EIR (Equipment Identity Register)

The Equipment Identity Register is the database of mobile-device identities (IMEIs) in a mobile network, classified into white (allowed), grey (monitored), and black (blocked) lists. The MSC, SGSN, MME, or AMF queries the EIR during attach to enforce equipment policy, refusing service to stolen, cloned, or non-type-approved devices. EIRs feed and are fed by industry-shared blocklists (e.g. GSMA IMEI Database) to deter device theft across operators.

Categories: Core NetworkIdentity and SubscriberProtocols and Standards

EIR in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Subscriber identifiers (IMSI, SUPI, MSISDN, IMEI) anchor authentication, charging and lawful interception. Any protocol that leaks a permanent identifier is treated as a privacy defect, which is why 5G introduced SUCI concealment on the air interface.

To place EIR in the wider telecom-security picture, review SAS, GUTI, ADSL, AES, Conformance Testing and Confidentiality — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.