Valid

GB/T 46462-2025Technical requirements on communication security of 5G mobile communication network (English PDF)

5G移动通信网通信安全技术要求

Open the GB/T 46462-2025 preview as PDF

Preview — first pages of GB/T 46462-2025 (full document: 217 pages)

This is a limited preview

Buy now to download the full PDF (217 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

October 31, 2025

Implementation date

February 1, 2026

Scope

GB/T 46462-2025 is the English-translated version of 5G移动通信网通信安全技术要求.

GB/T 46462-2025 is the Chinese national standard covering securing a 5G network - the subscriber identity protection that closes the IMSI catcher, the authentication and key agreement, the security of the radio and the transport, the network slicing isolation, the service based architecture interfaces, and the roaming boundary. At 107,500 words, the second largest document in the catalogue. First edition, under the Ministry of Industry and Information Technology. In force from 1 February 2026. Issued on 31 October 2025, it has been in force since 1 February 2026.

Document preview — GB/T 46462-2025

National Standard of the People's Republic of China

ICS
33.020
Classification
M 04

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • 1.Scope1
  • 2 Normative References1
  • 3.1 Terms and Definitions4
  • 3.2 Abbreviations6
  • 4.Security Architecture Overview9
  • 4.1 Security Domain9
  • 4.2 Security Functions at the Edge of the 5G Core Network10
  • 4.3 Security Functions in 5G Core Networks10
  • 5.Safety Requirements and Functional Requirements11
  • 5.1 General Safety Requirements11
  • 5.2 UE Security Requirements11
  • 5.3 gNB Security Requirements13
  • 5.4 ng-eNB Security Requirements15
  • 5.5 AMF Safety Requirements15
  • 5.6 SEAF Safety Requirements15
  • 5.7 UDM Security Requirements16
  • 5.8 Core Network Security Requirements16
  • 5.9 Security Visibility and Configurability Requirements19
  • 5.10 Algorithms and Algorithm Selection Requirements 20 5.11 5G-RG Security Requirements21
  • 5.12 NSSAAF Safety Requirements21
  • 6.Security procedures between UE and 5G network functional entities21
  • 6.1 Master Authentication and Key Negotiation21
  • 6.2 Hierarchical structure of keys and derivation and distribution mechanism30
  • 6.3 Security Context36
  • 6.4 Non-access stratum security mechanisms38
  • 6.5 RRC Security Mechanism42
  • 6.6 Access Layer User Plane Security Mechanisms42
  • 6.7 Security Algorithm Negotiation45
  • 6.8 State Transition Safety Handling50
  • 6.9 Mobility Management Security58
  • 6.10 Dual-Connect Security67
  • 6.11 Safety procedures during RRC connection reconstruction73
  • 6.12 User Privacy Protection74
  • 6.13 Signaling Flow of PDCPCOUNT Verification77
  • 6.14 Roaming Guidance Security Mechanism77
  • 6.15 Security Mechanism for UE Parameter Update via UDM Control Plane 81 6.16 5G Cellular IoT Security83
  • 7.Security of non-cellular access to 5G core networks87
  • 7.1 Access Security Principles87
  • 7.2 Authentication Security Process for Untrusted Non-Cellular Access88
  • 7.3 Security Procedures for Trusted Non-Cellular Wireless Access91
  • 7.4 Wired Access Security Procedures96
  • 8.1 General Safety Requirements100
  • 8.2 Security process for mobility registration from EPS to 5GS based on N26 interface100
  • 8.3 Switching process from 5GS to EPS based on N26 interface101
  • 8.4 Switching process from EPS to 5GS based on N26 interface104
  • 26 Interface107
  • 8.6 Mapping of Security Contexts109
  • 9.1 Basic Principles110
  • 2 Interface110
  • 3 Interface111
  • 9.4 Security Mechanisms of the Xn Interface111
  • 9.5 Security mechanisms using GTP or DIAMETER protocol interfaces111
  • 9.6 Security Protection Mechanism for gNB Internal Interfaces111
  • 9.7 Security Mechanisms for Non-Service-Based Interfaces within the 5G Core Network 112 10 IMS Emergency Call Security113
  • 10.2 Unauthenticated IMS emergency calls to114
  • 11.Security procedures for UE interaction with external data networks via 5G network116
  • 11.1 General requirements for secondary authentication between EAP-based AAA servers and external data networks116
  • 11.2 Secondary Authentication Process116
  • 11.3 Re-authentication process119
  • 11.4 Revocation of Authentication Authorization120
  • 12 Security protection for Network Open Functional Entity (NEF)120
  • 12.1 Basic Principles120
  • 12.2 Two-way authentication120
  • 12.3 Safety protection between NEF and AF120
  • 12.4 Authorization Verification of AF Requests120
  • 12.5 Support for CAPIF121
  • 13 Service-Oriented Interface Security121
  • 13.1 Security protection at the network layer or transport layer121
  • 32 Interface123
  • 13.3 Authentication and Static Licensing137
  • 13.4 Authorization during NF service requests140
  • 13.5 Security Capability Negotiation among SEPPs151
  • 14 Security Services152
  • 14.1 Security Services Provided by AUSF152
  • 14.2 Security Services Provided by UDM153
  • 14.3 Security Services Provided by NRF154
  • 15 Network Slice Management Security154
  • 15.1 Overview154
  • 15.2 Two-way authentication154
  • 15.3 Security Protection for Management Interactions Between Service Producers and Users155
  • 15.4 Authorization Verification of Management Service Request Messages155
  • 16.Dual-connectivity security in non-standalone networking161
  • 2 Interface162
  • 16.3 Additions and modifications to DRB (Data Radio Bearer) and/or SRB (Signaling Radio Bearer) in SgNB162
  • 16.4 Activation of DRB encryption/decryption/integrity protection and SRB encryption/decryption/integrity protection162
  • 16.6 S-KgNB Update165
  • 16.7 Switching Process165
  • 16.8 Periodic Local Authentication Process166
  • 16.9 Wireless connection failure recovery166
  • 16.10 Avoid keystream reuse due to DRB type changes166
  • 16.11 Security between UE and SgNB166
  • 17.1 Call continuity from NR to UTRAN167
  • 17.2 Emergency Calls Continuing from NR to UTRAN 168 18 5G LAN Service Security168
  • 18.1 Overview168
  • 18.2 Authentication and Authorization168
  • 18.3 UP Security Policy Processing169
  • 19.Security of Time-Sensitive Network Services169
  • 19.1 Overview169
  • 19.2 Access Security for UEs with 5G STSC Enabled169
  • 19.3 Protecting user plane data in TSC includes (g)PTP control messages in bridged mode169
  • 19.4 Time synchronization interface exposed 169 20 5G High Reliability, Low Latency, and Security Requirements169
  • 20.1 Overview169
  • 20.2 Security Assurance for Redundant Transmission169
  • 20.3 Redundant transmission of N3/N9 interface170
  • 21 Edge computing security170
  • 21.1 Overview170
  • 21.2 Security of Network Exposure to Edge Application Servers170
  • 22 User license requirements171
  • 22.1 Overview171
  • 22.2 User consent required171
  • 23 Enhanced security mechanisms for 5G multicast services172
  • 23.1 MBSF Requirements172
  • 23.2 MBSTF requirement172
  • 23.3 Security Mechanisms for xMB-C/MB2-C and xMB-U/MB2-U Interfaces172
  • 23.4 MBS Streaming Security Mechanisms172
  • 23.5 Security protection for 5MBS and eMBMS interoperability174
  • 24 Large-Scale IoT Message Security174
  • 24.1 Overview174
  • 24.2 Authentication and Authorization between 5G IoT Messaging Terminals and 5G IoT Messaging Servers 174 24.3 5G IoT Messaging System Interface Security Protection175
  • 24.4 Identity Authentication and Authorization between Application Server and 5G IoT Messaging Server175
  • 24.5 Authentication and Authorization between the Message Gateway and the 5G IoT Message Server 175 Appendix A (Normative) Encryption and Integrity Protection Algorithms 176 A.1 Empty Encryption and Integrity Protection Algorithm 176 A.2 128-bit encryption algorithm 176 A.3 128-bit Integrity Protection Algorithm 177 A.4 Test data for security algorithms 178 Appendix B (Informative) Implementing Master Authentication Based on Additional EAP Methods 180 B.1 Basic Principles 180 B.2 Initial Authentication and Key Negotiation 180 B.3 Key Derivation 184 Appendix C (Normative) Key Derivation Function 185 C.1 KDF Interface and Input Parameter Construction 185 C.2 KAUSF derivation function 185 C.3 Derivation functions of CK' and IK' 185 C.4 Derivation functions of RES* and XRES* 185 C.5 Derivation functions of HRES* and HXRES* 186 C.6 KSEAF derivation function 186 C.7 KAMF Derivation Function 186 C.8 Algorithm Key Derivation Function 187 C.9 Derivation functions of KgNB and KN3IWF 187 C.10 NH derivation function 188 C.11 KNG-RAN* derivation function of target base station gNB 188 C.12 KNG-RAN* Derivation Function of Target Base Station ng-eNB 188 C.13 Derivation of KAMF to KAMF' under Moving Conditions 189 C.14 Derivation of KAMF to KASME' under Interoperability 189 C.15 Derivation of KASME to KAMF' under Interoperability 189 C.16 Derivation of the KSN with Dual Connections 190 C.17 SoR-MAC-IAUSF generation function 190 C.18 SoR-MAC-IUE generation function 190 C.19 UPU-MAC-IAUSF Generation Functions 191 C.20 UPU-MAC-IUE/UPU-XMAC-IUE generation functions 191 C.21 Derivation of KAMF to KASME_SRVCC under Interoperability 191 C.22 Derivation functions of KTIPSec and KTNAP 191 C.23 KIAB generation function 192 Appendix D (Normative) 5G EAP-AKA Parameter Definition Requirements 193 D.1 Overview 193 D.2 User Privacy 193 D.3 User Identity and Key Derivation 194 Appendix E (Normative) Non-Public Networks 195 E.1 Overview 195 E.2 SNPN Authentication 195 E.3 SNPN Service Network Name.199 E.4 Modify the CAGID list in the UE.199 E.5 SNPN's SUPI Privacy.199 E.6 Certification in PNI-NPN.199 E.7 SNPN License.199 E.8 SEPP and Internet-related Security Procedures.199 Security of UE online signing in E.9 SNPN.200 Appendix F (Normative) SUCI Protection Methods 202 F.1 Basic Principles 202 F.2 Empty Mode 202 F.3 Elliptic Curve Cryptography (ECIES) 202 Appendix G (Normative) Security Requirements for Integrated Access and Backhaul 206 G.1 Overview 206 G.2 Safety Requirements and Functions 206 G.3 IAB Node Integration Process 206 G.4 Management Data Protection between IAB Nodes and OAM 208 Appendix H (Normative) 5G System Network Automation Enabling Security 209 H.1 Overview 209 H.2 NF service user authorization process for accessing data via DCCF 209 H.3 NF service user authorization process for accessing data via DCCF (via MFAF return notification) 211 H.4 Data Security Protection via Message Frames 212 Data transmission protection between H.5 AF and NWDAF 212 H.6 NF data transmission protection 212 H.7 User Consent Requirement 212 References213

Foreword

This document complies with the provisions of GB/T 1.1-2020 "Standardization Work Guidelines Part

1.Structure and Drafting Rules of Standardization Documents". Drafting. Some content in this document may involve patents. The issuing organization of this document assumes no responsibility for identifying patents. This document was proposed by the Ministry of Industry and Information Technology of the People's Republic of China. This document is under the jurisdiction of the National Telecommunications Standardization Technical Committee (SAC/TC485). This document was drafted by: China Mobile Communications Group Co., Ltd., China Academy of Information and Communications Technology, ZTE Corporation, and Shanghai... Nokia Bell AG, China Information and Communication Technology Group Corporation, China United Network Communications Group Co., Ltd., China Telecom Zike Technology Network Information Security Co., Ltd., Qualcomm Wireless Communications Technology (China) Co., Ltd., Huawei Technologies Co., Ltd., Beijing Xiaomi Mobile Software Co., Ltd., Ericsson (China) Communications Co., Ltd., China Telecom Group Co., Ltd., Inspur Communications Technology Co., Ltd., Beijing Unisplendour Corporation Unisoc Communication Technologies Co., Ltd., Beijing Shouxin Technology Co., Ltd., Zhengzhou Xinda Jiean Information Technology Co., Ltd., Beijing Haohan Deepin Information Technology Co., Ltd., Apple R&D (Beijing) Co., Ltd., Heng'an Jiaxin (Beijing) Technology Co., Ltd., Xi'an Tonghe Telecom Equipment Testing Co., Ltd., Bodin Shihua (Beijing) Technology Co., Ltd., Beijing Dongfangtong Network Technology Co., Ltd., Beijing Qimingxingchen Information Technology Co., Ltd. Security Technology Co., Ltd., H3C Technologies Co., Ltd. The main drafters of this document are. Qi Minpeng, Wu Rong, Ping Jing, Liu Chang, You Shilin, Yuan Qi, Yang Hongmei, Lu Wei, Liu Weihua, Zhang Leyi, and Yao Ge. Xu Hui, Wang Jun, Du Zhimin, Li Na, Huang Xiaoting, Xie Zecheng, Bai Jingpeng, Guo Longhua, Tian Yongchun, Li Xiaohua, Zhang Weiqiang, Cui Tingting, Chen Tao Pang Shaomin, Tong Jing, Guo Shu, Song Hua, Meng Juan, Li Xing, Jiang Faqun, Zhou Lei. 5G mobile communication network communication security technical requirements

1 Scope

GB/T 46462-2025 is the Chinese national standard covering securing a 5G network - the subscriber identity protection that closes the IMSI catcher, the authentication and key agreement, the security of the radio and the transport, the network slicing isolation, the service based architecture interfaces, and the roaming boundary. At 107,500 words, the second largest document in the catalogue. First edition, under the Ministry of Industry and Information Technology. In force from 1 February 2026. Issued on 31 October 2025, it has been in force since 1 February 2026.

This document establishes the communication security architecture for 5G mobile communication networks, and specifies the access security, network security, and user privacy of 5G mobile communication networks. It describes the technical requirements and security functions of communication security, such as privacy protection and security services, and the relevant security procedures. This document applies to the construction of 5G mobile communication network security architecture, definition of security requirements, and security capabilities for individual and enterprise scenarios. Forcefully implement.

2 Normative references

The contents of the following documents, through normative references within the text, constitute essential provisions of this document. Dated citations are not included. For references to documents, only the version corresponding to that date applies to this document; for undated references, the latest version (including all amendments) applies. This document. YD/T 2910-2015 LTE/SAE Security Technical Requirements YD/T 4743-2024 Technical Requirements for Multicast Broadcast in 5G Mobile Communication Network Core Network YD/T 6423-2025 Technical Requirements for 5G Mobile Communication Networks Supporting Non-Public Networks (Phase II) 3GPP TS

17.9.0 Non-Access Stratum (NAS) Functions Related to Mobile Stations (MS) in Idle Mode [Non-Ac- 3GPP TS

24.302 Access to the 3GPP Evolved Packet Core (EPC) protocol via non-cellular means; Phase 3 3GPP TS24.501v

17.9.0 Non-access stratum (NAS) protocol for 5G systems (5GS); Phase 3 work) Toolkit (USAT)] requirements)

3 Interface

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 217 pages — is available in the English PDF.

How to Buy GB/T 46462-2025

  1. 1Add to cart. Click the "Buy GB/T 46462-2025" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
217 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 46462-2025

$3,215.00

$2,735.00for partners