5G Security

5G introduces the most significant security overhaul in mobile network history: a service-based architecture (SBA) using HTTP/2 and TLS, subscriber identifier privacy via SUCI/SUPI concealment, the Security Edge Protection Proxy (SEPP) for roaming interconnect, 256-bit cryptographic keys, and network-slicing isolation.

This hub gathers Ultimate Guide coverage of the 5G security model, including the nuanced details of 3GPP TS 33.501 (e.g., user-plane integrity protection is mandatory to support but optional to activate), alongside the operational realities of securing 5G non-standalone (NSA) and standalone (SA) deployments.

In-depth chapters

Frequently asked questions about 5g security

What is SUPI and SUCI in 5G, and how do they protect subscriber privacy?

SUPI (Subscription Permanent Identifier) is the permanent subscriber identity in 5G, replacing the IMSI. SUCI (Subscription Concealed Identifier) is an encrypted version of the SUPI transmitted over the air interface, using the home network's public key. This prevents IMSI catching attacks where passive eavesdroppers could previously identify and track subscribers.

How do you assess the security of a 5G core network?

Assessing a 5G core involves testing the SBA interfaces (HTTP/2 APIs) for injection and authorization flaws, evaluating NRF access controls and OAuth 2.0 token validation, testing SEPP configuration and inter-PLMN security, verifying slice isolation, and auditing the container/cloud infrastructure hosting the network functions. Each 5G-specific function (AMF, SMF, UPF, etc.) has unique security test cases.

What is 5G standalone (SA) vs. non-standalone (NSA) and which is more secure?

5G NSA uses a 5G radio layer anchored to a 4G LTE core, inheriting LTE's security properties and limitations. 5G SA deploys the full 5G core (5GC), enabling native 5G security features like SUCI, SEPP, SBA with TLS, and network slicing. SA is significantly more secure because it eliminates the 4G trust-model dependencies and enables end-to-end 5G security controls.

How does the 5G Service-Based Architecture (SBA) improve security?

The 5G SBA decomposes monolithic network functions into modular, independently deployable services communicating over HTTP/2 with TLS. This enables fine-grained access control via the Network Repository Function (NRF), OAuth 2.0-based service authorization, and clear separation of concerns—making it easier to apply security policies and isolate compromised functions.

What is the Security Edge Protection Proxy (SEPP) in 5G?

The SEPP is a mandatory 5G network function that sits at the operator's roaming boundary, replacing the unsecured SS7/Diameter interconnect model. It provides end-to-end message-level security (via JOSE/JWE) and transport-layer protection (TLS 1.3) for all inter-operator signaling, enforcing topology hiding and message filtering at the roaming edge.

How is private 5G security different from public 5G security?

Private 5G networks (SNPN standalone or PNI-NPN integrated with a public operator) share the same 3GPP security architecture as public 5G — SUCI, 5G-AKA, SBA TLS, SEPP for roaming — but the threat model differs. Private networks emphasize isolation from the internet and the enterprise IT/OT domain, credential provisioning outside SIM/eSIM (SNPN can use non-3GPP credentials), and controls over on-premise gNBs and UPFs. Compliance drivers shift from GSMA/NIS2 to IEC 62443 and enterprise policy.

What are the SEPP requirements for 5G roaming under 3GPP Release 16+?

Under 3GPP TS 33.501 the SEPP is mandatory for inter-PLMN N32 signaling: mutual TLS on N32-c for the negotiation of security capabilities, and either TLS or PRINS on N32-f for the actual JSON-based service traffic. When IPX providers must modify messages, PRINS is required so that sensitive IEs (SUPI, location, keys) are JWE-encrypted end-to-end while non-sensitive IEs remain modifiable under a signed patch. OAuth 2.0 tokens issued by the home NRF authorize NF-to-NF calls across the boundary.

How has mobile network security evolved from 2G to 5G?

Security has progressed from the weak, one-way authentication of 2G (GSM) to mutual authentication and stronger encryption in 3G (UMTS), then to EPS-AKA and IPsec-protected backhaul in 4G (LTE). 5G introduces SUPI/SUCI privacy, 256-bit keys, service-based architecture with TLS, and network slicing isolation—each generation addressing the shortcomings of its predecessor.

What is 5G network slicing and what are its security challenges?

Network slicing allows operators to create multiple virtual networks on shared physical infrastructure, each with tailored security policies and resource guarantees. Security challenges include slice isolation enforcement (preventing cross-slice attacks), per-slice authentication, resource exhaustion from one slice affecting others, and the complexity of managing security policies across hundreds of slices.

What are the top security risks in a private 5G deployment?

Enterprise/private 5G (SNPN/PNI-NPN under 3GPP TS 23.501) inherits the standard 5G threat model plus enterprise-specific risks: weak site-to-site connectivity between distributed UPFs, misconfigured slice isolation, exposed OAM/O1 interfaces on the RAN, use of test/default SUCI provisioning, and unpatched containerized NFs on shared enterprise Kubernetes. GSMA PN.01 and ENISA "5G for Verticals" describe the baseline hardening; add strict OT/IT segmentation and per-slice policy on the AMF/SMF.

What are the security implications of network slicing for enterprises?

Network slicing (3GPP TS 23.501) gives enterprises isolated logical networks over shared 5G infrastructure — potentially with dedicated AMF, SMF, UPF and RAN resources per slice. Security implications: slice-level isolation only as strong as the shared control plane hardening (NRF, AUSF, UDM); risk of URSP misconfiguration mapping enterprise apps to the wrong slice; management-plane exposure via O1/OAM if enterprise operators are given slice-specific admin access; NF sharing across slices means a compromised NF affects all tenants. ENISA "5G for Verticals" and GSMA PN.01 give the baseline controls.

How does 5G-AKA differ from EPS-AKA in LTE?

5G-AKA enhances EPS-AKA with home-network verification of authentication results, SUPI concealment via SUCI, support for 256-bit key derivation, and binding of the serving network name into the authentication process. These changes prevent certain impersonation attacks and add an extra layer of home-network control over roaming authentication.

See all telecom security FAQs

Related glossary terms

Browse the full telecom security glossary

Related comparisons

Compliance crosswalks

Regulation by jurisdiction

More on 5g Security

Browse all topic hubs, the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.