5G-ENSURE Security research archive

Reference · Standardisation

3GPP releases: where each security feature actually arrived

Security features in mobile networks arrive on a schedule, in numbered sets. Knowing which set a feature belongs to is what separates a protection that is deployed from one that is merely specified.

Figure 1

What each release group changed

Surface Release 13 and 14 Release 15 Release 16 and 17 Permanent identity over the air Open, as in every earlier generation Concealment specified, mandatory tosupport Concealment unchanged, deploymentoptional False base station Not addressed Not addressed Studied, detection left to the network Interconnect signalling Trusted by assumption Policed at a dedicated edge element Extended as roaming models multiply Devices that are not phones Narrowband device classes added Carried into the 5G core A middle device class added

Figure 1. Read a row rather than a column: a surface is rarely closed in one release, and the two rows still open in the rightmost column are the reason this silo exists. The pages below set out each group in detail.

1Premise

Why the release number is the useful unit

Mobile network specifications are developed continuously and frozen periodically. Each freeze is given a number, and that number becomes the reference point for everything downstream: chipsets are built to a release, networks are upgraded to a release, and a feature that exists in a later release does not exist in a network that has not reached it.

For security this matters more than it does for most features, because a protection is only as present as its weakest available alternative. A network that supports a modern protection and also still carries an older generation offers both, and a device will use whichever it ends up on. Asking whether a protection exists is therefore the wrong question; the useful questions are which release introduced it, whether the deployment has that release, and whether anything older is still reachable.

This is the reason the pages here are organised by release instead of by topic. A topic page can say that subscriber identities are concealed on 5G. Only a release view makes it obvious that the concealment arrived with the first 5G set, that the generations running beside it never had it, and that whether it is switched on was left to the operator.

2Pages

The releases, grouped

Three pages covering five releases: the pre-5G groundwork, the first 5G security architecture, and the two phases that extended it.

The archive’s own account of the standardisation process, written from inside it while it was happening, is on the standardisation page.

3Lag

The gap between a release and a network

A release being frozen starts a long process. The specification has to be implemented in chipsets, which then have to appear in devices, and in network equipment, which then has to be bought, installed and configured by operators whose upgrade cycles are measured in years and whose priorities are driven by capacity before security. A feature specified in one year is commonly serving subscribers four or five years later, and in some markets considerably longer.

Two consequences follow, and both come up constantly in discussions of mobile network security. The first is that the answer to whether a protection exists depends on which question is being asked: it can be specified, implemented, deployed, and switched on, and those are four different states with years between them. The second is that older generations are not decommissioned when a new one arrives. They keep carrying traffic, often for coverage in places the new radio does not reach, and a device that can use them will use them when it has to.

That is why a release-by-release account is more useful here than a list of 5G security features. A feature list invites the conclusion that the protections are in force. The release view makes visible that each one has a date, that networks reach those dates unevenly, and that the weakest generation a device can be induced onto is the one that determines its exposure. The mechanism by which that inducement works is described on the false base station page, and it is the reason a fallback to an older generation matters as much as anything in the current one.

QQuestions

Questions and answers

What is a 3GPP release?

A numbered, frozen set of specifications. Work on features proceeds continuously, but at intervals the current state is declared complete and given a number, so that equipment makers and operators have a fixed target to build against. A release is therefore a boundary in time, not a product, and a feature belongs to the release in which its specification was frozen.

Which release is 5G?

Release 15 carried the first complete 5G set, in two stages: a non-standalone configuration that used a 4G core, and then the standalone configuration with the 5G core. Releases 16 and 17 are also 5G and extended it considerably, so "5G" names a family that begins at 15, not a single release.

Why do these pages stop at Release 17?

Because that is where the security story this archive belongs to has settled into ordinary maintenance. The releases after it continue to add features, and the identity and interface protections that this collection’s subject turns on were established across 15 to 17.

Does the archive itself cover these releases?

Only the earliest of them, and only from the outside. The project closed while the first 5G set was still being finalised, so its own documents describe the problem mid-transition. The distinction is kept explicit throughout.