Telecommunications

5G, core network and edge with post-quantum handshake at massive scale

5G Standalone (5G-SA) introduces IPsec between gNB and UPF, HTTP/2 in service-based-architecture (SBA), and EAP-AKA' authentication. All negotiated classically. ETSI, GSMA FS.31, and ENISA have already published PQC introduction recommendations — with deadlines 2027-2030. Operators with 80M+ subscribers cannot big-bang: Crypto-Agility Hub + gradual per-network-slice rollout is the answer.

5G-SA
3GPP Release 17+
RFC draft
X25519MLKEM768
GSMA FS.31
compliance
< 100 KB
IoT SDK
PosQuantum · Telecommunications

Three scenarios where PosQuantum acts

1

5G-SA backhaul PQ IPsec

Context

European Tier-1 operator with 78k gNBs, IPsec backhaul terminating at regional UPF. 20 years of state-adversary-harvestable traffic.

Risk

IKEv2 + ECDSA-P256 at tunnel setup. User-plane traffic (subscriber data) encrypted with AES but session key derived from classical DH.

PosQuantum solution

PQSL Secure Channel as overlay above IPsec (dual-wrap) OR direct kernel-module replacement with hybrid handshake X25519 + ML-KEM-768. Crypto-Agility Hub enables per-geography rollout with instant rollback.

2

CDN edge with TLS 1.3 hybrid

Context

European CDN operator with 340 PoPs. 12M requests/second peak. Sensitive clients (banking, healthcare, gov) require PQC readiness evidence.

Risk

TLS 1.3 with X25519. Even with ECDSA cert, session key is harvestable. Chrome already supports ML-KEM-768 hybrid — browsers move faster than servers.

PosQuantum solution

PQSL Enterprise at edge with X25519MLKEM768 (RFC draft) support. Per-cert migration via Crypto-Agility Hub. PQ handshake metrics exposed in Prometheus for client validation.

3

Massive MQTT (IoT roaming)

Context

MNO with 8M M2M/IoT lines on LTE-M/NB-IoT. 2.3B MQTT messages/day. Clients in critical sectors (automotive OEM, city smart-meters, logistics fleets).

Risk

MQTT over TLS 1.2 with ECDHE. Messages contain IoT commands — if an adversary decrypts retroactively, they learn operational patterns + can replay future commands.

PosQuantum solution

PQSL MQTT Handler on operator's Mosquitto/HiveMQ broker. Client Embedded-C SDKs compatible with NB-IoT (footprint < 100 KB). Migration Scanner validates per-client compatibility before forcing upgrade.

Reference architecture

1

1. RAN

PQSL kernel module in gNB (PQ-IPsec on backhaul).

2

2. 5G-SA core

PQSL Enterprise at UPF/AMF/SMF; Crypto-Agility Hub for gradual negotiation.

3

3. CDN edge

PQSL TLS termination with hybrid X25519MLKEM768.

4

4. IoT brokers

PQSL MQTT Handler in Mosquitto/HiveMQ; Embedded-C SDK on devices.

5

5. Ops telemetry

PQ handshake metrics exposed in Prometheus + Grafana for SRE.

Applicable PosQuantum products

PQSL Enterprise
PQSL MQTT Handler
PUCE Stream
Secure Channel
Crypto-Agility Hub

Regulatory compliance covered

ETSI TS 119 312GSMA FS.31ENISA PQCNIS2 (telco)3GPP SA3

PQC roadmap for your 5G Standalone and CDN?

We present technical slides aligned with GSMA FS.31 and ETSI TS 119 312 — 2-day workshop with network engineering.