5G NR Security Basics | 5G NR Security Termination Points

This page describes 5G NR Security Basics. It mentions 5G NR security key derivation algorithm and 5G NR Security Termination Points.

The Wireless security is very critical due to its open air interface since its evolution. Due to this various wireless technologies such as GSM, 3G, LTE, 5G uses various security algorithms to provide robust wireless connection to the users. The purpose is to provide confidentiality and integrity protection of data and signaling across various points across the 5G network.

5G NR provides security of following.
• For User data (i.e. DRBs)
• For RRC Signalling (i.e. SRBs)

5G NR Security Key Derivation

5G security key derivation

The figure-1 depicts 5G security key derivation algorithm as 5G NR standard. Following table-1 mentions meanings of symbols used in the algorithm.

Keys Description
Keys for AMF • KAMF derived by ME
Keys for NAS signalling • KNAS(int) derived by ME and AMF from KAMF
• KNAS(enc) derived by ME and AMF from KAMF
Keys for gNB • KgNB derived by ME and AMF from KAMF
Keys for UP traffic KUP(enc), KUP(int)
Keys for RRC Signalling KRRC(int), KRRC(enc)
Other intermediate keys • NH: derived by ME and AMF to provide forward security
• KgNB* derived by ME and gNB when performing a horizontal or vertical key derivation.

5G NR Security Key Termination Points

Following are the 5G NR security termination points as described in 3GPP TS 38.300 Release 15 document.

Security Point Ciphering Integrity Protection
NAS Signaling AMF AMF
RRC Signaling gNB gNB
User Plane Data gNB gNB

• 3GPP TS 38.300 V15.2.0 (June 2018), NR and NG-RAN Overall Description; Stage 2

