Glossary term · Identifier

RPAUID

Restricted ProSe Application User ID

Identifier →

RPAUID is a privacy-preserving ProSe application identifier used for service authorization and discovery in direct device-to-device communication, which protects a user's permanent subscription identity.

Introduced
Rel-13
Specifications
11 specs
Category
Identifier
Introduced
Rel-13
Specifications
11 specs
RPAUID Description Purpose Related Classification Specifications

Description

The Restricted ProSe Application User ID (RPAUID) is a critical privacy-enhancing identifier defined within the 3GPP Proximity Services (ProSe) architecture. It serves as a temporary, application-layer alias for a user within the context of a specific ProSe-enabled application. The RPAUID is derived from, but not directly linkable to, the user's permanent subscription identifier (such as IMSI or SUPI) through cryptographic functions managed by the ProSe Function in the network. Its primary role is to facilitate discovery and communication between ProSe-enabled User Equipments (UEs) while obfuscating the user's true identity from other UEs and, in some scenarios, from the application servers.

Architecturally, the RPAUID is generated and managed by the ProSe Function, a core network entity specified for ProSe. When a UE registers for ProSe services, the ProSe Function, in coordination with the Home Subscriber Server (HSS), can assign or authorize the use of an RPAUID for a specific ProSe Application ID. This identifier is then used in ProSe discovery procedures (Model A or Model B) and direct communication setup. In discovery messages, the RPAUID is included to indicate which application on the discovering UE is seeking or announcing availability, allowing the receiving UE's application layer to match it against authorized or interesting applications without knowing the discoverer's global identity.

The RPAUID operates within a broader ProSe identifier framework that includes the ProSe Application Code and ProSe Restricted Code. It is 'restricted' because its scope and validity are limited—typically to a specific application, a certain geographical area, or a time window. This limitation is a key privacy mechanism, preventing long-term tracking of a user across different services or locations. The management of RPAUID lifecycle—including generation, assignment, refreshment, and revocation—is detailed in specifications like TS 23.303 (ProSe architecture) and TS 33.303 (ProSe security). Its use is essential for fulfilling regulatory privacy requirements while enabling innovative peer-to-peer and public safety services that rely on direct device discovery.

Purpose & Motivation

The RPAUID was introduced to solve the inherent privacy conflict in device-to-device discovery services. Early direct communication concepts risked exposing a user's permanent, unique identifier (like IMSI) during broadcast-based discovery processes, enabling unauthorized tracking and profiling. The primary motivation was to enable commercial and public safety ProSe applications—such as social networking, local service discovery, and direct communication for first responders—without compromising user privacy.

Before RPAUID, similar services might have relied on application-specific identifiers managed solely at the application layer, lacking integration with network-level authentication and authorization. This could lead to security vulnerabilities and inconsistent user experiences. The RPAUID provides a standardized, network-assisted method where privacy is built into the architecture. It allows the network operator's ProSe Function to act as a trusted third party, issuing temporary identifiers that are valid only within a controlled context. This addresses limitations of previous ad-hoc solutions by providing a secure, scalable, and privacy-by-design mechanism that is integral to the 3GPP standards, ensuring interoperability and compliance with global data protection regulations.

Classification

Part ofProSe

Evolution Across Releases

Rel-13 Initial

Introduced as part of the foundational Proximity Services (ProSe) architecture for LTE. Defined the RPAUID concept for Layer 2 discovery and direct communication, establishing its role in privacy protection, generation by the ProSe Function, and association with ProSe Application IDs.

Explore further

Broader topics and technologies where RPAUID plays a role.

Defining Specifications

3GPP specifications that define or reference RPAUID, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.303 vj00 Proximity Services (ProSe) Stage 2 Rel-19
TS 23.304 vk10 5G Proximity Services (ProSe) Stage 2 Rel-20
TS 24.334 vj00 ProSe Protocols and Procedures Rel-19
TS 24.554 vk00 Proximity-based Services (ProSe) in 5G System Rel-20
TS 29.343 vj00 PC2 Reference Point Stage 3 Specification Rel-19
TS 29.345 vj00 Diameter-based PC6/PC7 interfaces for ProSe Rel-19
TS 29.555 vk00 5G DDNMF Service Based Interface Stage 3 Rel-20
TS 29.557 vj40 5G ProSe Application Function Service Rel-19
TS 29.559 vk00 5G PKMF Service Based Interface Rel-20
TS 33.303 vj00 ProSe Security Specification for EPS Rel-19
TS 33.503 vk00 5G ProSe Security Specification Rel-20