GBA (Generic Bootstrapping Architecture)
Also known as: Generic Bootstrapping Architecture
Categories: Identity and SubscriberSecurity ControlsProtocols and Standards
GBA in context
Subscriber identifiers (IMSI, SUPI, MSISDN, IMEI) anchor authentication, charging and lawful interception. Any protocol that leaks a permanent identifier is treated as a privacy defect, which is why 5G introduced SUCI concealment on the air interface.
Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.
To place GBA in the wider telecom-security picture, review CAP, USIM, SM-DP+, Key Management, OASIS and VPN: each entry cross-references back to this page so you can walk the topic in either direction.
Related terms
Related topic hubs
- Open RAN Security O-RAN xApp/rApp, E2/A1/O1 interfaces and RIC security.
- VoLTE Security IMS/VoLTE signaling risk: SIP, IMS-AKA, media plane attacks.
- IMS Security Training Training on IMS, VoLTE/VoNR, SIP and RCS security.
- Silent SMS Type-0 SMS location tracking and detection.
More from the TelcoSec Glossary
Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.