Announcements

New 5G White Paper Available: Initial Non-Access Stratum Message Security

NIST | NCCoE

The NIST National Cybersecurity Center of Excellence (NCCoE) has released the initial public draft Cybersecurity White Paper (CSWP) 36F, Initial Non-Access Stratum (NAS) Message Security, which describes a 5G security feature that protects sensitive information in the Initial Non-Access Stratum (NAS) Message and explains how organizations can verify these protections in deployed 5G networks.

This white paper is part of the NCCoE’s work to accelerate the adoption of 5G security features by demonstrating their implementation on our operational 5G security testbed and providing actionable implementation guidelines to help network operators enhance the cybersecurity and privacy of 5G systems and supporting infrastructures.

Background

Current 5G standards include specifications to address cybersecurity and privacy challenges present in previous generations of cellular systems. In 4G, the initial handshake message used to establish a connection between the device and the network—the Initial NAS Message—was sent without encryption or integrity protection. This leaves the 4G user device and the core network vulnerable to man-in-the-middle attacks.

Current 5G specifications allow the device to send the security-sensitive contents of the initial NAS message in an encrypted and integrity protected form.

This white paper describes how the NCCoE demonstrated these capabilities and explains how organizations can verify these protections in deployed 5G networks to protect the security and privacy on their networks.

By demonstrating security features on our operational 5G testbed, we aim to deliver real-world implementation insights to advance 5G security and inform the next generation of wireless security technologies and standards. 

Submit Your Feedback!

This white paper is available for public comment through September 7, 2026. Visit the NCCoE project page to learn more and download the white paper today!