PMD

Pseudonym Mediation Device functionality

Security →
Introduced in R99

PMD is a network-based privacy functionality that translates temporary radio interface pseudonyms into permanent subscriber identifiers within the core network to protect user identity from eavesdroppers.

Category
Security
Introduced
R99
Where
Services › IMS
Specifications
8 specs
PMD Description Purpose Related Classification Specifications

Description

The Pseudonym Mediation Device (PMD) functionality is a security and privacy mechanism specified within 3GPP standards, particularly in TS 23.271 (Location Services) and TS 33.117 (Lawful Interception architecture). It is not necessarily a standalone physical node but a logical function that can be integrated within core network elements like the Home Location Register (HLR), Home Subscriber Server (HSS), or a dedicated node. Its primary role is to maintain the separation between a user's permanent long-term identity and the temporary, frequently changing identities used over the air interface to prevent tracking.

In operation, when a subscriber attaches to the network, the core network assigns a temporary identifier, such as a Temporary Mobile Subscriber Identity (TMSI) in GSM/UMTS or a Globally Unique Temporary Identity (GUTI) in LTE/5G. This pseudonym is used in most signaling messages over the radio access network to avoid transmitting the permanent International Mobile Subscriber Identity (IMSI). However, within the secure core network domain, various functions (e.g., charging, lawful interception, location services) require mapping back to the permanent subscriber identity.

The PMD functionality performs this mediation. It maintains the binding between the currently allocated pseudonym (TMSI/GUTI) and the corresponding IMSI. When a network function receives a request or a record containing only a pseudonym, it can query the PMD to resolve it to the IMSI. Crucially, this resolution happens only within the protected core network, ensuring the IMSI is never exposed on the radio link. The PMD must be a highly secure and trusted entity with strict access controls, as it holds the key mapping for user privacy.

Its architecture involves interfaces with other core network entities. For lawful interception, the PMD (or a Mediation Function that includes PMD capabilities) provides the identity mapping to the Lawful Interception system, allowing authorized agencies to correlate intercepted communications with a specific subscriber's permanent identity, as required by legal frameworks. In location services, it enables location requests based on a pseudonym to be correctly routed to the serving node holding that subscriber's context.

Purpose & Motivation

The PMD functionality was created to resolve a fundamental tension in cellular network design: the need for network operations and lawful interception to identify subscribers uniquely, versus the privacy requirement to protect subscribers from being tracked or identified by eavesdroppers on the radio interface. Without such a mechanism, the permanent IMSI would need to be transmitted frequently, making subscribers vulnerable to location tracking and identity theft via IMSI catchers.

The problem it addresses is maintaining subscriber identity confidentiality while preserving necessary network functionality. Early cellular systems had limited use of temporary identifiers, and the mapping was often handled in a distributed, non-standardized way. The standardization of the PMD functionality, particularly in the context of lawful interception (LI), provided a clear, secure, and standardized method for authorized entities to resolve pseudonyms. This was crucial for complying with legal requirements for LI across different countries and network architectures.

Historically, its development was driven by the evolution of privacy features (like TMSI) in 2G/3G and the subsequent need for a standardized mediation point for lawful interception mandates introduced in the late 1990s and early 2000s. It ensures that even as networks use stronger over-the-air privacy techniques, the ability for lawful, authorized identity resolution for legal, operational, and emergency service purposes remains intact and is performed in a controlled, auditable manner within the secure network core.

Classification

Related approachesIMSITMSIGUTI

Evolution Across Releases

R99 Initial

Introduced the Pseudonym Mediation Device (PMD) functionality within the 3GPP lawful interception architecture (TS 33.107/108). Defined its role as a mediation function that provides pseudonym to permanent identity (IMSI) resolution for intercepted communication content and intercept related information (IRI). Established it as a key component for enabling lawful interception in networks employing subscriber identity confidentiality (TMSI).

Explore further

Broader topics and technologies where PMD plays a role.

Defining Specifications

3GPP specifications that define or reference PMD, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TR 21.905 vj00 3GPP Technical Terms and Definitions Rel-19
TS 23.271 vj00 LCS Stage 2 Specification Rel-19
TS 23.273 vj50 5G Location Services Stage 2 Architecture Rel-19
TS 25.411 vj00 Iu Interface Layer 1 Specification Rel-19
TS 29.173 vj00 Diameter-based SLh Interface for LCS Rel-19
TS 32.271 vj20 3GPP LCS Charging Management Spec Rel-19
TS 32.272 vj00 Charging for Push-to-Talk over Cellular (PoC) Rel-19
TS 32.278 vj00 Monitoring Events Offline Charging Specification Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.