3GPP 5G Security Architecture (TS 33.501)
Evidence request list. 43 controls, 43 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Access Security
Non-3GPP access (untrusted Wi-Fi, wireline) must use N3IWF or TNGF with IKEv2 and IPsec for secure tunneling to the 5G core, with authentication anchored in 5G AKA.
- N3IWF configuration
- IKEv2 policy
- IPsec algorithm selection
- Weak IKEv2 cipher suites
- Certificate validation skipped
- Trusted vs untrusted access mixed
Authentication
Mutual authentication between UE and network must use 5G AKA or EAP-AKA' procedures involving the AUSF, UDM, SEAF, and ARPF, producing keys anchored at the SEAF for serving network derivation.
- AUSF configuration
- Test reports for AKA flows
- Key hierarchy documentation
- EAP-AKA' fallback not tested
- Authentication failure handling weak
- Replay protection unverified
Authentication Procedures
Primary authentication and key agreement based on EAP-AKA' and 5G-AKA protocols
- AUSF and UDM authentication configuration baseline
- SUCI/SUPI handling specification implementation review
- Primary authentication test vectors and conformance evidence
- Key derivation diagrams (KAUSF, KSEAF, KAMF, KgNB)
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Maintain the 5G key hierarchy from K to KAUSF, KSEAF, KAMF, and access stratum keys with documented derivation functions.
- Key hierarchy diagram
- KDF implementation review
- Key lifecycle SOP
- No KDF code review
- Missing key destruction logs
- Undocumented key flows
Authentication procedure using EAP-AKA' protocol for 5G
- AUSF and UDM authentication configuration baseline
- SUCI/SUPI handling specification implementation review
- Primary authentication test vectors and conformance evidence
- Key derivation diagrams (KAUSF, KSEAF, KAMF, KgNB)
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Apply integrity and confidentiality protection to NAS signalling between UE and AMF using selected 5G algorithms.
- NAS SMC trace logs
- Algorithm negotiation records
- AMF configuration baseline
- NULL integrity allowed
- Weak ciphers in policy
- No algorithm capability validation
Core Network Security
UDM and UDR store sensitive subscriber data including long-term keys and authentication credentials. Storage must be protected with appropriate physical, logical, and cryptographic controls.
- HSM attestation
- UDR encryption configuration
- Access control matrices
- Long-term keys in software
- DBA access not segregated
- Backups unencrypted
Cryptography
Supported algorithms include NEA0/NIA0 (null), 128-NEA1/NIA1 (SNOW 3G), 128-NEA2/NIA2 (AES), 128-NEA3/NIA3 (ZUC). Operators must configure policies to disallow null algorithms in production.
- Algorithm selection policy
- Operator configuration evidence
- Lawful intercept exception documentation
- Null algorithms allowed for emergency calls broadly
- 256-bit support roadmap missing
- Test devices in production with weak algorithms
General Security Architecture
Define the overall 5G security architecture covering UE, RAN, core network, and service-based interfaces with documented trust boundaries.
- 5G security architecture diagram
- Trust boundary map
- Network domain security policy
- Outdated architecture diagrams
- Missing trust boundary definitions
- No SBA security overlay
Network access security, network domain security, user domain security, application domain security, SBA domain security, visibility and configurability of security
- 5G security architecture diagrams aligned to TS 33.501
- Security feature group inventory and assignment
- Inter-stratum trust boundary documentation
- Conformance test reports against TS 33.501
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Grouping of network entities for security in home and visited networks and protected communication links
- 5G security architecture diagrams aligned to TS 33.501
- Security feature group inventory and assignment
- Inter-stratum trust boundary documentation
- Conformance test reports against TS 33.501
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Security roles of AUSF, SEAF, SIDF, and other NFs
- 5G security architecture diagrams aligned to TS 33.501
- Security feature group inventory and assignment
- Inter-stratum trust boundary documentation
- Conformance test reports against TS 33.501
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Identifiers and Privacy
The SUPI must never be transmitted in cleartext over the radio interface. SUCI (concealed identifier) must be derived using the home network public key via ECIES schemes to prevent IMSI catcher attacks.
- SUCI configuration evidence
- Home network key management procedures
- UE provisioning records
- Null scheme used for SUCI
- Home key rotation not defined
- Legacy SIM provisioning bypasses SUCI
Interworking
Interworking between 5GS and EPS requires secure mapping of security contexts during handover and idle mode mobility, preventing downgrade and ensuring key freshness.
- N26 interface configuration
- Mobility test reports
- Key mapping procedures
- Context mapping not tested
- Downgrade attack risk
- Inter-PLMN handover untested
Key Management
5G key hierarchy starts from long-term key K stored in USIM and ARPF, deriving CK/IK, KAUSF, KSEAF, KAMF, and subsequent NAS and AS keys with separation between security contexts.
- Key derivation function tests
- ARPF/UDM hardening evidence
- USIM personalization audit
- Key separation not validated across contexts
- Long-term keys not in HSM
- Derived keys logged
Management Security
Operations and management interfaces to 5G NFs must be authenticated, encrypted, and logged. Administrative access requires strong authentication, role separation, and privileged access management.
- PAM configuration
- Admin access logs
- MFA enrollment for ops staff
- Shared admin accounts
- Unencrypted SNMP
- No session recording for privileged actions
Non-3GPP Access Security
Security for access to 5G core via untrusted non-3GPP access networks through N3IWF
- N3IWF configuration baseline and IPsec tunnel policy
- TNGF authentication flow records for trusted non-3GPP access
- Wireline 5G access (W-5GAN) security configuration
- EAP based authentication test logs for non-3GPP access
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Provide operators with visibility into active security parameters and ability to configure algorithm preferences.
- Security configuration dashboard
- Algorithm preference policy
- Operator runbook
- No security visibility tooling
- Static configurations
- Missing operator training
Security for access to 5G core via wireline access networks
- N3IWF configuration baseline and IPsec tunnel policy
- TNGF authentication flow records for trusted non-3GPP access
- Wireline 5G access (W-5GAN) security configuration
- EAP based authentication test logs for non-3GPP access
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Privacy
Privacy protections include SUCI concealment, GUTI reallocation, paging strategies that avoid permanent identifier leakage, and minimization of subscriber data in signaling outside trust boundaries.
- GUTI reallocation policy
- Paging configuration
- Privacy impact assessment
- GUTI reallocation infrequent
- Tracking via persistent identifiers possible
- PIA not completed
Roaming Security
Security Edge Protection Proxies protect signaling between visited and home PLMNs over N32, using TLS for N32-c and PRINS (application layer security) for N32-f to handle IPX intermediaries.
- SEPP certificate inventory
- PRINS policy
- IPX agreement documents
- N32 message inspection rules
- TLS-only N32-f without PRINS
- Modification rules unreviewed
- IPX trust assumptions undocumented
Steering of roaming information sent to UE must be protected for authenticity and integrity using SoR-MAC to prevent unauthorized PLMN selection manipulation.
- SoR configuration
- UDM SoR procedure logs
- USIM SoR support evidence
- SoR-MAC not enabled
- UE acknowledgment not enforced
- List update freshness not managed
SBA Security
5G SBI between Network Functions must be protected using TLS 1.2 or higher with mutual authentication via certificates. Direct communication may use OAuth 2.0 for service authorization.
- TLS certificate inventory
- OAuth 2.0 token policies
- NF profile registrations
- Self-signed certificates in production
- TLS 1.2 with weak ciphers
- Mutual TLS not enforced
NF service consumers must obtain access tokens from the NRF to invoke services on NF service producers. Tokens must be validated for scope, audience, expiry, and signature.
- NRF configuration
- OAuth scope definitions
- Token validation logs
- Scope checks omitted
- Long token lifetimes
- NRF compromise risk not modeled
Security Architecture
5G security architecture defines security domains including UE, access network, serving network, and home network, with trust boundaries that govern key derivation, authentication, and authorization flows.
- Security domain diagrams
- Trust model documents
- Interface specifications
- Roaming agreements
- Trust boundaries not documented for partners
- Domain assumptions not validated
- Roaming interface threats unaddressed
Security for NAS and AS Protocols
Protect access stratum traffic via PDCP layer integrity and ciphering for user plane and RRC signalling.
- PDCP configuration
- AS SMC validation
- User plane integrity enablement record
- UP integrity disabled
- Missing AS SMC verification
- Mismatched algorithm IDs
RRC and UP security over air interface including ciphering and integrity protection
- AS security mode command sequence test logs
- RRC and UP integrity and ciphering algorithm policy
- Key hierarchy and refresh policy documentation
- Capture and analysis of RRC security mode procedures
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Key derivation hierarchy from KAUSF to KgNB, KNAS and lower-level keys
- AS security mode command sequence test logs
- RRC and UP integrity and ciphering algorithm policy
- Key hierarchy and refresh policy documentation
- Capture and analysis of RRC security mode procedures
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Maintain security context during intra and inter system handovers with proper key refresh and vertical key derivation.
- Handover key derivation logs
- Xn/N2 handover test results
- Key refresh policy
- Reused keys across cells
- No NCC counter validation
- Missing handover security tests
Security for Specific Services
Security considerations and requirements for network slicing
- Network slice security policy and slice isolation design
- NSSAI authentication and authorisation records
- Slice-specific key derivation and lifecycle documentation
- Penetration test report covering inter-slice isolation
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Security for Multi-access Edge Computing in the 5G system
- MEC platform hardening baseline and security configuration
- Edge node onboarding and attestation records
- Application-to-edge authentication flows
- Edge platform vulnerability scan reports
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Security considerations for Ultra-Reliable Low-Latency Communication services
- URLLC security profile referencing latency-aware controls
- Integrity protection algorithm selection records
- URLLC test reports showing meeting of security SLOs
- Threat model for ultra-reliable low-latency communications
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Security for Integrated Access and Backhaul nodes
- IAB node integration and authentication procedure records
- Backhaul security key hierarchy documentation
- IAB topology diagrams with trust boundaries
- IAB security test reports per 3GPP profile
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Service Based Architecture Security
Security for NF registration, discovery and authorization using NRF
- NRF configuration baseline with TLS and mutual authentication settings
- OAuth 2.0 access token policy and scope definitions for NFs
- SBA topology diagram with security boundaries
- NF profile registration approval workflow records
- Audit logs of NF discovery requests and access token issuance
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Use OAuth 2.0 client credentials grant for NF to NF service authorization with NRF as authorization server.
- Authorization server configuration
- Token validation policy
- NRF audit logs
- No token scope enforcement
- Long lived tokens
- Missing NRF audit trail
Secure inter PLMN N32 interface using SEPP with application layer protection (PRINS) or TLS, including topology hiding.
- SEPP configuration
- N32-c handshake logs
- Topology hiding policy
- No SEPP deployed
- Missing JWE protection for N32-f
- Topology leaks in error messages
NF service consumer authorization using OAuth 2.0 tokens issued by NRF
- NRF configuration baseline with TLS and mutual authentication settings
- OAuth 2.0 access token policy and scope definitions for NFs
- SBA topology diagram with security boundaries
- NF profile registration approval workflow records
- Audit logs of NF discovery requests and access token issuance
- Missing or weak mutual authentication between network functions
- OAuth scope definitions overly broad for NF access
- Slice isolation not validated by independent testing
- Key hierarchy refresh policy not enforced
Service Security
5G IMS services use SIP signaling with security mechanisms including IMS AKA, IPsec, and TLS to protect signaling and media between UE and IMS core.
- IMS AKA configuration
- SIP TLS settings
- Media encryption (SRTP) policy
- SIP over UDP unprotected
- SRTP not enforced
- P-CSCF security capabilities outdated
Signaling Security
NAS signaling between UE and AMF must be integrity protected and confidentiality protected using NAS keys derived from KAMF, with negotiated algorithms from the 5G security algorithm set.
- NAS SMC test reports
- Algorithm policy
- AMF configuration
- Null algorithm permitted in production
- Algorithm downgrade detection missing
- Replay window not configured
Access Stratum security protects RRC signaling and user plane between UE and gNB using AS keys derived from KgNB, with PDCP-layer ciphering and integrity protection.
- gNB configuration
- PDCP test reports
- UP integrity policy from SMF
- UP integrity disabled at high rates
- Integrity policy not enforced per slice
- Key change on handover not verified
SMC procedures activate NAS and AS security. The network selects algorithms based on UE security capabilities, with bidding-down attack prevention by including UE capabilities in protected SMC.
- SMC trace logs
- Algorithm selection policy
- Bidding-down test cases
- Capability echo not verified
- Algorithm policy permits weak choices
- SMC reject handling untested
Slicing
Network slice isolation must prevent cross-slice information leakage and ensure that authentication, authorization, and access for one slice cannot affect another slice. Slice-specific authentication may apply.
- Slice isolation architecture
- NSSAA configuration
- Slice access policies
- Shared NF without slice tagging
- NSSAA not deployed
- Slice boundary leakage in OAM
User Plane
User plane integrity protection may be enabled per-DRB based on SMF policy and UE/gNB capability. Full-rate UP integrity is mandated for 5G UEs to mitigate user plane manipulation attacks.
- UP integrity policy templates
- UE capability matrices
- gNB capability reports
- UPIP disabled by default
- Policy not enforced per slice
- Legacy UE assumption blocks UPIP
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.