6G Security

6G is the next generation of mobile networks after 5G, currently being defined by ITU-R (IMT-2030 framework) and standardized by 3GPP from Release 20 onward, with commercial deployment expected around 2030. Unlike prior generations, 6G security is being designed rather than retrofitted: it inherits 5G's service-based architecture and SUPI/SUCI privacy model, but must additionally accommodate AI/ML-native network functions, integrated sensing and communication (ISAC), sub-terahertz spectrum, terrestrial/non-terrestrial convergence, and the cryptographic transition to post-quantum algorithms.

The 6G threat surface expands along three axes that do not have direct 5G analogues. First, AI/ML control loops embedded in the RAN, core, and management plane become both targets (data poisoning, model extraction, adversarial inputs) and tools (autonomous defense, anomaly detection). Second, ISAC turns the network itself into a sensor — every base station becomes a passive radar of its coverage area — which creates entirely new privacy and lawful-interception questions that 3GPP SA3 is only beginning to scope. Third, the migration to post-quantum cryptography (NIST FIPS 203/204/205, based on CRYSTALS-Kyber and CRYSTALS-Dilithium) must land before cryptographically relevant quantum computers exist, which means key exchange, subscriber authentication, and the SUCI concealment scheme all need PQC-ready variants during the 6G specification window.

This hub aggregates what Ultimate Guide covers today on the 5G foundations 6G will build on (SBA, SEPP, SUPI/SUCI, slicing) and the emerging 6G-specific work streams: NGMN, Hexa-X, ETSI ISG, 3GPP SA3, and the ITU-R IMT-2030 usage-scenario framework. It is a forward-looking reference — definitions and threat models are cited from public standards drafts and working-group deliverables only; specific commercial roadmaps are out of scope.

Frequently asked questions about 6g security

What is Integrated Sensing and Communication (ISAC) in 6G?

Integrated Sensing and Communication is a 6G capability where the radio waveform is used simultaneously for data transmission and passive/active sensing of the environment — position, velocity, and presence of objects and people in the cell. It is one of the six IMT-2030 usage scenarios defined by ITU-R. From a security standpoint ISAC creates new privacy questions (the network itself becomes a sensor of its coverage area), new lawful-interception scope, and new attack surfaces (sensing data poisoning, false-target injection).

When is 6G expected to be commercially deployed and what should security teams start doing now?

ITU-R IMT-2030 targets 6G specifications around 2028–2030, with first commercial deployments generally forecast for the 2030 window. Security teams should already be tracking three inputs: (1) 3GPP Release 20+ studies on AI/ML-native security, integrated sensing and communication (ISAC), and post-quantum profiles; (2) GSMA PQ.03 for PQC migration in signaling and roaming; (3) ETSI ISG SAI for AI-security threat models that will feed 6G designs. Investment now in PQC hybrid pilots and AI/ML threat modeling will pay off directly against 6G rollout timelines.

What is post-quantum cryptography and does it affect mobile networks today?

Post-quantum cryptography (PQC) refers to cryptographic algorithms believed to resist attacks by cryptographically relevant quantum computers. NIST standardized the first three PQC algorithms in 2024 as FIPS 203 (ML-KEM, based on CRYSTALS-Kyber), FIPS 204 (ML-DSA, based on CRYSTALS-Dilithium), and FIPS 205 (SLH-DSA). For mobile networks, PQC is being scoped by 3GPP SA3 for future releases and is a design input for 6G — subscriber identity concealment (SUCI), TLS in the 5G SBA, and IPsec on N32 are the most sensitive to a "harvest now, decrypt later" adversary.

What is threat intelligence sharing in telecom (T-ISAC)?

The GSMA's Telecommunications Information Sharing and Analysis Centre (T-ISAC) enables operators to share threat intelligence about attacks, vulnerabilities, and indicators of compromise. By pooling knowledge across the industry, operators can detect and respond to attacks faster, particularly for threats that exploit roaming interconnects where visibility requires cross-operator collaboration.

What security considerations exist for 6G networks?

While 6G is still in the research phase (expected around 2030), security considerations include AI-native security architectures, physical-layer security using terahertz frequencies, integrated sensing-and-communication security, digital twin-based security testing, and privacy-preserving computation for distributed intelligence. 6G aims to make security a foundational design principle rather than an add-on layer.

When should operators migrate to post-quantum cryptography?

The migration is already in flight. NIST published ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) as final standards in August 2024. The pragmatic operator timeline: 2025–2026 inventory of long-lived keys and identify HNDL-critical interfaces (SUCI, LI, N32, X.509 roots); 2026–2028 pilot hybrid KEMs on TLS 1.3 and IKEv2 for high-value flows; 2028+ align with 3GPP Release 20+ PQC profiles. US NSM-10 sets a 2035 deadline for national-security systems; commercial telecom should not lag far behind.

See all telecom security FAQs

Related glossary terms

Browse the full telecom security glossary

More on 6g Security

Browse all topic hubs, the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.