← All insights
compliance mandates6 min read

5G network slicing and the lawful intercept gap: what operators need to resolve before SA scale

Network slicing is one of the defining capabilities of 5G SA: the ability to partition a physical network into multiple logical networks, each with its own performance characteristics, isolation properties, and subscriber population. For enterprise private network use cases, IoT deployments, and premium consumer services, slicing offers meaningful differentiation. It also introduces a lawful intercept architecture challenge that the industry has not yet fully resolved.

What slicing changes about intercept

In a non-sliced network, a target identifier — a SUPI or IMSI — is associated with sessions on a single logical network. The LI system activates intercept for that identifier and receives all sessions associated with it. In a sliced network, the same subscriber may have simultaneous sessions on multiple slices: a default slice for voice and basic data, a premium slice for video streaming, an enterprise slice for VPN access. Each slice may be instantiated on different UPFs with different intercept configurations.

A CALEA or ETSI-compliant intercept activation against a target on a sliced network must capture all sessions across all slices associated with the target. If the LI system's intercept activation reaches only the default slice UPF — because the slice-aware intercept activation mechanism is not implemented — sessions on other slices are not intercepted. This is a capability gap, not a technical limitation: 3GPP has specified the mechanism for per-slice and cross-slice intercept in TS 33.127, but implementation is not universal.

The enterprise slice complication

Enterprise private network slices present a specific complication. The enterprise may operate the slice under a network sharing or MVNE arrangement with control over some network functions. The intercept obligation under national frameworks typically attaches to the public network operator, but the enterprise may control the UPF that carries the traffic. The question of who is obligated to implement intercept capability on an enterprise slice — and how the two parties coordinate — is not clearly resolved in most national frameworks.

This question will become more pressing as enterprise 5G slicing deployments scale. Operators offering enterprise slice services should be developing a compliance position on slice-level intercept that addresses both the technical architecture and the responsibility allocation between the operator and the enterprise customer.

Implementation priorities

Operators should assess their 5G SA deployment roadmap against their slicing rollout plans and identify where slice-aware LI implementation is a prerequisite for commercial service. Specifically: if a slice is being offered commercially, the operator should confirm that the LI system can activate intercept on a per-slice basis, that cross-slice activation is supported for targets with multi-slice sessions, and that the NSSAI is available as a target identifier in the warrant management workflow.

Where these capabilities are not yet implemented, the operator has a choice: delay commercial slicing until LI implementation is complete, or launch with a documented capability gap and an accelerated remediation timeline. The former is preferable from a compliance standpoint; the latter is sometimes commercially necessary. In either case, the capability gap should be documented and disclosed to regulatory contacts rather than left as an undisclosed risk.

Yaana Technologies

Ready to audit your intercept stack?

Talk to the Yaana team about secure-by-design infrastructure for your network.

Request a Meeting →