Description
The Lawful Interception Provisioning Function (LIPF) is a standardized Network Function (NF) within the 5G Core (5GC) architecture, introduced as part of the enhanced lawful interception framework for 5G systems. Its primary role is to act as a centralized provisioning point for all lawful interception-related configuration data required by various intercepting Network Functions (I-NFs) and the Lawful Interception Function (LIF). The LIPF stores and manages interception warrants, which include details such as the target's identity (e.g., SUPI, MSISDN), the scope of interception (e.g., content of communications, intercept-related information), authorized agencies, and the duration of the interception order. It provides this information to other NFs upon request or via subscription/notification mechanisms.
Operationally, when a lawful interception request is authorized, the relevant administrative authority (e.g., the Law Enforcement Agency via the Lawful Interception Administration Function) provisions the interception warrant into the LIPF. The LIPF then distributes the necessary configuration to the appropriate network functions. For example, it may provision a target's identity to the Access and Mobility Management Function (AMF) to trigger interception when the target UE registers or establishes a session. It may also provision data to the Session Management Function (SMF), User Plane Function (UPF), or other NFs involved in monitoring content or collecting intercept-related information. The LIPF uses standardized service-based interfaces, likely based on HTTP/2, to communicate with consumer NFs, aligning with the 5GC's service-based architecture principles.
The LIPF plays a crucial role in separating the provisioning logic from the interception execution logic. This centralization simplifies management, improves auditability, and ensures consistency. It prevents the need for each individual NF to be configured separately for interception tasks, which is vital in a dynamic, cloud-native 5G environment where NFs can be instantiated and scaled elastically. The LIPF interacts with the Lawful Interception Function (LIF), which handles the secure delivery of intercepted data to the collection function. By managing the 'what' and 'who' of interception, the LIPF allows the I-NFs to focus on the 'how'—the actual technical implementation of intercepting the specified traffic or events for the provisioned targets.
Purpose & Motivation
The LIPF was created to address the challenges of implementing lawful interception in the 5G Core's service-based architecture (SBA). Previous 3GPP architectures had more monolithic network elements where LI configuration was often handled via proprietary or element-specific management interfaces. With 5G's decomposition into numerous, independently scalable Network Functions, manually provisioning interception parameters across dozens of potential NF instances became operationally complex, error-prone, and slow.
The motivation for standardizing the LIPF was to provide an automated, centralized, and standardized method for provisioning interception warrants. This solves the problem of consistency—ensuring all relevant NFs have the same, up-to-date information about interception targets. It also addresses the need for agility in cloud-native deployments, allowing new NF instances to automatically retrieve necessary LI configuration. The LIPF was driven by regulatory requirements that mandate efficient and reliable lawful interception capabilities, necessitating a modern architectural approach that matches the flexibility and distribution of 5G networks while maintaining strict compliance controls.
Release Timeline
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (7 CRs across 3 releases). Complements the general historical overview above with the evidence-based evolution of this function.
Studied in Rel-16, normative work from Rel-17.
In Release 17, the LIPF's role was clarified and its procedures were refined. Specifically, it was defined that for Handover Requirements in LI, the LIPF sends only a single Activate Task to the BBIFF-C, and a correction was made to clarify that the LIPF does not provision a triggered LI-LCS Client. Furthermore, a new informative annex detailing LIPF logic was introduced.
In Release 18, the LIPF logic diagrams and annexes were updated to incorporate STIR/SHAKEN aspects and to correct related errors. Furthermore, the logic diagrams were revised to specify the use of the IBCF in its role as a Triggering Function (LTF) instead of its role as an IRI Point of Interception (IBCF (IRI-POI)). These updates refine the technical documentation for provisioning and managing interception points.
In Release 19, the LIPF's role was enhanced to explicitly act as a secure proxy for the Lawful Interception Control Function (LICF) in all communications with other network functions, based on the new capability for "Proxying Information from LICF via LIPF." This formalizes that all instructions and audit communications from the LICF to POIs, Triggering Functions, and Mediation/Delivery Functions are now routed through the LIPF, with the exception of direct LEA communication.
- Proxying Information from LICF via LIPF TS 33.127CR0260
Explore further
Broader topics and technologies where LIPF plays a role.
Defining Specifications
3GPP specifications that define or reference LIPF, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TS 33.127 vj50 | Lawful Interception Architecture and Functions | Rel-19 |
| TS 33.128 vj50 | 3GPP TS 33.128: Lawful Interception Protocols | Rel-19 |