Protocol Simulations / 5G SUCI Construction

What you will do: Enter a 15-digit SUPI, pick Profile A (X25519), Profile B (P-256) or Profile C (ML-KEM, hybrid or pure), then execute eleven steps from home-network key generation to SUCI assembly and SIDF decryption.

Worked example: Default SUPI 310260123456789 under Profile A: X25519 ECDH, X9.63-KDF, AES-128 MSIN encryption and a MAC tag, then Decrypt SUCI at SIDF recovers the original SUPI.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with 5G Security

For your role

Developer / Engineer
Execute the steps from Home Network Key Generation through the UE's SUCI construction with Execute Step: Profile A uses Curve25519 and AES-128, and the Operator view shows the exact values a network's de-concealment side would compute.
Security Architect
Switch between Operator view and IMSI-catcher view: the catcher sees only ephemeral ciphertext, never the SUPI, which is the property a PQC profile has to preserve when Curve25519 is replaced; Customize… changes the profile and identifiers.
Researcher / Academic
Run the 5G PQC Known Answer Tests panel and use Plain English beside each step to check the construction against the 3GPP profile; the live HSM mode runs the key agreement in softhsmv3.

An IMSI catcher within radio range sees every packet your phone broadcasts. SUCI conceals your identity so the catcher sees only ephemeral ciphertext — never your real IMSI.

Profile A · Curve25519 + AES-128 · Live HSM on · SUPI 310260123456789

Live HSM Mode Active

SoftHSM3 · PKCS#11 v3.2 · Rust · session open

Running in PKCS#11 / softhsmv3 mode
Setup
0/3
UE · SUCI
0/5
Inspect
0/1
Network · SIDF
0/2
Step 1 of 11 — Home Network Key Generation (Profile A)

1. Home Network Key Generation (Profile A)

The home network operator provisions a long-term asymmetric key pair. For Profile A, 5G mandates the use of Curve25519 (X25519), a state-of-the-art elliptic curve tailored for speed and security. The private key is securely stored for use by the SIDF (Subscription Identifier De-concealing Function) at the UDM for SUCI deconcealment, while the public key (32 bytes) is distributed to USIMs during SIM personalization.

📱
USIM
UE Side
Generating HN Key Pair...
☁️
Home Network
UDM / SIDF
// SoftHSMv3 WASM: Generate Home Network X25519 Key
const { pubHandle, privHandle } = hsm_generateECKeyPair(hsmd, sessionHandle, 'X25519'
, false, 'derive');

// Or inject Profile A explicit test vectors for KAT validation:
const hnPrivHandle = await hsm_injectTestKey(
  hsmd, sessionHandle, hnPrivBytes, 'X25519'
);
TERMINAL OUTPUT
Click Execute to run this step.

Execute a step to see live PKCS#11 operations.

5G PQC Known Answer Tests

NIST FIPS 203/204 · NIST SP 800-227 (hybrid combiner) · 3GPP TS 33.501 Annex C.4

Click Run validation tests to run 6 use-case scenarios. Evidence in this set: NIST ACVP-Server reference sample — Expected values copied from the public NIST ACVP-Server repository with immutable source identity.; Published standard KAT — Expected values printed in a cited standard or consensus RFC.; Functional round-trip — Output produced by an implementation is consumed by the same or paired implementation..

Reference samples from the public NIST ACVP-Server repository · NIST FIPS 203/204 · NIST SP 800-227 (hybrid combiner) · 3GPP TS 33.501 Annex C.4 · Generated keys are for educational use only.

Try it

Switch to the IMSI-catcher view during the SUCI steps. What does the catcher see?

Next step

Turn it into a plan: Hybrid Transition Planner

This tool practises the 5G Security module, phase 5 (Pilots & Migration); Hybrid Transition Planner produces a deliverable of that phase.

Next in Protocol Simulations