How to Handle LI When Your Core Network Is Outsourced or Hosted

outsourced core network - lawful interception compliance illustration

The outsourcing of core network infrastructure has become an increasingly common strategy for MVNOs and smaller operators seeking to reduce capital expenditure and accelerate time to market. Cloud-hosted core networks, Network-as-a-Service (NaaS) offerings, and managed core network services allow operators to launch and scale without the significant investment required to build and operate their own core infrastructure. However, this architectural model creates specific challenges for lawful interception that operators must address to maintain regulatory compliance.

When the core network is outsourced, the technical capability to intercept communications resides with the infrastructure provider rather than with the operator that holds the regulatory obligation. This article examines the challenges this creates, the models for addressing them, and the practical steps operators should take to ensure compliance when their core network is hosted or managed by a third party.

LI with an Outsourced Core Network

The fundamental challenge of outsourced core networks for LI is the separation of the legal obligation from the technical capability. The operator — as the registered provider of public electronic communications services — bears the legal obligation for lawful interception. But the interception points, the network functions that process subscriber communications, and the infrastructure needed to capture and deliver intercepted data are operated by a third party.

This separation is more acute than in the traditional MVNO-MNO relationship, where the MNO at least recognises that it operates a telecommunications network with inherent regulatory obligations. Core network hosting providers may come from IT infrastructure or cloud computing backgrounds and may not have deep familiarity with telecommunications regulatory requirements, including lawful interception. The operator cannot assume that the hosting provider has considered LI in its infrastructure design or operational processes.

The regulatory position is clear across European markets: outsourcing infrastructure does not outsource regulatory responsibility. The operator remains fully accountable for LI compliance, regardless of how its network is deployed or who operates the underlying infrastructure. Regulators will not accept the operator’s dependency on a third-party provider as an excuse for non-compliance.

Core Network Hosting Models and LI Implications

The implications for LI depend on the specific hosting model. In a dedicated hosted model, the operator has its own instance of the core network functions, running on the hosting provider’s infrastructure. The operator may have administrative access to configure the network functions, including LI-related settings. In this model, the operator can potentially deploy its own LI mediation function and interface it with the hosted network functions, subject to the hosting provider’s cooperation on network connectivity and access.

In a shared or multi-tenant model, the operator shares core network function instances with other tenants of the hosting provider. This model is more cost-effective but creates additional complexity for LI, as the interception must be isolated to the specific operator’s subscribers without affecting other tenants’ traffic. The hosting provider must implement tenant-aware interception capabilities that can segregate traffic by operator.

In a fully managed model, the hosting provider operates the core network on behalf of the operator, handling all configuration, maintenance, and operational tasks. The operator has limited or no direct access to the network functions. In this model, the operator must rely entirely on the hosting provider to implement and execute LI capabilities, which requires comprehensive contractual arrangements and validated technical solutions.

Contractual Requirements

The contract between the operator and the core network hosting provider is the primary tool for ensuring LI compliance in an outsourced model. The contract should explicitly address lawful interception, covering the hosting provider’s obligation to support LI functionality within the hosted infrastructure, the specific LI interfaces that must be implemented and supported, the response times for activating and deactivating intercepts, the security and confidentiality requirements for handling intercepted data, the audit and testing rights of the operator, the process for implementing regulatory updates and new LI requirements, and the liability allocation for LI failures.

Operators should not accept generic language or vague commitments regarding LI support. The contract should specify the concrete technical and operational deliverables that the hosting provider must supply, and should include measurable service levels with meaningful penalties for non-performance. LI compliance is a legal obligation with potential criminal consequences for the operator, and the contractual arrangements must reflect this seriousness.

Technical Architecture Options

Several technical architecture options can address LI in an outsourced core network environment. The first option is the operator-managed mediation model, where the operator deploys its own LI mediation platform and connects it to the hosted core network functions via the standard LI interfaces (X1/X2/X3 in 5G or equivalent proprietary interfaces). This requires the hosted network functions to expose LI interfaces that the operator’s mediation platform can consume. The operator retains control over warrant management, data delivery, and the handover interfaces to law enforcement.

The second option is the hosting provider-managed LI model, where the hosting provider deploys and operates the LI infrastructure as part of the hosted core network service. The hosting provider handles interception activation, data capture, and delivery to law enforcement on behalf of the operator. This model simplifies the operator’s technical requirements but requires significant trust in the hosting provider and comprehensive contractual and audit arrangements.

The third option is a hybrid model, where certain LI functions are provided by the hosting provider (such as the internal interception function within the network elements) and others are managed by the operator (such as the mediation function and handover interfaces). This model can provide a practical balance between operator control and hosting provider capability.

Security Considerations

The security of intercepted data in an outsourced environment requires particular attention. Intercepted communications are among the most sensitive data types in any telecommunications operation, and their protection is both a legal requirement and a practical necessity. In an outsourced model, intercepted data may traverse the hosting provider’s infrastructure, creating additional exposure points that must be secured.

The operator should ensure that intercepted data is encrypted both in transit and at rest within the hosting provider’s infrastructure. Access to LI systems and data should be strictly controlled and limited to authorised personnel, with comprehensive audit logging. The hosting provider’s personnel should be subject to appropriate vetting and confidentiality requirements. Physical security of the data centre hosting the LI infrastructure should meet the standards required by the national regulatory framework.

The operator should also consider the jurisdictional implications of hosting intercepted data in a third-party data centre. If the data centre is located in a different country from the operator’s home market, questions about data sovereignty, cross-border data transfers, and the applicability of foreign legal regimes may arise. Operators should ensure that the location of the hosting infrastructure is compatible with their regulatory obligations and that appropriate data protection safeguards are in place.

Testing and Validation

Regardless of the technical model chosen, the operator must validate the LI capability through end-to-end testing. This testing should cover all interception scenarios required by the national framework, including voice, SMS, and data interception using various target identification methods. The testing should verify not only that interceptions can be activated and data delivered, but also that the response times, data quality, and security meet the required standards.

The testing process should involve the national technical authority or LEMF where required, and should be conducted under conditions that are representative of the production environment. Operators should plan for multiple test iterations and should maintain test documentation as evidence of compliance.

Conclusion

Outsourcing the core network does not outsource the obligation for lawful interception. Operators using hosted or managed core network services must proactively address LI compliance through comprehensive contractual arrangements, validated technical solutions, and rigorous testing. The specific approach will depend on the hosting model, the operator’s technical capabilities, and the requirements of the national regulatory framework. By treating LI compliance as a first-class requirement in the core network hosting decision — not an afterthought — operators can achieve the cost and efficiency benefits of outsourcing while maintaining full compliance with their lawful interception obligations.

Vendor Selection Considerations

When selecting a core network hosting provider, operators should include LI capability as a key evaluation criterion alongside performance, scalability, and cost. Ask prospective hosting providers about their existing LI capabilities and experience. Do they currently support LI for other operator customers? What LI interfaces do they expose from their network functions? Do they have validated integrations with LI mediation platform vendors? What is their track record for supporting regulatory updates and new LI requirements? A hosting provider that cannot demonstrate meaningful LI capability and experience represents a significant compliance risk, regardless of how attractive their commercial offering may be.

Operators should also evaluate the hosting provider’s willingness and ability to support the operator during the LI testing and certification process with the national technical authority. This process typically requires close collaboration between the operator, the hosting provider, and potentially the LI mediation platform vendor. A hosting provider that is responsive, technically capable, and committed to supporting LI compliance will be a far more valuable partner than one that treats LI as a peripheral concern. The choice of hosting provider has long-term implications for the operator’s ability to maintain LI compliance as regulatory requirements evolve, and this factor should be weighted accordingly in the selection process.

Managing LI with an outsourced core network requires clear contractual frameworks and regular compliance verification. The outsourced core network arrangement must include explicit provisions for lawful interception.

Related Articles

For further reading on related topics, explore these articles:

External Resources

The following external resources provide additional context and official documentation:

Scroll to Top
ICS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.