LIID

Lawful Interception Identifier

Security →
Introduced in Rel-8

LIID is a unique identifier assigned to a target, such as a subscriber or IP address, to enable law enforcement to unambiguously request and audit the interception of specific communications from a network operator.

Category
Security
Introduced
Rel-8
Where
Core Network › 5G Core
Specifications
2 specs
LIID Description Purpose Related Classification Detected Changes Specifications

Description

The Lawful Interception Identifier (LIID) is a critical parameter within the 3GPP lawful interception (LI) architecture, defined in the Handover Interface (HI) specifications. It serves as a unique, persistent reference for a specific interception task or target within the network operator's domain. When a Law Enforcement Agency (LEA) issues a lawful interception warrant, it includes a LIID which is then used in all subsequent communications between the LEA's Monitoring Facility (MF) and the network operator's Administration Function (ADMF) and Delivery Functions (DF). The LIID is generated by the LEA or the network operator (as per national regulations) and is included in every Interception Related Information (IRI) and Content of Communication (CC) report sent to the LEA. This allows the LEA to correlate all intercepted data—call metadata, SMS details, IP session information, and actual voice/data content—back to the original warrant and the specific target. Technically, the LIID is carried within the standardized HI2 and HI3 interfaces using protocols like X.500/X.509 and IP-based transport. Its presence ensures that even if a target changes their IMSI, MSISDN, or IP address during the interception period, all intercepted data can still be correctly associated with the same warrant and target instance, maintaining the integrity and continuity of the interception operation.

Purpose & Motivation

The LIID was introduced to address significant operational challenges in pre-3GPP Release 8 lawful interception systems. Earlier implementations often relied solely on dynamic identifiers like IMSI or MSISDN to identify the target within interception reports. However, these identifiers can change (e.g., SIM swap, number portability) or be temporarily unavailable, causing intercepted data to be misassociated or lost, potentially jeopardizing an investigation. Furthermore, without a unique, warrant-specific identifier, it was difficult for Law Enforcement Agencies to manage multiple concurrent interceptions for the same target under different warrants or to accurately audit which data belonged to which legal authorization. The LIID solves these problems by providing a stable, warrant-level identifier that persists for the duration of the interception order, independent of the target's network identifiers. This was motivated by the increasing complexity of telecommunications, including the rise of IP-based services (VoIP, messaging apps) and multi-device users, which made tracking targets based solely on traditional identifiers insufficient. The LIID thus enhances the precision, reliability, and legal defensibility of lawful interception operations in modern networks.

Classification

Part ofIRI
Related approachesADMFDF2DF3HI2HI3

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (1 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-16 1 change

In Release 16, the specification formalized the usage of the LIID and other parameters for correlation. It introduced the flexibility for an operator to assign either a unique LIID for each target identity or a single LIID for multiple identities pertaining to the same target, based on an agreement with the LEA. The update also explicitly recommended using a single LIID to simplify correlating IMS signaling with GSN-delivered Content of Communication at the LEMF.

  • Usage of LIID and other parameters TS 33.127CR0010

Explore further

Broader topics and technologies where LIID plays a role.

Defining Specifications

3GPP specifications that define or reference LIID, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 33.108 vj00 LI Handover Interface Specification Rel-19
TS 33.127 vj50 Lawful Interception Architecture and Functions Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.