5G core and network security
Security architecture for the core network and network border
More on thisIndustries / Telecom
Secure communications networks and manage keys for SIM, eSIM and 5G.
Consulting. Integration. Operations.

Built around your industry.
Your priorities
We secure core and access networks, manage SIM and eSIM keys in hardware security modules, and integrate 5G core networks with billing and customer management.
Security architecture for the core network and network border
More on thisIntegration architecture with interface catalog and data contracts
More on thisGap analysis and action plan for TKG and NIS2
More on thisFrom strategy to implementation
Six fields of expertise. Explore the scope that fits your project.
Our approach
The 5G core consists of network functions that run as containers on Kubernetes and communicate over a service-based architecture with HTTP/2. We secure this communication under 3GPP TS 33.501 with mutual TLS and OAuth 2.0 tokens from the NRF, separate network slices from the management plane and harden the cloud platform. At the network border the SEPP protects roaming signaling, and signaling firewalls filter SS7 and Diameter from legacy networks. We test network components under 3GPP SCAS and evaluate the vendors' GSMA NESAS reports.
A mobile operator brings a 5G standalone core into service; all network functions talk over mutual TLS, and the SEPP filters roaming partner signaling before the first roaming agreement goes live.
Our approach
With the subscriber key K and the operator value OPc, the network computes the authentication vectors for 5G AKA at every registration, using MILENAGE or TUAK. We move this computation and the de-concealment of the SUCI, the concealed subscriber identifier, into hardware security modules, so keys never sit in plain text in the UDM or the authentication center. We advise vendor-neutrally on Utimaco 5G Protect, Entrust nShield 5c and Thales Luna, take over key files from card vendors through transport keys and protect eSIM profiles on the SM-DP+ platform under GSMA SGP.22.
A mobile operator moves SUCI de-concealment and authentication vectors into an HSM cluster; the Ki stocks migrate in recorded ceremonies without subscribers needing new SIM cards.
Our approach
Operations and business support systems control ordering, provisioning, faults and billing and must keep pace with every new network function. We place an integration layer with TM Forum Open APIs and event processing between the network and business systems, so products are built without point-to-point links. Network capabilities such as SIM swap checks, location verification or quality on demand are exposed to business customers in a controlled way through CAMARA APIs and the NEF, with permissions, consent and logging.
A mobile provider offers banks a CAMARA API for SIM swap checks; every request runs through the API gateway with permission and logging, without direct access to the core network.
Our approach
A mobile network constantly produces performance data, alarms, call detail records and signaling events, which usually sit in separate tools. We merge these sources on a data platform by streaming and train models that detect load peaks, radio cell outages and suspicious signaling patterns early. Traffic and location data are pseudonymized under the TDDDG and GDPR, and every alert is traceable to its data source and model version.
A network operator detects unusual signaling patterns from a roaming network before subscribers are affected; the alert reaches the security operations center with data source and model version.
Our approach
The TKG obliges operators of public networks to appoint a security officer, keep a security concept and report significant security incidents, and NIS2 adds an early warning within 24 hours and a notification within 72 hours. We set up a security operations center with SIEM for core network, IT and cloud, connect detection, classification and reporting path and prepare templates for the Federal Network Agency and the BSI. We map the security catalog of the Federal Network Agency and the BSI in an ISMS under ISO 27001 and back it with evidence.
A fiber provider links network operations and the SOC through a shared reporting workflow; an outage with suspected attack is classified and sent as an early warning within the deadline.
Our approach
Quantum computers will break RSA and elliptic curves, on which TLS in the core network, IPsec in the transport network, the eSIM PKI and SUCI concealment rely today. Symmetric algorithms such as TUAK with 256-bit keys are considered resistant, but SIM cards and their keys stay in the field for many years. We inventory algorithms, keys and certificates across core, roaming and eSIM, check the HSMs for ML-KEM and ML-DSA and plan the migration in stages along the work of 3GPP and the GSMA.
A mobile operator builds an inventory across core network, roaming and eSIM; new SIM batches receive TUAK with 256-bit keys, and the internal PKI moves to hybrid certificates first.

Typical project situations
A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.
Illustrative situations, not customer references.
01 / Telecom
5G standalone core shortly before launch, SUCI de-concealment in software, HSM in the authentication center with announced end of support.
HSM cluster across several sites for 5G AKA and SUCI de-concealment, migration of the Ki stocks in recorded ceremonies.
Subscriber keys only inside the HSM, cutover without SIM swap, evidence for the security concept and the audit.
02 / Telecom
NIS2 newly applies, network operations and IT security use separate tools, no reporting path to the Federal Network Agency and the BSI.
SIEM integration of network and IT, classification scheme, reporting workflow with templates, exercises with network operations and management.
Reports possible within the statutory deadlines, documented exercises, gaps to the security catalog closed.
03 / Telecom
Business customer device fleets need eSIM under SGP.32, profile keys sit in a database, GSMA accreditation is still pending.
HSM integration of the SM-DP+ platform, key ceremonies, APIs for business customers with permissions and logging.
Profile keys inside the HSM, evidence for SAS-SM accreditation, profiles reach devices through versioned interfaces.
Working together
From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.
How we work
Core network, key processes, interfaces and regulatory gaps
Target architecture, HSM deployment, integration path, operating model
HSMs, core network protection, interfaces and SOC in stages and maintenance windows
Monitoring, incident reporting, audits, knowledge transfer
Before our first conversation
Start with a concrete challenge. These four questions help us find the right direction together.
Book a first consultationYour current challenge and the outcome you are aiming for.
An overview of sites, applications and interfaces.
Project dates, maintenance windows and known dependencies.
The right people from IT, security and operations.
Six fields of action from the 5G core to post-quantum cryptography, planned, integrated and operated by OTOKO®. Subscriber keys stay in certified hardware security modules, and every measure is documented for the Federal Network Agency, the BSI and auditors.
IT solutions for telecommunications protect the core network, signaling and subscriber identities, connect the network with business systems and prove the duties under the TKG and NIS2 to the authorities. OTOKO® covers six fields of action: 5G core and network security, subscriber keys and eSIM on HSMs, OSS/BSS integration and API exposure, network analytics and anomaly detection, security operations and incident reporting under NIS2 and TKG, and a PQC roadmap for long-lived subscriber keys and signaling.
The difference from a pure consulting project lies in operations and evidence. Every key ceremony, network function and interface comes with a record, a version and the documents that the TKG security catalog, NIS2 and auditors ask for. Cryptography and hardware security modules are our core competence. Subscriber keys, SUCI keys and eSIM profile keys therefore live in certified devices rather than in software.
Cryptography and hardware security modules are our core competence. We plan and operate subscriber keys, SUCI keys and eSIM profile keys in certified devices with recorded ceremonies.
The entire solution runs in German data centers. This covers hosted HSMs, the data platform for network analytics and the security operations center.
We work with operators of critical infrastructure and regulated industries. We know what the Federal Network Agency, the BSI, auditors and information security expect of public telecommunications networks.
One team accompanies you from consulting to operations. Cryptography specialists, core network security architects and data engineers work with your network operations from assessment to day-to-day operation.
Most operators do not fail on network technology but on grown systems, scattered keys and gaps in the evidence.
01
Ki and OPc values arrive as files from card vendors, are imported into several systems and partly sit outside any HSM.
02
Network functions in the 5G core partly talk without mutual TLS, roaming partners reach signaling without SEPP filtering and legacy SS7 and Diameter signaling stays unfiltered.
03
Ordering, provisioning and billing run over point-to-point links, so every new network function and every new product needs months of integration.
04
NIS2 and the TKG require reports within fixed deadlines, but network operations, the security operations center and the regulatory team work with separate tools.
| On-Premises | German cloud | Hyperscaler | |
|---|---|---|---|
| Data location | Your data centers, your HSMs and core network sites | Data centers in Germany, operated under ISO 27001 | Azure, AWS or Google Cloud, German region selectable |
| Operation | Your network operations or OTOKO® as managed service | OTOKO®, with audit rights for your organization | Shared, platform services by the provider |
| Tools | HSM clusters, Kubernetes for network functions, SIEM in your own network | Hosted HSMs, integration and data platform, SOC | Cloud HSM services, managed Kubernetes and data services |
| Suited for | Authentication, SUCI de-concealment, core network | SM-DP+, partner APIs, security operations center | Network analytics, BSS applications, load peaks |
| Compliance | Full control, evidence from your ISMS and security concept | Processing agreement under GDPR, location Germany, TKG evidence | Processing agreement, standard contractual clauses, review against the security catalog |
Collaboration
Project
Clearly scoped undertaking such as an HSM migration in the authentication center or a SEPP rollout, with a defined result, milestones and acceptance.
Team reinforcement
Cryptography specialists, core network security architects or integration developers work in your teams, with your tools and in your change processes.
Managed service
OTOKO® operates HSM clusters, the integration layer or the security operations center with agreed service levels, reports and the evidence that the TKG and NIS2 require.
Five requirements that bind network operators and service providers, with what they demand and what OTOKO® delivers for them.
| Requirement | Demands | OTOKO® delivers |
|---|---|---|
| TKG | Technical and organizational safeguards, a security officer, a security concept, implementation of the security catalog of the Federal Network Agency and the BSI, reporting of significant security incidents | Security concept, mapping of the security catalog, evidence on critical components, reporting process and templates for the Federal Network Agency |
| NIS2 | Risk management, supply chain security, accountability of management, early warning within 24 hours and notification within 72 hours | Risk analysis, supplier assessment, management training, SOC with reporting workflow and documented exercises |
| GDPR | Legal basis, data minimization, protection of traffic and location data together with the TDDDG, processing agreements, data protection impact assessment | Data protection concept for network analytics, pseudonymization, retention periods, processing agreement with location Germany |
| ISO 27001 | Information security management system with risk treatment, Annex A controls, internal audits and management review | ISMS setup with telecom-specific controls under ISO/IEC 27011, audit preparation, operation of our services under ISO 27001 |
| 3GPP TS 33.501 | Security architecture of the 5G system with 5G AKA and EAP-AKA', SUCI concealment, TLS and OAuth 2.0 in the service-based architecture, SEPP at the network border | HSM-based authentication and SUCI de-concealment, certificate and authorization concept, SEPP configuration, test reports under 3GPP SCAS |
FAQ
15 answers about your industry, the project and ongoing operations.
The portfolio covers protection of the 5G core, subscriber keys and eSIM profiles in hardware security modules, OSS and BSS integration with network APIs, network analytics with data platforms, security operations with incident reporting under NIS2 and TKG, and a PQC roadmap. You commission single fields of action or the package, operated in your data center, in German data centers or on a hyperscaler.
Anyone who knows the key K and the OPc value of a SIM can impersonate the subscriber in the network and attack their connections. An HSM computes the authentication vectors and de-conceals the SUCI without keys leaving the device in plain text, and it logs every use. This lets you prove the protection to the Federal Network Agency, auditors and roaming partners.
We first check which duties from the TKG, NIS2 and the security catalog apply to your operation and compare them with existing measures. We then connect detection in the SOC, classification and reporting path into a workflow with deadlines and templates for the Federal Network Agency and the BSI. We work with operators of critical infrastructure and regulated industries and rehearse the workflow with network operations and management.
In many cases yes. We check firmware levels, certifications, vendor support and support for TUAK, SUCI de-concealment and new algorithms. A replacement is planned only where devices reach end of support or miss requirements, and subscriber keys migrate in recorded ceremonies without a SIM swap.
Within fixed limits. Traffic and location data fall under the TDDDG and GDPR and may only be processed for permitted purposes such as fault clearance or abuse detection. We pseudonymize them before analysis, limit retention periods and document the processing in a data protection impact assessment. Every model alert is traceable to its data source and model version.
Now, with the inventory. SIM cards, roaming certificates and eSIM root keys stay in use for many years, and signaling recorded today can be decrypted later. The inventory shows which connections and keys migrate first, and the roadmap ties the migration to new SIM batches, HSM renewals and the specifications of 3GPP and the GSMA.
Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.
A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.
Core network security architect: Security architecture for the 5G core, SEPP and network border. Cryptography specialist: HSM integration, key ceremonies, PQC roadmap. Integration developer: OSS/BSS interfaces, API gateway, CAMARA. Data engineer: Streaming platform, detection models, pseudonymization. Compliance consultant: TKG, NIS2, security catalog, incident reporting. Project lead: Milestones, maintenance windows, acceptance, reporting.
We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.
Core network, key processes, interfaces and regulatory gaps Prioritized list of measures, crypto inventory, gap analysis for TKG and NIS2
Project: Clearly scoped undertaking such as an HSM migration in the authentication center or a SEPP rollout, with a defined result, milestones and acceptance. Team reinforcement: Cryptography specialists, core network security architects or integration developers work in your teams, with your tools and in your change processes. Managed service: OTOKO® operates HSM clusters, the integration layer or the security operations center with agreed service levels, reports and the evidence that the TKG and NIS2 require.
Monitoring, incident reporting, audits, knowledge transfer Monitoring, key rotation, audit support, stepwise handover
We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.
Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.
Telecom
Let us discuss how your network, your subscriber keys, and your 5G core can work together securely.
Book a first consultation