Network slicing 5G technology creates both challenges and opportunities for lawful interception compliance. Network slicing is one of the defining capabilities of 5G Standalone (SA) architecture. By creating logically isolated network partitions on shared physical infrastructure, operators can tailor connectivity characteristics — latency, bandwidth, reliability, and security — to the specific requirements of different services, applications, or customer groups. For lawful interception, network slicing introduces both significant complications and, paradoxically, potential simplifications. Understanding how slicing affects LI targeting, execution, and delivery is essential for any operator deploying or planning a 5G SA network.
This article examines the intersection of network slicing and lawful interception, covering the technical architecture, the challenges for target identification and interception execution, the potential benefits that slicing can offer for LI operations, and the practical steps operators should take to ensure compliance in a sliced network environment.
How Network Slicing 5G Affects LI
In a 5G SA network, a network slice is a logically isolated end-to-end network that includes specific configurations of radio access, transport, and core network resources. Each slice is identified by a Single Network Slice Selection Assistance Information (S-NSSAI) value and is designed to meet particular service requirements. For example, one slice might be optimised for ultra-reliable low-latency communication (URLLC) serving autonomous vehicles, while another might be configured for massive machine-type communication (mMTC) serving IoT sensor networks, and a third might provide enhanced mobile broadband (eMBB) for consumer smartphones.
From a core network perspective, each slice may have its own dedicated instances of certain network functions — such as the SMF, UPF, and PCF — or may share network function instances with other slices. The degree of isolation between slices is configurable and depends on the operator’s deployment strategy and the requirements of the slice. This flexibility is a key advantage of slicing but also introduces complexity for functions that need to operate across slice boundaries, including lawful interception.
A single subscriber may simultaneously use services across multiple slices. A smartphone user might have their voice traffic routed through one slice, their video streaming through another, and their IoT companion device connected through a third. Each slice may have its own UPF, its own PDU session, and its own IP addressing. The subscriber’s traffic is distributed across these slices based on the Network Slice Selection Function (NSSF) and the subscriber’s slice subscription information.
Complications for LI Targeting
Network slicing complicates LI targeting in several ways. The most fundamental complication is that a target’s traffic may be spread across multiple slices, each potentially served by different UPF instances. A single interception order must result in the capture of all the target’s communications, regardless of which slice they traverse. This requires the LI system to identify all slices used by the target and to deploy interception points in each relevant slice.
Target identification in a sliced environment is more complex than in a non-sliced network. The same subscriber may appear with different session contexts, different IP addresses, and different QoS characteristics depending on which slice is serving a particular communication flow. The LI system must be able to correlate these different contexts back to a single target, using subscriber identity information from the AMF and the subscriber’s slice subscription profile.
The dynamic nature of slice allocation adds further complexity. Slices can be created, modified, and terminated dynamically, and a target’s traffic may move between slices as service requirements change. The LI system must track these changes in real time and adjust interception configurations accordingly. A static interception configuration that was correct at the time of activation may become incomplete if the target’s slice assignments change during the interception period.
Another complication arises from the potential for different slices to be operated by different entities. In some business models, an enterprise or vertical industry partner may operate its own slice on the operator’s infrastructure, potentially with its own network functions and operational management. The question of who is responsible for lawful interception within such a slice — the infrastructure operator, the slice tenant, or both — is a regulatory and contractual question that has not yet been fully resolved in most jurisdictions.
How Slicing Can Simplify LI
Despite these complications, network slicing can also offer potential benefits for lawful interception. The logical isolation of slices means that traffic within a slice is already segregated from traffic in other slices. If the target’s communications are confined to a specific slice, the interception can be focused on that slice, potentially reducing the volume of non-target traffic that the LI system must process and filter.
Slicing can also enable more granular interception. Instead of intercepting all of a target’s traffic — which in a modern smartphone environment can include significant volumes of background data, software updates, and other non-relevant traffic — slicing could potentially allow the interception to be focused on specific service types or communication flows. This granularity could reduce the processing burden on the LI system and the analysis burden on law enforcement, though the legal and procedural frameworks for such selective interception have not yet been fully developed.
From a security perspective, the isolation between slices can provide additional protection for the LI function. By deploying LI components within a dedicated, secure slice — or by ensuring that LI traffic between network functions and the mediation platform is carried on a separate, isolated transport path — operators can enhance the confidentiality and integrity of the interception process.
3GPP Standards for LI in Sliced Networks
The 3GPP LI architecture for 5G, defined in TS 33.127 and TS 33.128, addresses network slicing explicitly. The standards require that the LI system be capable of intercepting a target’s communications across all slices used by that target. The X1 interface must support the specification of slice-related parameters, and the X2 and X3 interfaces must be capable of delivering IRI and CC from interception points within any slice.
The standards define that the AMF, which handles the target’s registration and mobility management, is a key interception point for slice-related IRI. When a target registers with the network and is allocated to one or more slices, the AMF generates IRI events that include the slice information. The LI system uses this information to configure interception at the appropriate UPFs within each allocated slice.
The NSSF and the subscription data stored in the UDM also play roles in the LI process. The NSSF determines which slices are available to a subscriber, and the UDM contains the subscriber’s slice subscription information. The LI system may need to interact with these functions to obtain the information needed to configure comprehensive interception across all relevant slices.
Implicaciones prácticas para los operadores
Operators deploying 5G SA networks with slicing capabilities should address LI requirements from the earliest stages of slice design and deployment. Several practical steps are recommended. First, ensure that your LI system is aware of the slice architecture and can dynamically discover and configure interception points within any slice. This requires integration between the LI system and the slice management functions, including the NSSF and the network slice management function (NSMF).
Second, verify that the UPFs deployed within each slice support the X3 interface for content delivery to the LI mediation function. If a slice uses a UPF that does not support X3, the operator will have a gap in its interception capability for traffic traversing that slice. This is a procurement requirement that should be included in all UPF vendor specifications.
Third, develop procedures for handling interception orders that span multiple slices. The LI operations team must understand how to configure interceptions that cover all of a target’s slice allocations and how to adjust configurations when slice assignments change. Automation of this process is highly recommended, as manual configuration across multiple slices is error-prone and slow.
Fourth, address the governance and contractual dimensions of LI in shared or enterprise-operated slices. If third parties operate slices on your infrastructure, the responsibilities for lawful interception must be clearly defined in the commercial agreements and must align with the regulatory requirements of each relevant jurisdiction.
Conclusión
Network slicing in 5G SA introduces both challenges and opportunities for lawful interception. The distribution of a target’s traffic across multiple slices, the dynamic nature of slice allocation, and the potential for third-party slice operation all complicate the interception process. At the same time, the logical isolation and granularity of slicing can offer new approaches to targeted, efficient interception. For operators, the key is to address LI requirements proactively in slice design, to ensure that their LI systems are slice-aware and dynamically adaptable, and to establish clear governance for interception responsibilities in multi-tenant slice environments. By doing so, operators can meet their compliance obligations while leveraging the full potential of 5G network slicing.
Looking ahead, the evolution of network slicing toward more dynamic, intent-based models will further increase the complexity of LI in sliced environments. Future networks may feature slices that are created and destroyed on demand, with resources allocated and released in real time based on service demands. The LI system must evolve alongside these capabilities, maintaining comprehensive interception coverage even as the underlying network topology changes continuously. Operators that invest in flexible, standards-compliant LI solutions today will be better prepared to adapt to these future developments and to maintain uninterrupted compliance as their 5G networks mature.
As network slicing 5G deployments mature, the interception challenges will evolve. Operators should design their network slicing 5G LI architecture with future scalability in mind.
Artículos relacionados
Si desea leer más sobre temas relacionados, consulte estos artículos:
- Interfaces X1/X2/X3 en 5G: la arquitectura LI del 3GPP explicada
- eSIM e interceptación legal: Qué significa la arquitectura RSP para el cumplimiento de la normativa
- DNS cifrado (DoH/DoT) y su impacto en las capacidades de interceptación legal
Recursos externos
Los siguientes recursos externos proporcionan contexto adicional y documentación oficial:


