Previously in this series, the foundational architecture of the Radio Access Network (RAN) was examined, including how radio protocol stacks are operated between User Equipment (UE) and base stations. Key radio-interface threats were also analyzed, ranging from International Mobile Subscriber Identity (IMSI) catchers and False Base Stations (FBS) to downgrade attacks, Radio Frequency (RF) jamming, and ciphering bypasses. More details can be found in Part 1 and Part 2 of the series.
Understanding these attack vectors naturally raises a pivotal architectural question:
“How does the telecommunications industry systemically mitigate these risks across global > networks built by disparate equipment vendors?”
The answer lies in rigorous international standardization. Wireless security cannot rely on security-through-obscurity or proprietary implementation tweaks. Mobile networks represent multi-vendor, globally roaming ecosystems where, for example, a handset manufactured in Asia must securely attach to an operator’s network in Europe using base stations manufactured in North America. Baseline security mechanisms must be mathematically defined, procedurally specified, and strictly enforced across all network layers.
The primary governing body driving these standards is the 3rd Generation Partnership Project (3GPP), specifically 3GPP Service and System Aspects Working Group 3 (SA3). 3GPP SA3 is responsible for defining the overall security architecture, threat models, cryptographic algorithms, key management protocols, and interface protection mechanisms across generations of cellular technology.1
This third installment of the “Securing the RAN” series examines how 3GPP standards have evolved from 3G to 5G to systematically address historical radio interface vulnerabilities. It provides a technical deep dive into 5G System (5GS) security specifications, particularly 3GPP TS 33.501, analyzes major enhancements introduced in Releases 15, 16, and 17, drawing on landmark research and standardization insights from industry leaders such as Ericsson, explores Open RAN (O-RAN Alliance) security paradigms, and examines the emerging security frontiers of 5G-Advanced in Releases 18 and 19.
The Historical Evolution: From 3G to 4G Security Baselines
To appreciate the security posture of 5G New Radio (NR), we must first understand the structural deficiencies inherent in legacy network generations and how each 3GPP release iteratively addressed them.
3G Security Architecture: Establishing Mutual Authentication
2nd Generation (2G) Global System for Mobile Communications (GSM) networks suffered from a fundamental architectural vulnerability: one-way authentication. The network authenticated the subscriber through the Subscriber Identity Module (SIM) card using algorithms such as COMP128, but the handset did not authenticate the legitimacy of the network. This design flaw enabled IMSI catchers: rogue base stations that impersonated legitimate cell towers to harvest permanent subscriber identities and force unencrypted voice connections.
When 3GPP specified 3G Universal Mobile Telecommunications System (UMTS) security in TS 33.102, it introduced 3G Authentication and Key Agreement (AKA), establishing true mutual authentication. The network transmitted a random challenge alongside an Authentication Tousimken containing a Sequence Number protected by a master Network Authentication Key. The Universal Subscriber Identity Module (USIM) inside the handset verifies this token to confirm the network’s identity before responding with its expected cryptographic calculation. Furthermore, 3G introduced integrity protection for Radio Resource Control (RRC) signaling using the KASUMI/f9 algorithms, alongside payload encryption via f8.
Despite these advances, 3G retains two major architectural vulnerabilities.
- The initial identity exchange occurs in unencrypted plain text over the air interface. An attacker operating a rogue NodeB can broadcast a high-power signal, force nearby UE to attach, and request the subscriber’s permanent IMSI in plain text.
- User-plane data lacks integrity protection entirely; while ciphering is supported, man-in-the-middle attackers can alter payload bits without detection.2
4G Security: Key Hierarchies and Control Plane Isolation
3GPP addressed several 3G shortcomings in 3GPP TS 33.401 for 4th Generation (4G) Evolved Packet System (EPS). A core innovation was the strict separation of Non-Access Stratum (NAS) messages, exchanged directly between the UE and the Mobility Management Entity (MME), from Access Stratum (AS) messages, exchanged between the UE and the eNodeB base station.
To enforce this isolation, 4G introduced a strict key hierarchy branching from a master subscriber secret through intermediate mobility keys to distinct encryption and integrity keys for the NAS and AS layers. This key tree ensures that physically compromising an eNodeB tower exposes only local session keys, preventing an adversary from obtaining master core network keys. Control-plane protection is mandatory over the Long-Term Evolution (LTE) air interface using standardized Advanced Encryption Standard (AES), SNOW 3G, or ZUC cryptographic algorithms.
However, 4G LTE retains critical security gaps. Initial attach procedures still transmit the plain-text IMSI over the air whenever a temporary identifier is absent or invalidated by a rogue station. Additionally, while 4G specifies ciphering for user-plane data, it omits User Plane Integrity Protection. Attackers can exploit this gap through bit-flipping techniques, successfully modifying DNS query destinations inside encrypted IP packets without violating lower-layer checks.3
The 5G Security Paradigm Shift: 3GPP Release 15 and 16 Baseline
3GPP set out to fundamentally redesign wireless security in 3GPP TS 33.501, constructing 5G NR on a Zero Trust foundation. The architecture, shown in Figure 1, explicitly assumes that underlying transport networks, radio interfaces, and edge execution environments are inherently untrusted.1

SUPI and SUCI: Eradicating the IMSI Catcher Vector
The most critical architectural upgrade in 5G NR is the total elimination of plain text identity transmissions over the air. The Subscription Permanent Identifier (SUPI), is never sent unencrypted over the radio interface. Instead, the UE calculates a Subscription Concealed Identifier (SUCI) using the Elliptic Curve Integrated Encryption Scheme (ECIES), as seen in Figure 2.

During manufacturing, the home network provisions its public key into the secure enclave of the USIM. When attaching to a next-generation NodeB (gNB), the UE generates an ephemeral elliptic curve key pair and uses Elliptic Curve Diffie-Hellman (ECDH) key agreement to derive a shared secret with the home network’s public key. The Mobile Subscriber Identification Number (MSIN) portion of the subscriber identity is then encrypted using AES-128-GCM or HMAC-SHA-256 derived from this shared secret.
The resulting SUCI payload contains the scheme identifier, the home network public key ID, the ephemeral public key, and the encrypted ciphertext block. Only the Unified Data Management (UDM) core function in the subscriber’s home network possesses the corresponding private key required to decrypt the SUCI. Because an adversary operating an FBS lacks this private key, they cannot decrypt the subscriber’s identity. Replay attacks are neutralized because every attach request generates a fresh ephemeral key pair, producing a completely unique ciphertext string.15
User Plane Integrity Protection in 5G NR
To close the bit-manipulation vulnerabilities inherent in 4G, 3GPP Release 15 introduced User Plane Integrity Protection (UPIP) for Standalone 5G networks. In addition to ciphering, user plane Packet Data Convergence Protocol (PDCP) data units are appended with a 32-bit Message Authentication Code for Integrity (MAC-I).16
Running cryptographic integrity algorithms at multi-gigabit speeds introduces significant processing overhead on hardware platforms. Consequently, Release 15 permitted a fallback where networks could limit UPIP data rates. Release 16 removed this bottleneck by mandating full-data-rate UPIP hardware support across all 5G devices and base stations,67 allowing operators to enforce strict integrity policies per session based on application sensitivity.1
Security Separation in Disaggregated gNB Architectures
Under 3GPP TS 38.401, the physical 5G base station is disaggregated into a Central Unit Control Plane (gNB-CU-CP), Central Unit User Plane (gNB-CU-UP), and Distributed Units (gNB-DUs).8 This disaggregation isolates sensitive key material. Master base station keys reside exclusively inside the secure processing enclave of the CU-CP. Because DUs deployed on physical street poles are exposed to theft or physical tampering, 3GPP specifications dictate that no master encryption keys are ever stored on the DU. The DU processes radio frames without possessing the keys needed to decrypt user traffic or control signaling.
Deep-Dive: 3GPP Release 17 RAN Security Advances
Building upon the baseline established in Releases 15 and 16, 3GPP Release 17 introduced advanced security enhancements to protect migration deployments, direct device-to-device communications, time-critical industrial networks, and legacy interfaces.9
Backporting UPIP to 4G Core Options
During the multi-year transition to Standalone 5G, operators rely heavily on Non-Standalone (NSA) 5G, where an LTE eNodeB acts as the master node connected to a legacy 4G evolved packet core. To protect these hybrid deployments from user plane tampering without requiring operators to replace their entire 4G core infrastructure, 3GPP backported 5G UPIP to 4G radio access networks in Release 17.
3GPP cleverly repurposed a specific signaling bit in the UE Network Capability Information Element in order to communicate UPIP support without breaking compatibility with legacy 4G MMEs. Octet 4, bit 1 (originally reserved for a future integrity algorithm designated as EIA7) was reassigned to indicate EPS-UPIP support. Because legacy MMEs pass this capability field transparently to the base station, updated eNodeBs and UEs can negotiate cryptographic user plane integrity protection over existing 4G core networks seamlessly.10
Security for 5G Proximity-Based Services (5G ProSe / Sidelink)
Release 17 standardized 5G Proximity Services (ProSe) over the PC5 Sidelink interface, enabling devices to communicate directly with one another without routing data through a base station or core network. This architecture supports direct device discovery and UE-to-Network relaying for out-of-coverage scenarios.
To secure direct discovery, Release 17 defines cryptographic MAC signing and code scrambling to prevent rogue eavesdroppers from tracking devices or spoofing identities. When a handset acts as a relay for an out-of-coverage device, end-to-end security is maintained directly between the remote device and the 5G Core Network via NAS keys, ensuring the intermediate relay handset cannot decrypt or alter the payload traffic passing through it.9
Industrial Internet of Things (IoT) and Time-Sensitive Communication Security
In automated smart factories, 5G replaces physical industrial cables using Time-Sensitive Communication (TSC). These systems require microsecond clock synchronization to coordinate robotics and machinery. If an attacker tampers with or delays timing frames over the air interface, automated assembly lines can experience physical damage. Release 17 introduced cryptographic signature verification for time-synchronization distribution frames, preventing rogue stations from injecting false timing information.49
Mitigating False Base Stations and Radio Capability Protection
Rogue base stations frequently attempt radio capability downgrade attacks. In these scenarios, an attacker intercepts the handset’s capability response and strips out references to advanced encryption or integrity algorithms before forwarding the message to the real network, forcing a fallback to weak security settings. Release 17 mitigated this attack by introducing Radio Access Capability Signaling Protection (RACS). The UE generates a cryptographic signature over its capability payload, which the network validates against a central management function; any mid-air tampering invalidates the signature and halts the session.11
Evolutionary Comparison Across 3GPP Generations
The evolutionary path from 3G to 5G Release 17 reflects a systematic hardening of the radio access network across all functional domains, detailed in Table 1 below:
| Security Dimension | 3G (UMTS) | 4G (LTE) | 5G Release 15/16 | 5G Release 17 |
|---|---|---|---|---|
| Subscriber Privacy | Cleartext IMSI over the air2 | Cleartext IMSI over the air3 | SUCI asymmetric encryption via ECIES1 | Enhanced key rotation and anti-tracking rules11 |
| Control Plane Integrity | Mandatory RRC Integrity2 | Mandatory RRC and NAS Integrity3 | Mandatory RRC and NAS Integrity1 | Mandatory RRC/NAS Integrity + RACS Capability Signing11 |
| User Plane Integrity | Unprotected2 | Unprotected in 4G Core3 | Supported; configurable per Protocol Data Unit (PDU) session167 | Backported to 4G Core via repurposed EIA7 capability bit10 |
| Base Station Key Isolation | Centralized NodeB keys2 | Hierarchical key tree (K_ASME → K_eNB)3 | Hierarchical key tree (K_ASME → K_gNB)1 | Cryptographic isolation across CU-CP, CU-UP, and DU nodes8 |
| Direct Sidelink Protection | Not Supported | Basic safety messaging | Baseline 5G Sidelink1 | Full ProSe direct discovery & relay payload isolation9 |
| False Base Station Defense | Vulnerable to IMSI catching2 | Vulnerable to IMSI catching & downgrade attacks3 | SUCI blocks IMSI catchers entirely1 | RACS digital signatures prevent capability downgrade11 |
Emerging Paradigms: Open RAN and 5G-Advanced (Releases 18 and 19)
As mobile architectures transition into 5G-Advanced (3GPP Releases 18 and 19)1213 and embrace disaggregated, multi-vendor Open RAN ecosystems,1415 the RAN security perimeter expands far beyond traditional monolithic base stations.
Open RAN (O-RAN Alliance) Zero Trust Security Architecture
While 3GPP defines cellular protocols, the O-RAN ALLIANCE specifies open, disaggregated interfaces connecting multi-vendor RAN components as illustrated by Figure 3. Disaggregation introduces new open interfaces, including E2 (connecting the RAN Intelligent Controller to radio nodes), A1, O1, and the Open Fronthaul interface between DUs and Radio Units.14

To secure this multi-vendor environment, O-RAN Working Group 11 (WG11) established a Zero Trust architecture. All control, management, and telemetry interfaces require mandatory mutual Transport Layer Security (mTLS) with X.509 certificates to prevent man-in-the-middle attacks between vendor components.
Furthermore, because Near-Real-Time and Non-Real-Time RAN Intelligent Controllers (RIC) execute third-party algorithmic micro-apps (xApps and rApps), WG11 specifies strict API access control, sandbox isolation, and conflict mitigation functions. These measures prevent compromised micro-apps from maliciously altering beamforming vectors or triggering unprompted cell handovers.15
Ambient IoT Security (Release 19): Protecting Zero-Power Nodes
3GPP Release 19 introduces standardized support for Ambient IoT; ultra-low-power devices that harvest energy from ambient RF, thermal, or kinetic sources without conventional batteries. Because passive tags lack the energy required to execute complex asymmetric cryptography, 3GPP SA3 designed ultra-lightweight challenge-response protocols using compact symmetric ciphers. Base stations obfuscate tag query commands with pseudo-random seeds, preventing unauthorized RF readers from querying tags to track inventory or individuals.13
Integrated Sensing and Communication Privacy (Release 19)
In 3GPP Release 19, the air interface incorporates Integrated Sensing and Communication (ISAC), enabling base stations to perform radar-like physical target tracking and spatial mapping using reflected radio signals.
To prevent unsanctioned physical surveillance of non-subscribers, Release 19 establishes strict privacy consent frameworks alongside Spatial Resolution Throttling. When scanning unauthorized or residential sectors, the base station intentionally degrades its sensing accuracy, preventing precise physical profiling while preserving communication performance.13
AI/ML Air Interface and Satellite (NTN Phase 3) Security
5G-Advanced embeds Artificial Intelligence (AI) directly into the physical layer for beam management and channel prediction (Releases 18/19 AI/ML). Standardized defenses mandate Federated Learning with differential privacy, ensuring raw channel measurement logs never leave the device during model training. Base station schedulers also incorporate anomaly detection to fall back to deterministic algorithms if adversarial RF noise is detected.1213
Concurrently, Release 18/19 Non-Terrestrial Network (NTN Phase 3) specifications address space-borne base stations on Low Earth Orbit satellites. These specs require space-grade Hardware Security Modules (HSMs) to protect encryption keys in orbit, combined with multi-beam Doppler shift verification to validate a device’s physical location on Earth independently of potentially spoofed GPS signals.1213
Practical Recommendations for Network Operators
Standardized security features are only effective when properly configured and enforced in operational networks. Operators are encouraged to implement the following baseline deployment practices:
- Enforce Mandatory UPIP: Configure PDU session profiles to mandate UPIP Required67 across critical enterprise slices, financial services, industrial control networks, and mission-critical voice (VoNR) sessions to block user plane bit-manipulation attacks.1
- Automate SUCI Key Lifecycle Management: Ensure home network public keys are securely provisioned into USIM profile templates, rotate private keys regularly within core UDM nodes, and enforce strict policies that disable cleartext identity fallbacks.15
- Enforce Zero Trust Transport Enclaves: Implement mandatory mTLS or Internet Protocol Security (IPsec) with Internet Key Exchange version 2 (IKEv2) across all disaggregated F1, E1, Xn, N3, and O-RAN E2 Fronthaul transport links, treating all backhaul networks as untrusted infrastructure.
Conclusion
The evolution of 3GPP standards from 3G to 5G-Advanced Release 19 demonstrates a fundamental paradigm shift: cellular security has evolved from reactive patching to proactive, zero-trust architectural design.
Where legacy generations suffered from plain text identities and unverified user plane data, 5G establishes robust mathematical defenses. SUCI encryption permanently neutralizes traditional IMSI catchers, UPIP eliminates bit-flipping threats, and disaggregated CU/DU architectures isolate master cryptographic keys from physical tower compromise, while Release 18/19 5G-Advanced standards extend these protections to zero-power IoT, radar privacy, and satellite constellations.
Standardization remains the bedrock of global mobile security. By adhering strictly to 3GPP SA3 specifications and enforcing rigorous configuration policies, network operators can ensure their radio access networks remain resilient against sophisticated adversaries.
3GPP, Security architecture and procedures for 5G system, 3GPP TS 33.501.
3GPP, 3GPP System Architecture Evolution (SAE); Security architecture, 3GPP TS 33.401.
R. Sethi, A. Kadam, K. Prabhu, and N. Kota, “Security considerations to enable time-sensitive networking over 5G,” 2022. Available: https://www.researchgate.net/figure/GPP-5G-security-architecture_fig3_363386647
S. M. S. Hussain, “SUCI computation on UE,” Discrete Works, May 8, 2022. Available: https://www.discreteworks.com/transform/2022/05/08/suci-computation-on-ue.html
3GPP, Release 15. Available: https://www.3gpp.org/specifications-technologies/releases/release-15
3GPP, Release 16. Available: https://www.3gpp.org/specifications-technologies/releases/release-16
M. Wifvesson and P. K. Nakarmi, “5G Release 17: Overview of new RAN security features,” Ericsson Blog, Oct. 2022. Available: https://www.ericsson.com/en/blog/2022/10/3gpp-release-17-security-ran
3GPP, Study on User Plane Integrity Protection (UPIP) for Evolved Universal Terrestrial Radio Access (E-UTRA), 3GPP TR 33.853.
3GPP, Study on 5G Security aspects of False Base Stations (FBS), 3GPP TR 33.809.
3GPP, Release 18. Available: https://www.3gpp.org/specifications-technologies/releases/release-18
3GPP, Release 19. Available: https://www.3gpp.org/specifications-technologies/releases/release-19
O-RAN ALLIANCE Security Work Group, O-RAN ALLIANCE Security Update 2026, O-RAN ALLIANCE, 2026. Available: https://www.o-ran.org/blog/o-ran-alliance-security-update-2026
O-RAN ALLIANCE WG11, O-RAN Security Architecture Specification, O-RAN Technical Specification.



