What is written down · chapter 11 of 14 · 12 minutes
11 The specification family: 241 documents, and the two that are IMS
The whole document map of this subject — the two documents at its centre, the family around them, the studies, and the three things this list cannot tell you.
11.1 Why this subject has no single document
Most courses in this school are a guided read of one specification. This one cannot be, because IMS is not written down in one place. It is written down in 241 specifications [8], out of 3599 that 3GPP marks active altogether [9].
That is the first thing to understand about the subject. Somebody who has read TS 23.228 from cover to cover has read how the system is put together.
They have read nothing about what goes on the wire, nothing about emergency calls, nothing about talking to an old circuit-switched network, and nothing about what any of it does to the 5G core.
This chapter is the map. It says which document to open for which question, how much work has landed in each, and — at the end — the three limits of the list itself.
11.2 How a document got onto this list
Two tests, and a document is here if either is true.
-
T1. A work item names it as a document it will change. Somebody wrote down, in advance, that this piece of work would touch it.
-
T2. At least three IMS documents name it in the column that says which document a change targets. The work landed on it, declared or not.
Both are needed. The first catches documents nobody has got to yet; the second catches documents nobody declared.
The floor of three is deliberate, and 15 documents fall below it — named by one or two IMS change requests and by no work item at all [10]. They are left out because a single mention is as likely to be a filing mistake as a real link.
11.3 The two that are IMS
Two documents sit at the centre, and they answer different questions.
11.3.1 TS 23.228 — how the system is put together
This is the stage 2 description: the parts, what each one is for, and how a session moves between them. SA2 owns it, and its recorded rapporteur — the person who holds the pen — is Thomas Towle of Qualcomm TS 23.228.
It exists in every release from Rel-5 at version 5.15.0 to Rel-20 at 20.0.0, and 92 IMS documents in this register name it as the document they change [11].
Two things in that sentence matter. "Stage 2" means how the system is put together, not what it must do and not what the bytes look like. And "IP Multimedia Core Network Subsystem" is the documents' own name for IMS — the name you have to search for when the short form finds nothing.
11.3.2 TS 24.229 — what goes on the wire
This is the protocol: 3GPP's rules for using SIP, the message language a phone and the network speak to start, change and end a session. CT1 owns it, and its recorded rapporteur is Peter Leis of Nokia Networks TS 24.229.
It is the largest target in this register by a wide margin. 1680 of the 4939 IMS documents on record name it as the document they change [12] [13]. It too runs from Rel-5, at 5.26.0, to Rel-20 at 20.0.0.
The scope names two protocols that 3GPP did not write: SIP, the messages that start, change and end a session, and its companion the Session Description Protocol.
Both are the IETF's, and TS 24.229 is the profile — the account of which parts of them a 3GPP network uses and how. What that costs in maintenance is Maintenance is the main event: change requests and protocol alignment.
11.4 The family around them
Eight more documents make up the working family. The last column is how many IMS documents in this record name each one as the document they change.
| Document | What it is for | Group | IMS documents |
|---|---|---|---|
| TS 23.218 | the call model: how one session is originated and terminated | CT1 | 0 |
| TS 23.167 | emergency sessions | SA2 | 10 |
| TS 23.237 | service continuity — a session surviving a change of network | SA2 | 2 |
| TS 23.292 | centralized services — the same service whichever way the phone is attached | SA2 | 3 |
| TS 23.334 | the interface between the IMS-ALG and the access gateway | CT4 | 25 |
| TS 23.380 | restoration: handling an interruption of the servers its scope names | CT4 | 22 |
| TS 22.228 | the stage 1 requirements: what the system must do at all | SA1 | 31 |
| TS 22.173 | multimedia telephony and its supplementary services | SA1 | 0 |
The two zeros are worth a pause. TS 23.218 and TS 22.173 are on this list because work items declared them, not because change requests landed on them in the window this record covers. A zero here means "nothing arrived that this store can see", never "nothing was ever done to it".
Three of the eight say what they are for in one sentence, and the sentences are short enough to be worth having whole.
The wording of that last one is the document's own, typing mistake and all. The register copies what is there rather than tidying it, which is the only way a quotation is worth anything.
Three names in those sentences are left as they stand: S-CSCF, P-CSCF and IMS-ALG. The register holds no expansion of any abbreviation, so this course does not say what those letters stand for, and neither should you unless you have the definitions clause of a specification open in front of you.
11.5 Talking to everything else
IMS was built into a world that already had telephone networks, and two documents carry that weight.
TS 29.163 is interworking with circuit-switched networks — the old telephone world of the PSTN, ISDN, GSM and UMTS. CT3 owns it and 228 IMS documents change it TS 29.163.
TS 29.165 is the interface between two IMS networks, which is what a call crosses when it leaves one operator for another. Also CT3, 190 IMS documents TS 29.165.
TS 24.371 is WebRTC access to IMS: reaching the same services from a browser rather than from a phone's own software. CT1, 160 IMS documents TS 24.371.
Security has its own pair. TS 33.226 is the security assurance specification for IMS — the checklist a product is tested against — with 48 IMS documents naming it, of which four are change requests TS 33.226.
TR 33.926 holds the threats and critical assets behind it, with 35 TR 33.926.
11.6 The media, the browser and the test lab
A call is not only signalling. Nine more documents cover what the media does, what the newest kinds of session look like, and how a device is tested.
| Document | What it is for | Group | IMS documents |
|---|---|---|---|
| TS 26.114 | multimedia telephony: media handling and interaction | SA4 | 15 |
| TS 26.223 | telepresence media handling | SA4 | 38 |
| TS 24.103 | telepresence, stage 3 | CT1 | 30 |
| TS 26.264 | augmented-reality real-time communication over IMS | SA4 | 2 |
| TS 26.567 | split rendering over IMS | SA4 | 73 |
| TS 24.186 | IMS data channel applications, stage 3 | CT1 | 9 |
| TS 34.229-1 | device conformance testing for the SIP profile | RAN5 | 72 |
| TR 24.930 | signalling flows for session setup, a report | CT1 | 2 |
| TS 29.292 | interworking with the server that handles centralized services | CT3 | 17 |
The newest idea in that list is the data channel, and TS 23.228 defines it in two sentences that are worth reading before anybody explains it to you.
A web page, downloaded into the phone, running inside a call. That is a long way from what Release 5 set out to build, and it lands in the same stage 2 document as everything else.
The conformance row matters for a different reason. TS 34.229-1 is where a device is tested against the SIP profile, so a rule that never reaches it is a rule nothing checks. It runs from Rel-5 at 5.2.0 to Rel-19 at 19.6.0 TS 34.229-1.
11.7 The studies
A study report is homework: published once, binding on nobody, and usually the better first read because it says why rather than what.
| Report | What it studied | Group | IMS documents |
|---|---|---|---|
| TR 23.794 | putting the existing IMS on the 5G core, Rel-16 | SA2 | 190 |
| TR 23.700-10 | the second phase, CT1's part | CT1 | 101 |
| TR 23.700-11 | the second phase, CT3's part | CT3 | 7 |
| TR 23.700-12 | the second phase, CT4's part | CT4 | 59 |
| TR 29.866 | disaster prevention and restoration, Rel-19 | CT4 | 106 |
| TR 29.867 | IMS resiliency, Rel-20 | CT4 | 73 |
| TR 23.801-04 | IMS architecture enhancement, Rel-20 | SA2 | 47 |
The three phase-two reports are one study split by group, and their document counts are very different: CT1's part drew 101 papers and CT3's drew 7. Splitting a study across three groups is normal here, so reading one of the three leaves the other two groups' work unread.
The two newest are not settled text. TR 23.801-04 stands at 0.1.0, which is a working draft, and TR 29.867 has reached 1.0.0 TR 23.801-04 TR 29.867. Below 1.0.0 nothing in a report has been agreed as a conclusion.
11.8 What IMS work does to the 5G core
The most surprising part of the map is how much IMS work lands in documents that are not IMS documents at all.
TS 23.501 is the architecture of the 5G system itself. IMS work changes it so that IMS appears there as a consumer of 5G core services, and 33 IMS documents name it TS 23.501.
TS 29.562 is the 5G system's Home Subscriber Server services, stage 3 — one of the few titles in this subject that spells its own abbreviation out. 230 IMS documents name it, which makes it the second-largest target in this register TS 29.562.
Two more carry serious traffic: TS 29.514, the policy authorisation service, with 100 IMS documents, and TS 29.513, the signalling flows and quality-of-service mapping that go with it, with 75 TS 29.514 TS 29.513.
11.9 Three limits of this list, stated plainly
L1. 72 of the 241 have no parsed text on this machine. The register's own list of what is missing says so, and TR 23.794 and TR 22.823 are among them [8] TR 22.823. Those documents may be named and counted here. They may not be quoted, and none of their clauses may be cited, because there are no words on this machine to check a quotation against.
L2. Four numbers a work item names have no catalogue row at all. The 241 are the numbers that have one [8]. Four more — 22.928, 24.998, 26.22 and 31.134 — are named by a work item as documents it changes, and the specification catalogue here holds no row for them. They get no title, no type and no owning group in this course, because inventing one would be a guess wearing a fact's clothes.
L3. A version's stored date is the day its file went up. Nearly every version in this register carries a day, and that day is when the file appeared on the 3GPP server — not when the document was published, and not when anybody approved it TS 23.228. Two of the 2178 stored release versions have no day at all. So "TS 23.228 Rel-20 20.0.0" is a fact and "TS 23.228 Rel-20 came out in June" is not.
11.10 Where this fits with the rest of the course
The counts in this chapter are counts of change requests, and what a change request is, why there are so many of them, and what the outcome words on them mean is Maintenance is the main event: change requests and protocol alignment.
Which of these documents is being written right now, and by whom, is What is running now: Releases 18 to 20. How to look any of them up yourself, and what the record still will not tell you afterwards, is Reading the record yourself, and what it cannot tell you.
If you read two documents and no more, read TS 23.228 for how the system is put together and TS 24.229 for what is on the wire TS 23.228 TS 24.229. Everything else on this page is a detail of one or the other.
Where the numbers in this chapter come from
- the scope of 23.228 the opening sentences of clause 1 of the parsed text at /var/www/whatthespec.net/data/friendlyspec/json/23228/20.0.0/, copied word for word, read 2026-08-05
- the scope of 24.229 the opening sentences of clause 1 of the parsed text at /var/www/whatthespec.net/data/friendlyspec/json/24229/20.0.0/, copied word for word, read 2026-08-05
- the scope of 23.218 the opening sentences of clause 1 of the parsed text at /var/www/whatthespec.net/data/friendlyspec/json/23218/19.0.0/, copied word for word, read 2026-08-05
- the scope of 23.380 the opening sentences of clause 1 of the parsed text at /var/www/whatthespec.net/data/friendlyspec/json/23380/20.0.0/, copied word for word, read 2026-08-05
- the scope of 22.173 the opening sentences of clause 1 of the parsed text at /var/www/whatthespec.net/data/friendlyspec/json/22173/20.0.0/, copied word for word, read 2026-08-05
- "Application data channel" as 23.228 defines it the paragraph of clause 3.1 of the parsed text at /var/www/whatthespec.net/data/friendlyspec/json/23228/20.0.0/ that begins 'Application data channel', copied word for word, read 2026-08-05
- "Data channel application" as 23.228 defines it the paragraph of clause 3.1 of the parsed text at /var/www/whatthespec.net/data/friendlyspec/json/23228/20.0.0/ that begins 'Data channel application', copied word for word, read 2026-08-05
- 241 specifications this work touches catalogue rows for every document a work item names as one it changes, plus every one named in the change-request column of at least 3 IMS documents, asked of /var/www/whatthespec.net/data/database/api/spec_catalog.sqlite on 2026-08-05
- 3599 3GPP specifications are marked active altogether catalogue rows whose active column is yes, asked of /var/www/whatthespec.net/data/database/api/spec_catalog.sqlite on 2026-08-05. The flag is about the catalogue row and says nothing about whether work is running
- 15 documents are named by fewer than 3 IMS change requests and by no work item specifications named in the change-request column of one or two IMS documents and by no work item (23.288, 24.109, 24.259, 24.322, 24.379, 24.39, 24.481, 24.484 and more); left out of the register because one document is as likely a filing mistake as a real link, asked of /var/www/whatthespec.net/data/database/api/api.sqlite on 2026-08-05
- 92 IMS documents name 23.228 as the document they change IMS documents whose change-request column names 23.228, asked of /var/www/whatthespec.net/data/database/api/api.sqlite on 2026-08-05, of which 92 are of type CR, CR pack or draftCR
- 1680 IMS documents name 24.229 as the document they change IMS documents whose change-request column names 24.229, asked of /var/www/whatthespec.net/data/database/api/api.sqlite on 2026-08-05, of which 1675 are of type CR, CR pack or draftCR
- 4939 IMS meeting documents rows of table `tdoc` whose work item column holds, as a whole word, one of the 177 IMS acronyms — 159 different spellings of that column match, because it sometimes carries two work item names at once, asked of /var/www/whatthespec.net/data/database/api/api.sqlite on 2026-08-05
Check yourself
Answers appear when you pick one, with where they come from.
Q11.1 How does a document get onto this course's list of 241 specifications?
Those are the two tests, and a document passes if either is true. One catches what was promised, the other catches what actually landed. 241 specifications this work touches
Q11.2 Which document carries by far the most IMS change traffic?
1680 of the 4939 IMS documents in this record name TS 24.229 as the document they change. TS 23.228 is named by 92. 1680 IMS documents name 24.229 as the document they change
Q11.3 A stored version carries a date. What is that date?
The register says so in the entry itself. Publication day and approval day are not held anywhere on this machine. TS 23.228
Q11.4 72 of the 241 specifications have no parsed text on this machine. What may a course do with them?
No parsed text means no words to check a quotation against. Naming and counting are safe; quoting is not. 241 specifications this work touches
Q11.5 TR 23.794 and TS 23.228 are different kinds of document. What is the difference?
TR 23.794 is the Rel-16 study on putting IMS on the 5G core. TS 23.228 is the stage 2 rule. The study fed the rule and never replaced it. TR 23.794
This chapter was built from a source register generated 2026-08-05. A fresher build of the register may hold different numbers.