SOI

Start Of Interception

Security →
Introduced in Rel-16

SOI is the standardized reference point in a 3GPP network that marks the beginning of a lawful interception data flow for authorized agencies.

Category
Security
Introduced
Rel-16
Where
Radio Access Network › NG-RAN (5G)
Specifications
3 specs
SOI Description Purpose Detected Changes Specifications

Description

Start Of Interception (SOI) is a fundamental architectural concept defined within the 3GPP specifications for Lawful Interception (LI). It represents the precise logical point within a network node or function where the duplication of intercept-related information (IRI) and content of communication (CC) for a specific target begins. The SOI is not a physical interface but a standardized reference location that ensures consistent implementation across different vendors and network elements. Its definition is crucial for demarcating responsibilities and ensuring that the intercepted data is complete, accurate, and legally admissible.

Architecturally, the SOI sits within the Intercepting Control Element (ICE), which is the network node (e.g., MME, SMF, UPF, AMF) that performs the actual interception. When a lawful authorization is activated for a target, the ICE identifies the relevant communication sessions or events associated with that target. The SOI is the instantiation point where the ICE starts copying the designated IRI (metadata like call records, location) and CC (voice, data, messaging content) from its internal processing paths. This copied data is then formatted and delivered via the Handover Interface (HI) to the Law Enforcement Monitoring Facility (LEMF).

The role of SOI is to provide a clear and unambiguous technical definition for where interception commences. This is vital for network operators to prove compliance with legal frameworks, as it defines the scope of data collection. It ensures that interception is applied correctly only after authorization and that all required data from the point of interception onward is captured without omission. The specifications detailing SOI, such as TS 33.128, provide the framework for its implementation within various 5G network functions, including the User Plane Function (UPF) for content interception and the Access and Mobility Management Function (AMF) for intercept-related information.

Purpose & Motivation

SOI was created to address the need for a standardized, reliable, and legally defensible mechanism to initiate lawful interception within 3GPP-based mobile networks. As telecommunications became essential infrastructure, legal frameworks worldwide mandated that operators provide capabilities for lawful interception to support criminal investigations and national security. Without a standardized definition for where interception starts, implementations could vary, leading to incomplete data capture, challenges in verifying compliance, and potential legal disputes over the admissibility of evidence.

Historically, interception mechanisms were often proprietary and integrated in an ad-hoc manner. The 3GPP standardization of SOI, particularly emphasized from Release 16 onwards with the 5G system, provides a common reference that all network equipment vendors and operators must adhere to. This solves the problem of interoperability and ensures that law enforcement agencies receive a consistent format and complete data stream, regardless of the underlying network vendor. It addresses the technical and legal requirement to precisely define the moment and location of data duplication to maintain the integrity of the interception process from start to finish.

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (4 CRs across 3 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Studied in Rel-16, normative work from Rel-17.

Rel-17 2 changes

In Release 17, the SOI (Start Of Interception) function was enhanced to specifically handle scenarios where a target UE is already active in the network when interception begins. This included the introduction of a new xIRI record type, the AMFStartOfInterceptionWithRegisteredUE, generated by the AMF when it detects interception activation for a UE that is already registered in the 5GS. Additionally, the release clarified the inclusion of the time of registration or session establishment within the relevant start of interception xIRI reports.

  • Update to start of interception with registered UE record at the AMF TS 33.128CR0253
  • Time of registration/session establishment in Start of Interception related xIRIs TS 33.128CR0334
Rel-18 1 change

In Release 18, the key new feature for the SOI function was the addition of Start of Interception Records specifically for RCS reporting, as indicated by the Change Request title. This enhancement builds upon the existing framework where various network functions like the AMF, SMF, and UDM generate specific xIRI records (e.g., AMFStartOfInterceptionWithRegisteredUE) when interception is activated on a target in different states. The update formally extends this interception reporting capability to cover the Rich Communication Services (RCS) domain.

  • Addition of Start of Interception Records for RCS reporting TS 33.128CR0610
Rel-19 1 change

In Release 19, the key new development for the Start of Interception (SOI) function was the formal alignment of the PTC (Proximity Services Communication) Start of Interception record. This update specifically defined the generation of a PTCStartOfInterception xIRI record by the PTC server when interception is activated on a target with an active PTC session or chat group, ensuring consistent reporting for this service scenario.

  • Alignment of PTC Start of Interception record TS 33.128CR0789

Explore further

Broader topics and technologies where SOI plays a role.

Defining Specifications

3GPP specifications that define or reference SOI, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 33.128 vj50 3GPP TS 33.128: Lawful Interception Protocols Rel-19
TR 38.820 vg10 NR; 7-24 GHz Frequency Range Study Rel-16
TR 38.877 vi10 Technical Report Rel-18
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.