NDS

Network Domain Security

Security →
Introduced in Rel-8 Also in: Core Network, Services, Radio Access Network

NDS is the 3GPP security framework for protecting signaling and user data exchanges within and between network domains by establishing security associations, encryption, and integrity protection.

Category
Security
Introduced
Rel-8
Where
Security
Also touches
3 segments
Specifications
17 specs
NDS Description Purpose Related Classification Detected Changes Specifications

Description

Network Domain Security (NDS) is a cornerstone 3GPP security architecture that provides confidentiality, integrity, and replay protection for control plane (signaling) and user plane data traversing network domains. A 'network domain' is defined as a portion of the network managed by a single administrative authority, such as an operator's core network or a partner's network. NDS ensures that communications between Network Functions (NFs) or between network elements across different domains are secure, preventing eavesdropping, tampering, and spoofing. It operates primarily at the IP layer, securing IP-based protocols used within the 3GPP architecture.

The architecture of NDS is built around the concept of Security Gateways (SEGs) and the application of Internet Protocol Security (IPsec). In its classic form, used for inter-operator interfaces like Za (between SEPPs), traffic between security domains passes through SEGs at each domain's border. These SEGs establish IPsec Encapsulating Security Payload (ESP) tunnels in tunnel mode, providing end-to-end security between the gateways. Within a single, trusted operator domain, NDS/IP (a profile of NDS) can be applied, often using IPsec in transport mode directly between network functions, or increasingly relying on Transport Layer Security (TLS) as specified in modern architectures. NDS defines security policies, key management procedures (often using Internet Key Exchange protocol versions like IKEv1 or IKEv2), and the cryptographic algorithms to be used.

Its role is pervasive and critical. NDS secures vital interfaces such as the N2 (between the (R)AN and the AMF), N3 (between the (R)AN and the UPF), N4 (between the SMF and UPF), and N6 (between the UPF and the Data Network). In the 5G Service-Based Architecture (SBA), NDS principles are extended through the use of TLS for HTTP/2-based service-based interfaces (e.g., N8, N10, N12) between producer and consumer NFs. The framework ensures that even if the underlying transport network is untrusted, the payload remains protected. It is a mandatory layer of defense that isolates the trusted 3GPP core from external IP networks and secures internal communications against insider threats.

Purpose & Motivation

NDS was created to address the fundamental shift of telecom networks from closed, circuit-switched systems using SS7 signaling to open, IP-based packet-switched architectures. Legacy SS7 networks had inherent physical security but were vulnerable to logical attacks. The migration to IP in 3GPP Release 4 onwards exposed signaling and user data to all the threats prevalent on the public internet, such as interception, manipulation, and denial-of-service attacks. A standardized, robust security framework for the network layer was urgently needed.

Before NDS, security was often implemented in an ad-hoc manner or was limited to the radio access link (e.g., using algorithms like A5 in GSM). There was no unified standard for securing the core network backhaul and inter-operator connections. NDS solved this by adopting and profiling well-established IETF protocols like IPsec and IKE, tailoring them for the specific reliability, scalability, and interoperability needs of carrier-grade networks. It provided a clear model for securing domain boundaries, enabling secure interconnection between different operators' networks (a key requirement for roaming) and creating a 'walled garden' of trust for the operator's own infrastructure, which became increasingly critical with the move towards all-IP networks in 4G and 5G.

Classification

Part ofIPSec

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (6 CRs across 2 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 3 changes

In Release 15, the NDS/IP framework was updated to include application layer cryptographic profiles, expanding its scope beyond the network layer. It also clarified the physical protection requirements for NDS/IP deployments and introduced general Security Gateway (SEG) support for non-Service-Based Architecture interfaces, ensuring broader compatibility.

  • Update NDS/IP scope with application layer crypto profiles TS 33.210CR0050
  • Correction of Note on physical protection for NDS/IP use TS 33.501CR0331
  • General NDS/IP SEG support for non-SBA interfaces TS 33.501CR0642
Rel-16 3 changes

In Release 16, the scope of NDS/IP was updated to include application layer cryptographic profiles. This release also incorporated editorial corrections to the NDS/IP and NDS/AF (Authentication Framework) specifications.

  • Update NDS/IP scope with application layer crypto profiles TS 33.210CR0056
  • Editorial corrections to NDS/IP TS 33.210CR0068
  • Editorial corrections to NDS/AF TS 33.310CR0113

Explore further

Broader topics and technologies where NDS plays a role.

Defining Specifications

3GPP specifications that define or reference NDS, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 29.229 vj10 Diameter Protocol for Cx/Dx Interfaces Rel-19
TS 29.329 vj10 Diameter Protocol for Sh Interface Rel-19
TS 29.335 vj00 Ud Interface Protocol for UDC (Stage 3) Rel-19
TS 29.549 vj40 SEAL API Specification for Vertical Applications Rel-19
TS 32.372 vj00 Security Service for IRP Information Service Rel-19
TS 32.843 vd00 PS Domain Online Charging in Roaming Rel-13
TS 33.203 vj10 IMS Security Specification Rel-19
TS 33.204 vj00 TCAP Security (TCAPsec) Stage 2 Specification Rel-19
TS 33.210 vj20 UMTS Security for IP Networks Rel-19
TS 33.310 vj50 3GPP Authentication Framework for Network Nodes Rel-19
TS 33.402 vj00 Security for non-3GPP access to EPS Rel-19
TS 33.501 vk00 5G Security Architecture and Procedures Rel-20
TR 33.841 vg10 Security aspects; Study on 256-bit algorithms for 5G Rel-16
TR 33.938 vj10 3GPP Cryptographic Inventory for 5G Rel-19
TR 33.969 vj00 Security for Public Warning System (PWS) Rel-19
TS 36.401 vj00 E-UTRAN Overall Architecture Description Rel-19
TS 38.401 vj10 NG-RAN Architecture Specification Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.