SUPI

Subscription Permanent Identifier

Identifier →
Introduced in Rel-15 Also in: Security

SUPI is the globally unique, permanent identifier for a 3GPP subscription in 5G systems, serving as the fundamental identity for authentication and subscription management.

Category
Identifier
Introduced
Rel-15
Where
Core Network › 5G Core
Also touches
1 segments
Specifications
41 specs
SUPI Description Purpose Related Classification Detected Changes Specifications

Description

The Subscription Permanent Identifier (SUPI) is a critical concept in 5G system architecture, defined initially in 3GPP Release 15. It is a globally unique, non-changing identifier that permanently represents a user's subscription within the 3GPP ecosystem. The SUPI is used by the network for identification, authentication, authorization, and accounting purposes. It is stored securely in the Unified Data Management (UDM) and the Universal Subscriber Identity Module (USIM) on the user's device. The SUPI itself is never transmitted in clear text over the air interface to protect user privacy; instead, it is concealed using a privacy-preserving identifier called the Subscription Concealed Identifier (SUCI).

Architecturally, the SUPI is a key input to the 5G Authentication and Key Agreement (5G AKA) and Extensible Authentication Protocol (EAP)-AKA' procedures. During initial registration, the User Equipment (UE) generates a SUCI by encrypting the SUPI with the home network's public key, using the Elliptic Curve Integrated Encryption Scheme (ECIES). This SUCI is sent to the serving network (e.g., visited network in roaming scenarios). The serving network forwards the SUCI to the home network's Authentication Server Function (AUSF), which, with the help of the Subscription Identifier De-concealing Function (SIDF) in the UDM, decrypts it to retrieve the SUPI. The SUPI is then used to fetch the authentication vector and subscription profile from the UDM.

The SUPI can be in two main formats: an IMSI-based format or a Network Access Identifier (NAI) format. The IMSI-based SUPI follows the structure of an International Mobile Subscriber Identity (IMSI), consisting of a Mobile Country Code (MCC), Mobile Network Code (MNC), and Mobile Subscription Identification Number (MSIN). This ensures backward compatibility with legacy systems. The NAI-based SUPI is used for non-3GPP access (e.g., Wi-Fi) and follows the format username@realm. The SUPI's role extends beyond authentication; it is used in policy control (via the Policy Control Function (PCF)), charging (via the Charging Function (CHF)), and network slice selection (via the Network Slice Selection Function (NSSF)). Its permanent nature ensures consistent identification across sessions and mobility events, forming the backbone of subscription management in 5G.

Purpose & Motivation

The SUPI was introduced in 5G Release 15 to address privacy and security shortcomings of previous subscription identifiers, particularly the IMSI used in 4G LTE. In LTE, the IMSI was sometimes transmitted in clear text during initial attach procedures, making it vulnerable to eavesdropping and tracking attacks. This allowed malicious actors to identify and locate users, compromising privacy. The SUPI, combined with the SUCI mechanism, was designed to provide strong subscriber identity privacy by ensuring the permanent identifier is never exposed over the air.

Another motivation was to create a unified subscription identifier that works seamlessly across different access types (3GPP and non-3GPP) and supports emerging services like network slicing and IoT. The legacy IMSI was primarily designed for cellular access, whereas 5G envisions convergence with fixed and wireless local area networks. The SUPI's flexible formats (IMSI-based and NAI-based) accommodate this convergence, enabling consistent subscription management in heterogeneous networks.

Furthermore, the SUPI supports enhanced security protocols and home-routed traffic models in roaming scenarios. By keeping the SUPI concealed until it reaches the home network, it reduces the trust burden on visited networks and mitigates risks associated with international roaming. This aligns with 5G's design principles of security-by-design and privacy-by-design, addressing regulatory requirements like the General Data Protection Regulation (GDPR). The SUPI thus solves the dual problem of providing a robust, permanent subscription anchor while ensuring user privacy in an increasingly connected and scrutinized digital environment.

Classification

Part ofIMSI
Related approachesSUCI

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (55 CRs across 5 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 22 changes

In Release 15, the Subscription Permanent Identifier (SUPI) was newly introduced as the globally unique 5G subscription identifier. It was formally defined alongside its concealed counterpart, the SUCI, with specific formats including an IMSI-based type and a Network Access Identifier (NAI) format for network-specific identifiers. The release also detailed the structure for SUCI construction, including protection schemes, and specified procedures for its use in functions like AUSF discovery and AMF registration retrieval.

  • UDM Discovery with SUPI as input TS 23.501CR0091
  • Subscription Permanent Identifier TS 23.501CR0189
  • SUPI based paging TS 23.501CR0199
  • SUPI definition and NAI format TS 23.501CR0653
  • Remove the remaining instance of SUPI paging TS 24.501CR0055
  • Correction to SUPI definition due to NAI format TS 24.501CR0628

+ 16 more changes

Rel-16 15 changes

In Release 16, the SUPI function was extended to support new SUPI types and access scenarios, including formal definitions for 5G-RG and FN-RG devices and support for wireline access. The release also introduced the ability for a SUCI containing a GLI or GCI to act as a pseudonym for an IMSI-based SUPI and provided clarifications for the use of SUPI in EAP-AKA' key derivation and for devices using non-IMSI based SUPI types.

+ 9 more changes

Rel-17 13 changes

In Release 17, the SUPI function was enhanced to better support Stand-alone Non-Public Networks (SNPNs), including specific handling for IMSI-based SUPIs when accessing an SNPN using credentials owned by a Credential Holder (CH) and the use of a decorated NAI format for scenarios involving a CH with an AAA server. It also introduced clarifications for the SUPI/SUCI format used for onboarding and defined that a UE can enter a substate of NO-SUPI. Furthermore, updates were made to support the mapping of GPSIs and Group Identifiers to a SUPI list and to include SUPI information in UECM GET responses.

  • IMSI based SUPI support when access an SNPN using credentials owned by CH TS 23.501CR2919
  • Format of SUCI/SUPI used for Onboarding TS 23.501CR3097
  • Handling of SUPI/SUCI format when accessing to a SNPN TS 23.501CR3045
  • Update BSF NF profile to support SUPI and GPSI TS 23.501CR3108
  • SUPI type of onboarding SUPI TS 24.501CR3849
  • UE enter in substate NO-SUPI TS 24.501CR4327

+ 7 more changes

Rel-18 3 changes

In Release 18, the SUPI function was enhanced to support a decorated NAI format specifically for 5G Non-Seamless WLAN Offload (5G-NSWO), which modifies the standard NAI structure for use in that scenario. Furthermore, clarifications were provided for the NAI format of an Anonymous SUPI when used for 5G-NSWO in a Stand-alone Non-Public Network (SNPN) access mode. The release also introduced support for handling SUPI and GPSI for related UEs within the Gateway Mobile Location Centre (GMLC) API.

  • Decorated NAI format for 5G-NSWO for SUPI TS 23.003CR0696
  • Clarification on NAI format for Anonymous SUPI in 5G-NSWO in SNPN access mode. TS 23.003CR0698
  • GPSI and SUPI Support for Related UEs in GMLC API TS 29.515CR0145
Rel-19 2 changes

In Release 19, the SUPI function was enhanced to support the conversion of multiple SUPIs to their corresponding GPSIs within the UDM. Furthermore, the specification introduced the inclusion of a timestamp in the immediate event report for "SUPI-PEI association" events within the Exposure Function framework.

  • Support for Multiple SUPI to GPSI Conversion in UDM TS 29.503CR1305
  • Timestamp in EE immediate event report for "SUPI-PEI association" events TS 29.503CR1491

Explore further

Broader topics and technologies where SUPI plays a role.

Defining Specifications

3GPP specifications that define or reference SUPI, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.003 vj50 Numbering, addressing and identification in 3GPP Rel-19
TS 23.501 vk00 5G System Architecture Stage 2 Rel-20
TS 23.700 vk00 XR Services Application Enablement Layer Rel-20
TS 24.501 vj50 5G NAS Protocols Specification Rel-19
TS 24.502 vj20 5G Core Access via Non-3GPP Networks; Stage 3 Rel-19
TS 24.526 vj30 UE Policies for 5GS; Stage 3 Rel-19
TS 28.204 vi11 Charging management Rel-18
TR 28.840 vi10 Technical Report Rel-18
TS 29.503 vj50 UDM Service Based Interface Stage 3 Rel-19
TS 29.504 vj50 Nudr Service Based Interface Stage 3 Protocol Rel-19
TS 29.505 vj50 UDR Service for Subscription Data Usage Rel-19
TS 29.507 vj40 5G Access & Mobility Policy Control Service Rel-19
TS 29.508 vj40 5G Session Management Event Exposure Service Rel-19
TS 29.514 vj40 5G System; Policy Authorization Service; Stage 3 Rel-19
TS 29.515 vj50 Ngmlc Service Based Interface Protocol Rel-19
TS 29.517 vj40 5G AF Event Exposure Service Stage 3 Rel-19
TS 29.518 vj50 AMF Service Based Interface Protocol Rel-19
TS 29.519 vj40 UDR Usage for Policy & Exposure Data Rel-19
TS 29.520 vj40 5G Network Data Analytics Services Stage 3 Rel-19
TS 29.521 vj40 5G Binding Support Management Service Stage 3 Rel-19
TS 29.523 vj20 5G Policy Control Event Exposure Service Rel-19
TS 29.525 vj40 5G UE Policy Control Service Stage 3 Rel-19
TS 29.541 vj30 NEF Service-Based Interfaces for NIDD & SMS Rel-19
TS 29.550 vj20 5G Steering of Roaming Service Based Interface Rel-19
TS 29.571 vj50 Common Data Types for 5G Service Based Interfaces Rel-19
TS 29.591 vj40 5G NEF Southbound Services Stage 3 Rel-19
TS 29.594 vj20 5G Spending Limit Control Service Stage 3 Rel-19
TS 29.890 vg00 CT3 5G System Technical Report Rel-16
TS 31.102 vj40 USIM Application Specification Rel-19
TS 32.255 vk10 Telecom Management; Charging for 5G Data Connectivity Rel-20
TS 32.256 vj40 5G Connection & Mobility Charging Spec Rel-19
TS 32.291 vj40 Charging Management: Service-Based Interface Protocol Rel-19
TS 33.126 vj30 Lawful Interception Requirements Rel-19
TS 33.127 vj50 Lawful Interception Architecture and Functions Rel-19
TS 33.501 vk00 5G Security Architecture and Procedures Rel-20
TS 33.514 vk00 5G Security Assurance for UDM Rel-20
TR 33.741 vi01 Home Network Triggered Authentication Rel-18
TS 33.749 vj00 Study on security aspects of edge computing enhancement Rel-19
TS 33.835 vg10 Study on authentication and key management for apps Rel-16
TR 33.841 vg10 Security aspects; Study on 256-bit algorithms for 5G Rel-16
TR 33.938 vj10 3GPP Cryptographic Inventory for 5G Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.