Non-Access Stratum (NAS) Signaling Security

The Non-Access Stratum (NAS) is the signaling layer that runs end-to-end between the UE and the core-network mobility anchor, the MME in 4G EPS and the AMF in 5G 5GS, on top of the radio Access Stratum (AS). It carries the procedures the radio network is not allowed to read or modify: registration and attach, authentication and key agreement, security mode command, service request, mobility (TAU / Registration Update), session management (ESM in 4G, 5GSM in 5G) and detach. NAS is specified in 3GPP TS 24.301 for EPS and TS 24.501 for 5GS, with the security architecture in TS 33.401 (EPS) and TS 33.501 (5GS).

NAS security is what stands between a subscriber and a hostile or misconfigured radio. After successful authentication, the NAS Security Mode Command (SMC) negotiates the integrity algorithm (EIA in 4G, NIA in 5G) and ciphering algorithm (EEA in 4G, NEA in 5G), derives KNASint / KNASenc from KASME or KAMF, and from that point every NAS message is integrity-protected and, except for the small set of pre-authentication messages, ciphered. The integrity check is mandatory; ciphering can in principle be set to the null algorithm (EIA0/EEA0/NIA0/NEA0) and that policy choice is itself a security-relevant decision an operator has to make explicit.

This hub aggregates Ultimate Guide coverage of the NAS protocol stack and procedures between UE, eNodeB/gNB and MME/AMF; the NAS Security Mode Command flow, key hierarchy and algorithm selection; the known attack classes (pre-SMC unprotected messages abused by IMSI catchers and fake base stations, algorithm-downgrade and null-cipher exposure, replay and bidding-down on Registration / TAU, malformed EMM / 5GMM messages that have historically crashed mobility stacks, and information leaks from unciphered identity requests); the SUPI / SUCI concealment introduced in 5G to close the long-standing IMSI exposure of EPS-AKA; and the operator-side controls (strict integrity-mandatory policy, refusal of NEA0/EEA0 except where standardized, NAS-fuzzing in pre-deployment validation, baseband and core-side hardening against malformed NAS PDUs) that contain NAS-class abuse on a live network. See also the related Tracking Area Update (TAU) and 5G Security hubs.

Frequently asked questions about non-access stratum (nas) signaling security

How does 5G-AKA differ from EPS-AKA in LTE?

5G-AKA enhances EPS-AKA with home-network verification of authentication results, SUPI concealment via SUCI, support for 256-bit key derivation, and binding of the serving network name into the authentication process. These changes prevent certain impersonation attacks and add an extra layer of home-network control over roaming authentication.

What is the NAS protocol in LTE/5G?

The Non-Access Stratum (NAS) protocol handles signaling between the UE and the core network for session management, authentication (EPS-AKA/5G-AKA), and mobility. NAS messages can be integrity-protected and encrypted. Security vulnerabilities arise when null ciphering is allowed or when pre-authentication messages are exploited for device fingerprinting or denial-of-service.

What is IMS-AKA and how is it different from 5G-AKA?

IMS-AKA is the authentication and key agreement procedure used between an IMS subscriber (UE) and the IMS core (S-CSCF via I-CSCF), based on a separate IMS identity (IMPI/IMPU) and the ISIM application on the SIM card. It reuses the AKA challenge-response mechanism from 3G but at the IMS layer, and derives keys used for IPsec on the Gm interface. 5G-AKA operates at the access layer between the UE and the AMF/AUSF and secures the primary network attach. Both can run for the same subscriber: 5G-AKA for network access, IMS-AKA for VoLTE/VoNR service.

Are commercial IMSI catcher detection apps reliable?

Mixed. Apps that rely only on unprivileged Android APIs can flag some GSM-era anomalies (unexpected LAC changes, missing neighbor cells, weak ciphering indicators) but cannot inspect the LTE/5G radio stack in depth and often produce false positives. Reliable detection today combines dedicated SDR-based probes, network-side anomaly detection on the RAN and core (unexpected paging, TAU/RAU patterns), and passive sensor networks. Consumer apps are useful as awareness tools but not a substitute for operator-side detection.

When is 6G expected to be commercially deployed and what should security teams start doing now?

ITU-R IMT-2030 targets 6G specifications around 2028–2030, with first commercial deployments generally forecast for the 2030 window. Security teams should already be tracking three inputs: (1) 3GPP Release 20+ studies on AI/ML-native security, integrated sensing and communication (ISAC), and post-quantum profiles; (2) GSMA PQ.03 for PQC migration in signaling and roaming; (3) ETSI ISG SAI for AI-security threat models that will feed 6G designs. Investment now in PQC hybrid pilots and AI/ML threat modeling will pay off directly against 6G rollout timelines.

See all telecom security FAQs

Related glossary terms

  • LTE Long Term Evolution
  • Cipher
  • N1 N1 Reference Point
  • AMF Access and Mobility Management Function
  • SEAF SEcurity Anchor Function
  • AKA Authentication and Key Agreement
  • AUSF Authentication Server Function
  • Encryption
  • HSS Home Subscriber Server
  • NB-IoT Narrowband IoT

Browse the full telecom security glossary

Related comparisons

More on Nas Security

Browse all topic hubs, the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.