The 5G security architecture is a standards-defined protocol framework that extends beyond 4G LTE by mandating SUPI/SUCI subscriber identity concealment, mutual network authentication, and network slicing isolation as structural controls.
Those structural changes address specific, documented weaknesses in 4G LTE design. Passive subscriber tracking via IMSI catchers, absent user-plane integrity protection, and a flat authentication model that left network-to-device trust implicit were all known problems before 5G standardization began. The 5G security architecture encodes the fixes at the specification level rather than leaving them to operator configuration. How well those fixes hold depends on whether an operator deploys a non-standalone network (NSA) relying on existing 4G core infrastructure or a standalone network (SA) running a native 5G core, and on how rigorously slice isolation and integrity protection are enforced in practice.
How 4G LTE Handles Security

4G LTE security centers on the Evolved Packet System Authentication and Key Agreement protocol, known as EPS-AKA, a mechanism for SIM-based mutual authentication between a device and the network. The protocol establishes session keys for both confidentiality and control-plane integrity, but it carries structural limitations that became exploitable at scale.
- EPS-AKA (Evolved Packet System Authentication and Key Agreement)
- The mutual authentication protocol governing 4G LTE access. A device and the home network exchange credentials derived from the SIM to establish shared session keys. The exchange proves device legitimacy but does not require the network to prove its own identity to the device in all deployment configurations, leaving a gap that rogue base stations can exploit.
- IMSI (International Mobile Subscriber Identity)
- The permanent subscriber identifier transmitted in cleartext over the 4G LTE air interface during certain attach procedures. An IMSI catcher, also called a stingray or fake base station, exploits this exposure to track or intercept a subscriber without operator awareness.
- User-Plane Integrity Protection
- A cryptographic check ensuring that data packets between a device and the network have not been altered in transit. 4G LTE mandates confidentiality (encryption) for the control plane but does not require integrity protection for the user plane by default. That gap allows an attacker with radio access to modify user-plane traffic without detection.
- 4G LTE Encryption Algorithms
- 4G LTE supports AES-128, SNOW 3G, and ZUC as cipher options for both confidentiality and control-plane integrity. Cipher selection is negotiated per session; the encryption algorithm choice affects both performance and security posture, but optional user-plane integrity remains the larger structural gap.
The IMSI exposure problem in 4G LTE is not theoretical. SS7 (Signaling System 7) protocol weaknesses in the core network compound the radio-layer vulnerability, allowing subscriber location and call-intercept attacks that traverse legitimate carrier infrastructure. These are inherited design constraints, not implementation errors, which is why 5G security required a specification-level response rather than a patch.
What 3GPP TS 33.501 Changes in 5G
The 5G security architecture is defined in 3GPP TS 33.501, the governing specification for 5G System security procedures, which originated in Release 15 and has been maintained through Release 20 per the 3GPP specification portal. The two core authentication protocols introduced are 5G-AKA and EAP-AKA prime (Extensible Authentication Protocol-AKA'), both of which add explicit network authentication and subscriber identity concealment absent from EPS-AKA.
Subscriber identity concealment is the architectural mechanism that addresses the IMSI exposure problem in 4G LTE. In 5G, each subscriber has a SUPI (Subscription Permanent Identifier), the permanent identifier stored on the SIM, and a SUCI (Subscription Concealed Identifier), a per-transmission encrypted form of the SUPI. The SUCI is generated on the device using the home network's public key before any identifier is transmitted over the air interface, so a passive observer capturing radio traffic cannot recover the SUPI. Subscriber identity concealment is enforced at the specification level in 5G-AKA, not left as an operator option.
| Dimension | 4G LTE (EPS-AKA) | 5G (5G-AKA / EAP-AKA prime) |
|---|---|---|
| Authentication model | Device authenticates to network; network-to-device proof is implicit in some configurations | Explicit mutual authentication mandated; both sides prove identity |
| Subscriber identifier over air | IMSI transmitted in cleartext on attach; vulnerable to IMSI catchers | SUCI (concealed form of SUPI) transmitted; permanent identifier never exposed over air |
| Identity concealment mechanism | None specified; TMSI (Temporary Mobile Subscriber Identity) used after initial attach but IMSI exposed at attach | SUPI/SUCI concealment mandated; home network public key encrypts identifier before transmission |
| Home network verification | Limited; visited network carries significant trust by default | Home network explicitly verifies authentication vectors, reducing roaming interception risk |
| Governing specification | The 4G LTE (EPS) security architecture specification | The 5G System security architecture specification |
EAP-AKA prime supports certificate-based authentication paths relevant to enterprise and IoT deployments, while 5G-AKA preserves SIM-based authentication for consumer mobile. Both protocols feed into the same subscriber identity concealment framework, and both require mutual authentication as a non-negotiable baseline under the 5G security architecture specification.
Encryption and Integrity Protection
The 5G security architecture shares cipher families with 4G LTE but changes the mandate scope significantly. Both generations support AES, SNOW 3G, and ZUC as encryption algorithm options for air-interface protection. The 5G specification defines these as NEA1 (AES), NEA2 (SNOW 3G), and NEA3 (ZUC) for confidentiality, and NIA1/NIA2/NIA3 as the corresponding integrity algorithm set. For TLS and transport-layer encryption at the application layer, 5G NR networks operate the same way as any IP-routed network, so the air-interface gains described here are complementary to, not replacements for, application-layer protections.
| Protection Layer | 4G LTE | 5G NR |
|---|---|---|
| Control-plane confidentiality | Mandatory (AES-128, SNOW 3G, ZUC) | Mandatory (same cipher families, NEA0-3 designations) |
| Control-plane integrity protection | Mandatory | Mandatory |
| User-plane confidentiality | Mandatory | Mandatory |
| User-plane integrity protection | Optional; not required by default | Mandatory for standalone deployments |
| Encryption algorithm negotiation | Per-session cipher negotiation between device and network | Same negotiation model; operator priority list governs selection |
The user-plane integrity protection mandate in 5G is the operationally significant difference. In 4G LTE, an attacker with radio access who bypassed confidentiality could alter data in transit without the endpoint detecting modification. The 5G specification closes that gap by requiring integrity checks on the user plane for SA deployments. The CISA 5G Security and Resilience framework identifies this as one of the protocol-level improvements distinguishing 5G from its predecessor, noting that the 5G security architecture addresses weaknesses in prior-generation designs through specification-level controls rather than vendor-specific mitigations, per the CISA 5G security and resilience guidance.
Network Slicing and Isolation
Network slicing has no equivalent in 4G LTE. The 5G service-based architecture enables operators to partition a single physical radio access network (RAN) and core into logically isolated virtual networks, each with independent traffic handling, quality-of-service policies, and security parameters. Correct implementation of slice isolation is what limits lateral movement between service domains sharing physical infrastructure.
- Logical isolation per slice: Each network slicing instance receives its own control-plane and user-plane functions within the 5G core. Traffic from an industrial IoT slice does not traverse the same logical path as traffic from a consumer broadband slice on the same physical base station infrastructure.
- Lateral movement containment: A compromise in one slice, such as a malformed packet or a compromised IoT endpoint, does not propagate to adjacent slices when isolation is correctly configured. The RAN and core enforce slice boundaries through dedicated network function instances and separated session management.
- Security parameter independence: Different slices can carry different authentication requirements, encryption algorithm priorities, and integrity protection policies. A mission-critical slice for emergency services can enforce stronger controls than a general-purpose consumer slice without affecting the other's performance.
- Implementation dependency: The isolation guarantees that network slicing provides are specification-level. Misconfigured shared network functions, inadequate slice-level monitoring, or shared management plane components can undermine isolation in practice. Applying zero trust network architecture principles to slice access control reduces the residual risk from implementation gaps.
The commercial case for network slicing is that it enables operators to run consumer, enterprise, and critical infrastructure traffic on shared physical deployments without security boundary trade-offs. The security case is that it limits blast radius: an incident on one slice does not automatically become an incident across all services on the same RAN.
Non-Standalone vs Standalone Deployment Risk
The non-standalone network (NSA) deployment model is the architectural reality for most 5G rollouts today. In NSA mode, the 5G new radio (NR) provides the radio access network layer while control-plane functions remain anchored to the existing 4G evolved packet core (EPC). CISA's 5G strategy documentation explicitly notes that initial 5G deployments operate in NSA mode and that the transition to standalone network (SA) architecture, where a native 5G core replaces the 4G EPC entirely, will take years across most markets, per the CISA 5G Strategy.
The security implications of NSA deployment are concrete. The non-standalone network inherits vulnerabilities from the 4G core it depends on, including SS7 weaknesses and the absence of 5G-native subscriber identity concealment on signaling paths that traverse the EPC. The following risks are specific to NSA deployments and resolve only when operators migrate to SA architecture.
- 4G core vulnerability inheritance: The non-standalone network relies on EPC functions for session management and mobility. Any SS7 or Diameter protocol weakness in the 4G core remains exploitable regardless of the 5G NR radio layer above it.
- Incomplete subscriber identity concealment: SUPI/SUCI concealment protects the air interface in 5G NR, but signaling paths that revert to the 4G core for control-plane functions may expose subscriber identifiers in legacy formats that do not apply the SUCI mechanism.
- User-plane integrity protection gaps: The 5G NR specification mandates user-plane integrity protection for SA deployments. NSA deployments that route user-plane traffic through the 4G EPC may not enforce the same integrity protection requirements, depending on operator configuration.
- Network slicing unavailability: Full network slicing as defined in the 5G service-based architecture requires a native 5G core. NSA deployments cannot implement slice isolation at the core level, meaning the isolation benefits described in the previous section are not available until SA migration completes.
- Extended transition window: Migration from NSA to SA requires core network replacement, not just radio upgrades. Operators in markets with large installed 4G infrastructure bases face multi-year transition timelines, during which the non-standalone network model and its inherited risk profile remain the operational reality.
Threat Model Comparison: Inherited vs New Attack Surface
A threat model for 5G must account for two distinct attack surface categories: vulnerabilities inherited from 4G LTE that persist in NSA deployments, and new vectors introduced by the 5G security architecture's software-defined design. The 5G security specification addresses the first category through protocol changes; the second category is an expansion of scope that did not exist in 4G LTE. Monitoring both surfaces with SIEM and SOAR threat detection tooling is standard practice for critical infrastructure operators running 5G.
| Threat Category | 4G LTE Exposure | 5G Exposure |
|---|---|---|
| Subscriber identity tracking | IMSI catchers exploit cleartext IMSI on air interface; well-documented rogue base station technique | SUPI/SUCI concealment significantly reduces passive tracking; residual risk in NSA deployments where 4G core handles signaling |
| Core network signaling | SS7 protocol weaknesses enable location tracking and call interception via legitimate carrier infrastructure | SA deployments replace SS7 paths with HTTP/2-based service-based interfaces; NSA deployments retain SS7 exposure through the 4G EPC |
| Radio access network spoofing | Rogue base stations can force device attachment; EPS-AKA does not mandate explicit network-to-device proof in all configurations | Mutual authentication in 5G-AKA and EAP-AKA prime raises the bar; network must prove identity to device |
| Software-defined network components | Limited; 4G core functions largely hardware-based and vendor-specific | 5G service-based architecture introduces virtualized network functions with API attack surface; software vulnerabilities in network function implementations become network-layer risks |
| Disaggregated radio access network | Monolithic RAN vendor model limits supply chain exposure surface | Open RAN architectures disaggregate hardware and software; supply chain risk expands to software components from multiple sources |
| Critical infrastructure exposure | Network slicing unavailable; all services on shared infrastructure with no logical isolation | Misconfigured slices on critical infrastructure deployments create lateral movement paths that do not exist when isolation is correctly enforced |
The threat model shift is additive, not purely subtractive. 5G resolves several 4G LTE vulnerabilities at the specification level. It also introduces a software-defined attack surface that 4G LTE did not have, and the expanded RAN architecture creates supply chain considerations that a monolithic hardware model did not present. Operators treating the 5G security architecture as a complete solution without addressing the new software-defined and supply chain vectors will have an incomplete threat model.
Security Maturity: What to Evaluate When Deploying 5G
The 5G security architecture provides structural controls that 4G LTE does not, but realizing those controls requires deliberate configuration choices. Operators and enterprises deploying 5G for critical infrastructure should evaluate the following before treating the deployment as a security improvement over the previous generation.
- Confirm NSA or SA deployment mode: The non-standalone network and standalone network carry materially different security properties. Identify which 4G core functions the deployment still relies on and map those dependencies to the threat model before assuming 5G security controls are fully active.
- Verify user-plane integrity protection enforcement: Integrity protection on the user plane is mandatory for SA deployments under the 5G standalone security specification. For NSA deployments, verify whether the operator has configured integrity protection at the 5G NR layer or whether it reverts to 4G LTE behavior on the core path.
- Audit network slicing configuration: If the deployment uses network slicing for service separation, audit slice boundary enforcement at both the RAN and core levels. Confirm that shared management-plane components do not create implicit paths between slices, and that each slice's security parameter set matches its traffic classification.
- Assess RAN supplier security posture: The radio access network supplier's software security practices matter more in disaggregated Open RAN deployments than in monolithic RAN architectures. Review the supplier's vulnerability disclosure and patching cadence as part of the supply chain risk assessment.
- Validate subscriber identity concealment scope: Confirm that SUPI/SUCI concealment applies to all attach and re-attach procedures in the deployment. In NSA mode, identify which signaling paths traverse the 4G EPC and whether those paths carry subscriber identifiers in legacy formats without concealment.
No deployment is fully SA from day one in most markets, and the transition from NSA to SA is a multi-year infrastructure program. The practical question for operators is not whether 5G is more secure than 4G LTE in the abstract, but which specific controls from the 5G security architecture are active in their deployment today and which remain deferred to a future SA migration.
References
- CISA: 5G Security and Resilience.primary US government guidance on 5G security controls and critical infrastructure considerations.
- CISA 5G Strategy (PDF).covers NSA/SA transition timelines, inherited vulnerability framing, and federal 5G security posture.
- 3GPP TS 33.501: Security Architecture and Procedures for 5G System.governing specification for 5G-AKA, EAP-AKA prime, SUPI/SUCI concealment, and user-plane integrity protection mandates.
- ETSI: Mobile 4G Standards Overview.ETSI overview of the 4G LTE standards framework, including EPS-AKA and the encryption algorithm baseline.
Further reading
Frequently Asked Questions
Does 5G automatically eliminate IMSI catcher attacks?
No. SUPI/SUCI concealment in 5G protects the subscriber identifier over the air interface, making passive IMSI-catcher interception significantly harder, but does not eliminate all identity-exposure vectors, particularly in non-standalone deployments that still depend on a 4G core.
Is user-plane integrity protection mandatory in 5G?
Yes, for 5G standalone networks. The 5G standalone security specification introduced mandatory user-plane integrity protection, which was absent as a default requirement in 4G LTE. Operators deploying 5G in non-standalone mode may inherit 4G core behavior and should verify enforcement explicitly.
What security risks does a non-standalone 5G deployment inherit from 4G?
Non-standalone 5G networks rely on the existing 4G evolved packet core for control-plane functions. CISA notes this dependency means NSA deployments carry forward 4G vulnerabilities including SS7-related weaknesses in the core and the absence of 5G-native subscriber identity concealment in signaling paths that traverse the 4G core.









