GBA (Generic Bootstrapping Architecture)

Also known as: Generic Bootstrapping Architecture

GBA is a 3GPP framework (TS 33.220) that reuses the USIM's AKA credentials to bootstrap application-layer keys between the UE and a Network Application Function, without provisioning a separate secret per service. The BSF runs AKA with the HSS, then derives a Ks that both the UE and the NAF can use, enabling authenticated services such as MBMS key management, IMS single sign-on and 3GPP-based OTT authentication.

Categories: Identity and SubscriberSecurity ControlsProtocols and Standards

GBA in context

Subscriber identifiers (IMSI, SUPI, MSISDN, IMEI) anchor authentication, charging and lawful interception. Any protocol that leaks a permanent identifier is treated as a privacy defect, which is why 5G introduced SUCI concealment on the air interface.

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

To place GBA in the wider telecom-security picture, review Key Management, OASIS, X.500, SM-DP+, 2G and 3G — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.