GTP User Plane

Also known as: GTP User Plane

GTP-U (TS 29.281) is the user-plane variant of the GPRS Tunnelling Protocol that encapsulates subscriber IP packets inside UDP tunnels between RAN and core (S1-U, S5/S8-U, N3, N9). Each tunnel is identified by a TEID. GTP-U leaks and mis-scoped TEIDs are a classic vector for cross-subscriber traffic injection, redirection and data exfiltration, and are the reason a GTP firewall is mandatory on any 4G/5G user-plane border.

Categories: Radio Access NetworkCore NetworkSignaling

GTP-U in context

The radio access network is where mobile devices attach to the operator's infrastructure. Attacks in this layer include IMSI catching, rogue base stations and downgrade attacks; defenses rest on mutual authentication, integrity-protected signaling and Open RAN supply-chain hygiene.

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

To place GTP-U in the wider telecom-security picture, review IMS-AKA, N3, IAP, IPsec, TEID and GPRS: each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • GTP Security GTP-C/GTP-U threats across S5/S8, N3/N9 and GRX/IPX borders under GSMA FS.20.
  • GTP Firewall GSMA FS.20 GTP-C/GTP-U screening on GRX/IPX borders.
  • Signaling Firewall Unified SS7/Diameter/GTP/SMS signaling firewall framework.
  • SS7 Security SS7/MAP/CAP/SCCP attacks and defenses across 2G/3G interconnect.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.