SUPI (Subscription Permanent Identifier)

The Subscription Permanent Identifier is the 5G equivalent of the IMSI, identifying a subscriber within the home network of the operator. It is provisioned on the USIM and used for authentication and policy decisions. Crucially, the SUPI is never sent in cleartext over the radio interface, instead the UE encrypts it with the home network's public key to produce the SUCI, which is then used in all initial signalling, neutralising the IMSI-catcher class of attacks that affected earlier generations.

Categories: Radio Access NetworkRoaming and InterconnectIdentity and Subscriber

SUPI in context

The radio access network is where mobile devices attach to the operator's infrastructure. Attacks in this layer include IMSI catching, rogue base stations and downgrade attacks; defenses rest on mutual authentication, integrity-protected signaling and Open RAN supply-chain hygiene.

Roaming and interconnect are where two operators exchange signaling and user-plane traffic. Trust boundaries here are the primary attack surface for location tracking, SMS interception and fraud, which is why GSMA now mandates SEPP with PRINS on 5G interconnect.

To place SUPI in the wider telecom-security picture, review SUPI Concealment, AKA, iSIM, MNC, SUCI and Roaming: each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • 5G Security 5G SBA, SEPP, SUCI, 5G-AKA, N32 and service-based interface security.
  • Roaming Security IPX/GRX interconnect risk, home-routed vs local-breakout, SEPP.
  • Diameter Attacks S6a IDR/PUR/CLR abuse, subscriber tracking, LTE signaling attacks.
  • 5G NEF Security Network Exposure Function security in the 5G core.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.