Free preview · Cryptographic inventory: where 5G uses key pairs — opens in the course player
5G Security: SUCI to Post-Quantum
Security read the way a specification writes it: what is implemented against what is actually used, what a token reaches by default, what a protection policy may not lower, and which assurance evidence answers which question. It ends on post-quantum as an inventory exercise with owners and clocks, not a horizon.
What you'll learn
- Sort the estate into symmetric-only and asymmetric surfaces, write threat-register rows carrying an attacker level, and walk a SUCI stage by stage.
- Map identity exposure per access type, tell 5G-AKA from EPS-AKA by what the response binds, and inventory every key below the anchor.
- Record what mutual TLS each SBI segment actually uses, read NRF access-token claims and lifetimes, and score 3GPP against the zero-trust tenets.
- Pick the N32 mode each roaming path demands, enforce PRINS modification policy, and read every SEPP hardening requirement by the failure it prevents.
- Decide where transport IPsec is used rather than merely implemented, test the assumptions a virtualised function cannot check, and read assurance evidence honestly.
- Separate what Shor breaks from what Grover weakens, class every asset as harvest, forge or SUCI risk, and name who owns each migration.
- Rank the GSMA migration phases against your own inventory, weigh standalone against hybrid SUCI profiles, and match each asset to the clock that binds it.
Module 1 — Cryptographic inventory, threat register and SUCI concealment
4 lessons · 1 lab · ≈36 minSort the estate into symmetric-only and asymmetric surfaces, write threat-register rows carrying an attacker level, and walk a SUCI stage by stage.
Module 1 — Cryptographic inventory, threat register and SUCI concealment
4 lessons · 1 lab · ≈36 minSort the estate into symmetric-only and asymmetric surfaces, write threat-register rows carrying an attacker level, and walk a SUCI stage by stage.
- 19:04Cryptographic inventory: where 5G uses key pairsWatch free
- 29:04Threat-model register: assets before adversariesFree with an account
- 38:55SUCI concealment with ECIES: confidentiality, not authenticationFree with an account
- 48:31Protection scheme identifiers: provisioned, selected, computed whereFree with an account
- ~7 minFollow the Key to Its ParentCheckpoint
Nine parts of one reference network, filed by where their keys came from rather than by the algorithm sitting on the row.
Module 2 — Identity exposure, credentials and the keys below the anchor
6 lessons · 1 lab · ≈51 minMap identity exposure per access type, tell 5G-AKA from EPS-AKA by what the response binds, and inventory every key below the anchor.
Module 2 — Identity exposure, credentials and the keys below the anchor
6 lessons · 1 lab · ≈51 minMap identity exposure per access type, tell 5G-AKA from EPS-AKA by what the response binds, and inventory every key below the anchor.
- 110:10Identity exposure after SUCI: concealment is not unlinkabilityRequires subscription
- 28:415G-AKA versus EPS-AKA: the response binds the networkRequires subscription
- 37:33EAP-AKA′: the second primary method, same anchorRequires subscription
- 47:57NAS, RRC and user-plane keys: two parents, six keysRequires subscription
- 58:04NAS Security Mode Command: how bidding-down is caughtRequires subscription
- 68:18NSSAA: slice authorisation with someone else’s credentialsRequires subscription
- ~7 minWhat Did They Walk Away WithCheckpoint
Nine situations with the seal intact, and one verdict each: what does somebody watching actually carry away?
Module 3 — The service-based interface: TLS, tokens and delegated trust
5 lessons · 1 lab · ≈47 minRecord what mutual TLS each SBI segment actually uses, read NRF access-token claims and lifetimes, and score 3GPP against the zero-trust tenets.
Module 3 — The service-based interface: TLS, tokens and delegated trust
5 lessons · 1 lab · ≈47 minRecord what mutual TLS each SBI segment actually uses, read NRF access-token claims and lifetimes, and score 3GPP against the zero-trust tenets.
- 19:58Mutual TLS on the SBI: support is not useRequires subscription
- 29:02NRF Access-Token Claims: type-level by defaultRequires subscription
- 39:19NRF Access-Token Theft: containment without revocationRequires subscription
- 49:15SCP Indirect Communication: what the proxy removesRequires subscription
- 59:54Zero-Trust Tenets Against 3GPP: the scored gapRequires subscription
- ~8 minHow Far Does the Pass Reach?Interactive lab
Assemble a call on the service bus, read what its pass opens — then hand a copy to somebody it was never issued to and see what is left standing.
Module 4 — N32 interconnect beyond the border guard
4 lessons · 1 lab · ≈34 minPick the N32 mode each roaming path demands, enforce PRINS modification policy, and read every SEPP hardening requirement by the failure it prevents.
Module 4 — N32 interconnect beyond the border guard
4 lessons · 1 lab · ≈34 minPick the N32 mode each roaming path demands, enforce PRINS modification policy, and read every SEPP hardening requirement by the failure it prevents.
- 19:17N32-c and N32-f: the rule that picks the modeRequires subscription
- 29:01PRINS on N32-f: encrypt some, sign the editsRequires subscription
- 36:50N32-f protection floor: what the protection policy cannot lowerRequires subscription
- 48:45SEPP hardening requirements: read each one by its failureRequires subscription
- ~8 minWhat the Middle Can ReadInteractive lab
One roaming border. Settle what sits in the path, take the mode the specification leaves you, then switch the policy on one kind at a time and watch how little moves.
Module 5 — Transport, substrate, slices and the management plane
5 lessons · 1 lab · ≈35 minDecide where transport IPsec is used rather than merely implemented, test the assumptions a virtualised function cannot check, and read assurance evidence honestly.
Module 5 — Transport, substrate, slices and the management plane
5 lessons · 1 lab · ≈35 minDecide where transport IPsec is used rather than merely implemented, test the assumptions a virtualised function cannot check, and read assurance evidence honestly.
- 18:04RAN transport IPsec: implemented, then decidedRequires subscription
- 27:57Virtualised network-function trust: four assumptions to verifyRequires subscription
- 35:23Slice isolation security: what an SLA can promiseRequires subscription
- 47:05OAM and orchestration plane: where recorded intrusions landedRequires subscription
- 56:43NESAS and SCAS: what assurance evidence provesRequires subscription
- ~6 minWhat the Folder ProvesCheckpoint
A release arrives with a folder of evidence, and it is tempting to read the folder as one verdict. File each question under whatever could actually answer it — including the ones nothing in the folder ever will.
Module 6 — Post-quantum readiness: the honest threat model
4 lessons · 1 lab · ≈36 minSeparate what Shor breaks from what Grover weakens, class every asset as harvest, forge or SUCI risk, and name who owns each migration.
Module 6 — Post-quantum readiness: the honest threat model
4 lessons · 1 lab · ≈36 minSeparate what Shor breaks from what Grover weakens, class every asset as harvest, forge or SUCI risk, and name who owns each migration.
- 18:32Shor versus Grover on 5G: what breaks, what weakensRequires subscription
- 28:27Harvest-now, forge-later and SUCI: three exposure timelinesRequires subscription
- 310:05Asymmetric surface map: who owns each migrationRequires subscription
- 49:22Cryptographic agility and diversity: a slot, not a weldRequires subscription
- ~6 minWhat They Had to Hold AlreadyCheckpoint
The same surfaces as lesson one, filed this time by what an attacker would have had to hold before a key-recovering machine was worth anything.
Module 7 — Post-quantum readiness: the migration
4 lessons · 1 lab · ≈37 minRank the GSMA migration phases against your own inventory, weigh standalone against hybrid SUCI profiles, and match each asset to the clock that binds it.
Module 7 — Post-quantum readiness: the migration
4 lessons · 1 lab · ≈37 minRank the GSMA migration phases against your own inventory, weigh standalone against hybrid SUCI profiles, and match each asset to the clock that binds it.
- 18:06GSMA post-quantum migration phases: the ranking is yoursRequires subscription
- 29:56Post-quantum SUCI profiles: standalone and hybrid, bothRequires subscription
- 39:20Hybrid key exchange in IKEv2: the measured costRequires subscription
- 49:22Post-quantum migration clocks: which one binds which assetRequires subscription
- ~7 minEvery Row Names Its SourceCheckpoint
The finished migration plan, audited a line at a time: which cells carry somebody else’s conclusion, which carry a measurement, and which are yours to sign.
New to the terminology? Look up any acronym in the telecom glossary.
Take the certification exam
Earns a certificate49 questions · 60 min · 65% to pass. Score 65%+ to earn your TELCOMA Certified 5G Security Specialist — a QR-verifiable certificate.
Not ready yet? Take a free 20-question mock exam first.
Study materials
Download the 5G Security: SUCI to Post-Quantum question bank and slide deck — every signal check in the course, with answers, plus every figure.
- Question BankPDF45 KB
- Slide DeckPPTX21 MB
Unlock every lesson in 5G Security: SUCI to Post-Quantum
Stream all 32 lessons, follow the 7-module path, and earn the TELCOMA 5G Security Specialist certificate.
- Every module unlocked
- Labs & full-length practice exams
- Verifiable certificate
- TELCOMA since 2009