| Edition 21 | 27 September 2026 |
Release 19’s TR 33.700-41 answered the key-length question before 6G studies began: 256-bit algorithms are added and the 128-bit ones stay. Today’s AEAD and post-quantum work starts from that decision.
In 60 seconds
TS 35.240–35.248. The 6G AEAD study builds on them.This study is unusual: its key-issue and solution clauses are both “void”. It was an analysis, and the result is in the conclusions:
There are currently no security threats to 128-NIA1, 128-NIA2, 128-NIA3, 128-NEA1, 128-NEA2, 128-NEA3.
introduce 256-bit crypto algorithms to coexist with existing 128-bit algorithms. The three families are AES-256, SNOW 5G and ZUC-256.
The report was approved as v19.0.0 at SA#105 in September 2024. Rapporteur: Yuto Nakano (KDDI). It follows the earlier TR 33.841 (Vodafone), which first looked at 256-bit algorithms.
“Coexist” is the important word. 3GPP did not declare 128-bit algorithms weak. It added a stronger option that networks and devices negotiate. The 6G AEAD study (TR 33.771, Edition 19) uses the same approach. Its combined-mode 256-NCA4/5/6 algorithms sit next to encryption-only and integrity-only 256-bit algorithms, all derived from SNOW, AES and ZUC.
The post-quantum track is separate. In 3GPP Highlights, Stawros Orkopoulos (Nokia) explains that symmetric keys of 128 bits or more are already considered safe against quantum attack. The quantum risk (“harvest now, decrypt later”) is to public-key cryptography. That is TR 33.703’s job, with NIST’s ML-KEM, ML-DSA and SLH-DSA as the preferred algorithms.
Agreed
Release 20 introduces the 256-bit algorithm specifications in TS 35.240 to TS 35.248. TS 35.240’s rapporteur is Stawros Orkopoulos (Nokia).
Still open
When 256-bit becomes mandatory to support in 6G devices and networks, rather than optional. No 3GPP decision on that exists yet.
Watch next
Sources
Report contents are read from FriendlySpec renders of the draft TRs. Drafts change at every meeting; nothing in a draft TR is agreed until its conclusions are.