Skip to content
5G/6G Academy
Watch free

Free preview · Cryptographic inventory: where 5G uses key pairs — opens in the course player

TELCOMA 5G Security Specialist

5G Security: SUCI to Post-Quantum

Security read the way a specification writes it: what is implemented against what is actually used, what a token reaches by default, what a protection policy may not lower, and which assurance evidence answers which question. It ends on post-quantum as an inventory exercise with owners and clocks, not a horizon.

32 lessons≈4.6h of video7 modulesEarns TELCOMA 5G Security Specialist

What you'll learn

  • Sort the estate into symmetric-only and asymmetric surfaces, write threat-register rows carrying an attacker level, and walk a SUCI stage by stage.
  • Map identity exposure per access type, tell 5G-AKA from EPS-AKA by what the response binds, and inventory every key below the anchor.
  • Record what mutual TLS each SBI segment actually uses, read NRF access-token claims and lifetimes, and score 3GPP against the zero-trust tenets.
  • Pick the N32 mode each roaming path demands, enforce PRINS modification policy, and read every SEPP hardening requirement by the failure it prevents.
  • Decide where transport IPsec is used rather than merely implemented, test the assumptions a virtualised function cannot check, and read assurance evidence honestly.
  • Separate what Shor breaks from what Grover weakens, class every asset as harvest, forge or SUCI risk, and name who owns each migration.
  • Rank the GSMA migration phases against your own inventory, weigh standalone against hybrid SUCI profiles, and match each asset to the clock that binds it.

Module 1Cryptographic inventory, threat register and SUCI concealment

4 lessons · 1 lab · ≈36 min

Sort the estate into symmetric-only and asymmetric surfaces, write threat-register rows carrying an attacker level, and walk a SUCI stage by stage.

  1. 1
    Cryptographic inventory: where 5G uses key pairsWatch free
    9:04
  2. 2
    Threat-model register: assets before adversariesFree with an account
    9:04
  3. 3
    SUCI concealment with ECIES: confidentiality, not authenticationFree with an account
    8:55
  4. 4
    Protection scheme identifiers: provisioned, selected, computed whereFree with an account
    8:31
  5. Follow the Key to Its ParentCheckpoint

    Nine parts of one reference network, filed by where their keys came from rather than by the algorithm sitting on the row.

    ~7 min

Module 2Identity exposure, credentials and the keys below the anchor

6 lessons · 1 lab · ≈51 min

Map identity exposure per access type, tell 5G-AKA from EPS-AKA by what the response binds, and inventory every key below the anchor.

  1. 1
    Identity exposure after SUCI: concealment is not unlinkabilityRequires subscription
    10:10
  2. 2
    5G-AKA versus EPS-AKA: the response binds the networkRequires subscription
    8:41
  3. 3
    EAP-AKA′: the second primary method, same anchorRequires subscription
    7:33
  4. 4
    NAS, RRC and user-plane keys: two parents, six keysRequires subscription
    7:57
  5. 5
    NAS Security Mode Command: how bidding-down is caughtRequires subscription
    8:04
  6. 6
    NSSAA: slice authorisation with someone else’s credentialsRequires subscription
    8:18
  7. What Did They Walk Away WithCheckpoint

    Nine situations with the seal intact, and one verdict each: what does somebody watching actually carry away?

    ~7 min

Module 3The service-based interface: TLS, tokens and delegated trust

5 lessons · 1 lab · ≈47 min

Record what mutual TLS each SBI segment actually uses, read NRF access-token claims and lifetimes, and score 3GPP against the zero-trust tenets.

  1. 1
    Mutual TLS on the SBI: support is not useRequires subscription
    9:58
  2. 2
    NRF Access-Token Claims: type-level by defaultRequires subscription
    9:02
  3. 3
    NRF Access-Token Theft: containment without revocationRequires subscription
    9:19
  4. 4
    SCP Indirect Communication: what the proxy removesRequires subscription
    9:15
  5. 5
    Zero-Trust Tenets Against 3GPP: the scored gapRequires subscription
    9:54
  6. How Far Does the Pass Reach?Interactive lab

    Assemble a call on the service bus, read what its pass opens — then hand a copy to somebody it was never issued to and see what is left standing.

    ~8 min

Module 4N32 interconnect beyond the border guard

4 lessons · 1 lab · ≈34 min

Pick the N32 mode each roaming path demands, enforce PRINS modification policy, and read every SEPP hardening requirement by the failure it prevents.

  1. 1
    N32-c and N32-f: the rule that picks the modeRequires subscription
    9:17
  2. 2
    PRINS on N32-f: encrypt some, sign the editsRequires subscription
    9:01
  3. 3
    N32-f protection floor: what the protection policy cannot lowerRequires subscription
    6:50
  4. 4
    SEPP hardening requirements: read each one by its failureRequires subscription
    8:45
  5. What the Middle Can ReadInteractive lab

    One roaming border. Settle what sits in the path, take the mode the specification leaves you, then switch the policy on one kind at a time and watch how little moves.

    ~8 min

Module 5Transport, substrate, slices and the management plane

5 lessons · 1 lab · ≈35 min

Decide where transport IPsec is used rather than merely implemented, test the assumptions a virtualised function cannot check, and read assurance evidence honestly.

  1. 1
    RAN transport IPsec: implemented, then decidedRequires subscription
    8:04
  2. 2
    Virtualised network-function trust: four assumptions to verifyRequires subscription
    7:57
  3. 3
    Slice isolation security: what an SLA can promiseRequires subscription
    5:23
  4. 4
    OAM and orchestration plane: where recorded intrusions landedRequires subscription
    7:05
  5. 5
    NESAS and SCAS: what assurance evidence provesRequires subscription
    6:43
  6. What the Folder ProvesCheckpoint

    A release arrives with a folder of evidence, and it is tempting to read the folder as one verdict. File each question under whatever could actually answer it — including the ones nothing in the folder ever will.

    ~6 min

Module 6Post-quantum readiness: the honest threat model

4 lessons · 1 lab · ≈36 min

Separate what Shor breaks from what Grover weakens, class every asset as harvest, forge or SUCI risk, and name who owns each migration.

  1. 1
    Shor versus Grover on 5G: what breaks, what weakensRequires subscription
    8:32
  2. 2
    Harvest-now, forge-later and SUCI: three exposure timelinesRequires subscription
    8:27
  3. 3
    Asymmetric surface map: who owns each migrationRequires subscription
    10:05
  4. 4
    Cryptographic agility and diversity: a slot, not a weldRequires subscription
    9:22
  5. What They Had to Hold AlreadyCheckpoint

    The same surfaces as lesson one, filed this time by what an attacker would have had to hold before a key-recovering machine was worth anything.

    ~6 min

Module 7Post-quantum readiness: the migration

4 lessons · 1 lab · ≈37 min

Rank the GSMA migration phases against your own inventory, weigh standalone against hybrid SUCI profiles, and match each asset to the clock that binds it.

  1. 1
    GSMA post-quantum migration phases: the ranking is yoursRequires subscription
    8:06
  2. 2
    Post-quantum SUCI profiles: standalone and hybrid, bothRequires subscription
    9:56
  3. 3
    Hybrid key exchange in IKEv2: the measured costRequires subscription
    9:20
  4. 4
    Post-quantum migration clocks: which one binds which assetRequires subscription
    9:22
  5. Every Row Names Its SourceCheckpoint

    The finished migration plan, audited a line at a time: which cells carry somebody else’s conclusion, which carry a measurement, and which are yours to sign.

    ~7 min

New to the terminology? Look up any acronym in the telecom glossary.

Study materials

Download the 5G Security: SUCI to Post-Quantum question bank and slide deck — every signal check in the course, with answers, plus every figure.

  • Question BankPDF45 KB
  • Slide DeckPPTX21 MB
7-day money-back guarantee

Unlock every lesson in 5G Security: SUCI to Post-Quantum

Stream all 32 lessons, follow the 7-module path, and earn the TELCOMA 5G Security Specialist certificate.

  • Every module unlocked
  • Labs & full-length practice exams
  • Verifiable certificate
  • TELCOMA since 2009