Description
A Certification Authority (CA) is a fundamental component of the Public Key Infrastructure (PKI) within 3GPP security architectures. It is a trusted third-party entity responsible for issuing, revoking, and managing digital certificates. These certificates bind a public key to the identity of a subscriber, a network function (like a gNB or AMF), or a service, enabling cryptographic verification. The CA's core operation involves verifying the identity of an entity requesting a certificate (the subject), signing the certificate with its own private key to create a trusted credential, and publishing the corresponding Certificate Revocation List (CRL) or supporting Online Certificate Status Protocol (OCSP) to declare invalidated certificates. The trust in the entire system hinges on the CA's private key being securely safeguarded and its operational policies being rigorously audited.
In a 3GPP ecosystem, multiple CAs can exist, forming a hierarchy. A root CA, which is self-signed and inherently trusted, issues certificates to subordinate intermediate CAs. These intermediate CAs then issue end-entity certificates to network elements and User Equipment (UE). This hierarchical model allows for scalable trust management and limits the exposure of the root CA's critical private key. The validation of a certificate involves verifying the digital signature chain back to a trusted root CA certificate pre-provisioned in the verifying entity's trust store. This process is central to protocols like TLS/DTLS for securing N1, N2, and N3 interfaces in 5G, and for authentication in scenarios like 5G Network Function service-based architecture.
The CA's role extends beyond mere issuance. It enforces a Certificate Policy (CP) and Certification Practice Statement (CPS) that define the security controls, lifecycle management procedures, and liability frameworks. Key management ceremonies for CA key generation and storage are performed in highly secure, often offline, Hardware Security Modules (HSMs). In 3GPP, CAs support various certificate profiles as defined in specifications, including those for UICC, SUCI/SUPI protection, and network function authentication. The integrity of the PKI, and thus the security of authentication and confidentiality mechanisms in 3GPP networks, is directly dependent on the correct and secure operation of the Certification Authority.
Purpose & Motivation
The Certification Authority exists to solve the fundamental problem of establishing trust in a large-scale, distributed digital environment like a mobile network. Prior to PKI, secure key distribution for symmetric cryptography was cumbersome and did not scale for millions of subscribers and thousands of network nodes. The CA enables asymmetric cryptography by providing a verifiable and trusted association between a public key and an identity. This allows any entity to verify the authenticity of another entity without pre-sharing a secret, which is essential for scenarios like initial network attachment, roaming, and secure service discovery.
Historically, as 3GPP networks evolved from 2G (which used a shared secret in the SIM) to 3G and beyond, the need for more flexible, service-oriented security grew. The introduction of IP-based services, IMS, and later cloud-native 5G core networks demanded a standardized, interoperable method for authentication and secure communication between previously unknown parties. The CA and PKI provide this by decoupling the trust establishment (managed by the CA) from the secure communication (executed by the end entities using certificates). It addresses limitations of proprietary or centralized key management systems by providing a standardized, scalable, and auditable framework for digital trust that underpins modern 3GPP security features like AKA, EAP-TLS, and SEAL.
Detected Changes Across Releases
from 3GPP Change RequestsSpecific changes extracted from the „Change history“ tables of 3GPP specifications (2 CRs across 2 releases). Complements the general historical overview above with the evidence-based evolution of this function.
Explore further
Broader topics and technologies where CA plays a role.
Defining Specifications
3GPP specifications that define or reference CA, with the latest known release. Sourced from the 3GPP document catalog — see methodology.
| Specification | Title | Release |
|---|---|---|
| TR 21.905 vj20 | 3GPP Terminology and Definitions | Rel-19 |
| TR 22.980 vj00 | Network Composition Feasibility Study | Rel-19 |
| TS 23.057 vj00 | Mobile Execution Environment (MExE) Specification | Rel-19 |
| TS 24.109 vj00 | HTTP Digest AKA & GAA Stage 3 | Rel-19 |
| TS 24.587 vj30 | V2X Services Protocols for 5G System | Rel-19 |
| TS 25.211 vj00 | UTRA FDD Layer 1: Transport & Physical Channels | Rel-19 |
| TS 25.214 vj00 | UTRA FDD Physical Layer Procedures | Rel-19 |
| TS 25.222 vj00 | UTRA TDD Multiplexing & Channel Coding | Rel-19 |
| TR 26.917 vj00 | TV Service Enhancements over 3GPP | Rel-19 |
| TS 28.314 vk00 | Management and Orchestration - Plug and Connect | Rel-20 |
| TS 29.109 vj00 | GAA Bootstrapping Interfaces (Zh, Dz, Zn, Zpn) | Rel-19 |
| TS 31.113 v1800 | USAT Interpreter Byte Code Specification | Rel-8 |
| TS 32.373 v1900 | IRP Security Services CORBA Solution | Rel-9 |
| TS 32.376 vj00 | Security services for IRP Solution Set | Rel-19 |
| TS 32.501 vj00 | Self-Configuration of Network Elements Concepts | Rel-19 |
| TS 32.808 v1800 | Common User Profile Storage Framework | Rel-8 |
| TS 33.220 vj10 | Generic Authentication Architecture (GAA) Security | Rel-19 |
| TS 33.221 vj00 | Subscriber Certificate Distribution via GBA | Rel-19 |
| TS 33.222 vj00 | Secure HTTP Access in GAA | Rel-19 |
| TS 33.303 vj00 | ProSe Security Specification for EPS | Rel-19 |
| TS 33.310 vj50 | 3GPP Authentication Framework for Network Nodes | Rel-19 |
| TS 33.320 vj00 | H(e)NB Subsystem Security Architecture | Rel-19 |
| TS 33.776 vj00 | Study of ACME for 5G SBA | Rel-19 |
| TS 33.790 vj10 | Security for Next-Gen Real-Time Communication Phase 2 | Rel-19 |
| TS 33.805 vc00 | 3GPP Network Product Security Assurance Methodology | Rel-12 |
| TS 33.820 v1830 | Home NodeB/eNodeB Security Architecture | Rel-8 |
| TS 33.823 vc20 | GBA Web Browser Integration Study | Rel-12 |
| TR 33.876 vi01 | Technical Report on Certificate Management | Rel-18 |
| TS 33.880 vf10 | Security Study for Enhanced Mission Critical Services | Rel-15 |
| TS 33.885 ve10 | Security Study for V2X Services | Rel-14 |
| TR 33.969 vj00 | Security for Public Warning System (PWS) | Rel-19 |
| TS 36.101 vk00 | LTE UE Radio Transmission and Reception | Rel-20 |
| TS 36.104 vj20 | E-UTRA/NB-IoT Base Station RF Requirements | Rel-19 |
| TS 36.108 vj40 | SAN RF & Performance for NB-IoT and 5G Broadcast | Rel-19 |
| TS 36.141 vj10 | RF Test Methods for LTE and NB-IoT Base Stations | Rel-19 |
| TS 36.181 vj40 | RF Test Methods and Conformance for Satellite Access Nodes | Rel-19 |
| TS 36.300 vj20 | E-UTRAN Radio Interface Protocol Architecture | Rel-19 |
| TS 36.307 vj30 | Release Independent Features for Rel-19 UEs | Rel-19 |
| TS 36.331 vj30 | E-UTRA RRC Protocol Specification | Rel-19 |
| TS 36.714 | 3GPP TR 36.714 | R99 |
| TS 36.715 | 3GPP TR 36.715 | R99 |
| TS 36.716 | 3GPP TR 36.716 | R99 |
| TS 36.761 vf00 | Extended-Band 12 Study Report | Rel-15 |
| TR 36.770 vi00 | Technical Report for High Power UE in LTE Band 14 | Rel-18 |
| TS 36.790 vf00 | LAA/eLAA for CBRS 3.5GHz Band in US | Rel-15 |
| TS 36.807 va00 | LTE Advanced UE Radio Requirements Study | Rel-10 |
| TS 36.808 va10 | LTE Carrier Aggregation Base Station RF Requirements | Rel-10 |
| TS 36.825 vd00 | Study on Additional LTE TDD Configurations | Rel-13 |
| TS 36.852 | 3GPP TR 36.852 | R99 |
| TS 36.853 | 3GPP TR 36.853 | R99 |
| TS 36.855 vd00 | E-UTRA Positioning Enhancements Study | Rel-13 |
| TS 36.858 ve00 | LTE 2.6 GHz SDL Band Technical Report | Rel-14 |
| TS 36.860 | 3GPP TR 36.860 | R99 |
| TS 36.867 vd00 | LTE DL 4 Rx Antenna Port Study TR | Rel-13 |
| TS 36.894 vd00 | Study on LTE Measurement Gap Enhancement | Rel-13 |
| TS 36.895 vd00 | 700 SDL Band for LTE Carrier Aggregation | Rel-13 |
| TS 36.899 | 3GPP TR 36.899 | R99 |
| TS 37.104 vj40 | NR, E-UTRA, UTRA, GSM/EDGE and NB-IoT Multi-Standard Radio | Rel-19 |
| TS 37.141 vj40 | RF Test Methods and Conformance for Multi-Standard Radio Base Stations | Rel-19 |
| TS 37.145 vj40 | AAS Base Station Radiated Requirements | Rel-19 |
| TS 37.320 vj30 | Minimization of Drive Tests Overview | Rel-19 |
| TS 37.716 | 3GPP TR 37.716 | R99 |
| TS 37.717 | 3GPP TR 37.717 | R99 |
| TS 37.718 | 3GPP TR 37.718 | R99 |
| TS 37.808 vc00 | PIM Handling for Base Stations Study | Rel-12 |
| TS 37.812 vb30 | Multi-band Multi-standard Radio BS Requirements | Rel-11 |
| TS 37.814 vc00 | L-band Supplemental Downlink for UTRA/E-UTRA | Rel-12 |
| TS 37.842 vd30 | BS RF Requirements for Active Antenna Systems | Rel-13 |
| TR 37.843 vf70 | AAS BS Radiated RF Requirement Background | Rel-15 |
| TS 37.863 | 3GPP TR 37.863 | R99 |
| TS 37.864 | 3GPP TR 37.864 | R99 |
| TS 37.865 | 3GPP TR 37.865 | R99 |
| TS 37.866 | 3GPP TR 37.866 | R99 |
| TS 37.872 vf10 | Technical Report on SUL & LTE-NR DC with SUL | Rel-15 |
| TR 37.878 vi00 | Technical Report on Rel-18 NR V2X Band Combinations | Rel-18 |
| TS 37.898 vj00 | Rel-19 HPUE for EN-DC Band Combinations | Rel-19 |
| TR 37.901 vf10 | UE Application Layer Data Throughput Performance | Rel-15 |
| TR 37.985 vj00 | Overview of V2X features in LTE and NR | Rel-19 |
| TS 38.101 vj40 | UE Radio Transmission and Reception; Satellite Access | Rel-19 |
| TS 38.104 vk00 | NR and NB-IoT Base Station RF Characteristics and Performance | Rel-20 |
| TS 38.108 vj40 | Satellite Access Node radio transmission and reception | Rel-19 |
| TS 38.113 vj20 | BS Electromagnetic Compatibility (EMC) | Rel-19 |
| TS 38.124 vj00 | NR UE EMC Requirements | Rel-19 |
| TS 38.133 vk00 | NR RRM Requirements | Rel-20 |
| TS 38.141 vj40 | BS Conformance Testing (TR 38.141) | Rel-19 |
| TS 38.161 vj30 | UE TRP and TRS Requirements | Rel-19 |
| TS 38.174 vj20 | NR Integrated Access and Backhaul (IAB) Requirements | Rel-19 |
| TS 38.175 vj00 | EMC for NR IAB Nodes | Rel-19 |
| TS 38.176 vj40 | IAB Conformance Testing | Rel-19 |
| TS 38.181 vj40 | NR Satellite Access Node RF Conformance Testing | Rel-19 |
| TS 38.202 vj00 | 5G NR Physical Layer Services | Rel-19 |
| TS 38.307 vk00 | 3GPP TS 38307 vk00: Release Independent Features for NR UEs | Rel-20 |
| TS 38.331 vj30 | NR Radio Resource Control Protocol Specification | Rel-19 |
| TS 38.521 vj10 | UE Conformance Spec for NR Satellite Access | Rel-19 |
| TS 38.522 vj40 | 3GPP TS 38522 vj40: UE Conformance Test Applicability | Rel-19 |
| TS 38.523 vj40 | UE Conformance Specification for 5G NR | Rel-19 |
| TS 38.561 vj10 | UE TRP and TRS Conformance Testing for FR1 | Rel-19 |
| TS 38.716 | 3GPP TR 38.716 | R99 |
| TS 38.717 | 3GPP TR 38.717 | R99 |
| TS 38.718 | 3GPP TR 38.718 | R99 |
| TS 38.719 vj10 | NR Inter-band CA/DC Configurations | Rel-19 |
| TS 38.746 vj00 | High Power UE for NR Inter-band CA/DC | Rel-19 |
| TS 38.750 vj00 | High Power UE for NR Inter-band CA/DC | Rel-19 |
| TS 38.755 vj10 | NR FR1 DL Fragmented Carriers Study | Rel-19 |
| TS 38.792 vj00 | UE RF Requirements for PC1.5 Inter-band UL CA/DC | Rel-19 |
| TS 38.793 vj00 | Simultaneous Rx/Tx Band Combinations TR | Rel-19 |
| TR 38.803 ve40 | Study on Coexistence and RF Feasibility for 5G NR | Rel-14 |
| TR 38.804 ve00 | Study on New Radio Access Technology; Radio Interface Protocol Aspects | Rel-14 |
| TR 38.810 vg70 | NR OTA Test Methods Study | Rel-16 |
| TS 38.817 | 3GPP TR 38.817 | R99 |
| TR 38.820 vg10 | NR; 7-24 GHz Frequency Range Study | Rel-16 |
| TR 38.825 vg00 | Study on NR Industrial IoT | Rel-16 |
| TS 38.831 vg10 | UE RF Requirements for FR2 Enhancements | Rel-16 |
| TR 38.839 vh00 | Simultaneous Rx/Tx band combinations | Rel-17 |
| TR 38.841 vh00 | High power UE for NR inter-band CA | Rel-17 |
| TR 38.842 vh00 | High Power UE for NR CA with Multiple Bands | Rel-17 |
| TR 38.846 vi10 | Technical Report | Rel-18 |
| TS 38.870 vj50 | Enhanced OTA Test Methods for NR TRP and TRS | Rel-19 |
| TS 38.873 vg00 | NR Band n48 Technical Report | Rel-16 |
| TR 38.880 vi00 | Technical Report for 3Tx inter-band UL CA and EN-DC | Rel-18 |
| TR 38.881 vi00 | Technical Report on Lower MSD for Inter-band CA/EN-DC/DC | Rel-18 |
| TR 38.884 vi20 | Technical Report | Rel-18 |
| TR 38.889 vg00 | NR-based access to unlicensed spectrum study | Rel-16 |
| TR 38.894 vi00 | Technical Report | Rel-18 |
| TR 38.899 vi00 | Technical Report for High Power UE | Rel-18 |
| TR 38.903 vj30 | Derivation of Measurement Uncertainties and Test Tolerances for UE Conformance Tests | Rel-19 |