Navigation

Get in touch
Logo
News

Industries / Telecom

Connect networks. Protect communications.

Secure communications networks and manage keys for SIM, eSIM and 5G.

Consulting. Integration. Operations.

white and black satellite dish on top of white building — illustrative image

Built around your industry.

  • Mobile network operators
  • Fixed-line and fiber providers
  • MVNOs and IoT connectivity providers
  • Private campus network operators

Your priorities

Understand the challenge. Shape the solution.

We secure core and access networks, manage SIM and eSIM keys in hardware security modules, and integrate 5G core networks with billing and customer management.

01

5G core and network security

Security architecture for the core network and network border

More on this
02

OSS/BSS integration and API exposure

Integration architecture with interface catalog and data contracts

More on this
03

Security operations and incident reporting under NIS2 and TKG

Gap analysis and action plan for TKG and NIS2

More on this

From strategy to implementation

Six service modules

Six fields of expertise. Explore the scope that fits your project.

015G core and network security3GPP TS 33.501 · SEPP · OAuth 2.0

Our approach

The 5G core consists of network functions that run as containers on Kubernetes and communicate over a service-based architecture with HTTP/2. We secure this communication under 3GPP TS 33.501 with mutual TLS and OAuth 2.0 tokens from the NRF, separate network slices from the management plane and harden the cloud platform. At the network border the SEPP protects roaming signaling, and signaling firewalls filter SS7 and Diameter from legacy networks. We test network components under 3GPP SCAS and evaluate the vendors' GSMA NESAS reports.

Full scope
  • Security analysis of the service-based architecture with network functions, the N2, N3 and N32 interfaces and management access
  • Mutual TLS between network functions, OAuth 2.0 authorization through the NRF and certificate management for the core
  • SEPP configuration with N32 filtering plus signaling firewalls for SS7 and Diameter under GSMA FS.11 and FS.19
  • Hardening of Kubernetes, container images and the transport network with IPsec under 3GPP TS 33.210
  • Acceptance tests for network functions under 3GPP SCAS and evaluation of the vendors' NESAS audit reports

A mobile operator brings a 5G standalone core into service; all network functions talk over mutual TLS, and the SEPP filters roaming partner signaling before the first roaming agreement goes live.

What you get

  • Security architecture for the core network and network border
  • Hardened network functions with certificate and authorization concept
  • Test reports under 3GPP SCAS with a list of measures
Discuss this topic
02Subscriber keys and eSIM on HSMsUtimaco 5G Protect · Entrust nShield 5c · Thales Luna 7 Network HSM

Our approach

With the subscriber key K and the operator value OPc, the network computes the authentication vectors for 5G AKA at every registration, using MILENAGE or TUAK. We move this computation and the de-concealment of the SUCI, the concealed subscriber identifier, into hardware security modules, so keys never sit in plain text in the UDM or the authentication center. We advise vendor-neutrally on Utimaco 5G Protect, Entrust nShield 5c and Thales Luna, take over key files from card vendors through transport keys and protect eSIM profiles on the SM-DP+ platform under GSMA SGP.22.

Full scope
  • Target architecture for ARPF, SIDF and the authentication center with HSM clusters across several sites
  • 5G AKA and EAP-AKA' computation with MILENAGE and TUAK inside the HSM, migration of existing Ki and OPc stocks
  • SUCI de-concealment under ECIES profile A and B with the home network key pairs inside the HSM
  • Import of card vendor output files through transport keys, key ceremonies with quorum and records
  • HSM integration of the SM-DP+ platform under GSMA SGP.22 and SGP.32 with evidence for GSMA SAS-SM accreditation

A mobile operator moves SUCI de-concealment and authentication vectors into an HSM cluster; the Ki stocks migrate in recorded ceremonies without subscribers needing new SIM cards.

What you get

  • HSM target architecture for authentication and SUCI de-concealment
  • Recorded key ceremonies and migration evidence
  • Operations manual with key rotation and emergency procedures
Discuss this topic
03OSS/BSS integration and API exposureTM Forum Open APIs · CAMARA · Apache Kafka

Our approach

Operations and business support systems control ordering, provisioning, faults and billing and must keep pace with every new network function. We place an integration layer with TM Forum Open APIs and event processing between the network and business systems, so products are built without point-to-point links. Network capabilities such as SIM swap checks, location verification or quality on demand are exposed to business customers in a controlled way through CAMARA APIs and the NEF, with permissions, consent and logging.

Full scope
  • Interface catalog across OSS, BSS, network inventory and core network with data contracts and owners
  • Integration layer with API gateway and Apache Kafka under TM Forum Open APIs for ordering and provisioning
  • Connection of network functions through the NEF and network management interfaces for automated service activation
  • Exposure of CAMARA APIs such as SIM Swap, Device Location and Quality on Demand with OAuth 2.0 and consent management
  • Automated tests, versioning and load tests per interface before release to partners

A mobile provider offers banks a CAMARA API for SIM swap checks; every request runs through the API gateway with permission and logging, without direct access to the core network.

What you get

  • Integration architecture with interface catalog and data contracts
  • Tested and versioned interfaces for network and partners
  • Release and permission concept for external network APIs
Discuss this topic
04Network analytics and anomaly detectionApache Kafka · Apache Flink · MLflow

Our approach

A mobile network constantly produces performance data, alarms, call detail records and signaling events, which usually sit in separate tools. We merge these sources on a data platform by streaming and train models that detect load peaks, radio cell outages and suspicious signaling patterns early. Traffic and location data are pseudonymized under the TDDDG and GDPR, and every alert is traceable to its data source and model version.

Full scope
  • Streaming platform for performance data, alarms, call detail records and signaling events from radio and core network
  • Models for anomaly detection in load, cell availability and signaling, validated against historical incidents
  • Detection of abuse patterns such as fraudulent SIM swaps and Wangiri calls
  • Pseudonymization of traffic and location data with retention periods under the TDDDG and GDPR
  • Model operations with versioning, drift monitoring and handover of alerts to network operations and the SOC

A network operator detects unusual signaling patterns from a roaming network before subscribers are affected; the alert reaches the security operations center with data source and model version.

What you get

  • Data platform for network and signaling data
  • Versioned detection models with model card
  • Data protection concept with pseudonymization and retention periods
Discuss this topic
05Security operations and incident reporting under NIS2 and TKGMicrosoft Sentinel · Splunk · MITRE ATT&CK

Our approach

The TKG obliges operators of public networks to appoint a security officer, keep a security concept and report significant security incidents, and NIS2 adds an early warning within 24 hours and a notification within 72 hours. We set up a security operations center with SIEM for core network, IT and cloud, connect detection, classification and reporting path and prepare templates for the Federal Network Agency and the BSI. We map the security catalog of the Federal Network Agency and the BSI in an ISMS under ISO 27001 and back it with evidence.

Full scope
  • Gap analysis against the security catalog, NIS2 duties and the existing security concept with prioritized measures
  • SIEM integration of core network, signaling firewalls, cloud platform and office IT with telecom use cases
  • Incident classification and reporting workflow with deadlines for early warning, notification and final report
  • Incident response playbooks for outages, signaling attacks and compromised access, with exercises
  • ISMS under ISO 27001 and ISO/IEC 27011 with evidence for the Federal Network Agency, the BSI and auditors

A fiber provider links network operations and the SOC through a shared reporting workflow; an outage with suspected attack is classified and sent as an early warning within the deadline.

What you get

  • Gap analysis and action plan for TKG and NIS2
  • SOC use cases and reporting workflow with templates
  • ISMS evidence for the security catalog and audits
Discuss this topic
06PQC roadmap for subscriber keys and signalingML-KEM (FIPS 203) · ML-DSA (FIPS 204) · TUAK

Our approach

Quantum computers will break RSA and elliptic curves, on which TLS in the core network, IPsec in the transport network, the eSIM PKI and SUCI concealment rely today. Symmetric algorithms such as TUAK with 256-bit keys are considered resistant, but SIM cards and their keys stay in the field for many years. We inventory algorithms, keys and certificates across core, roaming and eSIM, check the HSMs for ML-KEM and ML-DSA and plan the migration in stages along the work of 3GPP and the GSMA.

Full scope
  • Crypto inventory of TLS in the core, IPsec, SEPP, eSIM PKI, SUCI keys and HSMs with rating by lifetime
  • Assessment of subscriber keys by key length and SIM card lifetime in the field, TUAK with 256-bit keys for new cards
  • Check of the HSMs for firmware with ML-KEM, ML-DSA and hybrid modes
  • Hybrid certificates and hybrid TLS for network functions, SEPP and management access in a pilot
  • Staged roadmap along the work of 3GPP and the GSMA Post-Quantum Telco Network Taskforce

A mobile operator builds an inventory across core network, roaming and eSIM; new SIM batches receive TUAK with 256-bit keys, and the internal PKI moves to hybrid certificates first.

What you get

  • Crypto inventory with risk rating
  • Migration roadmap for core network, roaming and eSIM
  • Pilot report on hybrid TLS with test results
Discuss this topic
gray metal tower with accessories — illustrative image
Telecom

Typical project situations

Where change becomes tangible.

A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.

Illustrative situations, not customer references.

01 / Telecom

HSM-based authentication at a mobile operator

5G standalone core shortly before launch, SUCI de-concealment in software, HSM in the authentication center with announced end of support.

Solution

HSM cluster across several sites for 5G AKA and SUCI de-concealment, migration of the Ki stocks in recorded ceremonies.

Subscriber keys only inside the HSM, cutover without SIM swap, evidence for the security concept and the audit.

Discuss this topic

02 / Telecom

Incident reporting at a fiber provider

NIS2 newly applies, network operations and IT security use separate tools, no reporting path to the Federal Network Agency and the BSI.

Solution

SIEM integration of network and IT, classification scheme, reporting workflow with templates, exercises with network operations and management.

Reports possible within the statutory deadlines, documented exercises, gaps to the security catalog closed.

Discuss this topic

03 / Telecom

eSIM platform at an IoT connectivity provider

Business customer device fleets need eSIM under SGP.32, profile keys sit in a database, GSMA accreditation is still pending.

Solution

HSM integration of the SM-DP+ platform, key ceremonies, APIs for business customers with permissions and logging.

Profile keys inside the HSM, evidence for SAS-SM accreditation, profiles reach devices through versioned interfaces.

Discuss this topic

Working together

A clear path. With your team.

From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.

How we work

  1. 01

    Assessment

    Core network, key processes, interfaces and regulatory gaps

    Prioritized list of measures, crypto inventory, gap analysis for TKG and NIS2
  2. 02

    Concept

    Target architecture, HSM deployment, integration path, operating model

    Target architecture, HSM selection, interface catalog, reporting concept, operating model
  3. 03

    Implementation

    HSMs, core network protection, interfaces and SOC in stages and maintenance windows

    Integrated systems, recorded ceremonies, test reports, documentation, acceptance per stage
  4. 04

    Operations

    Monitoring, incident reporting, audits, knowledge transfer

    Monitoring, key rotation, audit support, stepwise handover

Before our first conversation

You do not need all the answers yet.

Start with a concrete challenge. These four questions help us find the right direction together.

Book a first consultation
  1. 01

    What should change?

    Your current challenge and the outcome you are aiming for.

  2. 02

    Which systems are involved?

    An overview of sites, applications and interfaces.

  3. 03

    What sets the boundaries?

    Project dates, maintenance windows and known dependencies.

  4. 04

    Who needs to be involved?

    The right people from IT, security and operations.

Background & decision criteria

What are IT solutions for telecommunications?

Six fields of action from the 5G core to post-quantum cryptography, planned, integrated and operated by OTOKO®. Subscriber keys stay in certified hardware security modules, and every measure is documented for the Federal Network Agency, the BSI and auditors.

IT solutions for telecommunications protect the core network, signaling and subscriber identities, connect the network with business systems and prove the duties under the TKG and NIS2 to the authorities. OTOKO® covers six fields of action: 5G core and network security, subscriber keys and eSIM on HSMs, OSS/BSS integration and API exposure, network analytics and anomaly detection, security operations and incident reporting under NIS2 and TKG, and a PQC roadmap for long-lived subscriber keys and signaling.

The difference from a pure consulting project lies in operations and evidence. Every key ceremony, network function and interface comes with a record, a version and the documents that the TKG security catalog, NIS2 and auditors ask for. Cryptography and hardware security modules are our core competence. Subscriber keys, SUCI keys and eSIM profile keys therefore live in certified devices rather than in software.

Why OTOKO® for telecommunications

  • Cryptography and HSM

    Cryptography and hardware security modules are our core competence. We plan and operate subscriber keys, SUCI keys and eSIM profile keys in certified devices with recorded ceremonies.

  • German data centers

    The entire solution runs in German data centers. This covers hosted HSMs, the data platform for network analytics and the security operations center.

  • Critical infrastructure and regulated industries

    We work with operators of critical infrastructure and regulated industries. We know what the Federal Network Agency, the BSI, auditors and information security expect of public telecommunications networks.

  • One team through to operations

    One team accompanies you from consulting to operations. Cryptography specialists, core network security architects and data engineers work with your network operations from assessment to day-to-day operation.

Delivery and details

Most operators do not fail on network technology but on grown systems, scattered keys and gaps in the evidence.

Subscriber keys in many hands

Ki and OPc values arrive as files from card vendors, are imported into several systems and partly sit outside any HSM.

Core network without end-to-end protection

Network functions in the 5G core partly talk without mutual TLS, roaming partners reach signaling without SEPP filtering and legacy SS7 and Diameter signaling stays unfiltered.

OSS and BSS as bottleneck

Ordering, provisioning and billing run over point-to-point links, so every new network function and every new product needs months of integration.

Reporting duties without a reporting path

NIS2 and the TKG require reports within fixed deadlines, but network operations, the security operations center and the regulatory team work with separate tools.

Three operating models
On-PremisesGerman cloudHyperscaler
Data locationYour data centers, your HSMs and core network sitesData centers in Germany, operated under ISO 27001Azure, AWS or Google Cloud, German region selectable
OperationYour network operations or OTOKO® as managed serviceOTOKO®, with audit rights for your organizationShared, platform services by the provider
ToolsHSM clusters, Kubernetes for network functions, SIEM in your own networkHosted HSMs, integration and data platform, SOCCloud HSM services, managed Kubernetes and data services
Suited forAuthentication, SUCI de-concealment, core networkSM-DP+, partner APIs, security operations centerNetwork analytics, BSS applications, load peaks
ComplianceFull control, evidence from your ISMS and security conceptProcessing agreement under GDPR, location Germany, TKG evidenceProcessing agreement, standard contractual clauses, review against the security catalog

Collaboration

Project

Clearly scoped undertaking such as an HSM migration in the authentication center or a SEPP rollout, with a defined result, milestones and acceptance.

  • Assessment, concept, implementation, handover
  • Fixed price or effort by milestone
  • Suited for HSM migrations, 5G rollouts and audit preparation

Team reinforcement

Cryptography specialists, core network security architects or integration developers work in your teams, with your tools and in your change processes.

  • Onboarding into network operations, change procedures and maintenance windows
  • Scalable as the project progresses
  • Suited for operators with their own team and capacity gaps

Managed service

OTOKO® operates HSM clusters, the integration layer or the security operations center with agreed service levels, reports and the evidence that the TKG and NIS2 require.

  • Monitoring, key rotation, updates and support
  • Audit rights, service levels and exit plans in the contract
  • Suited for providers without their own operations team for HSMs or the SOC

Five requirements that bind network operators and service providers, with what they demand and what OTOKO® delivers for them.

Standards and evidence
RequirementDemandsOTOKO® delivers
TKGTechnical and organizational safeguards, a security officer, a security concept, implementation of the security catalog of the Federal Network Agency and the BSI, reporting of significant security incidentsSecurity concept, mapping of the security catalog, evidence on critical components, reporting process and templates for the Federal Network Agency
NIS2Risk management, supply chain security, accountability of management, early warning within 24 hours and notification within 72 hoursRisk analysis, supplier assessment, management training, SOC with reporting workflow and documented exercises
GDPRLegal basis, data minimization, protection of traffic and location data together with the TDDDG, processing agreements, data protection impact assessmentData protection concept for network analytics, pseudonymization, retention periods, processing agreement with location Germany
ISO 27001Information security management system with risk treatment, Annex A controls, internal audits and management reviewISMS setup with telecom-specific controls under ISO/IEC 27011, audit preparation, operation of our services under ISO 27001
3GPP TS 33.501Security architecture of the 5G system with 5G AKA and EAP-AKA', SUCI concealment, TLS and OAuth 2.0 in the service-based architecture, SEPP at the network borderHSM-based authentication and SUCI de-concealment, certificate and authorization concept, SEPP configuration, test reports under 3GPP SCAS

FAQ

Good questions. Clear answers.

15 answers about your industry, the project and ongoing operations.

Industry & expertise6 questions

Which IT solutions for telecommunications does OTOKO® offer?

The portfolio covers protection of the 5G core, subscriber keys and eSIM profiles in hardware security modules, OSS and BSS integration with network APIs, network analytics with data platforms, security operations with incident reporting under NIS2 and TKG, and a PQC roadmap. You commission single fields of action or the package, operated in your data center, in German data centers or on a hyperscaler.

Why do subscriber keys belong in a hardware security module?

Anyone who knows the key K and the OPc value of a SIM can impersonate the subscriber in the network and attack their connections. An HSM computes the authentication vectors and de-conceals the SUCI without keys leaving the device in plain text, and it logs every use. This lets you prove the protection to the Federal Network Agency, auditors and roaming partners.

How does OTOKO® implement the reporting duties under NIS2 and TKG?

We first check which duties from the TKG, NIS2 and the security catalog apply to your operation and compare them with existing measures. We then connect detection in the SOC, classification and reporting path into a workflow with deadlines and templates for the Federal Network Agency and the BSI. We work with operators of critical infrastructure and regulated industries and rehearse the workflow with network operations and management.

Can existing HSMs in the authentication center stay in operation?

In many cases yes. We check firmware levels, certifications, vendor support and support for TUAK, SUCI de-concealment and new algorithms. A replacement is planned only where devices reach end of support or miss requirements, and subscriber keys migrate in recorded ceremonies without a SIM swap.

May network data be used for analytics and AI?

Within fixed limits. Traffic and location data fall under the TDDDG and GDPR and may only be processed for permitted purposes such as fault clearance or abuse detection. We pseudonymize them before analysis, limit retention periods and document the processing in a data protection impact assessment. Every model alert is traceable to its data source and model version.

When should network operators start with post-quantum cryptography?

Now, with the inventory. SIM cards, roaming certificates and eSIM root keys stay in use for many years, and signaling recorded today can be decrypted later. The inventory shows which connections and keys migrate first, and the roadmap ties the migration to new SIM batches, HSM renewals and the specifications of 3GPP and the GSMA.

Getting started & delivery5 questions

Can we start with a single area of expertise?

Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.

What should we prepare for the first conversation?

A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.

Who needs to participate in the project?

Core network security architect: Security architecture for the 5G core, SEPP and network border. Cryptography specialist: HSM integration, key ceremonies, PQC roadmap. Integration developer: OSS/BSS interfaces, API gateway, CAMARA. Data engineer: Streaming platform, detection models, pseudonymization. Compliance consultant: TKG, NIS2, security catalog, incident reporting. Project lead: Milestones, maintenance windows, acceptance, reporting.

How do you determine the schedule and effort?

We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.

What does the first stage deliver?

Core network, key processes, interfaces and regulatory gaps Prioritized list of measures, crypto inventory, gap analysis for TKG and NIS2

Operations & development4 questions

How can we work together?

Project: Clearly scoped undertaking such as an HSM migration in the authentication center or a SEPP rollout, with a defined result, milestones and acceptance. Team reinforcement: Cryptography specialists, core network security architects or integration developers work in your teams, with your tools and in your change processes. Managed service: OTOKO® operates HSM clusters, the integration layer or the security operations center with agreed service levels, reports and the evidence that the TKG and NIS2 require.

What happens at handover to operations?

Monitoring, incident reporting, audits, knowledge transfer Monitoring, key rotation, audit support, stepwise handover

Can we expand to further sites or systems later?

We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.

How do we keep the solution maintainable?

Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.

Telecom

Let's discuss your next step.

Let us discuss how your network, your subscriber keys, and your 5G core can work together securely.

Book a first consultation

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.