← Archive · 6G Tracker
 

Daily Dose of 6G

The 256-bit decision 6G security builds on

Release 19’s TR 33.700-41 answered the key-length question before 6G studies began: 256-bit algorithms are added and the 128-bit ones stay. Today’s AEAD and post-quantum work starts from that decision.

In 60 seconds

  • Concluded (Rel-19): no current threats to 128-NEA1/2/3 or 128-NIA1/2/3.
  • Concluded: introduce 256-bit AES-256, SNOW 5G and ZUC-256 to coexist with the 128-bit set, not replace it.
  • Concluded: existing Security Mode Command negotiation and key derivation work for both key lengths without change.
  • Rel-20: the algorithm specs go into TS 35.240–35.248. The 6G AEAD study builds on them.
SASA3 · TR 33.700-41, Release 19

What SA3 actually concluded

This study is unusual: its key-issue and solution clauses are both “void”. It was an analysis, and the result is in the conclusions:

  • There are currently no security threats to 128-NIA1, 128-NIA2, 128-NIA3, 128-NEA1, 128-NEA2, 128-NEA3.
  • The intent is to introduce 256-bit crypto algorithms to coexist with existing 128-bit algorithms. The three families are AES-256, SNOW 5G and ZUC-256.
  • Algorithm identifiers still need assigning in normative specs. The NAS and AS Security Mode Command procedures can negotiate the new algorithms without protocol redesign.
  • Existing key derivation and truncation work for both 128-bit and 256-bit keys.

The report was approved as v19.0.0 at SA#105 in September 2024. Rapporteur: Yuto Nakano (KDDI). It follows the earlier TR 33.841 (Vodafone), which first looked at 256-bit algorithms.

SAWhy it matters for 6G

Coexistence, not migration

“Coexist” is the important word. 3GPP did not declare 128-bit algorithms weak. It added a stronger option that networks and devices negotiate. The 6G AEAD study (TR 33.771, Edition 19) uses the same approach. Its combined-mode 256-NCA4/5/6 algorithms sit next to encryption-only and integrity-only 256-bit algorithms, all derived from SNOW, AES and ZUC.

The post-quantum track is separate. In 3GPP Highlights, Stawros Orkopoulos (Nokia) explains that symmetric keys of 128 bits or more are already considered safe against quantum attack. The quantum risk (“harvest now, decrypt later”) is to public-key cryptography. That is TR 33.703’s job, with NIST’s ML-KEM, ML-DSA and SLH-DSA as the preferred algorithms.

SARelease 20

Where it goes next

Agreed

Release 20 introduces the 256-bit algorithm specifications in TS 35.240 to TS 35.248. TS 35.240’s rapporteur is Stawros Orkopoulos (Nokia).

Still open

When 256-bit becomes mandatory to support in 6G devices and networks, rather than optional. No 3GPP decision on that exists yet.

Watch next

  • SA3 Prague (12–16 Oct): CRs assigning 256-bit algorithm identifiers, and the first AEAD normative proposals.
  • SA3 PQC: the post-quantum study’s recommendations for public-key algorithms in 6G.

Sources

Report contents are read from FriendlySpec renders of the draft TRs. Drafts change at every meeting; nothing in a draft TR is agreed until its conclusions are.