Reference · Release 13 and 14
Release 13 and 14: the groundwork the 5G security set was built on
Neither release was 5G and neither closed the identity problem. Both added the kinds of device the 5G security architecture would afterwards have to be written around.
Published
1Release 13
Release 13: machine-type communication at scale
The defining additions in Release 13 were about devices that are not phones. Narrowband and low-complexity machine-type categories were specified to make it practical to attach very large numbers of cheap, low-power devices to a mobile network: meters, sensors, trackers, things expected to run for years on a battery and to send small amounts of data infrequently. The release also added means of using unlicensed spectrum alongside licensed, and further antenna work on the radio side.
None of that is a security feature, and the security specifications of the release are largely continuous with what preceded them. The significance is in what it committed the network to serving. A handset has a power budget that can absorb cryptographic work, an owner who notices when it misbehaves, and a replacement cycle of a few years. The new categories have none of the three. A device that must last a decade on one battery cannot afford expensive protocol exchanges, has nobody watching it, and will still be in service long after the assumptions behind its credentials have expired.
That is the constraint the archive’s own work on group authentication addresses: if authenticating each device individually is too expensive for a population of this size and this power budget, the exchange has to be restructured.
2Release 14
Release 14: vehicles, broadcast, and the studies underneath
Release 14 added direct vehicular communication, allowing vehicles to exchange messages with each other and with roadside equipment, and extended the broadcast and multicast capabilities. It also carried a substantial body of study work whose output landed in the release that followed, which is the ordinary rhythm of the process: the investigation happens in one release and the specification in the next.
The vehicular work introduced a security problem that does not arise for handsets. A vehicle broadcasting its position and speed to whatever is nearby has to be believable without being identifiable, because a receiver needs to know the message is genuine and a bystander must not be able to follow the vehicle by listening. Those two requirements pull against each other, and the resolution involves rotating credentials instead of a single durable identity. It is the same tension that the subscriber identity presents, in a setting where the answer had to be found immediately.
What neither release did was revisit the disclosure of the permanent subscriber identity. The problem was well documented by this point, the equipment to exploit it was commonplace, and the fourth generation ended with the fallback intact. A fix would have meant changing the exchange that every existing device already implemented, and that is the kind of change a new generation absorbs and a maintenance release does not.
3Inheritance
What the first 5G set inherited from them
Read forwards from here, the shape of Release 15’s security work is easier to follow. It arrived with a network expected to serve handsets, constrained long-lived devices and vehicles at once, in a core that had been redesigned as a set of services. The identity problem was the outstanding item on a list that the previous two releases had lengthened.
Release 15 is where the identity disclosure, the key hierarchy and the protection of the new interfaces are all addressed together, and where the concealment described on the concealment page is introduced.
DRecords
Specifications in this archive that bear on it
The device population these releases added is the subject of the archive’s work on admitting constrained devices efficiently and on constraining what an admitted device may reach.
| Cluster | Specification | Concern | Pages |
|---|---|---|---|
| T3.1 | IoT group AKA | Group authentication for constrained devices | 13 |
| T3.5 | Micro-segmentation | Segment boundaries inside the network | 13 |
| T3.5 | Access control | Access control at management interfaces | 12 |
QQuestions
Questions and answers
Were Releases 13 and 14 5G?
No. Both are fourth-generation releases, and the first 5G radio and core specifications were frozen in Release 15. They matter to a 5G security account because they introduced the device classes and use cases that the 5G security architecture then had to accommodate.
What was the most consequential addition for security?
The low-cost, long-lived device categories. They changed no security mechanism directly; they changed the population the mechanisms had to serve, introducing devices with constrained power budgets and service lives measured in years, against the two or three of a handset.
Did they address the identity disclosure problem?
No. The permanent subscriber identity was still transmitted in the clear in the circumstances that made it collectable, and it remained so for the whole of the fourth generation. That is the gap the first 5G set closed.
Why group two releases on one page?
Because their security significance is the same significance: neither introduced a headline security mechanism, and both are consequential for what they added to the device population. Separating them would produce two pages making the same point about different feature lists.