EIR

Equipment Identity Register

Security →
Introduced in Rel-4 Also in: Core Network, Services

EIR is a security database in mobile networks that stores and validates device identities (IMEIs) to check if they are blacklisted, gray-listed, or white-listed, preventing unauthorized or problematic devices from accessing the network.

Category
Security
Introduced
Rel-4
Where
Management
Also touches
2 segments
Specifications
17 specs
EIR Description Purpose Related Classification Detected Changes Specifications

Description

The Equipment Identity Register (EIR) is a critical security entity within the core network of GSM, UMTS, LTE, and 5G systems. It functions as a centralized database that maintains lists of International Mobile Equipment Identities (IMEIs), which are unique identifiers assigned to mobile devices. The EIR classifies IMEIs into three lists: a white list for known valid devices, a black list for devices reported as stolen, barred, or technically faulty, and a gray list for devices under observation (e.g., with anomalies). When a user equipment (UE) attempts to attach to the network, the Mobility Management Entity (MME) in 4G or the Access and Mobility Management Function (AMF) in 5G queries the EIR to verify the device's IMEI.

The EIR works by receiving IMEI check requests via standardized interfaces, such as the S13 interface in LTE (between MME and EIR) or the N5g-eir service-based interface in 5G (between AMF and EIR). Upon receiving a request, the EIR searches its database and returns a response indicating the list status of the IMEI. Key components include the database engine for storing IMEI records, authentication and authorization modules to secure access, and synchronization mechanisms to update lists from external sources like the Central Equipment Identity Register (CEIR) or operator inputs. In 5G, the EIR is implemented as a network function (NF) that can be deployed in cloud-native environments, offering scalability and flexibility.

In the network architecture, the EIR plays a defensive role against device-related fraud and theft. By blocking blacklisted devices, it deters the use of stolen phones and reduces insurance claims. It also helps maintain network integrity by preventing faulty devices from causing interference or service degradation. The EIR's integration with other security functions, such as the Authentication Server Function (AUSF) and Unified Data Management (UDM), enhances overall network security posture. Its operations are governed by specifications like 29.272 and 29.273 for interfaces and 33.857 for security aspects, ensuring interoperability across different generations of mobile networks.

Purpose & Motivation

The EIR was created to combat the rising issue of mobile phone theft and cloning in early GSM networks. Before its introduction, stolen devices could be easily reused on networks, leading to financial losses for users and operators, and encouraging crime. The EIR provides a standardized mechanism to track and block such devices, thereby protecting consumers and reducing the incentive for theft. Its development was driven by the need for a global, interoperable system to share stolen device information, facilitated by entities like the GSMA's Central Equipment Identity Register (CEIR).

Historically, without an EIR, operators had limited means to verify device legitimacy, relying on manual reporting and local blacklists. The EIR automated this process, enabling real-time checks during network attachment. Over releases, its purpose expanded to address device faults and regulatory requirements, such as blocking non-compliant or counterfeit devices. In 5G, the EIR evolved to support new service-based architectures and integrate with network slicing, ensuring device security per slice. It solves problems of device fraud, network abuse, and supports lawful interception by providing reliable device identification, thereby enhancing trust in mobile communications.

Classification

Part ofCEIR
Specific typesADDCEIR
Related approachesIMEI

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (2 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Studied in Rel-4, normative work from Rel-15.

Rel-15 2 changes

In Release 15, the primary update for the Equipment Identity Register (EIR) function was the introduction of OpenAPI definitions for the 5G-EIR. This included specific updates to these OpenAPI specifications and a focus on reusing common data types within the EIR's OpenAPI framework to ensure consistency.

  • 5G-EIR OpenAPI Updates TS 29.511CR0005
  • Reuse of data types in EIR OpenAPI TS 29.511CR0014

Explore further

Broader topics and technologies where EIR plays a role.

Defining Specifications

3GPP specifications that define or reference EIR, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TR 21.905 vj00 3GPP Technical Terms and Definitions Rel-19
TS 28.702 vj00 Core Network NRM IRP Information Service Rel-19
TS 29.272 vj40 Diameter Interfaces for MME/SGSN Rel-19
TS 29.273 vj10 AAA Protocols for Non-3GPP Access in EPS & 5GS NSWO Rel-19
TS 29.511 vj10 5G Equipment Identity Register Service Interface Rel-19
TS 32.102 vj00 Telecom Management Physical Architecture Framework Rel-19
TS 32.140 vj00 Subscription Management (SuM) requirements Rel-19
TS 32.141 vj00 Subscription Management (SuM) Architecture Rel-19
TS 32.240 vj40 Charging Management Architecture & Principles Rel-19
TS 32.250 vj00 Circuit Switched Offline Charging Rel-19
TS 32.272 vj00 Charging for Push-to-Talk over Cellular (PoC) Rel-19
TS 32.401 vj00 Performance Management Concept & Requirements Rel-19
TS 32.632 vb00 Core Network Resources IRP: Network Resource Model Rel-11
TS 32.732 vb00 IMS Network Resource Model IRP: Information Service Rel-11
TS 32.808 v1800 Common User Profile Storage Framework Rel-8
TR 33.857 vh10 Enhanced Security for Non-Public Networks Rel-17
TS 52.402 vj00 GSM Performance Management Measurements Rel-19