IKEv2 (Internet Key Exchange version 2)

Also known as: Internet Key Exchange v2, IKE version 2

IKEv2 (RFC 7296) is the key negotiation protocol used to establish and rekey IPsec Security Associations. In mobile networks IKEv2 authenticates gNB, eNB, SEG and untrusted non-3GPP access (ePDG, N3IWF) using certificates or EAP-AKA', and negotiates ESP parameters for S1-U, X2, N2, N3 and Wi-Fi calling tunnels. Modern deployments require strong DH groups (19/20/21), AEAD ciphers and disabling weak PSK modes.

Categories: Radio Access NetworkSecurity ControlsProtocols and Standards

IKEv2 in context

The radio access network is where mobile devices attach to the operator's infrastructure. Attacks in this layer include IMSI catching, rogue base stations and downgrade attacks; defenses rest on mutual authentication, integrity-protected signaling and Open RAN supply-chain hygiene.

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

To place IKEv2 in the wider telecom-security picture, review 6G, DOCSIS, EAP, MPLS, SSH and SRv6 — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.