3GPP TS 33.501 → GSMA FS.21
3GPP TS 33.501 is the normative 5G security architecture. FS.21 is the operator-facing implementation baseline. This crosswalk clarifies which parts of 33.501 FS.21 operationalises, and which fall outside its scope.
Scope: 5G roaming and interconnect (N32). Access-stratum and NAS security are out of scope.
| Category | 3GPP TS 33.501 | GSMA FS.21 | Notes |
|---|---|---|---|
| SEPP function | 33.501 §5.9.3 | FS.21 §4 | FS.21 mandates SEPP deployment at all roaming borders. |
| N32-c handshake | 33.501 §13.1 | FS.21 §4.1 | Mutual TLS, cipher suite requirements. |
| N32-f PRINS | 33.501 §13.2 | FS.21 §4.2 | JOSE (JWE/JWS) message-level protection. |
| Modification policies | 33.501 §13.2.4 | FS.21 §4.3 | Per-IE modification rules with IPX providers. |
| IPUPS | 33.501 §5.9.10 | FS.21 §6 | Inter-PLMN UP Security gateway. |
Gaps
- Access-stratum security (33.501 §6) is out of FS.21 scope.
- Slice-level security (33.501 §5.9.11) is not yet in FS.21.
Key takeaways
- FS.21 = the deployable subset of 33.501 for interconnect.
- Modification policies are the operator-negotiable control most often missed.
- Slice security remains an emerging area outside current FS.21.