3GPP TS 33.127: architecture and functions
TS 33.127 is the Stage 2 architecture specification for modern 3GPP LI. It allocates responsibilities among administration, points of interception, mediation/delivery, and receiving functions across mobile-system services.
Safety boundary: this chapter teaches lawful, governed system design from public standards. It does not provide operational targeting, activation, decryption, surveillance-evasion, or covert collection instructions.
The mental model
| Concept | Plain meaning | Control that must travel with it |
|---|---|---|
| Stage 2 | Turns requirements into logical functions and reference points | Products may combine roles only with preserved controls |
| ADMF | Administers authorized LI state | Protect from service-plane and ordinary operations |
| POI | Observes relevant authorized information in a network function or service | Bind output to current provisioning |
| MF/DF | Mediates and delivers IRI or CC | Transformation must be traceable |
| LEMF | Authorized receiving environment | Endpoint and jurisdiction are verified |
| Service coverage | Architecture applies across defined 5G/EPS/IMS services | Capability claims must name the release and service |
Apply it as a controlled workflow
- Select the 3GPP release and supported service set.
- Map logical functions to real network functions, vendors, and responsibility.
- Draw control, IRI, and CC flows with trust boundaries.
- Define state propagation, correlation, scaling, and failover.
- Test roaming, slicing, service chaining, and mixed-release conditions conceptually.
- Keep a release-aware architecture decision and conformance record.
Evidence to demand
- Each logical function has an accountable owner and least-privilege identity.
- Co-located functions retain separate authorization and audit boundaries.
- Topology change cannot orphan active lawful state.
- Unsupported services fail visibly rather than appearing compliant.
Failure to reason about
A vendor appliance combines ADMF and mediation for simplicity. This can be acceptable only if access, data, logging, key, approval, and failure boundaries still enforce separation. A box boundary is not a control boundary.
Feynman check
33.127 assigns jobs: who manages the lawful task, where allowed service information is observed, who prepares it, and where it is received.