EPS-UPIP

EPS User-Plane Integrity Protection

Security →
Introduced in Rel-17

EPS-UPIP is a 5G-era EPS security feature that provides integrity protection for user-plane data over the radio interface to safeguard against tampering and injection attacks.

Category
Security
Introduced
Rel-17
Where
Core Network › 5G Core
Specifications
2 specs
EPS-UPIP Description Purpose Related Classification Detected Changes Specifications

Description

EPS User-Plane Integrity Protection (EPS-UPIP) is a security enhancement defined in 3GPP specifications TS 24.301 (NAS) and TS 24.501, introduced to provide integrity protection for user-plane (UP) data packets in EPS networks. Prior to its introduction, EPS primarily relied on encryption (ciphering) for UP confidentiality, but integrity protection was typically only applied to control-plane signaling (NAS and RRC). EPS-UPIP extends integrity safeguards to the actual user data traversing the radio access between the UE and the eNodeB, ensuring data has not been altered, replayed, or injected by an attacker.

The feature operates by having the UE and the network apply an integrity algorithm to user-plane data packets, generating an integrity tag (or MAC) that is appended to or associated with the data. This process occurs at the Packet Data Convergence Protocol (PDCP) layer for the radio interface. The integrity key used is derived from the existing EPS security key hierarchy. Specifically, it utilizes keys derived from K_eNB, which itself originates from K_ASME. The activation of UP integrity protection is negotiated during the security mode command procedure between the UE and the network, based on network policies and UE capabilities.

Architecturally, EPS-UPIP involves the UE, the eNodeB, and the MME. The MME determines whether to activate the feature based on subscription data, local policy, and the UE's security capabilities indicated during attachment. The actual integrity protection and verification are performed by the PDCP entities in the UE and the eNodeB. The introduction of this feature required updates to the PDCP protocol and the security mode control procedures to support the negotiation and activation of integrity algorithms for the user plane. It represents a significant shift towards aligning EPS security with the more comprehensive 'always-on' integrity protection model pioneered in 5G (NR) systems.

Purpose & Motivation

EPS-UPIP was introduced in 3GPP Release 17 to address the growing security threats to user data in mobile networks, particularly the risk of active attacks on the radio interface. Prior to Release 17, EPS user-plane security focused almost exclusively on encryption (confidentiality), leaving data vulnerable to malicious tampering, injection, or replay attacks that could corrupt data streams or inject malicious content without detection. The motivation came from the increased sensitivity of services (e.g., industrial IoT, financial transactions, remote operations) and the desire to elevate 4G security to be more consistent with 5G principles.

Its creation was driven by lessons from 5G design, where user-plane integrity protection is a default and fundamental part of the security architecture. EPS-UPIP allows operators to enhance the security posture of their existing EPS deployments, especially for critical IoT and enterprise services, without requiring a full migration to 5G. It solves the problem of data authenticity and integrity for the vast installed base of LTE devices and networks, closing a known security gap. The feature is part of the broader 'EPS security enhancements' work item aimed at backward-porting key 5G security features to the EPS architecture.

Classification

Part ofPDCP

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (3 CRs across 2 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-17 2 changes

In Release 17, the specification introduced support indication for EPS User-Plane Integrity Protection (EPS-UPIP) in the 5G Core network and provided clarification for the EPS-UPIP supported indicator. This involved defining that a UE supporting EPS-UPIP must set a specific bit in the UE network capability information element during an ATTACH REQUEST. The release also explicitly notes that, in this specification release, the EPS-UPIP supported bit is only applicable for a UE supporting dual connectivity with NR.

  • Introduction of EPS-UPIP support indication in 5GC TS 24.501CR3701
  • Clarification of EPS-UPIP supported indicator TS 24.301CR3704
Rel-18 1 change

In Release 18, a correction was made to ensure the EPS-UPIP supported indicator is properly included in the S1 UE network capability information element during mobility and periodic registration request procedures. This addresses a previous omission where the bit was only explicitly mandated in the attach request message, as stated in the specification. The update clarifies the signaling for this capability, which in this release is only applicable for a UE supporting dual connectivity with NR.

  • Missing EPS-UPIP bit in the S1 UE network capability IE of the mobility and periodic REGISTRATION REQUEST TS 24.501CR4461

Explore further

Broader topics and technologies where EPS-UPIP plays a role.

Defining Specifications

3GPP specifications that define or reference EPS-UPIP, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 24.301 vj60 NAS protocol for Evolved Packet System Rel-19
TS 24.501 vj50 5G NAS Protocols Specification Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.