3GPP TS 33.126: LI requirements
TS 33.126 is the modern 3GPP requirements specification. It describes what LI support must achieve across provisioning, detection, capture, delivery, and de-provisioning while protecting LI information and limiting access to authorized personnel.
Safety boundary: this chapter teaches lawful, governed system design from public standards. It does not provide operational targeting, activation, decryption, surveillance-evasion, or covert collection instructions.
The mental model
| Concept | Plain meaning | Control that must travel with it |
|---|---|---|
| Stage 1 requirements | States service needs and required outcomes | It is not a deployment recipe |
| Provisioning | Authorized parameters reach appropriate functions | Least information and independent approval apply |
| Detection | Relevant service activity is recognized under authorization | No collection outside active scope |
| Capture | Authorized IRI or CC is made available | Preserve service semantics and integrity |
| Delivery | Material reaches the approved mediation/LEMF path | Secure, timely, complete, and accountable |
| De-provisioning | LI state is removed at end | Expiry must survive control-plane failure |
Apply it as a controlled workflow
- Translate each applicable requirement into architecture responsibility.
- Map requirement to function, interface, owner, threat, and evidence.
- Resolve national options and service applicability.
- Design negative behavior for unauthorized, unsupported, and expired state.
- Exercise lifecycle transitions under network-function scaling and failover.
- Maintain traceability when release or service capability changes.
Evidence to demand
- A requirements compliance matrix links each clause-level obligation to tests.
- Only authorized personnel and workloads can access LI management information.
- Scaling does not duplicate or omit lifecycle state.
- De-provisioning is proven across every relevant network function.
Failure to reason about
A cloud-native network function autoscaling event creates a new instance. If authorized state propagation is late, service events may be missed; if stale bootstrap state is used, scope may be exceeded. Requirements must drive secure, consistent instance lifecycle.
Feynman check
33.126 says what the mobile system must accomplish safely. Later specifications explain architecture and protocol details.