[Paper Review] The current state of affairs in 5G security and the main remaining security challenges
This paper analyzes the current state of 5G protocol security, identifying critical vulnerabilities inherited from LTE and new flaws in 5G's authentication and privacy mechanisms. It proposes integrating a public key infrastructure with digital certificates to replace trust in pre-authentication messages, enabling end-to-end validation of base station signals and mitigating attacks like IMSI catchers and spoofing.
The first release of the 5G protocol specifications, 3rd Generation Partnership Project (3GPP) Release 15, were published in December 2017 and the first 5G protocol security specifications in March 2018. As one of the technology cornerstones for Vehicle-to-Vehicle (V2X), Vehicle-to-Everything (V2E) systems and other critical systems, 5G defines some strict communication goals, such as massive device connectivity, sub-10ms latency and ultra high bit-rate. Likewise, given the firm security requirements of certain critical applications expected to be deployed on this new cellular communications standard, 5G defines important security goals. As such, 5G networks are intended to address known protocol vulnerabilities present in both legacy GSM (Global System for Mobile Communications) networks as well as current LTE (Long Term Evolution) mobile systems. This manuscript presents a summary and analysis of the current state of affairs in 5G protocol security, discussing the main areas that should still be improved further before 5G systems go live. Although the 5G security standard documents were released just a year ago, there is a number of research papers detailing security vulnerabilities, which are summarized in this manuscript as well.
Motivation & Objective
- Address persistent security vulnerabilities in 5G protocols that stem from legacy LTE and 2G architectures.
- Identify and analyze pre-authentication message-based attacks that bypass current 5G security mechanisms.
- Propose a scalable, cryptographically robust solution to replace implicit trust in base station messages.
- Advocate for the integration of public key infrastructure (PKI) and digital certificates into 5G core architecture to enable end-to-end authentication.
- Highlight the urgent need for a holistic, architecture-level redesign of 5G security beyond point fixes.
Proposed method
- Analyzes 5G Release 15 specifications, focusing on the Authentication and Key Agreement (AKA) protocol and SUPI/SUCI mechanisms.
- Evaluates existing LTE vulnerabilities—especially IMSI catchers and pre-authentication message spoofing—within the 5G context.
- Proposes a digital certificate-based system where base stations sign broadcast messages using operator-issued certificates.
- Introduces time-stamped signatures to prevent replay attacks, enhancing message integrity and authenticity.
- Recommends a hierarchical trust model with a global root CA and regional CAs, with mobile operators as end-entity certificate issuers.
- Advocates for replacing the term 'pre-authentication message' with a cryptographically verified, certificate-secured communication model.
Experimental results
Research questions
- RQ1What are the main security vulnerabilities in 5G protocols that persist from LTE and earlier generations?
- RQ2How do current 5G mechanisms like SUPI and SUCI fail to prevent pre-authentication message-based attacks?
- RQ3What architectural changes are necessary to eliminate implicit trust in base station signals?
- RQ4Can public key infrastructure (PKI) and digital certificates effectively secure 5G broadcast messages and prevent spoofing?
- RQ5What role should a trusted Certificate Authority (CA) and root of trust play in securing the 5G ecosystem at scale?
Key findings
- Despite improvements, 5G's current security model still relies on implicit trust in pre-authentication messages, leaving it vulnerable to spoofing and IMSI/SUPI tracking.
- The SUCI mechanism, while protecting SUPI confidentiality, does not prevent all pre-authentication attacks, especially those exploiting message integrity before AKA execution.
- Researchers have already identified critical flaws in the new 5G AKA protocol, indicating that cryptographic design alone is insufficient without architectural hardening.
- A digital certificate-based solution with time-stamped signatures can effectively prevent replay and spoofing attacks on broadcast messages.
- Integrating PKI with a hierarchical trust model—including a global root CA and operator-level certificate issuance—can provide end-to-end authentication and eliminate trust in unverified base stations.
- The absence of a standardized, system-wide PKI in 5G specifications leaves a critical gap that must be addressed before full-scale deployment.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.