Authorization

Authorisation is the process of deciding what an authenticated principal is allowed to do, distinct from authentication (who they are). Models include role-based, attribute-based, and policy-based access control. In modern telecom, authorisation is enforced at many layers, OAM access controls, OAuth2 scopes between 5G Network Functions, fine-grained API gateways, under least-privilege principles.

Categories: Core NetworkSecurity ControlsInternet and Routing

Authorization in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

To place Authorization in the wider telecom-security picture, review Decryption, SCP, DNN, 3G, 5G SBA and ACL — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.