5G-ENSURE Security research archive

Reference · Distinction

Lawful interception and IMSI catchers are not the same thing

Both are described as interception and both can end with a record of who was where. They work in different places, and the difference decides what oversight is even possible.

1Inside

Interception that runs inside the network

Mobile networks are built with interception as a designed function, because operators are required by law in most jurisdictions to be able to provide it. It is a feature of the network elements, specified alongside everything else, with defined interfaces for delivering the result to whoever is entitled to receive it.

Because it is a designed function, it has the properties of one. It happens at the operator, against a subscription the operator can already identify, under an authorisation that arrives through a defined process. It is configured, which means it is logged, which means the question of who intercepted what and on whose authority has an answer that exists somewhere in the operator’s systems. Whether that answer is reviewed, by whom, and how often, varies enormously by jurisdiction, and that variation is the substance of most of the public argument about it.

The technical point for this archive is narrower. The capability is inside a system with an owner, an audit trail and a regulator, and every one of those three exists because the capability was put there deliberately.

2Outside

Interception that stands outside it

A device that impersonates a cell is not part of any network. It does not need the operator’s cooperation, its authorisation or its knowledge, and it does not appear in its records. It works by exploiting behaviour that the mechanism page describes: a handset selecting the most attractive cell, and a protocol that retains a way to ask for a permanent identity.

The consequences of being outside are not incidental. There is no configuration, so there is no log. There is no subscription list, so the collection is not restricted to a target: everything in range that attaches is collected, and the selection happens afterwards, if at all. There is no interface for delivering results, so there is no record of what was delivered to whom. And there is no scope or expiry, because nothing issued one.

This is why the two things being called the same word is a real problem. Assurances about the regulation of interception describe the first mechanism. The second is not made lawful or unlawful by those assurances, and it is not made visible by them either.

3Convergence

Where the distinction is genuinely blurred

Two things complicate the clean split. The first is that a device on the street may well be operated under a warrant, by an authority entitled to use it. The authorisation is then real, but the technical properties do not improve: the collection still sweeps everything in range and still leaves no record at the operator, so the authorisation covers an activity whose extent cannot be reconstructed from the network afterwards.

The second is that identity collection sits awkwardly in the definitions. Much regulation is written around the interception of communications, and a device that only harvests identities is not intercepting a communication in that sense: it is learning who is present. Whether that is interception, surveillance, or something the framework did not anticipate is a genuinely open question in several jurisdictions, and the pages here describe the mechanism without resolving it.

What the fifth generation changes is narrower than either question. Concealing the subscriber identity, as described on the concealment page, removes the value of collection from outside the network while leaving interception inside it exactly as it was, because the home network can still resolve what a street-side device cannot. The asymmetry is deliberate: the design closes the unaccountable path and leaves the accountable one open.

QQuestions

Questions and answers

Is a device that captures identities on a street lawful?

It depends entirely on jurisdiction, on who is operating it and under what authority, and it is a question for a lawyer. What can be said technically is that the capability is not confined to anyone: the equipment is not exotic, and the network behaviour it relies on is public and documented.

Does an operator know when a device like this is used nearby?

Not straightforwardly. The device is not connected to the operator network and is not visible in its management systems, so it produces no record there. Networks can look for indirect evidence, such as subscriptions dropping and reattaching in patterns that do not match the operator’s own configuration, but that is inference from operational data.

Why does the distinction matter if the outcome is similar?

Because the controls are attached to the mechanism, not to the outcome. Interception at the operator is bounded by a warrant, a scope, a duration and a record that can be audited afterwards. Interception from a device on the street has none of those attached to it by construction, so a claim that a jurisdiction regulates interception says nothing about whether a given collection was regulated.