Decrypted 5G NR trace reveals dual security layers in a real attach session

A publicly shared 5G NR packet capture, released alongside its decryption keys as part of Wireshark work-item 19757, offers a rare look at genuine radio security in action. The 151-frame trace, spanning roughly 49 seconds, uses real AES-based ciphering and integrity protection rather than the null cipher common in lab captures. The session shows two separate security procedures running in parallel: one between the device and the core network, and another between the device and the radio base station, each using different keys and peers. A single frame illustrates both states simultaneously, with the radio layer decrypted and readable while the core network payload remains an opaque encrypted blob. A third security layer, IPsec protecting IMS signaling within the user plane, adds further complexity beneath the 5G stack.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in