GMK

Group Management Key

Security →
Introduced in Rel-12 Also in: Security

GMK is a cryptographic key used in 3GPP networks to secure group communications and management procedures by providing authentication, integrity protection, and confidentiality for group members.

Category
Security
Introduced
Rel-12
Where
Services
Also touches
1 segments
Specifications
12 specs
GMK Description Purpose Related Classification Detected Changes Specifications

Description

The Group Management Key (GMK) is a fundamental security credential in 3GPP architectures, specifically designed to protect group-based services. It is a symmetric cryptographic key that is shared among all legitimate members of a group and trusted network entities, such as the Group Management Server (GMS) or ProSe Function. The GMK serves as a root key for deriving other security keys used for various protection functions, including authentication between group members and the network, integrity protection of group management signaling, and encryption of group communication traffic. Its management lifecycle—generation, distribution, storage, and revocation—is critical to the security of services like Mission Critical Push-to-Talk (MCPTT), Proximity Services (ProSe) direct communication, and IoT group messaging.

Architecturally, the GMK is typically generated by a central authority within the network, such as the GMS residing in the home network or a dedicated Key Management Center. For ProSe, the ProSe Function may generate the GMK. The key is then securely distributed to each group member's UE via protected signaling channels, often using individual subscriber keys for over-the-air encryption during distribution. Once stored in the UE's secure environment (e.g., in the Group Management Client), the GMK is used to derive session-specific keys, such as the Group Traffic Key (GTK) for encrypting user plane data or the Group Integrity Key (GIK) for protecting control messages. This key hierarchy ensures that compromise of a derived session key does not expose the root GMK.

The operation of GMK involves several protocols and interfaces. For example, in MCPTT, when a UE joins a group, the GMS authenticates the UE and then provisions the GMK (or a key-encrypting key to deliver the GMK) to the UE's GMC. The specifications detail key derivation functions (KDFs) that use the GMK along with other parameters like group identifiers and sequence numbers to produce fresh keys. The GMK is also periodically updated or rekeyed by the network to maintain forward and backward secrecy, especially when group membership changes. In ProSe scenarios, the GMK may enable direct secure communication between UEs without network infrastructure, using the key for mutual authentication and encryption over the PC5 reference point.

Purpose & Motivation

The GMK was introduced to address the lack of standardized, secure key management for group communications in cellular networks, a gap that became critical with the standardization of Mission Critical Services and ProSe in Release 12. Prior to this, group services either used insecure methods or relied on application-layer security that was not integrated with network authentication, making them vulnerable to eavesdropping, impersonation, and replay attacks. The need for secure, low-latency group communications for public safety and critical infrastructure demanded a network-level security solution.

The creation of the GMK provides a unified cryptographic foundation for group security within the 3GPP framework. It solves the problem of scalable and efficient key distribution for dynamic groups by defining a centralized key management architecture. This allows the network to control group membership cryptographically; only UEs possessing the valid GMK can participate in secure group communications. It addresses limitations of pairwise keying, which would require a separate key for each pair of members and does not scale for large groups.

Historically, security in cellular networks focused primarily on individual subscriber authentication (e.g., using Ki in SIM cards). The GMK extends this paradigm to groups, enabling new service models. Its design was motivated by requirements from public safety organizations for secure push-to-talk and proximity-based communication during emergencies. By integrating with existing 3GPP security frameworks like the Authentication and Key Agreement (AKA), the GMK ensures that group security leverages the robust subscriber authentication already in place, while adding the necessary group-oriented key management to support both network-based and direct device-to-device communication scenarios.

Classification

Part ofAKA
Related approachesProSeMCPTT

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (1 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 1 change

In Release 15, the primary new introduction for the GMK function was a clarification of its management procedures. This clarification specifically addressed the role of the Group Management Server (GMS) in originating the Group Master Key (GMK) and its secure, individual transfer to group members. The update ensured that authorized users, such as those performing discreet listening in Mission Critical services, could obtain the GMK without violating end-to-end encryption requirements for the group.

  • GMK management clarification TS 33.180CR0054

Explore further

Broader topics and technologies where GMK plays a role.

Defining Specifications

3GPP specifications that define or reference GMK, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.784 vg00 Discreet Listening for Mission Critical Services Rel-16
TS 24.380 vj10 MCPTT Media Plane Control Protocol Rel-19
TS 24.581 vj00 MCVideo Media Plane Control Protocol Specification Rel-19
TS 24.582 vj00 MCData Media Plane Control Protocols Rel-19
TS 29.380 vj00 MCPTT-LMR Interworking Media Plane Control Rel-19
TS 29.582 vj00 MCData Interworking with LMR Systems Rel-19
TS 33.179 vdc0 MCPTT Security Architecture and Procedures Rel-13
TS 33.180 vk00 Security of Mission Critical (MC) Service Rel-20
TS 33.303 vj00 ProSe Security Specification for EPS Rel-19
TS 33.879 vd10 MCPTT Security Study Rel-13
TS 33.880 vf10 Security Study for Enhanced Mission Critical Services Rel-15
TR 33.938 vj10 3GPP Cryptographic Inventory for 5G Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.