connectivity) and the ISIM simultaneously for accessing IMS services over that bearer. This separation allows for independent management of credentials and services. The ISIM's role is foundational for IMS security and service portability, as the subscriber's IMS identity and credentials are physically stored on a portable, tamper-resistant card.

Purpose & Motivation

The ISIM was created to provide a secure, portable, and standardized identity module specifically for the IMS, which is a service architecture separate from the traditional cellular access networks. Before ISIM, early IMS implementations often used soft credentials (username/password stored in the device) or attempted to derive IMS identities from cellular identities (like IMSI). These approaches had security weaknesses (soft credentials are vulnerable) or limitations in flexibility (tight coupling to cellular subscription).

A dedicated module was necessary because IMS authentication (IMS AKA) is different from the cellular network authentication (used by SIM/USIM). IMS uses SIP-based protocols and requires identities formatted as URIs or NAIs, not MSISDN or IMSI. The ISIM provides a secure hardware container for these new identity formats and the associated cryptographic keys, ensuring a high level of security equivalent to that of cellular access. It also enables service portability; a user can move their UICC to a new device and immediately have their IMS identity and services available.

Its introduction in Release 5 coincided with the initial standardization of IMS. It solved the problem of how to securely and manageably provision IMS subscriptions to end-users. By leveraging the existing UICC platform, it allowed operators to offer IMS services using a familiar, secure distribution mechanism (the SIM card). The ISIM established a clear separation of credentials, allowing a user to have independent subscriptions for cellular access and IMS services, even if provided by the same operator.

Classification

Part ofUSIM
Related approachesIMPIIMPU

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (4 CRs across 2 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 1 change

In Release 15, the ISIM function was updated to support Mission Critical Services. Specifically, the release introduced the capability for the ISIM to store and provide Mission Critical Services configuration data. This enhancement allowed the ISIM application to contain the necessary service settings for these critical communications.

  • Mission Critical Services configuration data update to ISIM TS 31.103CR2
Rel-18 3 changes

In Release 18, the ISIM function was enhanced with new elementary files (EFs) for specific configurations. These additions include an EF for Access Control to GBA_U_APIs and an EF for IMS Data Channel configuration. Furthermore, the existing EF for IMS Data Channel configuration on the ISIM was updated.

  • Add EF of Access Control to GBA_U_APIs for the ISIM TS 31.103CR1
  • Add EF of IMS Data Channel configuration to the ISIM TS 31.103CR1
  • Update EF of IMS Data Channel configuration on the ISIM TS 31.103CR2

Explore further

Broader topics and technologies where ISIM plays a role.

Defining Specifications

3GPP specifications that define or reference ISIM, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TR 21.905 vj00 3GPP Technical Terms and Definitions Rel-19
TR 22.944 vj00 UE Functionality Split Scenarios and Requirements Rel-19
TR 22.980 vj00 Network Composition Feasibility Study Rel-19
TS 23.228 vj50 IMS Stage-2 Service Description Rel-19
TS 23.700 vk00 XR Services Application Enablement Layer Rel-20
TS 24.167 vj00 3GPP IMS Management Object Specification Rel-19
TS 24.186 vj60 IMS Data Channel applications Rel-19
TS 24.229 vj50 IMS call control protocol based on SIP and SDP Rel-19
TS 31.103 vj00 ISIM Application Specification Rel-19
TS 31.829 vd00 ISIM Conformance Requirements Technical Report Rel-13
TR 31.901 ve00 USIM/ISIM/USAT Feature Review Study Rel-14
TS 32.181 vj00 User Data Convergence Management Framework Rel-19
TS 32.182 vj00 UDC Common Baseline Information Model (CBIM) Rel-19
TS 32.808 v1800 Common User Profile Storage Framework Rel-8
TS 33.141 vj00 Security for Presence Service (Ut reference point) Rel-19
TS 33.203 vj10 IMS Security Specification Rel-19
TS 33.812 v920 M2M Remote Subscription Management Security Rel-9
TR 33.978 v1800 Interim Security for Early IMS Rel-8
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.