LIPF

Lawful Interception Provisioning Function

Security →
Introduced in Rel-16

LIPF is the 5G core network function that provisions lawful interception configuration data to other Network Functions, centralizing the management of parameters like target identities for consistent enforcement.

Category
Security
Introduced
Rel-16
Where
Core Network › 5G Core
Specifications
2 specs
LIPF Description Purpose Detected Changes Specifications

Description

The Lawful Interception Provisioning Function (LIPF) is a standardized Network Function (NF) within the 5G Core (5GC) architecture, introduced as part of the enhanced lawful interception framework for 5G systems. Its primary role is to act as a centralized provisioning point for all lawful interception-related configuration data required by various intercepting Network Functions (I-NFs) and the Lawful Interception Function (LIF). The LIPF stores and manages interception warrants, which include details such as the target's identity (e.g., SUPI, MSISDN), the scope of interception (e.g., content of communications, intercept-related information), authorized agencies, and the duration of the interception order. It provides this information to other NFs upon request or via subscription/notification mechanisms.

Operationally, when a lawful interception request is authorized, the relevant administrative authority (e.g., the Law Enforcement Agency via the Lawful Interception Administration Function) provisions the interception warrant into the LIPF. The LIPF then distributes the necessary configuration to the appropriate network functions. For example, it may provision a target's identity to the Access and Mobility Management Function (AMF) to trigger interception when the target UE registers or establishes a session. It may also provision data to the Session Management Function (SMF), User Plane Function (UPF), or other NFs involved in monitoring content or collecting intercept-related information. The LIPF uses standardized service-based interfaces, likely based on HTTP/2, to communicate with consumer NFs, aligning with the 5GC's service-based architecture principles.

The LIPF plays a crucial role in separating the provisioning logic from the interception execution logic. This centralization simplifies management, improves auditability, and ensures consistency. It prevents the need for each individual NF to be configured separately for interception tasks, which is vital in a dynamic, cloud-native 5G environment where NFs can be instantiated and scaled elastically. The LIPF interacts with the Lawful Interception Function (LIF), which handles the secure delivery of intercepted data to the collection function. By managing the 'what' and 'who' of interception, the LIPF allows the I-NFs to focus on the 'how'—the actual technical implementation of intercepting the specified traffic or events for the provisioned targets.

Purpose & Motivation

The LIPF was created to address the challenges of implementing lawful interception in the 5G Core's service-based architecture (SBA). Previous 3GPP architectures had more monolithic network elements where LI configuration was often handled via proprietary or element-specific management interfaces. With 5G's decomposition into numerous, independently scalable Network Functions, manually provisioning interception parameters across dozens of potential NF instances became operationally complex, error-prone, and slow.

The motivation for standardizing the LIPF was to provide an automated, centralized, and standardized method for provisioning interception warrants. This solves the problem of consistency—ensuring all relevant NFs have the same, up-to-date information about interception targets. It also addresses the need for agility in cloud-native deployments, allowing new NF instances to automatically retrieve necessary LI configuration. The LIPF was driven by regulatory requirements that mandate efficient and reliable lawful interception capabilities, necessitating a modern architectural approach that matches the flexibility and distribution of 5G networks while maintaining strict compliance controls.

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (7 CRs across 3 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Studied in Rel-16, normative work from Rel-17.

Rel-17 3 changes

In Release 17, the LIPF's role was clarified and its procedures were refined. Specifically, it was defined that for Handover Requirements in LI, the LIPF sends only a single Activate Task to the BBIFF-C, and a correction was made to clarify that the LIPF does not provision a triggered LI-LCS Client. Furthermore, a new informative annex detailing LIPF logic was introduced.

  • LIPF logic: new informative annex TS 33.128CR0199
  • HR LI: Only one Activate Task to the BBIFF-C from LIPF TS 33.128CR0270
  • LALS: Correcting the error that infers as if LIPF provisions the triggered LI-LCS Client TS 33.128CR0168
Rel-18 3 changes

In Release 18, the LIPF logic diagrams and annexes were updated to incorporate STIR/SHAKEN aspects and to correct related errors. Furthermore, the logic diagrams were revised to specify the use of the IBCF in its role as a Triggering Function (LTF) instead of its role as an IRI Point of Interception (IBCF (IRI-POI)). These updates refine the technical documentation for provisioning and managing interception points.

  • LIPF logic diagram updates to include STIR/SHAKEN aspects TS 33.128CR0394
  • LIPF Logic Annex – updates to fix a few errors related to STIR/SHAKEN tables TS 33.128CR0411
  • LIPF logic diagram uses IBCF (LTF) instead of IBCF (IRI-POI) TS 33.128CR0465
Rel-19 1 change

In Release 19, the LIPF's role was enhanced to explicitly act as a secure proxy for the Lawful Interception Control Function (LICF) in all communications with other network functions, based on the new capability for "Proxying Information from LICF via LIPF." This formalizes that all instructions and audit communications from the LICF to POIs, Triggering Functions, and Mediation/Delivery Functions are now routed through the LIPF, with the exception of direct LEA communication.

  • Proxying Information from LICF via LIPF TS 33.127CR0260

Explore further

Broader topics and technologies where LIPF plays a role.

Defining Specifications

3GPP specifications that define or reference LIPF, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 33.127 vj50 Lawful Interception Architecture and Functions Rel-19
TS 33.128 vj50 3GPP TS 33.128: Lawful Interception Protocols Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.