Comprehensive reference of mobile network terms, components, and technologies
354 terms across 1 categories
Filter: Security · Clear filter
Third Generation Mobile Communications System
3GMS refers to the comprehensive security architecture and mechanisms defined for 3G (UMTS) networks. It provides a framework for authentication, confidentiality, and integrity protection, establishing the foundation for secure mobile communications beyond 2G systems. Its principles influenced later generations.
5G Equipment Identity Register
The 5G-EIR is a network function that validates the status of mobile devices (UEs) by checking their International Mobile Equipment Identity (IMEI) against blacklists, greylists, and whitelists. It prevents stolen, fraudulent, or non-compliant devices from accessing the 5G network, enhancing security and reducing fraud.
AKMA Key IDentifier
The AKMA Key IDentifier (A-KID) uniquely identifies the AKMA Application Key (K_AKMA) generated during the AKMA authentication procedure. It enables application functions to securely retrieve the K_AKMA from the AAnF (AKMA Anchor Function) for service authentication and key derivation. This is crucial for secure, network-assisted authentication for third-party application services.
Additional Mobile Subscriber Integrated Services Digital Network Number
A-MSISDN is an additional MSISDN assigned to a user for lawful interception purposes. It enables authorized agencies to intercept communications on a specific subscription without revealing the user's primary MSISDN to the intercepting entity, ensuring operational security and privacy compliance.
Authentication Algorithm A3
A3 is a cryptographic algorithm used in GSM and early UMTS networks for user authentication. It processes a random challenge (RAND) and a secret key (Ki) to generate a signed response (SRES) for verifying subscriber identity. This foundational security mechanism prevents unauthorized network access and protects against impersonation attacks.
Authentication and Key Agreement Algorithm 38
A38 is a combined cryptographic algorithm that performs both authentication (A3) and key generation (A8) functions in GSM and early 3GPP networks. It generates a signed response (SRES) for user verification and a ciphering key (Kc) for encrypting radio communications. This integrated approach streamlined security operations in 2G systems, providing essential protection against unauthorized access and eavesdropping.
Encryption Algorithm A5/1
A5/1 is a stream cipher encryption algorithm used to secure voice and data communications over the GSM radio interface. It protects the confidentiality of user traffic between the mobile station and the base transceiver station by generating a keystream to encrypt the transmitted bitstream. Its introduction was critical for providing basic privacy in early digital cellular networks, though it has since been deprecated due to cryptographic weaknesses.
GSM Encryption Algorithm A5/2
A5/2 is a deliberately weakened stream cipher encryption algorithm used in early GSM networks for voice and data confidentiality. It was designed with export restrictions in mind, providing minimal security that could be easily broken by intelligence agencies. Its inclusion in GSM standards represents a historical compromise between security requirements and political export controls.
Encryption Algorithm A5/0-7
A family of stream cipher algorithms used for encrypting user data and signaling over the air interface in GSM and early UMTS networks. It protects the confidentiality of communications between the mobile station and the base station. The 'X' denotes variants (A5/0 to A5/7) with different security strengths, where A5/0 provides no encryption.
Ciphering Key Generating Algorithm A8
A cryptographic algorithm used in GSM and early 3GPP systems to generate the ciphering key (Kc) from the subscriber authentication key (Ki) and a random challenge (RAND). It forms part of the A3/A8 authentication and key agreement mechanism, enabling secure voice and data encryption over the air interface. This foundational security component protects user communications from eavesdropping.
Authentication, Authorization, and Accounting
AAA is a security framework for controlling user access to network services and tracking resource usage. It authenticates user identity, authorizes permitted actions, and accounts for service consumption for billing and auditing. It is fundamental for secure, billable, and manageable mobile and IP networks.
Anti-Bidding down Between Architectures
ABBA is a security mechanism in 5G that prevents bidding-down attacks between different network architectures (e.g., 4G EPC and 5G Core). It ensures that a user's security capabilities are not downgraded to a less secure level when moving between networks, protecting against man-in-the-middle attacks.
Authentication and Authorization for Constrained Environments
ACE is a 3GPP security framework for authenticating and authorizing devices in resource-constrained environments, such as IoT. It enables secure, lightweight access to network services for devices with limited power, memory, or processing capabilities. This is crucial for scaling massive IoT deployments while maintaining security.
Administrative Access Condition
ADM (Administrative Access Condition) is a security mechanism in UICC/USIM applications that controls access to Elementary Files (EFs). It represents the highest privilege level where file access is managed by the administrative authority that created the file, typically the mobile operator or service provider. This ensures critical subscriber data and network parameters remain protected from unauthorized modification.
Administration Function
The ADMF (Administration Function) is a core component of the 3GPP Lawful Interception (LI) architecture. It serves as the central administrative interface for authorized law enforcement agencies (LEAs) to manage interception requests, including activation, deactivation, and modification. Its existence ensures that interception activities are properly authorized, controlled, and isolated from the operational network, maintaining both legal compliance and network security.
Authenticated Encryption with Associated Data
AEAD is a cryptographic primitive that simultaneously provides confidentiality, integrity, and authenticity for data in 3GPP systems. It encrypts the payload while generating an authentication tag for both the ciphertext and additional associated data that remains unencrypted. This is fundamental for securing 5G and beyond protocols.
Advanced Encryption Standard
AES is a symmetric block cipher standardized by NIST and adopted by 3GPP for securing user data and signaling. It provides strong confidentiality and integrity protection for air interface and core network traffic. Its efficiency and proven security are fundamental to 3GPP system trust.
Authentication Framework
A comprehensive security framework in 3GPP networks that provides authentication, authorization, and key agreement (AKA) procedures. It establishes mutual authentication between the user equipment (UE) and the network, ensuring secure access and protecting against unauthorized usage. Its standardized mechanisms are fundamental to the trust model of cellular networks.
Authentication Header
AH is a security protocol within IPsec that provides connectionless integrity, data origin authentication, and optional anti-replay protection for IP packets. It authenticates the entire IP packet header and payload, ensuring data hasn't been modified in transit. This is crucial for securing communication between network elements in 3GPP architectures.
Anonymity Key
A cryptographic key used in 3GPP networks to protect user identity during authentication procedures. It prevents tracking of subscribers by ensuring temporary identities cannot be linked to permanent identifiers. This is fundamental for subscriber privacy in mobile communications.
Authentication and Key Agreement
AKA is a fundamental security protocol used in 3GPP networks for mutual authentication between a user's device (UE) and the network, and for establishing session keys. It ensures that only authorized users access the network and that their communications are encrypted and integrity-protected. It is the cornerstone of security for 3G, 4G, and 5G systems.
Asymmetric Key Index
AKI is a security parameter used in 3GPP networks to identify which public key from a pair should be used for authentication or encryption. It's essential for managing multiple cryptographic keys in subscriber identity modules (SIM/USIM) and network elements, enabling secure key lifecycle management and preventing authentication failures during key updates.
Authentication and Key Management for Applications
AKMA is a 3GPP security framework that enables application functions (AFs) to securely authenticate and establish keys with UEs without direct authentication. It leverages the 3GPP primary authentication, allowing AFs to reuse the UE's network credentials for secure application-level communication, reducing signaling overhead and enhancing security.
Authentication credential Repository and Processing Function
The ARPF is a critical 5G security function that securely stores and processes authentication credentials like long-term keys. It performs cryptographic operations for authentication and key derivation, forming the foundation for secure subscriber access and network protection against unauthorized use.
Administrator Root Public Key
The ARPK is a cryptographic public key used in 3GPP's Generic Bootstrapping Architecture (GBA) to authenticate and authorize a Network Application Function (NAF) administrator. It enables secure, automated provisioning of application-specific keys for services, ensuring that only authorized entities can manage subscriber security contexts. This is critical for protecting service access and preventing unauthorized administrative actions.
Access Security Management Entity
The Access Security Management Entity (ASME) is a logical function in 3GPP networks responsible for managing security keys for user equipment (UE) during access authentication and key agreement procedures. It acts as a key intermediary, receiving authentication vectors from the home network and deriving the access-specific keys used to secure communications between the UE and the access network (e.g., eNB in LTE, gNB in 5G). Its role is critical for establishing a secure and trusted connection, ensuring key separation between different access technologies and network domains.
Authentication Centre
The Authentication Centre (AUC) is a core network security entity that generates authentication vectors (triplets/quintuplets) for subscriber verification. It securely stores subscriber authentication keys (Ki) and cryptographic algorithms to prevent unauthorized network access and protect user privacy. The AUC is essential for ensuring secure authentication and confidentiality in GSM, UMTS, and evolved 3GPP networks.
Authenticable Non-3GPP Devices
AUN3 refers to non-3GPP devices (like Wi-Fi access points or fixed network equipment) that can be authenticated by the 5G core network. It enables secure integration of diverse access technologies into the 5G system, allowing operators to extend services beyond traditional cellular networks while maintaining consistent security policies.
Authentication Server Function
The AUSF is a core network function in 5G that performs primary authentication and key agreement (AKA) for user equipment. It is central to the 3GPP security architecture, ensuring secure access to 5G services by verifying subscriber identities and establishing secure session keys. Its separation from other functions enhances security and supports network slicing.
Authentication Token
AUTN is a network-generated token used in 3GPP authentication and key agreement (AKA) protocols. It authenticates the network to the user equipment (UE), proving legitimacy and preventing attacks like man-in-the-middle. It is fundamental for establishing mutual authentication and securing the initial network attachment.
Re-synchronisation Token
AUTS is a security token used in 3GPP networks to re-synchronize the sequence number (SQN) between a User Equipment (UE) and the Authentication Centre (AuC) during the AKA protocol. It is generated by the UE when it detects a sequence number synchronization failure, allowing the network to securely recover and continue authentication. This mechanism is critical for preventing denial-of-service attacks and ensuring robust, uninterrupted service for subscribers.
Bootstrapping Transaction Identifier
B-TID is a unique identifier generated during the Generic Bootstrapping Architecture (GBA) authentication process. It serves as a session reference for subsequent application security, enabling secure service access without repeated full authentication. This identifier is crucial for efficient authentication and key management in 3GPP networks.
CTS Ciphering Key Generation Algorithm
A cryptographic algorithm used in GSM systems to generate ciphering keys for encrypting communication between mobile stations and the network. It ensures confidentiality of user data and signaling messages by deriving session-specific encryption keys from authentication parameters. This foundational security mechanism protects against eavesdropping on radio interfaces.
CTS Authentication Key Generation Algorithm
B2 is a cryptographic algorithm used in 3GPP systems to generate authentication keys for Cordless Telephony System (CTS) security. It provides the foundation for secure authentication between CTS mobile stations and the network, ensuring subscriber identity protection and preventing unauthorized access. This algorithm is essential for maintaining the integrity of CTS authentication procedures.
Bearer Binding Intercept and Forwarding Function
A Lawful Interception (LI) function that intercepts and forwards user plane traffic associated with a specific bearer. It is a critical component in 3GPP networks for enabling authorized surveillance by binding intercepted traffic to the correct target identity and session context.
Bootstrap Data Channel
A secure communication channel established between a device and a network during initial bootstrap procedures to exchange sensitive configuration data. It provides authenticated and encrypted transport for critical provisioning information before the device can access regular network services, ensuring secure onboarding in 5G and beyond networks.
BootstrappingInfo-Request message
A Diameter message used in the 3GPP Generic Authentication Architecture (GAA) to request bootstrapping information from the Bootstrapping Server Function (BSF). It initiates the authentication and key agreement process between a user equipment and network application functions, enabling secure service access without separate credentials.
Bootstrapping Server Function
The Bootstrapping Server Function (BSF) is a core network function within the Generic Authentication Architecture (GAA). It provides a secure method for applications and network functions to dynamically obtain authentication credentials and cryptographic keys, eliminating the need for pre-shared secrets. This is crucial for securing service access and protecting user data.
Basic Vulnerability Testing
BVT is a standardized security testing methodology defined by 3GPP to systematically identify and assess vulnerabilities in mobile network elements and interfaces. It provides a framework for security evaluation against a baseline of common attack vectors, ensuring a fundamental level of security robustness. This is crucial for maintaining network integrity and protecting against unauthorized access and service disruption.
Certification Authority
A trusted entity that issues and manages digital certificates in 3GPP networks, enabling secure authentication and communication. It establishes a Public Key Infrastructure (PKI) to verify the identity of network elements, users, and services, forming the foundation for trust in security protocols.
Cipher Block Chaining (Mode)
Cipher Block Chaining (CBC) is a symmetric encryption mode that chains plaintext blocks together using XOR operations with previous ciphertext blocks before encryption. This ensures identical plaintext blocks produce different ciphertext blocks, providing strong confidentiality for 3GPP user data and signaling. It's fundamental to UMTS, LTE, and 5G security architectures.
Cipher Block Chaining Message Authentication Code
CBC-MAC is a cryptographic message authentication code algorithm that provides data integrity and authentication in 3GPP systems. It operates using block cipher encryption in cipher block chaining mode to generate a fixed-size authentication tag. This ensures that transmitted data hasn't been tampered with and verifies the sender's authenticity.
Corporate Control Key
A security mechanism introduced in 3GPP Release 4 to authenticate and authorize corporate network access via public mobile networks. It enables secure corporate communications by providing a dedicated authentication key separate from the user's SIM credentials, ensuring corporate data remains isolated from personal subscriber data.
Certificate Configuration Message
A security message used to provision and manage digital certificates in 3GPP networks. It enables secure distribution of public key certificates and certificate status information between network entities and user equipment, forming a foundation for authentication and encryption services.
CTS Random Challenge Value of the CTS-FP
CH1 is a random challenge value used in the Cordless Telephony System - Fixed Part (CTS-FP) authentication protocol. It serves as a cryptographic nonce to prevent replay attacks during the authentication process between a mobile station and the fixed network. This security mechanism ensures that each authentication session is unique and resistant to interception.
CTS Random Challenge Value of the CTS-MS
CH2 is a random challenge value used in the Cordless Telephony System (CTS) for authentication between the mobile station (CTS-MS) and the network. It serves as a critical security parameter in the challenge-response authentication mechanism, ensuring that only authorized devices can access CTS services by verifying cryptographic responses.
Challenge Handshake Authentication Protocol
CHAP is a three-way authentication protocol used to verify the identity of network access points and user equipment during connection establishment. It provides secure authentication without transmitting passwords in clear text, using challenge-response mechanisms with cryptographic hashing. This protocol is essential for preventing unauthorized access and protecting network resources in 3GPP systems.
Card Holder Verification
Card Holder Verification (CHV) is a security mechanism in 3GPP specifications for authenticating the user of a UICC or SIM card. It protects access to the card's services and data by requiring a PIN, ensuring that only the authorized cardholder can use the mobile subscription. This is a fundamental security feature for preventing unauthorized use of mobile devices and services.
Center for Internet Security
CIS is a security framework referenced in 3GPP specifications for establishing security baselines and controls. It provides standardized security configurations and benchmarks that network operators can implement to protect their infrastructure. While not a 3GPP-developed technology, its inclusion in specifications like 33.117 demonstrates its importance as an industry-recognized security reference.
Confidentiality Key
The Confidentiality Key (CK) is a cryptographic key used in 3GPP networks to encrypt user data and signaling messages, ensuring privacy over the air interface. It is a core component of the authentication and key agreement (AKA) process, generated alongside an integrity key (IK). Its primary role is to prevent eavesdropping and protect the confidentiality of communications between the user equipment and the network.
Ciphering Key Sequence Number
CKSN is a security parameter that identifies which ciphering key is currently active between the UE and network. It enables secure key management by synchronizing encryption keys during authentication and handover procedures, preventing security breaches from key mismatches.
Cipher Key for Single Radio Voice Continuity
A security key used to protect voice calls during a Single Radio Voice Call Continuity (SRVCC) handover from LTE/5G to legacy 2G/3G networks. It ensures call confidentiality and integrity is maintained during the inter-system mobility procedure, preventing security downgrades.
Certificate Management Messages over CMS
CMC is a protocol for managing digital certificates using the Cryptographic Message Syntax (CMS). It defines standardized messages for certificate enrollment, renewal, and revocation within 3GPP networks, enabling secure authentication and key management. This is crucial for establishing trust in network services, securing device-to-network communications, and supporting Public Key Infrastructure (PKI) operations.
Certificate Management Protocols
CMP defines standardized protocols for managing digital certificates in 3GPP networks. It enables automated enrollment, renewal, and revocation of certificates for network entities and devices, ensuring secure authentication and communication. This is critical for establishing trust in network operations and protecting against unauthorized access.
Critical National Infrastructure
Critical National Infrastructure (CNI) refers to telecommunications systems designated as essential for national security, economic stability, and public safety. In 3GPP, CNI encompasses specialized network capabilities, security requirements, and priority access mechanisms to ensure continuity during emergencies or national crises. It represents a framework for protecting vital communication services that society depends upon.
Ciphering Sequence Number for Core Network
COUNT-C is a time-variant parameter used for synchronization between ciphering and deciphering operations in 3GPP networks. It ensures cryptographic synchronization between the UE and network elements, preventing desynchronization that could lead to communication failures or security vulnerabilities. This parameter is fundamental to maintaining secure and reliable encrypted communications.
Control Plane Prose Remote User Key
A security key used for ProSe (Proximity Services) direct communication between UEs, managed via the control plane. It enables secure device-to-device communication without routing all traffic through the network core, crucial for public safety and commercial proximity services.
Certificate Present (in the MExE (U)SIM) - Third Party
CP-TP is a security mechanism within the MExE (Mobile Execution Environment) framework, specifically concerning third-party certificates stored on the (U)SIM. It enables secure authentication and authorization for third-party applications and services, ensuring trusted interactions between mobile devices and external entities. This is crucial for enabling secure value-added services and protecting against unauthorized access.
Commercial Product Assurance
Commercial Product Assurance (CPA) is a 3GPP security framework ensuring that commercial network products meet specified security requirements. It provides standardized security evaluation criteria for network equipment, addressing vulnerabilities in commercial off-the-shelf components. This framework is crucial for maintaining network integrity and preventing security breaches in 5G and beyond.
Content Protection Information
CPI is a security mechanism in 3GPP networks that provides information for protecting multimedia content, particularly in Multimedia Messaging Service (MMS). It enables secure content delivery by specifying encryption methods, key management, and usage rights, ensuring that only authorized users can access protected media.
Certificate Revocation List
A Certificate Revocation List (CRL) is a security mechanism in 3GPP networks that provides a list of digital certificates that have been revoked before their scheduled expiration. It is used by network entities to verify the validity and trustworthiness of certificates presented during authentication and secure communication. This is critical for maintaining the integrity of the Public Key Infrastructure (PKI) and preventing the use of compromised credentials.
Crypto Session Bundle Identifier
A unique identifier used in 3GPP's Mission Critical Services (MCS) to manage cryptographic sessions for secure group communications. It enables the bundling of multiple crypto sessions under a single identifier, facilitating efficient key management and secure media distribution for mission-critical voice, video, and data services.
Client-Server Key
A cryptographic key used in 3GPP's Generic Bootstrapping Architecture (GBA) to secure communication between a client (UE) and a network application server (NAF). It enables secure service access without requiring separate authentication procedures for each service. CSK is derived from the long-term shared secret between the UE and the network, providing a strong, service-specific security foundation.
Client-Server Key Identifier
A cryptographic identifier used in 3GPP's Generic Bootstrapping Architecture (GBA) to uniquely reference a shared secret key established between a client (UE) and a network application function (NAF). It enables secure authentication and key derivation for application-layer services without requiring separate credentials.
Certificate Signing Request
A Certificate Signing Request (CSR) is a standardized message format used in 3GPP networks to request a digital certificate from a Certificate Authority (CA). It contains the public key and identity information of the requesting entity, enabling secure authentication and encrypted communications. CSR is fundamental for establishing trust in network functions, user equipment, and service endpoints.
CTS-Personal Identification Number
A security credential used in the Circuit Switched FallBack (CSFB) mechanism for user authentication and authorization when a device falls back to a 2G/3G circuit-switched network. It ensures secure access to legacy voice services from LTE devices.
Common Vulnerabilities and Exposures
CVE is a standardized identifier system for publicly known cybersecurity vulnerabilities and exposures. It provides a unique, common identifier for each vulnerability, enabling consistent referencing across security tools, databases, and communication among vendors, researchers, and users. This is critical for coordinated vulnerability disclosure, tracking, and management within 3GPP networks.
Common Vulnerability Scoring System
CVSS is a standardized framework for assessing and rating the severity of security vulnerabilities in 3GPP networks. It provides a consistent, objective methodology for evaluating vulnerabilities based on exploitability, impact, and environmental factors. This enables operators and vendors to prioritize remediation efforts and communicate risk effectively across the telecommunications ecosystem.
Common Weakness Enumeration
CWE is a standardized list of software and hardware security weaknesses maintained by MITRE and referenced by 3GPP. It provides a common language for identifying, describing, and categorizing security vulnerabilities in telecommunications systems, enabling systematic security analysis and threat mitigation across the 5G ecosystem.
DECT Authentication Module
A security module used in DECT (Digital Enhanced Cordless Telecommunications) systems for subscriber authentication and key management. It securely stores subscriber identity and authentication credentials, enabling secure access to cordless networks. It is analogous to a SIM in GSM but for DECT-based services.
Data Authentication Pattern
A security mechanism defined in 3GPP specifications for authenticating data integrity and origin in telecommunications networks. It provides cryptographic assurance that data has not been tampered with and originates from a legitimate source, forming a fundamental building block for secure data exchange across network interfaces.
Device Application Tag
The Device Application Tag (DATE) is a security identifier used in 3GPP UICC/USIM applications to uniquely tag and manage specific applications on a secure element. It is crucial for enabling secure application management, authentication, and lifecycle operations for services like Over-The-Air (OTA) provisioning. Its standardized format ensures interoperability and secure identification across different network operators and device manufacturers.
Depersonalisation Control Keys
DCK (Depersonalisation Control Keys) are cryptographic keys used in 3GPP networks to securely erase or reset personalization data on Universal Integrated Circuit Cards (UICCs). They enable authorized network operators to remotely depersonalize SIM cards, which is critical for device management, security remediation, and preventing unauthorized reuse of compromised credentials.
Triple DES Encrypt Plug-in
A security plug-in implementing Triple DES (3DES) encryption for protecting sensitive data in 3GPP networks. It provides a standardized cryptographic mechanism for confidentiality, ensuring secure transmission and storage of user and signaling information. Its integration supports compliance with security requirements across various network interfaces and functions.
Differential Electromagnetic Analysis
DEMA is a side-channel attack technique that analyzes electromagnetic emissions from cryptographic hardware to extract secret keys. It measures tiny variations in electromagnetic radiation during cryptographic operations to deduce sensitive information. This is crucial for assessing and hardening the physical security of 3GPP network equipment against sophisticated attacks.
Data Encryption Standard
A symmetric-key block cipher algorithm used in early 3GPP specifications for encrypting user data and signaling. It provided confidentiality for circuit-switched services and certain authentication mechanisms. Its use has been deprecated in favor of stronger algorithms like AES due to its 56-bit key length being vulnerable to brute-force attacks.
Decrypted PIN
Decrypted PIN data, referring to the Personal Identification Number in a decrypted form after secure processing. In 3GPP, it is associated with authentication and security mechanisms, particularly in the context of USIM applications and secure services, ensuring that PIN information is handled securely during verification processes.
Differential Power Analysis
A side-channel attack method that analyzes variations in a device's power consumption to extract secret cryptographic keys. It is a significant security threat to mobile and IoT devices, necessitating robust countermeasures in 3GPP specifications to protect sensitive data and network integrity.
MCData Payload Cipher Key
DPCK is a cryptographic key used in 3GPP Mission Critical Data (MCData) services to encrypt and decrypt the payload of data messages. It ensures the confidentiality of sensitive information exchanged between public safety and critical communications users, forming a core part of the MCData security framework.
MCData Payload Protection Key
A cryptographic key used in Mission Critical Data (MCData) services to encrypt and protect the payload of data communications. It ensures confidentiality and integrity for sensitive data exchanged between public safety and critical communication users, which is essential for secure operational communications.
MCData Payload Protection Key
A cryptographic key used in 3GPP Mission Critical Data (MCData) services to encrypt and integrity-protect application payloads. It ensures confidentiality and data integrity for sensitive mission-critical communications, such as those used by public safety agencies.
Digital Signature Algorithm
A public-key cryptographic algorithm standardized by NIST (FIPS 186) for generating and verifying digital signatures. In 3GPP, it is used within security specifications for integrity protection, authentication, and non-repudiation, such as in the Authentication and Key Management for Applications (AKMA) framework or for securing management interfaces.
DTLS Extension to Establish Keys for SRTP
A key management extension that uses the DTLS handshake to negotiate cryptographic keys for Secure Real-time Transport Protocol (SRTP) sessions. It provides end-to-end security for real-time media streams like voice and video in IMS and WebRTC, ensuring confidentiality and integrity.
Triple DES Unwrap Plug-in
A cryptographic plug-in used within 3GPP security architectures to unwrap (decrypt) keys that have been encrypted using the Triple DES (3DES) algorithm. It is a component of key management and distribution systems, ensuring secure key delivery between network entities. Its role is critical for maintaining the confidentiality of cryptographic keys during transport.
Discovery User Confidentiality Key
A cryptographic key used in Proximity Services (ProSe) to ensure the confidentiality of messages exchanged during device-to-device discovery. It protects user identity and discovery-related information from eavesdroppers, enabling private discovery in LTE and 5G networks. This key is essential for secure peer discovery in public safety and commercial ProSe applications.
Discovery User Integrity Key
A cryptographic key used in Proximity Services (ProSe) to ensure the integrity and origin authentication of messages exchanged during device-to-device discovery. It protects discovery signaling from tampering and forgery, guaranteeing that discovery information comes from a legitimate source. This key is vital for trustworthy peer discovery in LTE and 5G ProSe.
Discovery User Scrambling Key
A cryptographic key used to scramble and secure discovery messages in Proximity Services (ProSe). It ensures that only authorized devices can decode discovery information, protecting user privacy and preventing unauthorized tracking or spoofing in device-to-device communication.
End-to-End Encryption
E2EE is a security method where data is encrypted on the sender's device and only decrypted on the recipient's device, preventing intermediaries like network operators or service providers from accessing the plaintext. In 3GPP, it secures user communication services like messaging and calling. It ensures privacy even against infrastructure providers.
Extensible Authentication Protocol
The Extensible Authentication Protocol (EAP) is a flexible framework defined by the IETF for network access authentication, widely adopted by 3GPP. It supports multiple authentication methods (EAP methods) and is a cornerstone for secure access in 3G, 4G, and 5G networks, especially for non-3GPP access.
Electronic Code-book (mode)
ECB is a basic block cipher mode of operation where each block of plaintext is encrypted independently with the same key. It is a foundational, but insecure, mode due to patterns in the plaintext being preserved in the ciphertext. Its importance lies in being a simple reference point for understanding more secure modes.
Elliptic Curve Digital Signature Algorithm
ECDSA is a cryptographic algorithm for generating digital signatures using elliptic curve cryptography. It provides authentication, data integrity, and non-repudiation with shorter key lengths than traditional RSA, offering equivalent security with greater efficiency. It is widely adopted in 3GPP for securing network signaling, device authentication, and platform integrity.
Elliptic Curve Integrated Encryption Scheme
ECIES is a hybrid encryption scheme combining elliptic curve cryptography for key agreement with symmetric encryption for data confidentiality. It is used in 3GPP for securing protocols like the 5G NAS transport of UE policies, providing efficient and strong encryption with a small key size.
Enhanced Client or Proxy
A security entity defined within the Security Assertion Markup Language (SAML) framework, used for secure identity and access management in 3GPP networks. It acts as an intermediary for authentication and authorization requests, enhancing the security and privacy of service access for users and devices.
EPS Encryption Algorithm
A set of standardized cryptographic algorithms used to encrypt user data and signaling messages on the LTE Evolved Packet System (EPS) interfaces. It ensures confidentiality and integrity of communications between the UE and the network. EEA forms a core part of the LTE/EPC security architecture.
EPS Integrity Algorithm
A cryptographic algorithm used in the Evolved Packet System (EPS) to provide integrity protection and verification of signaling messages between the User Equipment and the network. It ensures that control-plane data has not been tampered with during transmission.
Equipment Identity Register
The Equipment Identity Register (EIR) is a security database in mobile networks that stores and validates International Mobile Equipment Identities (IMEIs). It checks if a device is blacklisted (stolen or faulty), gray-listed, or white-listed, preventing unauthorized or problematic devices from accessing the network.
Extended Master Session Key
A cryptographically strong key derived during the 5G Authentication and Key Agreement (AKA) procedure. It serves as a root key for generating further keys used to secure specific network services and application sessions, extending security beyond the core network access stratum. It is crucial for enabling secure service-based architecture and network slicing.
EPS Authentication Vector
A set of cryptographic parameters used to authenticate a UE and establish security keys in the Evolved Packet System (EPS). It is generated by the HSS/AuC and sent to the MME to perform mutual authentication and key derivation, forming the foundation for secure communication in 4G networks.
EPS User-Plane Integrity Protection
A security feature introduced in 5G-era 3GPP releases that provides integrity protection for user-plane data traffic in the Evolved Packet System (EPS). It safeguards data against tampering and injection attacks over the radio interface, extending security beyond confidentiality.
EAP Re-authentication
ER is a security protocol extension that enables efficient re-authentication of a user or device without requiring a full EAP authentication exchange. It reduces signaling overhead and latency, particularly beneficial for fast handovers and frequent reconnections in mobile networks. This enhances user experience and network efficiency.
EAP Re-authentication Protocol
A protocol that enables fast and efficient re-authentication of a user or device without requiring a full EAP authentication exchange. It reduces signaling overhead and latency during handovers or session resumptions, which is critical for seamless mobility and service continuity in 3GPP and non-3GPP access networks.
Enhanced Vulnerability Analysis
A systematic security assessment methodology within 3GPP to identify, analyze, and mitigate vulnerabilities in network functions and protocols. It is crucial for proactively strengthening the security posture of mobile networks against evolving threats.
False Base Station
A rogue or malicious base station that impersonates a legitimate network cell to intercept, manipulate, or deny service to user equipment (UE). It is a critical security threat in mobile networks, enabling man-in-the-middle attacks, location tracking, and denial-of-service. 3GPP specifications define detection and mitigation mechanisms to protect against such attacks.
Fraud Detection System
A network-based system that monitors subscriber usage patterns and signaling events to identify and mitigate fraudulent activities like subscription fraud, cloning, or premium rate service abuse. It employs rules, statistical analysis, and machine learning to detect anomalies in real-time and near-real-time, protecting operator revenue.
Fraud Information Gathering System
A standardized system for collecting, exchanging, and analyzing fraud-related information across mobile network operators and financial institutions. It enables the detection and prevention of subscription fraud, payment fraud, and other malicious activities in telecommunications and associated services.
Federal Information Processing Standard
A set of U.S. government security standards for cryptographic modules, referenced in 3GPP for ensuring robust security in telecommunications systems. It defines requirements for encryption, authentication, and random number generation to protect sensitive data and communications.
Forum for Incident Response and Security Teams
A global forum for incident response and security teams (CSIRTs) to coordinate and share information on cybersecurity threats and vulnerabilities. It provides a trusted platform for collaboration, enabling faster response to security incidents across telecommunications networks and services.
Free and Open Source Software
FOSS refers to software whose source code is publicly accessible and can be freely used, modified, and distributed. In 3GPP, its use is governed by security policies to ensure network integrity and prevent vulnerabilities from being exploited in telecommunications infrastructure.
Fixed Part Authorisation Code
A security code derived from the CTS-PIN, used to authorize fixed network parts in cellular systems. It ensures secure access and authentication for fixed infrastructure components, preventing unauthorized network access.
General Authentication Architecture
A 3GPP security framework for authenticating users and devices to access network services and applications beyond the core cellular network. It provides a standardized method for service providers to leverage the robust authentication mechanisms of mobile networks (like SIM-based auth) for third-party applications, enabling secure single sign-on and identity federation.
Generic Bootstrapping Architecture
A security framework that allows a user device (UE) and a network application server to establish shared authentication keys. It leverages the existing 3GPP authentication infrastructure (AKA) to 'bootstrap' security for applications over HTTP, eliminating the need for separate credentials. This enables secure service access like streaming or messaging.
GPRS Encryption Algorithm
A family of stream cipher algorithms used to encrypt user data and signaling over the GPRS and EDGE radio interface. It ensures confidentiality of communications between the mobile station and the network, protecting against eavesdropping. Its implementation is a core security function in 2G/3G packet-switched domains.
GPRS-IMS-Bundled Authentication
GIBA is a 3GPP security mechanism that reuses the authentication performed for GPRS/UMTS packet access to subsequently authenticate the user to the IMS (IP Multimedia Subsystem). This eliminates the need for a separate IMS authentication procedure, streamlining network access and reducing signaling overhead for IMS services.
Group Key Transport Payload
A security payload defined in 3GPP for the secure transport of group keys, such as MBMS Service Keys or Group Communication System Enablers keys, over the network. It ensures that keys are delivered to authorized entities with integrity and confidentiality protection, which is critical for secure group communication and broadcast services.
Group Management Key
A cryptographic key used to secure group communications and management procedures in 3GPP networks. It enables authentication, integrity protection, and confidentiality for group members, forming the basis for secure group services like MCPTT and ProSe.
Group Master Key Identifier
An identifier used in 3GPP networks to uniquely reference a Group Master Key (GMK) within group communication security contexts. It enables secure group management for services like ProSe, V2X, and MBMS by allowing entities to retrieve the correct cryptographic key for encrypting/decrypting group traffic, ensuring confidentiality and integrity.
Generic Network Product Class
Generic Network Product Class (GNP) is a security and assurance concept defining a category of network products that implement a common set of 3GPP-defined functionalities. It enables standardized security evaluation and certification, ensuring products from different vendors meet consistent security requirements for a given network function.
GBA Push Information
GBA Push Information (GPI) is a security mechanism that enables a network application server to securely 'push' bootstrap information to a UE. It is part of the Generic Bootstrapping Architecture (GBA), allowing servers to initiate secure communication setup without prior shared secrets.
Generic Security Functionality
Generic Security Functionality (GSF) is a 3GPP security framework that provides a standardized, modular set of cryptographic functions and security protocols for protecting user plane data. It enables secure, efficient, and algorithm-agile encryption and integrity protection for services like Lawful Interception (LI) and media streaming, independent of the underlying transport.
GAA Service Identifier
The GAA Service Identifier (GSID) is a unique identifier used within the Generic Authentication Architecture (GAA) framework. It identifies a specific service or application that utilizes GAA for bootstrapping authentication and key agreement, enabling secure service access without separate user credentials.
Group Session Key
A cryptographic key used to secure group communications in 3GPP networks. It enables efficient and secure distribution of content or data to multiple devices simultaneously, such as in MBMS or MCPTT services. This is crucial for protecting broadcast and multicast traffic from eavesdropping and tampering.
Group User Key Identifier
A unique identifier for a Group User Key (GUK) used in 3GPP proximity-based services (ProSe). It enables secure group communication and discovery between devices by identifying the specific cryptographic key shared among a defined group of users, essential for public safety and commercial D2D applications.
GBA User Security Settings
GBA User Security Settings (GUSS) is a security profile used within the Generic Bootstrapping Architecture (GBA). It contains user-specific authentication credentials and security parameters, enabling secure authentication between a User Equipment (UE) and network application servers without requiring separate credentials for each service.
Hardware Mediated Execution Environment
A security architecture that uses hardware-based isolation to protect critical software execution from tampering. It ensures the integrity and confidentiality of sensitive operations, such as cryptographic functions and secure boot, by leveraging hardware-enforced boundaries. This is crucial for meeting stringent security requirements in 5G and beyond networks.
Home Operator
The Home Operator (HO) is the subscriber's primary mobile network provider, responsible for authentication, billing, and service provisioning. It is a fundamental concept in roaming and security architectures, enabling users to access services outside their home network through visited operators.
Hosting Party
The Hosting Party (HP) is a logical entity defined in 3GPP for secure service hosting and delegation scenarios, particularly for Proximity Services (ProSe). It acts as a trusted intermediary that can host applications or functions on behalf of a service provider, managing authentication and authorization within the 3GPP security framework.
HP Module
The HP Module is a standardized security component defined in 3GPP for hosting and executing sensitive applications and services. It provides a secure, isolated environment to protect critical functions and data from the underlying platform. This is essential for ensuring trust and integrity in network operations and service delivery.
Hash RESponse
A cryptographic value generated by the Universal Subscriber Identity Module (USIM) during 5G Authentication and Key Agreement (AKA). The HRES is the USIM's response to a network challenge, derived from a secret key and a random number, used by the network to verify the subscriber's authenticity.
Hash eXpected RESponse
A cryptographic hash value used in 5G authentication and key agreement (AKA) procedures. It is generated by the network and sent to the UE to verify the authenticity of the network and establish a secure connection. It is a core component of 5G's enhanced subscriber privacy and security.
Interception Access Point
A functional entity within a 3GPP network that provides lawfully authorized interception (LI) capabilities. It is the point where intercepted communication content (CC) and interception-related information (IRI) are duplicated and delivered to a Law Enforcement Monitoring Facility (LEMF). It is a critical component for regulatory compliance.
Initial Connectivity Function
A security function defined for Machine-Type Communication (MTC) and IoT devices. It acts as a trusted intermediary during a device's initial network attachment, facilitating secure bootstrap and credential provisioning, especially for devices with limited capabilities or pre-shared key material.
Interception Configuration Information
Interception Configuration Information (ICI) is a standardized set of data used to configure Lawful Interception (LI) functions within a 3GPP network. It defines the target (subscriber or service), the types of communication content and intercept-related information to be collected, and the delivery parameters to the Law Enforcement Monitoring Facility. ICI ensures a uniform and legally compliant interception process.
Identity Federation Framework
A framework, as profiled by the Liberty Alliance Project (LAP), that enables secure identity federation across different administrative domains and service providers. It allows users to use a single set of credentials to access multiple services.
Identity Event Function
A network function introduced in 5G for secure, privacy-preserving identity verification services. It acts as a trusted intermediary between a Relying Party (e.g., an online service) and an Identity Provider, enabling user attribute verification without exposing the user's full identity. It is central to 3GPP's identity management framework.
Internal Interception Function
A standardized network function responsible for the lawful interception of communications within a 3GPP network. It interfaces with law enforcement agencies, providing intercepted content and intercept-related information in a secure, regulated manner as mandated by national laws.
Integrity Key
The Integrity Key (IK) is a cryptographic key used in 3GPP systems to verify the integrity and authenticity of signaling messages and user data. It is generated during authentication and key agreement procedures and is essential for preventing message tampering, replay attacks, and ensuring data origin authentication.
Internet Key Exchange
Internet Key Exchange (IKE) is a protocol used to establish a secure, authenticated communication channel and to negotiate Security Associations (SAs) for IPsec. In 3GPP, it is used for securing interfaces between network functions, such as in Network Domain Security (NDS/IP) and for securing user plane data in certain scenarios.
Inferential Power Analysis
A security testing methodology used to evaluate the resilience of cryptographic implementations, particularly in 3GPP User Equipment (UE), against side-channel attacks that exploit power consumption variations. It is crucial for ensuring the robustness of authentication and encryption algorithms against physical tampering.
Internet Protocol Packet Reporting
IPPR is a Lawful Interception (LI) mechanism that enables the reporting of specific IP packet flows to authorized Law Enforcement Agencies (LEAs). It provides detailed, real-time metadata and content from targeted communications for security and investigative purposes, as mandated by legal frameworks.
Internet Protocol Security
Internet Protocol Security (IPSec) is a suite of protocols for securing IP communications by authenticating and encrypting each IP packet in a data stream. In 3GPP, it is used to protect control plane signaling and user plane data between network functions, especially over untrusted transport networks. It provides confidentiality, integrity, and authentication for network layer traffic.
Inter-PLMN User Plane Security
IPUPS is a security framework that provides confidentiality and integrity protection for user plane data traversing the N9 interface between two separate Public Land Mobile Networks (PLMNs). It secures inter-operator traffic in scenarios like roaming and interconnection, preventing eavesdropping and tampering.
Identity Query Function
The Identity Query Function (IQF) is a 5G network function that provides a privacy-preserving identity verification service. It allows a consuming network function (NF) to query whether a subscriber's concealed identifier (SUCI) corresponds to a valid subscription without learning the permanent subscriber identity (SUPI).
Intercept Related Information
IRI is the metadata and call-associated information collected during lawful interception of telecommunications. It includes details like identities, location, and timestamps, separate from the actual communication content (CC). It is essential for legal compliance and security investigations.
Internet Security Association Key Management Protocol
ISAKMP is a framework for establishing Security Associations (SAs) and cryptographic keys in IPsec-based secure tunnels. In 3GPP, it's used within the NDS/IP (Network Domain Security for IP) specification to secure communication between network entities, such as between eNBs and the core network over S1 and X2 interfaces.
IMS Subscriber Identity Module
The ISIM is a dedicated application on a UICC (smart card) that securely stores the subscriber's identity and authentication credentials for the IP Multimedia Subsystem (IMS). It enables secure access to IMS services like VoLTE and video calling by providing a unique private identity (IMPI) and facilitating authentication with the network.
ISO Transport Service on top of TCP
A standardized method for securely transporting ISO-based application protocol data units (APDUs), such as those used in PKI and certificate management, over a TCP/IP network. It provides a reliable, connection-oriented transport layer for security-related communications between network entities.
Java Cardâ„¢ Run Time Environment
The Java Card Run Time Environment (JCRE) is a secure, standardized software platform that enables Java-based applications (applets) to run on smart cards and embedded secure elements, such as UICCs used in mobile devices. It provides a protected execution environment with defined APIs for security services, memory management, and applet lifecycle control, crucial for hosting SIM/USIM applications.
JavaScript Object Signing and Encryption
A framework for securing JSON data through digital signatures, encryption, and message authentication codes (MACs). In 3GPP, it is used in service-based interfaces, such as the 5G core network, to protect API communications between network functions with standardized cryptographic operations.
JSON Web Encryption
JSON Web Encryption (JWE) is a standard for encrypting and securing data payloads using JSON-based structures. It provides confidentiality for sensitive information exchanged in 3GPP network APIs, such as user credentials or service parameters, ensuring data privacy and integrity during transmission between network functions.
JSON Web Signature
JSON Web Signature (JWS) is a standard for digitally signing JSON data to ensure integrity and authenticity. In 3GPP networks, it is used to sign messages and tokens, verifying that content has not been altered and originates from a trusted source, which is crucial for secure API communications and authentication processes.
JSON Web Token
JSON Web Token (JWT) is a compact, URL-safe token format for securely transmitting claims between parties. In 3GPP, it is used for authentication, authorization, and information exchange, enabling stateless sessions and trusted data sharing across network functions and external applications in 5G systems.
AKMA Application Key
A cryptographic key derived within the AKMA framework to secure application-level communication between a UE and an Application Function. It enables secure service access without requiring new authentication procedures for each application session, enhancing efficiency and security for 3GPP network-integrated services.
AKMA Anchor Key
The root, long-term symmetric key in the AKMA framework, generated from 5G core network authentication. It serves as the master secret from which application-specific keys (KAF) are derived, anchoring application security to the subscriber's primary network credential.
Ciphering Key
KC is a 64-bit cryptographic key used specifically with the A5 stream cipher algorithm to encrypt and decrypt user data and signaling over the radio interface in GSM and early 3GPP systems. It is derived from the subscriber's authentication process and is fundamental for ensuring confidentiality of communications.
Key Derivation Function
A cryptographic function that generates one or more secret keys from a master key and other input parameters. It is fundamental to 3GPP security architecture, enabling secure derivation of keys for encryption, integrity protection, and authentication across different network domains and services.
Key Encryption Key (TETRA)
A Key Encryption Key used in the TETRA (Terrestrial Trunked Radio) security context within 3GPP standards. It is a cryptographic key specifically employed to protect other keys during transport or storage, ensuring secure key distribution within critical communication systems.
Key For Control Signalling
A cryptographic key specifically derived to protect control plane signalling messages. It is used to ensure the confidentiality and integrity of critical network control commands and information, separating control plane security from user data plane security.
Key for Floor Control Identifier
A cryptographic key used to secure floor control messages in Mission Critical Push-to-Talk (MCPTT) services. It ensures that only authorized users can request or be granted the 'floor' (permission to speak) in group communications, preventing unauthorized talker access and eavesdropping.
Key Identifier for protecting KIc and KID
A key identifier used in early 3GPP specifications to reference the ciphering key (KIc) and integrity key (KID) in security procedures. It acts as an index or label for the active key set, enabling the network and UE to select the correct keys for protecting signaling and user data communications.
Key Management Service
A functional entity or service within 3GPP architectures responsible for the generation, distribution, storage, and lifecycle management of cryptographic keys. It is central to securing communications, especially in IMS-based services, Mission Critical Services, and network slicing, by providing a trusted source for keying material.
KMS Public Authentication Key
A public key used within the Key Management Service (KMS) framework for authentication. It enables secure, certificate-free device authentication and key establishment, crucial for IoT and MTC security. It underpins the 3GPP's lightweight security architecture for constrained devices.
Key Set Identifier
The Key Set Identifier (KSI) is a security parameter used in 3GPP systems to uniquely identify a specific set of cryptographic keys shared between a user device (UE) and the network. It is crucial for key hierarchy management, enabling the network and UE to select the correct keys for ciphering and integrity protection of signaling and user data.
Key Stream Segment
A Key Stream Segment (KSS) is a portion of the keystream generated by a stream cipher algorithm (like SNOW 3G or ZUC) used in 3GPP systems. It is produced by the cipher algorithm from a secret key and an initialization vector (IV) and is then combined (typically XORed) with plaintext data to produce ciphertext, providing confidentiality.
Lawful Access Location Services
A set of 3GPP standardized capabilities enabling law enforcement agencies to request and receive location information of a target subscriber's User Equipment (UE) for lawful interception purposes. It defines the interfaces, procedures, and security requirements to ensure authorized, reliable, and auditable access to location data.
Liberty Alliance Project
A now-sunset industry consortium that developed open standards for federated digital identity, single sign-on (SSO), and identity-based web services. Its specifications, notably the Identity Federation Framework (ID-FF), influenced early 3GPP work on authentication and service access, particularly for IP Multimedia Subsystem (IMS) and non-3GPP access.
Location Dependent Interception
A lawful interception (LI) capability that allows authorities to intercept communications based on the user's specific geographical location. It enables targeted surveillance when a user enters a predefined area, ensuring interception is only active under those conditions. This is crucial for legal compliance and efficient use of law enforcement resources.
Law Enforcement Agency
LEA refers to the authorized government or law enforcement body that requests and receives lawful interception data from telecommunications operators. In 3GPP, it defines the external entity for which standardized interfaces and procedures are implemented to support legal surveillance requirements on mobile networks.
Liberty-Enabled Client or Proxy
A LECP is a functional entity defined within the Liberty Alliance Project (LAP) framework for federated identity management. In 3GPP, it is referenced in the context of interworking between 3GPP networks and external IP-based service networks that use LAP protocols for authentication and single sign-on.
Law Enforcement Monitoring Facility
A standardized, secure facility operated by law enforcement agencies to lawfully intercept communications and related data from 3GPP networks. It is the authorized endpoint for receiving intercepted information, ensuring legal compliance and data integrity for investigations.
Lawful Interception
A standardized security and regulatory framework that enables authorized law enforcement agencies to intercept communications and related data within telecommunications networks. It is a critical compliance requirement for network operators, ensuring privacy laws are respected while supporting legal surveillance activities.
Lawful Interception Control Function
A core 5G network function responsible for the management, authorization, and activation of Lawful Interception (LI) orders. It acts as the central administrative control point, receiving interception warrants from Law Enforcement Agencies (LEAs) and orchestrating the interception across relevant Network Functions (NFs). It is essential for meeting legal and regulatory surveillance requirements.
Lawful Interception Identifier
A unique identifier assigned to a target (e.g., subscriber, IP address) for lawful interception purposes. It enables law enforcement agencies to uniquely and unambiguously request interception of specific communications from a network operator, ensuring precise targeting and auditability.
Lawful Interception Provisioning Function
The LIPF is a 5G core network function responsible for provisioning lawful interception (LI) configuration data to other Network Functions (NFs). It centralizes the management of LI-related parameters, such as target identities and event triggers, ensuring consistent enforcement across the network. It is a key component in standardizing and automating LI activation in 5G's service-based architecture.
Lawful Interception State Storage Function
A standardized function for storing and managing the state information required for lawful interception (LI) operations in 3GPP networks. It ensures that interception-related data, such as target identities and active intercept requests, is persistently stored and available across network functions, supporting regulatory compliance and lawful access.
LI Mirror IMS State Function
A Lawful Interception (LI) function introduced in 3GPP Release 14 for IMS networks. It mirrors the registration and session state information of a target user from IMS core functions (like CSCFs) to the Lawful Interception system, enabling authorized monitoring of IMS-based communication services.
LCS Privacy Indicator
A privacy control mechanism in 3GPP Location Services (LCS) that indicates whether a user's location information can be disclosed. It is a parameter set in the UE or network that governs authorization for location requests, helping to prevent unauthorized tracking. This is essential for complying with privacy regulations and protecting subscriber data.
Location Subscriber Authorization Function
A core network function responsible for authorizing location service requests for a target mobile subscriber. It verifies the legal and privacy rights of a requesting entity (e.g., an application or another network node) to obtain the subscriber's location information.
Location Triggering Function
The Location Triggering Function (LTF) is a network function that initiates location-based procedures for lawful interception and emergency services. It is defined within the 5G security architecture to provide standardized mechanisms for triggering location requests based on specific events or conditions.
Liberty-Enabled User Agent or Device
A user agent or device defined by the Liberty Alliance Project (LAP) that supports federated identity and single sign-on (SSO) capabilities. It enables secure access to services across different domains using identity federation protocols, enhancing user convenience and security in multi-provider environments.
Message Authentication Code
A cryptographic checksum used within the 3GPP authentication and key agreement (AKA) protocol to verify data integrity and authenticate the network to the user equipment. It is a core component of the authentication token (AUTN).
Message Authentication Code for Authentication
A cryptographic Message Authentication Code (MAC) used within the 3GPP Authentication and Key Agreement (AKA) protocol. It verifies the authenticity of authentication challenge messages exchanged between the network and the User Equipment (UE), ensuring they originate from legitimate parties and preventing impersonation attacks.
Message Authentication Code for Integrity
A Message Authentication Code (MAC) used to provide integrity protection and data origin authentication for signaling messages and, in some cases, user data in 3GPP networks. It ensures that control plane messages between the UE and the network have not been altered in transit and originate from an authorized entity.
Message Authentication Code for Mobile Application Part
A Message Authentication Code (MAC) used within the context of the Mobile Application Part (MAP) protocol, specifically for securing TCAP (Transaction Capabilities Application Part) user components. It provides authentication and integrity for certain legacy core network signaling transactions, particularly in pre-LTE networks like GSM and UMTS.
Resynchronisation Authentication Code
A cryptographic code used in UMTS and LTE to securely re-synchronise authentication vectors between the UE and network after a failure. It prevents replay attacks and ensures the integrity of the re-synchronisation procedure, maintaining service continuity.
Message Authentication Code T
MACT is a specific Message Authentication Code (MAC) value, denoted as T, generated during the AES-CMAC algorithm. It is a core component in 3GPP security protocols for providing data integrity and origin authentication. MACT is used in key derivation functions and security procedures within the Evolved Packet System (EPS) and 5G System.
Multicast/Broadcast Service Security Function
A network function in the 5G Core that provides security services specifically for multicast and broadcast traffic. It handles key management, authentication, and encryption for MBS sessions, ensuring secure content delivery to authorized UEs.
Malicious Communication Identity
A security service defined by 3GPP to identify and handle malicious communication attempts, such as fraud or harassment. It enables network operators to detect, report, and mitigate threats by verifying the identity of suspicious calls or messages. This is crucial for protecting subscribers and ensuring network integrity.
Message Digest
In 3GPP contexts, MD typically refers to a Message Digest, specifically a SHA-1 hash value used for integrity protection and authentication in various security procedures. It is a cryptographic hash function output that ensures data has not been altered, playing a critical role in securing signaling messages and user data.
Mediation and Delivery Function 2
A security function for lawful interception and data retention. It mediates and delivers intercepted communication content and associated data from network functions to law enforcement agencies, ensuring compliance with legal requirements.
Mediation and Delivery Function 3
A security function for lawful interception and data retention. It mediates and delivers event-based data and records for retained data to law enforcement or other authorized entities, supporting post-event forensic analysis.
MBMS key Generation and Validation Function
A security function within the MBMS (Multimedia Broadcast Multicast Service) architecture responsible for generating and distributing cryptographic keys used to protect broadcast and multicast content. It ensures that only authorized subscribers can access the service, providing confidentiality and integrity for point-to-multipoint delivery.
MBMS key Generation and Validation Storage
A secure storage function that works with the MGV-F to safeguard long-term MBMS cryptographic keys, such as the MBMS User Key (MUK) and MBMS Service Key (MSK). It ensures the persistent and protected retention of key material essential for subscriber authentication and service key derivation.
Misleading Information
Misleading Information (MI) refers to false or deceptive data injected into or generated within a wireless network with the intent to disrupt operations, degrade performance, or cause incorrect decisions. It is a key security threat model in 3GPP, particularly for positioning and location services, where it can spoof a UE's location.
Multimedia Internet KEYing
A key management protocol for securing real-time multimedia sessions, such as VoIP and video calls, in IMS and other 3GPP services. It establishes cryptographic keys and security associations between endpoints before media flows commence, ensuring confidentiality and integrity.
Multicast Key for Floor Control
A cryptographic key used in Multimedia Broadcast/Multicast Service (MBMS) to secure floor control signaling for group communication. It ensures that only authorized users can request or be granted the 'floor' (permission to speak) in mission-critical services like MCPTT.
Master Key Identifier
An identifier for a Master Key used in 3GPP security protocols, enabling the network and UE to select the correct cryptographic key from a set of stored keys for securing communication sessions. It is crucial for key management and session establishment.
MBMS Request Key
A cryptographic key used in Multimedia Broadcast Multicast Service (MBMS) security. It is generated by the BM-SC and provided to authorized users to request MBMS service keys, ensuring only authorized subscribers can access broadcast/multicast content. This is fundamental for secure content delivery and service authorization in MBMS.
Manufacturer Root Public Key
The Manufacturer Root Public Key (MRPK) is a foundational cryptographic key used in the 3GPP Generic Bootstrapping Architecture (GBA). It belongs to the device manufacturer and is used to authenticate the device's built-in private key, enabling secure bootstrapping of application-specific security keys between the device and network servers.
MBMS Sub-Channel Control Key
A security key used in Multimedia Broadcast Multicast Service (MBMS) to protect sub-channel control information. It ensures the integrity and confidentiality of scheduling and configuration data for broadcast/multicast services, preventing unauthorized access and service disruption.
Minimum Security Level
The MSL is a network-enforced security policy parameter associated with a subscriber. It defines the minimum required security algorithms (e.g., for ciphering) that must be used for that subscriber's communications, preventing fallback to weaker, compromised algorithms.
Minimum Security Level Data
A security mechanism defined in 3GPP to ensure a baseline level of protection for data transmission. It is used to enforce mandatory security algorithms and key lengths, preventing the use of weaker, compromised security settings. This is crucial for maintaining network integrity and user data confidentiality.
MBMS Traffic Key
The MBMS Traffic Key (MTK) is a cryptographic key used to encrypt broadcast and multicast traffic in Multimedia Broadcast Multicast Service (MBMS) systems. It ensures confidentiality and integrity of content delivered to multiple users simultaneously, protecting against unauthorized access and eavesdropping on broadcast transmissions.
Multicast User Key
A security key used in Multimedia Broadcast Multicast Service (MBMS) to encrypt traffic for a specific multicast/broadcast service. It ensures that only authorized subscribers who have purchased a service can decrypt and consume the content, protecting broadcast media revenue.
Multi-application Operating System
MULTOS is a multi-application smart card operating system standardized by 3GPP for secure element environments. It enables multiple applications to run securely on a single chip, supporting features like tamper resistance, application isolation, and dynamic management, crucial for SIM cards and IoT security.
Network Access Application
A secure application residing on the Universal Integrated Circuit Card (UICC) or SIM card that manages the authentication and key agreement procedures between a User Equipment (UE) and the mobile network. It is the software entity that executes the 3GPP authentication algorithms.
Network Application Function
The Network Application Function (NAF) is a core component of the Generic Authentication Architecture (GAA). It acts as a service provider application server that utilizes GAA-based authentication and key agreement mechanisms to securely authenticate users and establish secure communication channels. Its importance lies in enabling secure service access for applications like Multimedia Broadcast/Multicast Service (MBMS), User Plane Integrity Protection, and other network services without requiring separate, proprietary security infrastructures.
Non-Access Stratum Data via MME
NASDVM is a security mechanism that allows the MME to securely transfer small amounts of data between a UE and an application server using NAS signaling. It leverages the existing NAS security context to provide integrity and confidentiality for this data transfer without establishing a full user plane bearer.
Non-Authenticable Non-3GPP
NAUN3 refers to a category of Non-3GPP access networks (like untrusted Wi-Fi) that cannot perform authentication of the user or device towards the 5G core network. It represents an access type where the 3GPP system cannot verify the access network's security, requiring specific security and connection procedures.
Network Control Key
A cryptographic key used in GSM and UMTS networks to authenticate the network to the mobile device and secure signaling. It is part of the authentication quintet, derived alongside the ciphering key, ensuring network legitimacy and protecting against false base station attacks.
Network Device Protection Profile
A security framework defining standardized protection profiles for network devices within 3GPP systems. It ensures devices meet baseline security requirements, facilitating secure deployment and interoperability. This is crucial for hardening network infrastructure against evolving threats.
Network Domain Security
A comprehensive 3GPP security framework for protecting signaling and user data exchanges within and between network domains. It establishes security associations, encryption, and integrity protection for network interfaces (e.g., N2, N3, N4, N6). This is fundamental for securing core network communications.
Network Domain Security for IP based Protocols
A specific profile of the NDS framework tailored for securing communications within a single, trusted IP-based network domain, such as an operator's own core network. It typically employs IPsec in transport mode or TLS between network functions.
NR Encryption Algorithm
The standardized encryption algorithm used to protect user plane and control plane data confidentiality in 5G networks. It is a core component of the 5G security framework, ensuring that user data and signaling messages are encrypted over the air interface to prevent eavesdropping.
Network Equipment Security Assurance Group
A 3GPP working group responsible for developing and maintaining the Network Equipment Security Assurance Scheme (NESAS). It defines security requirements and assessment methodologies for vendor equipment, ensuring a standardized, industry-wide framework for evaluating and assuring the security of network products.
Network Equipment Security Assurance Scheme
A joint 3GPP and GSMA security assurance framework for mobile network equipment. It standardizes security requirements and independent evaluation processes for vendors, providing operators with a verified benchmark to assess and compare the security of network products in their supply chain.
Next Hop key
A security key used in 3GPP networks for forward security during handovers. It is derived from the current K_ASME or anchor key and is used to generate subsequent access stratum (AS) keys for the target base station, preventing compromise of future sessions if a current key is exposed. This is a fundamental mechanism for key hierarchy and handover security in LTE and 5G.
New radio Integrity Algorithm
NIA is a suite of cryptographic algorithms providing integrity protection for 5G signaling and user data. It ensures data is not tampered with during transmission between the UE and the network. Its standardized set allows for algorithm agility and robust security against evolving threats.
Network Product Class
A standardized classification framework for network security products, defined in 3GPP TS 33.916. It categorizes products based on security capabilities and assurance levels, enabling consistent evaluation and procurement across the industry. This ensures interoperability and a baseline security posture for network components.
Network Product Class Description
A detailed document that specifies the security requirements and evaluation criteria for a specific Network Product Class (NPC). Defined in 3GPP TS 33.916, it provides the exact technical and procedural benchmarks a product must meet to achieve a given NPC classification. It is the definitive reference for vendors and evaluators.
NR PC5 Encryption Key
A cryptographic key used to encrypt user data and control signaling over the NR PC5 sidelink interface in 5G V2X and ProSe. It ensures confidentiality for direct device-to-device communications, protecting against eavesdropping in critical applications like autonomous driving and public safety.
NR PC5 Integrity Key
A cryptographic key used to provide integrity and replay protection for signaling and data over the 5G NR PC5 sidelink. It ensures messages between devices are not altered or forged, which is vital for the safety and reliability of V2X and direct communication services.
New Security Context Indicator
A flag used in NGAP (Next Generation Application Protocol) signaling to indicate that a new security context has been established for a UE. It triggers the RAN node to apply fresh cryptographic keys, enhancing protection against replay attacks during handovers and connection resumptions.
Network Subset Control Key
A cryptographic key used in GSM-based authentication algorithms (COMP128 variants). It is derived from the subscriber's master key (Ki) and a network-specific subset identifier, allowing for differentiated authentication and encryption across different network subsets or roaming partners.
Network Time Protocol – Coordinated Universal Time
A security mechanism defined in 3GPP to securely distribute Coordinated Universal Time (UTC) using the Network Time Protocol (NTP). It provides authenticated and integrity-protected time synchronization essential for lawful interception, security logging, and network operation.
Online Certificate Status Protocol
An Internet protocol used for obtaining the revocation status of X.509 digital certificates in real-time. In 3GPP networks, it is adopted for secure credential management, enabling network functions and user equipment to verify if a certificate is still valid and not revoked before trusting it.
Output Feedback Mode
A mode of operation for a block cipher, standardized by 3GPP for cryptographic algorithms. In OFB mode, the cipher is used to generate a keystream, which is then XORed with the plaintext to produce ciphertext. It turns a block cipher into a synchronous stream cipher, useful for encrypting data where bit errors should not propagate.
OpenID Connect
OpenID Connect (OIDC) is an identity layer built on OAuth 2.0, enabling secure user authentication and authorization in 3GPP networks. It allows applications to verify user identity and obtain basic profile information in an interoperable and RESTful manner, crucial for third-party service access.
Operator Root Public Key
A cryptographic public key that serves as the trust anchor for an operator's Public Key Infrastructure (PKI). It is used to verify the authenticity of operator-signed data, such as network configuration policies or software updates, ensuring secure and trusted network operations.
Object Security for Constrained RESTful Environments
Object Security for Constrained RESTful Environments (OSCORE) is a security protocol that provides end-to-end protection for CoAP messages at the application layer. It encrypts and authenticates individual request/response payloads and options, securing IoT communications between devices and servers, even through untrusted intermediaries.
Operating System Protection Profile
OSPP is a security specification in 3GPP that defines protection profiles for operating systems used in network equipment, ensuring they meet rigorous security requirements. It addresses vulnerabilities in software platforms to safeguard against attacks, enhancing the overall security posture of mobile networks.
Over-The-Air-Key Management (TETRA)
A security mechanism for managing cryptographic keys over the air in TETRA networks. It enables secure distribution and updating of encryption keys to mobile devices, ensuring confidentiality and integrity of critical communications for public safety and professional users.
Over-The-Air Rekeying (P25)
A security procedure for remotely updating encryption keys in Project 25 (P25) digital two-way radio systems. It allows system administrators to change cryptographic keys across a fleet of radios without physical contact, essential for maintaining secure communications in public safety and government networks.
One Time Password
A security mechanism where a password is valid for only one login session or transaction, providing strong authentication and protection against replay attacks. In 3GPP, it's used for securing services like Multimedia Messaging Service (MMS) and user authentication.
Password Authentication Protocol
PAP is a simple authentication protocol that transmits unencrypted usernames and passwords over a network link. In 3GPP contexts, it is often referenced as a legacy or comparative mechanism within specifications for dial-up, GPRS, and early packet data authentication, though stronger protocols like CHAP are preferred.
Provider Authentication Policy Extension
PAPE is an extension to the OpenID authentication protocol that allows a Relying Party to request specific authentication policies from an OpenID Provider. In 3GPP, it is profiled in TS 33.924 to enhance security for web-based services by enabling policy-driven authentication strength requirements.
Pseudonym Certificate Authority
A trusted entity in 3GPP's V2X (Vehicle-to-Everything) security architecture that issues pseudonym certificates to vehicles. These certificates protect vehicle identity and location privacy while enabling secure authentication for V2X communications. Essential for privacy-preserving intelligent transportation systems.
Personalisation Control Key
A secret key used in the UICC/USIM to control the personalisation of the ME (Mobile Equipment) in 3GPP networks. It enables network operators or manufacturers to lock a device to a specific network, brand, or service provider, enforcing commercial agreements and subsidy models.
Private Call Key Identifier
An identifier for a cryptographic key used to secure private group communications in Mission Critical Push-to-Talk (MCPTT) services. It enables the secure distribution and management of keys for encrypting and authenticating private group calls, ensuring only authorized users can participate.
Padding Counter
A counter used in 3GPP security algorithms (specifically the f8 ciphering algorithm) to generate a unique keystream block for each frame. It prevents the reuse of the same keystream, which is critical for maintaining the confidentiality of user data and signaling over the air interface.
ProSe Encryption Key
A cryptographic key used in Proximity Services (ProSe) for securing direct communication between nearby User Equipments (UEs). It encrypts user plane data exchanged over the PC5 interface, ensuring confidentiality for Device-to-Device (D2D) and Vehicle-to-Everything (V2X) communications.
ProSe Group Key
The ProSe Group Key is a security key used in LTE Proximity Services (ProSe) for group communication. It enables secure one-to-many communication between devices in proximity, independent of the cellular network infrastructure. This key is essential for authenticating and encrypting group messages in public safety and commercial ProSe applications.
Personally Identifiable Information
Personally Identifiable Information (PII) is any data that can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context. In 3GPP, handling PII is governed by strict privacy and security specifications to protect subscriber data, encompassing identifiers like IMSI, MSISDN, IMEI, and location data.
ProSe Integrity Key
The ProSe Integrity Key (PIK) is a cryptographic key used to ensure the integrity and authenticity of messages exchanged in ProSe (Proximity Services) direct communication. It protects against message tampering and spoofing in device-to-device scenarios, which is critical for secure public safety and commercial proximity-based applications.
Personal Identification Number
A Personal Identification Number is a numeric password used to authenticate a user to a mobile device or network service. In 3GPP, PINs secure SIM/USIM cards, device access, and services, preventing unauthorized use. They are a fundamental subscriber identity and access control mechanism.
PIN Element
PINE (PIN Element) is a security component introduced in 3GPP Release 18 for managing PIN (Personal Identification Number) credentials in 5G systems. It provides a standardized framework for PIN verification and management, enhancing subscriber authentication and service access control. This is crucial for securing user equipment and network services that require PIN-based authorization.
Proof Key for Code Exchange
PKCE is a security extension for the OAuth 2.0 authorization code flow, designed to protect against authorization code interception attacks, particularly in public clients like mobile apps. It enhances security by having the client create and prove possession of a secret key during the authorization and token exchange processes.
Public-Key Cryptography Standards
PKCS refers to a suite of interoperability standards for public-key cryptography, originally developed by RSA Laboratories and widely adopted. In 3GPP, these standards define formats and protocols for secure key management, encryption, digital signatures, and certificate handling within the network and on UICCs.
Public Key Infrastructure
PKI is a framework of policies, roles, hardware, software, and procedures for creating, managing, distributing, using, storing, and revoking digital certificates. In 3GPP, it establishes trust for network entities, applications, and users, enabling secure authentication, encryption, and digital signatures across the ecosystem.
Pseudonym Mediation Device functionality
The Pseudonym Mediation Device (PMD) functionality is a network-based privacy feature defined for 3GPP networks. It acts as an intermediary that translates temporary identifiers (pseudonyms) used over the radio interface into permanent subscriber identifiers (like IMSI) within the core network, helping to protect user identity from eavesdroppers. It is a key component for subscriber identity confidentiality.
Pairwise Master Key
The Pairwise Master Key (PMK) is a cryptographic key derived during authentication and key agreement procedures in wireless networks. It serves as the root key for generating session-specific encryption keys used to secure the link between a user device (UE) and a network access point. It is fundamental to the security of Wi-Fi (IEEE 802.11i) and 3GPP-WLAN interworking.
Privacy Profile Register
The Privacy Profile Register is a network function that stores and manages a user's privacy settings and preferences related to location services and personal data exposure. It acts as an interface between the user and the network, enforcing policies that control what location information is shared, with whom, and under what circumstances.
Protocol for N32 Interconnect Security
A security protocol defined by 3GPP to protect signaling messages exchanged between two separate 5G core networks over the N32 interface. It ensures confidentiality, integrity, and replay protection for inter-public land mobile network (inter-PLMN) communications, such as during roaming scenarios.
Pseudo Random Number Generator
A cryptographic algorithm that generates a sequence of numbers with statistical properties similar to true randomness. In 3GPP security, it is fundamental for creating encryption keys, authentication challenges, and initialization vectors to protect user data and network signaling.
ProSe Relay User Key Identity
A security key identifier used in Proximity Services (ProSe) for relay communication. It uniquely identifies a security key used to protect communication between a remote User Equipment (UE) and a ProSe UE-to-Network Relay, ensuring secure access to network services via sidelink.
Public Safety Discovery Key
A security key used in 3GPP Proximity Services (ProSe) for public safety applications. It secures the discovery process between user equipment, ensuring that only authorized public safety officials can discover each other, especially in mission-critical, off-network scenarios.
ProSe Traffic Key
A cryptographic key used to secure direct device-to-device (D2D) communication in Proximity Services (ProSe). It provides confidentiality and integrity protection for user data transmitted directly between UEs without traversing the network infrastructure.
Protection against Unsolicited Communication for IMS
PUCI is a 3GPP security framework within IMS to identify and block unsolicited communication like spam calls and messages. It protects users from fraud and annoyance by defining detection mechanisms and network policies. This is crucial for maintaining trust in IP-based telephony services.
PIN Unblocking Key
A secret code used to unblock a SIM/USIM card when the Personal Identification Number (PIN) has been entered incorrectly too many times, locking the card. It restores access to the card's services without erasing stored data.
Public Validation Token
A security token used in 3GPP networks to validate the authenticity and integrity of public data or services, such as those provided by Application Servers (AS) or for user equipment (UE) authorization. It is a cryptographic mechanism that helps prevent spoofing and ensures that only legitimate entities can access or provide certain network services.
RANDom number (authentication parameter)
RAND is a critical random number used as a challenge in 3GPP authentication and key agreement (AKA) procedures. It is generated by the network and sent to the UE to compute authentication responses and derive session keys, ensuring secure access.
RANDom number for Mobile Station (USIM storage)
RANDMS is a random challenge value stored within the USIM's non-volatile memory. It is used as an input for generating the shared secret key (K) during the USIM personalization phase and for deriving keys in certain legacy GSM authentication contexts.
Authentication Response
RES is a critical authentication parameter in 3GPP systems. In 3G Authentication and Key Agreement (AKA), it is a response generated by the USIM and verified by the network to authenticate the user. In 2G, it is an authentication value delivered by the HLR/AuC. It proves the subscriber's identity and is fundamental for network access security.
Roll-Over Counter
A security counter used in 3GPP networks to prevent replay attacks on encrypted data. It increments with each new encryption session or data packet, ensuring cryptographic freshness. Its proper management is critical for maintaining the integrity and confidentiality of user plane and signaling traffic.
Root Public Key
A cryptographic public key used as the root of trust in 3GPP security architectures, particularly for securing UICC (SIM) applications and services. It enables secure bootstrapping and verification of credentials, ensuring the integrity and authenticity of the security chain from the root to end entities.
Rivest-Shamir-Adleman
RSA is a widely-used public-key cryptosystem for secure data transmission, digital signatures, and key exchange in 3GPP networks. It provides confidentiality, authentication, and integrity, forming a cornerstone of security protocols in cellular systems from 3G to 5G.
Security Association Database
A database maintained by a network node (e.g., gateway, firewall) that stores the parameters of active Security Associations (SA). It contains cryptographic keys, algorithms, lifetimes, and other context needed to secure IPsec or other security protocol communications.
Security Algorithms Group of Experts
A 3GPP expert group responsible for the design, evaluation, and standardization of cryptographic algorithms used for securing 3GPP systems. It develops the core authentication, integrity, and confidentiality algorithms (like Milenage, TUAK, SNOW 3G, AES) that protect user data and network signaling. Its work is fundamental to 3GPP network security.
Security Association Identifier
A unique identifier for a Security Association (SA) established between network entities, primarily defined in the context of Generic Bootstrapping Architecture (GBA). It references a set of security parameters, including keys and algorithms, used to secure communication links for applications like Multimedia Telephony (MMTel) and IP Multimedia Subsystem (IMS) services.
Sakai-Kasahara Key Encryption
SAKKE is an identity-based encryption (IBE) scheme standardized by 3GPP for secure group communication, particularly in Mission Critical Push-to-Talk (MCPTT) services. It enables efficient key distribution by deriving public keys directly from user identities, eliminating the need for public key certificates. This is crucial for scalable, low-latency secure group calls in public safety networks.
Security Assertion Markup Language
Security Assertion Markup Language (SAML) is an XML-based open standard for exchanging authentication and authorization data between parties, specifically between an identity provider (IdP) and a service provider (SP). In 3GPP, it is profiled for federated identity management, enabling single sign-on (SSO) for network operators and third-party application providers.
Security Assurance Requirements
A framework of mandatory security requirements and testing specifications for 3GPP network products and functions. It ensures that equipment and software implementations meet baseline security levels to protect against vulnerabilities and attacks, forming a critical part of network security certification.
Security Attributes Service
A service defined by the Object Management Group (OMG) and adopted by 3GPP for specifying and managing security-related attributes in a standardized way. It provides a framework for describing security characteristics of system components, facilitating interoperability in secure distributed systems, including telecommunications networks.
Simple Authentication and Security Layer
A framework for adding authentication and optional security layers to connection-based protocols. It provides a structured method for negotiating and using authentication mechanisms, enabling secure client-server communication in various 3GPP network services.
3GPP Security Assurance Specification
A suite of 3GPP specifications that define security evaluation and testing methodologies for network products and components. They provide a common framework for security assurance, enabling vendors, operators, and test labs to verify that products meet defined security requirements.
Security Compliance Testing
SCT refers to a suite of standardized test specifications and methodologies defined by 3GPP to verify the security implementation of network elements and user equipment. It ensures that products conform to 3GPP security requirements, protecting against vulnerabilities and ensuring interoperability.
Simple Certificate Validation Protocol
A protocol enabling a client to delegate complex certificate path validation and status checking to a trusted server. It simplifies certificate validation for constrained devices by offloading processing, ensuring secure and efficient PKI operations in 3GPP networks.
SIP Digest Authentication Vector
A set of cryptographic parameters used in 3GPP networks to authenticate users for IMS access via SIP-based services. It enables secure, standardized authentication for voice, video, and messaging over IP, protecting against unauthorized access and ensuring service integrity.
SS7 security gateway Encryption Algorithm identifier
A parameter used within 3GPP security specifications to identify the specific encryption algorithm negotiated for use between a Security Gateway (SEG) and another network entity in an IP-based NDS/IP (Network Domain Security) environment. It secures signalling traffic on core network interfaces.
Security Anchor Functionality
The SEAF is a core security function in the 5G Core network, part of the Authentication Server Function (AUSF). It acts as the primary security anchor point within the serving network, managing authentication and key agreement procedures with the UE. It is critical for establishing secure communication and enabling network access.
Security Assurance Methodology
SECAM is a 3GPP security assurance methodology that provides a standardized framework for evaluating and testing the security of network products and implementations. It defines security assurance requirements, testing procedures, and certification processes to ensure that 3GPP-compliant equipment meets specified security standards.
Security Protocol
SECP refers to standardized security protocols defined in 3GPP specifications for protecting management interfaces and communications within telecommunications networks. These protocols provide authentication, integrity protection, and confidentiality for network management transactions and configuration data exchanges.
Security Gateway
A network node that provides secure IPsec tunneling for control plane and user plane traffic between 3GPP and non-3GPP networks. It is crucial for protecting inter-network communication, especially for trusted non-3GPP access and IoT deployments, by establishing encrypted tunnels and performing security gateway functions.
SS7 security gateway Encryption Key
The SEK is a cryptographic key used to secure signaling traffic between SS7 security gateways (SEGs) in 3GPP networks. It is essential for protecting the confidentiality and integrity of SS7-based signaling messages, such as those for roaming, across untrusted IP networks like the internet. This prevents eavesdropping and manipulation of critical control-plane communications.
Simple Electromagnetic Analysis
Simple Electromagnetic Analysis (SEMA) is a type of side-channel attack that extracts secret information, like cryptographic keys, from a device by analyzing its unintentional electromagnetic (EM) radiation. It is a passive, non-invasive attack that exploits correlations between the device's internal data processing and its emitted EM field. 3GPP studies SEMA to define countermeasures for protecting USIMs and secure elements in mobile systems.
Security Edge Protection Proxy
The SEPP is a security proxy deployed at the network edge to protect the Service-Based Interface (SBI) within and between 5G Core networks. It authenticates and authorizes all SBI messages, applies security policies, and ensures confidentiality and integrity for inter-PLMN signaling, which is critical for roaming and network exposure.
Security Functional Requirements
SFR defines the mandatory security functions and capabilities that network elements and user equipment must implement to ensure a secure 3GPP system. It provides a standardized baseline for security across different releases and technologies, ensuring interoperability and a consistent security posture.
Secure Hash Algorithm
Secure Hash Algorithm (SHA) is a family of cryptographic hash functions standardized by NIST and widely adopted in 3GPP for security. It generates a fixed-size, unique digital fingerprint (hash) from input data, used for data integrity, digital signatures, and key derivation in network authentication and protection mechanisms.
Secure Hash Algorithm 2
SHA-2 is a family of cryptographic hash functions standardized by NIST and adopted by 3GPP. It provides data integrity and authentication, forming the foundation for digital signatures and key derivation in network security protocols. Its resistance to collision attacks is critical for securing signaling and user data.
Secure Hash Algorithm 3
SHA-3 is a cryptographic hash function standard (Keccak) developed by NIST as a future-proof successor to SHA-2. In 3GPP, it is specified as an optional algorithm for enhanced security resilience, offering a structurally different design based on sponge construction. It provides an alternative cryptographic primitive for integrity and authentication.
SS7 security gateway Integrity Algorithm identifier
An identifier used within SS7 security gateway protocols to specify the cryptographic integrity algorithm applied to signaling messages. It is part of the security mechanism for protecting legacy SS7-based core network interfaces, such as those used in 2G/3G roaming, against interception and tampering.
Subscription Identifier De-concealing Function
A security function within the 5G core network that retrieves the permanent subscription identifier (SUPI) from a concealed version (SUCI). It is a critical component of the Authentication Server Function (AUSF), enabling secure subscriber authentication while protecting user privacy on the radio interface.
SS7 Security Gateway Integrity Key
A cryptographic key used in 3GPP networks to ensure the integrity of signaling messages between an SS7 Security Gateway (SEG) and other network elements. It protects SS7-based protocols (like MAP and CAP) from tampering and replay attacks in inter-operator connections.
Subscriber Identity Module / Universal Subscriber Identity Module
A secure hardware or software module that stores subscriber identity, authentication keys, and service profiles. It enables secure network access, user authentication, and service personalization for mobile devices. It is the cornerstone of subscriber security and mobility in cellular networks.
SEAL Identity Management Client
A functional component within a device that acts as the client in the SEAL identity management framework. It interacts with the SIM-S server to provision, manage, and authenticate identities for secure edge applications. It enables devices to obtain and use verifiable credentials in distributed edge computing scenarios.
SEAL Identity Management Server
A network-based functional component that acts as the server in the SEAL identity management framework. It facilitates the issuance, verification, and management of decentralized identities and verifiable credentials for edge services. It acts as a trust anchor and intermediary between identity issuers, holders (SIM-C), and verifiers.
System Information Retrieval Function
A security function defined in 5G networks that enables a secure and efficient mechanism for a UE to retrieve system information (SI) from a network. It is part of the security architecture for the Service-Based Interface (SBI) within the 5G Core, ensuring that SI delivery is authenticated and integrity-protected.
SideLink Positioning Key Management Function
A network function introduced in 5G for Proximity Services (ProSe) and Vehicle-to-Everything (V2X). It is responsible for the generation, management, and distribution of cryptographic keys used to secure positioning-related communication over the Sidelink interface. It ensures the integrity and confidentiality of direct positioning measurements between devices.
The ETSI TC SMG Security Group
The SMG Security Group (SMG-SG) was a specialized subgroup within ETSI's Special Mobile Group (SMG) focused on the security aspects of GSM standards. It was responsible for designing and specifying the cryptographic algorithms and security protocols that protected GSM networks, including the A3/A8 authentication and key agreement algorithms and the A5 stream ciphers for radio interface encryption.
Security Objective
A formal statement defining a specific security property or goal that must be achieved within a 3GPP system or subsystem. It serves as a foundational requirement for designing and evaluating security mechanisms, ensuring the network protects against identified threats.
Start Of Interception
SOI is a standardized reference point within 3GPP networks that marks the beginning of a lawful interception data flow. It is a critical architectural component that enables network operators to fulfill legal obligations by providing authorized government agencies with access to intercepted communication content and associated data in a secure and standardized manner.
Simple Power Analysis
A side-channel attack technique that extracts secret information (e.g., cryptographic keys) from a device by analyzing its power consumption patterns during computation. In 3GPP, it is a considered threat model for UICC/USIM cards and network functions, driving requirements for side-channel resistant algorithms.
Service Provider Control Key
A cryptographic key used in 3GPP systems to authenticate and secure communications between the UE and service provider networks, enabling controlled access to services. It ensures that only authorized users can utilize specific network features, enhancing security and service management.
Security Policy Database
A database that stores IPsec security policies, defining the security services to be applied to IP packets traversing a secure interface. It is a core component of the IPsec architecture, enabling packet classification and the enforcement of security associations for secure communication.
Spam over IP Telephony
Unwanted, bulk, automated, or fraudulent voice or video calls delivered over IP-based telephony networks like VoLTE and VoNR. It is the telephony equivalent of email spam, posing security, privacy, and network efficiency challenges that 3GPP standards aim to mitigate.
Signalling Protection Key
A cryptographic key used in 5G to specifically protect sensitive signaling messages between the UE and the network, particularly for the Steering of Roaming (SoR) and UE Parameter Update (UPU) procedures. It ensures the integrity and confidentiality of these management commands.
Signalling Protection Key Identifier
A unique identifier for a signalling protection key used to secure communication between a UE and a network function. It is crucial for enabling integrity protection and confidentiality of signalling messages, particularly in services like IP Multimedia Subsystem (IMS) and the 5G Core network.
Sequence Number
SQN (Sequence Number) is a security parameter in 3GPP authentication and key agreement (AKA) protocols, used to ensure freshness and prevent replay attacks. It is generated by the network and verified by the UE, playing a critical role in mutual authentication and key derivation for secure communication in mobile networks from 2G to 5G.
Signed RESponse
An authentication value generated by a SIM or USIM during 2G Authentication and Key Agreement (AKA). It is a cryptographic response to a network challenge (RAND), used to verify the subscriber's identity and ensure secure network access.
Secure Real-time Transport Control Protocol
SRTCP is the secure version of the Real-time Transport Control Protocol (RTCP). It provides confidentiality, message authentication, and replay protection for the control traffic of multimedia sessions. This is essential for securing VoIP, video conferencing, and other real-time services in IMS and 5G networks.
Secure Real-time Transport Protocol
SRTP is a profile of RTP that provides confidentiality, message authentication, and replay protection for real-time media streams like voice and video. It is a fundamental security protocol for VoIP, video conferencing, and multimedia services in 3GPP's IMS and 5G networks.
Secure Real-time Transport Protocol Master Key
The SRTP Master Key is a cryptographic key used to derive session keys for encrypting and authenticating media streams in 3GPP networks. It ensures the confidentiality and integrity of real-time communication, such as VoLTE and VoNR, protecting against eavesdropping and tampering.
Secure Real-time Transport Protocol Master Salt
The SRTP Master Salt is a cryptographic non-secret value used alongside the SRTP Master Key in the key derivation function. It ensures that the generated session encryption and authentication keys are unique and unpredictable, even if the same master key is reused across different sessions or contexts.
SS7 Security Gateway
The SS7 Security Gateway (SS7-SEG) is a network function that secures the interconnection between SS7-based networks and IP-based networks, or between different operator domains. It provides firewall, filtering, and intrusion detection capabilities to protect the legacy SS7 signaling infrastructure from attacks originating over IP links.
Secure Shell
A cryptographic network protocol for secure remote login and command execution over an unsecured network. It provides strong authentication and encrypted data communications, replacing insecure protocols like Telnet and rlogin. It is crucial for secure management and configuration of network elements in 3GPP systems.
Secret Signing Key
A cryptographic key used for generating digital signatures to ensure message integrity and authenticity in 3GPP networks. It is a core component in security protocols for protecting signaling and user data, preventing tampering and spoofing.
Single Sign-On
Single Sign-On (SSO) is a user authentication mechanism that allows a user to access multiple applications or services with a single set of login credentials. It enhances user convenience and security by reducing password fatigue and centralizing authentication management. In 3GPP, it enables seamless access to network and third-party services.
Short Term Automatically Renewed
STAR is a security mechanism for automatically renewing short-term credentials, such as certificates or keys, without manual intervention. It is crucial for maintaining continuous security in dynamic networks, particularly for IoT devices and network functions, by ensuring credentials remain valid and reducing operational overhead.
Secure Telephone Identity Revisited
A framework of standards for cryptographically verifying the calling party's telephone number, combating caller ID spoofing and robocalls. It uses digital signatures (PASSporTs) attached to SIP signaling to attest that a call originates from an authorized source and that the caller ID has not been tampered with.
Subscription Concealed Identifier
SUCI is a privacy-preserving identifier used by a User Equipment (UE) during initial network registration before authentication. It is a cryptographic construct that conceals the user's permanent subscription identifier (SUPI) using public key encryption. This prevents tracking and eavesdropping on the user's identity over the air interface.
Split X3 LI Interworking Function
A functional entity that enables lawful interception (LI) in networks with a split architecture, specifically between the Control Plane (CP) and User Plane (UP). It acts as an intermediary, collecting and correlating interception-related information from both planes and delivering it to law enforcement agencies as mandated by regulations.
Trusted Computing Group
The Trusted Computing Group (TCG) is a consortium that develops and promotes open, vendor-neutral, global industry standards for trusted computing hardware and software. In 3GPP, its specifications are referenced to define security requirements for trusted environments, particularly for secure boot, remote attestation, and hardware-based root of trust in devices and network elements.
Traffic Encryption Key
A cryptographic key used to encrypt and decrypt user data (user plane) or signaling (control plane) traffic between the UE and the network. It is a fundamental element in securing communications over the air interface and within the core network.
Traffic Generating Key
A cryptographic key used in 3GPP networks to generate secure, realistic traffic patterns for lawful interception and monitoring systems. It ensures that intercepted traffic is indistinguishable from genuine user data, maintaining the integrity and secrecy of surveillance operations.
Transport Layer Security
A cryptographic protocol designed to provide secure, authenticated communication and data privacy over a network. In 3GPP systems, TLS is widely used to protect signaling and user plane traffic between network functions, and between user equipment and network servers (e.g., for IMS, HTTP-based services). It ensures integrity, confidentiality, and often mutual authentication.
Temporary IP Multimedia Private Identity
A temporary identifier used in IMS to protect the user's permanent private identity (IMPI) from exposure over the air interface. It enhances subscriber privacy and security during authentication and registration procedures.
Trusted Node Authentication
A security mechanism defined in 3GPP for authenticating trusted nodes within a network, such as network elements or gateways. It establishes a secure, trusted relationship between entities, ensuring that only authorized nodes can participate in network operations and signaling. This is fundamental for preventing unauthorized access and maintaining the integrity of the core network.
Tuak Operator Variant Algorithm Configuration Field
TOP is a configuration field used in the TUAK authentication and key agreement algorithm. It allows mobile network operators to customize and differentiate their implementation of the TUAK cryptographic functions, providing operator-specific security variants within the 3GPP standard.
Third Party Authorized Entity
A trusted external entity authorized by a mobile network operator to access network capabilities and user data for specific services. It enables secure third-party service integration, such as edge computing or IoT applications, while maintaining operator control and user privacy.
Transport Packet
A standardized packet format defined in 3GPP for securely transporting Lawful Interception (LI) related information, such as intercepted content or intercept related information, from a Lawful Interception function to a Law Enforcement Monitoring Facility. It ensures structured, reliable, and secure delivery of intercepted data.
Time Variant Parameter
TVP is a security parameter defined in 3GPP that varies over time, used in authentication and key agreement protocols. It enhances security by introducing dynamic elements that prevent replay attacks and ensure freshness. TVPs are critical for protecting user privacy and network integrity in mobile communications.
Unsolicited Communication
Communication initiated without prior consent or request from the recipient, often referring to unwanted messages like spam or fraud. In 3GPP, it encompasses mechanisms to detect, prevent, and mitigate such communications in mobile networks.
UMTS Encryption Algorithm
UEA is a family of stream cipher algorithms used to encrypt user data and signaling messages on the radio interface in UMTS networks. The primary algorithm, UEA1 (based on KASUMI), was designed to provide stronger confidentiality than the A5 algorithms used in GSM.
User Identity Authentication
User Identity Authentication (UIA) is a fundamental security process in 3GPP networks that verifies the identity of a user (or User Equipment) attempting to access network services. It protects against unauthorized access by validating credentials, typically using a challenge-response mechanism involving a secret key shared between the user's SIM/USIM and the network's Authentication Centre (AuC).
User Identifier for MIKEY-SAKKE
A cryptographic identifier used within the MIKEY-SAKKE (Multimedia Internet Keying - Sakai-Kasahara Key Encryption) protocol for secure group communication. It uniquely identifies a user within a Key Management Service (KMS) domain and is essential for key distribution and identity-based encryption in mission-critical and secure multimedia services.
Unique Key Encryption Key (P25)
A cryptographic key used in 3GPP's Proximity Services (ProSe) for Public Safety. It encrypts the ProSe Group Key, protecting group communication for mission-critical services like push-to-talk. This ensures secure, encrypted group calls for first responders operating in direct device-to-device mode.
UMTS LI Correlation
A functional component within the 3GPP Lawful Interception (LI) architecture, specifically for UMTS (3G) networks. Its primary role is to correlate intercepted communication content (CC) with associated Intercept Related Information (IRI) from the same target, ensuring a complete and legally admissible intercept record.
IP User Plane Integrity Protection
UP is a security mechanism that ensures the integrity of user plane data packets in 3GPP networks. It protects against unauthorized modification, insertion, or deletion of data during transmission between the UE and the network. This is crucial for maintaining data trustworthiness and service reliability, especially for sensitive applications.
User Plane ProSe Remote User Key
A security key used in 5G ProSe (Proximity Services) for direct communication between devices. It secures the user plane data exchanged over the PC5 reference point, ensuring confidentiality and integrity for services like public safety and V2X without traversing the network core.
UE Parameters Update
A security procedure in 5G where the network (AUSF/UDM) updates sensitive authentication parameters stored in the UE's Universal Subscriber Identity Module (USIM). It is triggered when network security policies change or credentials are compromised, ensuring long-term key freshness and mitigating key overuse.
Universal Subscriber Identity Module
The Universal Subscriber Identity Module (USIM) is a secure, tamper-resistant smart card application residing on a UICC (Universal Integrated Circuit Card) in 3GPP devices. It stores critical subscriber data, performs authentication and key agreement with the network, and provides a secure environment for applications. It is fundamental to subscriber identity management, network access security, and service provisioning in 3G, 4G, and 5G systems.
User Security Settings
A subset of the Generic User Security Settings (GUSS) containing security-related subscription data for a user. It is used for authentication and key agreement procedures, enabling secure access to network services. Its management is crucial for subscriber security and service continuity.
Untrusted Wireless Access Network
A non-3GPP access network (like Wi-Fi) that is not inherently trusted by the 3GPP core network. To securely integrate such access, UE connections are routed through an evolved Packet Data Gateway (ePDG) which establishes an IPsec tunnel, protecting traffic as it traverses the untrusted link. This is fundamental for secure non-3GPP access in EPS and 5GS.
Vulnerability Assessment
Vulnerability Assessment (VA) in 3GPP refers to systematic processes and requirements for identifying, evaluating, and reporting security weaknesses within network elements, protocols, and systems. It is a critical component of the 3GPP security assurance framework, ensuring that products and networks are resilient against attacks before deployment and operation.
WebRTC Authentication Function
The WebRTC Authentication Function (WAF) is a security entity within the IP Multimedia Subsystem (IMS) that provides authentication and key agreement services for WebRTC-based clients. It enables secure access to IMS services (like VoLTE) from web browsers by generating and validating authentication tokens, bridging web security models with 3GPP credentials.
Web Application Security
A 3GPP work item and set of specifications focused on identifying, analyzing, and providing security solutions for threats specific to web-based applications and services in mobile networks. It addresses vulnerabilities arising from the integration of web technologies (HTML5, JavaScript) with telecom network capabilities exposed via APIs.
Wireless Identity Module
A secure hardware or software component that stores the subscriber's identity (IMSI), authentication keys, and network applications for a 3GPP mobile device. It is the generic term encompassing physical SIM cards and their embedded (eSIM) and integrated (iSIM) successors. The WIM executes the authentication algorithms, securing the link between the user and the mobile network.
Wrong Password Attempts
A security counter that tracks the number of consecutive incorrect password entries during authentication procedures. It is a fundamental mechanism to prevent brute-force attacks and unauthorized access attempts in 3GPP networks, triggering protective actions when a threshold is exceeded.
Wireless Public Key Infrastructure
A Public Key Infrastructure (PKI) framework adapted for the constraints of wireless networks and mobile devices. It enables secure management of digital certificates, keys, and trust relationships for applications like mobile commerce, device authentication, and secure messaging in 3GPP systems.
Wireless Transport Layer Security
A security protocol for wireless applications, based on TLS, providing data integrity, privacy, and authentication. It was crucial for securing early mobile data services like WAP, adapting to the constraints of mobile networks and devices.
Computed MAC-I
X-MAC (Computed MAC-I) is a security parameter used in LTE and NR to verify the integrity and origin of RRC and NAS signaling messages. It is the expected Message Authentication Code computed by the receiving entity (UE or network) to compare against the received MAC-I for validation.
Expected Message Authentication Code
XMAC is a security parameter calculated by the USIM during the 3G Authentication and Key Agreement (AKA) procedure. It represents the expected value of the Message Authentication Code (MAC) received from the network. The USIM compares the XMAC with the received MAC to authenticate the network, preventing man-in-the-middle attacks.
Expected Message Authentication Code for Authentication
XMAC-A is a security value computed during the EPS Authentication and Key Agreement (AKA) procedure. The UE calculates XMAC-A and compares it with the MAC-A value received from the network within the authentication token (AUTN). A match authenticates the network to the UE, ensuring the connection is established with a legitimate operator network.
XML Protection Key
A cryptographic key used to protect XML-based messages in 3GPP networks, ensuring confidentiality and integrity for services like SMS and MMS. It is essential for securing application-layer protocols against interception and tampering.
Expected Response
XRES is the expected authentication response value generated by the network's HLR/AuC during 3G authentication. It is used by the VLR/SGSN to verify the legitimacy of a user's SIM/USIM by comparing it against the user's computed response (RES). This is a fundamental security mechanism to prevent unauthorized network access.