5G/6G Academy
5G/6G AcademyTelecom certifications · since 2009
5G Security

5G Security · Pro

NAS and AS security activation

Two-Phase Security Activation

After authentication completes and keys are derived, 5G activates security protection in two sequential phases. NAS security is established first, protecting signaling between the UE and the AMF. The AMF sends a NAS Security Mode Command selecting the ciphering algorithm (NEA) and integrity algorithm (NIA), using KNASenc and KNASint derived from KAMF. Critically, the SMC message itself is integrity-protected from the very first message, preventing downgrade attacks where an attacker tries to force weaker algorithms. The UE validates the command and replies with NAS Security Mode Complete.

Continue reading with Pro

Your free trial has ended. Subscribe to unlock the full lesson plus all 26 advanced levels, 732 lessons, labs, and 17 TELCOMA certification exams.

From $99/year·7-day money-back guarantee·Cancel anytime