2G / 3G

A stolen device that still works on your network is a compliance failure. An unconfigured device is a support call. One EIR handles both, from 2G through 5G SA, without a new platform at each generation.

AMTP · EIR
IMEI listsBlack, white, grey — real-time on attach
Coverage
DatabaseFast in-memory/DB
Welcome SMSAutomatic on new device — no probing systems
OTA triggerOption : Automatic on first attachment
Device tracingSupported where legal framework permits
subscribers on platform
2004
in production since
2G–5G
one platform, every generation
99.9999%
availability
00The problem

Most EIR deployments check mobile identifier (IMEI) against a black/white list for one network generation. Move to 4G and the EIR does not follow. Add 5G SA and the problem repeats. Each generation becomes a separate platform, a separate vendor, and a separate support contract, for a function that is doing the same job each time.

The operational cost is not the additional hardware. It is the fragmentation. Device policy that should be consistent across the network is now split across three systems that do not automatically stay in sync.

01How it works

EIRcore
MSC/VLR2G/3G attach
MME4G attach
5G SAOAI
SMSCWelcome SMS
01 / 04

Checked on every attachment

Every time a device attaches to the network, the network checks whether that device should be there. A handset on a stolen list that gets through is a compliance failure. A device on a managed enterprise whitelist that gets blocked is a service call. These checks happen on every attachment, in real time, on every generation the network runs.

02 / 04

Black, white, and grey lists

The Ouroboros EIR runs those checks across every generation the network carries, from a single deployment. Every IMEI is verified against white (permitted), grey (monitored), or black (barred) lists at attachment or at cell change. A blacklisted device is blocked immediately. A whitelisted device receives access according to its profile. A grey-listed device is tracked or subject to configured policy: monitored without an outright block.

03 / 04

One platform, every generation

A fast in-memory database handles attachment volume without adding latency to the procedure.

04 / 04

Welcome SMS and OTA built in

When a new subscriber attaches with a new device for the first time, the EIR can triggers a Welcome SMS automatically, with no external probing system required. The same event triggers OTA configuration, pushing APN settings and network parameters to the device before the subscriber notices they need configuring.

Reference architecture
Architecture diagram of the Ouroboros 3G/4G/5G EIR. The EIR core syncs with a black, grey and white list database fed by provisioning. In the 4G/5G half, the MME or SGSN checks equipment identity over S13 and the AMF over HTTP/2 OAI equipment-status. In the 2G/3G half, the MSC/VLR issues Check_IMEI requests during IMSI attach, location update, SMS and calls.

EIR — one equipment register from 2G to 5G

02Use cases

Stolen devices, enterprise whitelists, first-attach messaging and OTA — one register for all of it.

01

Block stolen or non-compliant devices

An IMEI reported stolen is added to the blacklist. Every subsequent attachment attempt is blocked immediately. Grey list policy handles devices under monitoring without a hard block.

02

Whitelist managed and enterprise devices

Operators providing managed services to enterprises define a whitelist of approved IMEIs. Only those devices access the dedicated APN or service tier. Non-listed devices are blocked or redirected without manual intervention.

03

Authorized brands

Regulator or operator can ban whole brand of phone.

04

Welcome SMS on first attachment

A new subscriber's first device attachment fires detect new roamer-in phone and trigger Welcome SMS.

05

5G SA device management

The OAI interface connects the EIR to 5G SA core functions. The same black, white, and grey list policy that governs older generations applies to 5G SA, managed from the one place.

06

National IMEI white list compliance

Regulatory obligations can request that a mobile to be accepted only if they had be legally sold (tax paid, identity checked).

03Specifications

IMEI lists
Black, white, grey per SQL interface or file
Check timing
Real-time on every network attachment
Network interfaces
MAP interface F/Gf, Diameter S13/S13', OAI Neir
Database
Fast in-memory/DB
OTA trigger
Option : Automatic on first attachment
Subscriber device tracing
Supported where legal framework permits
Standards compliancies
3GPP TS 29.272 (S13 interface), 29.002 (MAP+main manufacturer extensions), 29.511 (5G-SA), 22.016
Availability
99.9999%
Business model
OPEX rental · CAPEX licence
04Inside the platform

01

Single deployment from 2G to 5G SA

One EIR instance handles IMEI checking across all network generations. 5G SA connects via the OAI interface without a separate deployment. No second vendor or second support contract when the network upgrades. Device policy stays consistent across generations automatically.

02

Fast in-memory database

IMEI lookups run in memory at every attachment event. Blacklist enforcement does not add perceptible latency to the attachment procedure.

03

Welcome SMS without probing systems

New subscriber attachment triggers a Welcome SMS directly from the EIR. No external signalling probe required. First-contact messaging deploys without adding a probe platform to the architecture.

04

Automatic OTA on first attachment

The EIR fires an OTA trigger the first time a new device attaches. Configuration reaches the device before the subscriber notices it needs setting up. Support calls for manual APN and MMS configuration drop without requiring separate provisioning logic.

05

Grey list for policy-based tracking

Devices sit on a grey list without a binary block or allow decision: monitored, flagged, or subject to conditional access. Regulatory obligations for device monitoring are met without removing the device from service.

06

Subscriber device tracing

Where national law permits, the EIR tracks which subscriber is using which device at any given time. Law enforcement requests are handled from the EIR without additional audit infrastructure.

05Why Ouroboros

The cost of fragmented device management adds up over time: separate deployments, separate upgrade cycles, separate support calls when a policy needs changing. Device policy stays consistent because it is held and enforced in one place, not split across systems that drift apart.

Functions that usually arrive as separate systems are built in here, so there are fewer integration points to commission and maintain. Operators run device access control and subscriber onboarding from one deployment. In production since 2004, for operators including O2, eir, and Elisa.

OPEX rental and CAPEX licence are both available. Device management can start at launch and grow with the subscriber base rather than ahead of it.

Ouroboros Telecom

Which network generations are you running, and what device policy do you need to enforce? We'll propose an EIR configuration for what you run today and what you're building toward, on OPEX or CAPEX.