5G Security Architecture
Master 3GPP security: Privacy, Authentication, and Provisioning.
Why this matters: 5G's SUCI concealment and 5G-AKA protect subscriber identity at the protocol level — if that concealment breaks under a quantum attack, every subscriber on the network is de-anonymized retroactively, not just future ones.
Start here: Enter a 15-digit SUPI, pick Profile A, B or C (PQC), then execute the steps one by one: the subscriber identity is concealed into a SUCI and finally decrypted again by the home network.
For your role
- Developer / Engineer
- Subscriber privacy with ECIES Profiles A and B and the proposed KEM Profile C, mutual authentication with 5G-AKA and MILENAGE, then provisioning and key lifecycle: the SUCI tool runs the concealment live.
- Security Architect
- The proposed KEM-based Profile C beside Profiles A and B shows what changes in subscriber concealment under PQC; the provisioning step covers the supply-chain and key-lifecycle side.
What is 5G Security?
3GPP TS 33.501 defines the security architecture for 5G systems, introducing fundamental improvements over previous generations. In 2G/3G/4G networks, the subscriber's permanent identity (IMSI) was transmitted in cleartext over the air interface, enabling "IMSI catchers" — rogue base stations that intercept and track mobile users. 5G addresses this with , encrypting the subscriber identity before it ever leaves the device.
- IMSI sent in cleartext over the air
- IMSI catchers track & intercept users
- No subscriber identity privacy
- SUCI encrypts identity on the USIM
- -based concealment (Profile A/B)
- Mutual authentication ()
- Profile C: (Kyber) concealment
- Quantum-resistant subscriber privacy
- Research proposal — not a 3GPP profile
The Three Pillars of 5G Security
5G security rests on three pillars that work together to protect subscribers from identity theft, network impersonation, and supply chain attacks. Each pillar addresses a different phase of the subscriber lifecycle.
The USIM encrypts the subscriber's permanent identity () into a concealed identifier (SUCI) using ECIES or KEM. Only the Home Network can de-conceal it.
Mutual authentication ensures both the network and subscriber prove their identity. Uses the algorithm (AES-128 based) and a 5G-specific key hierarchy.
Secure SIM manufacturing and key distribution. Subscriber keys (K) are generated in , encrypted for transport, and stored in the operator's encrypted subscriber database.
SUCI Protection Schemes
3GPP defines multiple protection schemes for SUCI concealment. Each scheme uses a different asymmetric algorithm for key agreement, but all follow the same ECIES pattern: generate an ephemeral key, derive a shared secret, encrypt the MSIN, and compute a MAC tag.
Curve25519 elliptic curve ()
32-byte public keys
AES-128-CTR encryption
HMAC-SHA-256 integrity
Quantum-vulnerable
NIST secp256r1 curve (ECDH)
65-byte uncompressed public keys
AES-128-CTR encryption
HMAC-SHA-256 integrity
Quantum-vulnerable
ML-KEM-768 lattice-based KEM
1,184-byte public keys
AES-256-CTR encryption
HMAC-SHA3-256 integrity
Quantum-resistant
Profile C is not a 3GPP profile: TS 33.501 Annex C defines Profiles A and B and stops there. The name comes from a research proposal (Khan, Purification & Chang, Information 2025, 16, 617). It supports both hybrid (X25519 + ML-KEM) and pure PQC modes.
5G-AKA Authentication
5G-AKA (Authentication and Key Agreement) provides mutual authentication between the subscriber and the network. At its core is the MILENAGE algorithm, which uses AES-128 to compute five cryptographic functions from the subscriber key (K) and a random challenge (RAND):
CK and IK feed the 5G key hierarchy: KAUSF (anchor key) → KSEAF → KAMF → KNASint / KNASenc → KgNB (radio layer).
SIM Provisioning & Supply Chain
Before a subscriber can connect, their keys must be securely generated, written to the USIM, and delivered to the mobile operator. This supply chain is a critical trust boundary — if keys are leaked during manufacturing or transport, all subsequent security is compromised.
Post-Quantum Threat to 5G
Not all parts of 5G security are equally vulnerable to quantum computers. SUCI concealment relies on asymmetric cryptography (ECDH in Profile A/B), which is broken by . However, 5G-AKA authentication uses MILENAGE, which is built on AES-128 — a symmetric algorithm where only halves the effective key length to 64 bits, still computationally secure.
- SUCI Profile A (X25519 ECDH)
- SUCI Profile B (P-256 ECDH)
- risk
- MILENAGE / 5G-AKA (AES-128)
- SIM provisioning (AES symmetric)
- Profile C (ML-KEM lattice-based)
Profile C is the migration path to quantum-resistant subscriber privacy. It replaces ECDH key agreement with ML-KEM (Kyber) encapsulation, supporting both a hybrid transition mode (X25519 + ML-KEM-768) and a pure PQC target mode.
Hybrid Mode Secret Combination
Z_ecdh— X25519 ECDH shared secret (32 bytes)Z_kem— ML-KEM-768 encapsulated secret (32 bytes)Z = SHA-256(Z_ecdh ‖ Z_kem)— final 32-byte shared secret
SHA-256 binds both secrets so that breaking either classical or PQC alone is insufficient to recover Z. SHA3-256 is applied separately inside the ANSI X9.63 KDF. Pure mode sets Z = Z_kem directly (no combination needed).
Related Resources
Products shown here are a representative selection — not an exhaustive list. For the full vendor landscape with PQC readiness status, visit the Tools & Products tab in this module or browse the Migrate catalog →
Check off all sections and mark this reading done.
Related modules
- Government & Defense PQCSame track · Industries · Same migration phase · Shares ML-DSA, ML-KEM, X.509
- TLS BasicsSame migration phase · Shares ML-KEM, ML-DSA, X.509
- Digital AssetsSame track · Industries · Same migration phase · Shares ML-DSA, ML-KEM
- Financial Services & Payments PQCSame track · Industries · Same migration phase · Shares ML-DSA, ML-KEM
In the Industry Landscape
Check your understanding
20 questions on 5G Security, each with its answer and the reason.
Take the quizNext step
Practice it: 5G SUCI Construction5G SUCI Construction is the hands-on version of this module: the same ideas, run in your browser.
Learning module content can be inaccurate. Please double-check its information. Report inaccuracies in PQC Today GitHub Discussions.