Initial NAS Message Security: Applying 5G Cybersecurity and Privacy Capabilities
Michael Bartock (NIST) , Jeffrey Cichonski (NIST) , Parisa Grayeli (MITRE) , Sanjeev Sharma (MITRE)
This NIST Cybersecurity White Paper describes a 5G security feature that protects sensitive information in the Initial Non-Access Stratum (NAS) Message and explains how organizations can verify these protections in deployed 5G networks.
This white paper is part of the NCCoE’s work to accelerate the adoption of 5G security features by demonstrating their implementation on our operational 5G security testbed and providing actionable implementation guidelines to help network operators enhance the cybersecurity and privacy of 5G systems and supporting infrastructures.
Current 5G standards include specifications to address cybersecurity and privacy challenges present in generations of cellular systems. In 4G, the initial handshake message used to establish a connection between the device and the network—the Initial NAS Message—was sent without encryption or integrity protection. This leaves the 4G user device and the core network vulnerable to man-in-the-middle attacks.
Current 5G specifications allow the device to send the security-sensitive contents of the initial NAS message in an encrypted and integrity protected form.
This White Paper describes how the NCCoE demonstrated these capabilities and explains how organizations can verify these protections in deployed 5G networks to protect the security and privacy on their networks.
Publication:
Supplemental Material: Project homepage
Document History: 08/06/26: CSWP 36F (Draft)
general security & privacy
communications & wireless
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
