4G (LTE)

Fourth-generation cellular technology, standardised by 3GPP as Long Term Evolution; where enabled, its encryption protects the radio link to the base station, not traffic end to end.

4G is the fourth generation of mobile network technology, and LTE (Long Term Evolution) is the 3GPP standard that delivers it. NIST SP 800-187, Guide to LTE Security, describes its security architecture. The subscriber’s permanent identity lives on the SIM card (the UICC), and the SIM and the network authenticate each other through the authentication and key agreement (AKA) exchange. What that exchange proves is possession of the SIM, not the identity of the person holding the phone.

Where it is enabled, LTE encryption protects the air interface between the handset and the base station. Beyond the base station, traffic crosses the operator’s backhaul and core, and SP 800-187 records that confidentiality protection on the air interface and on the backhaul is optional in the specifications. Sensitive traffic therefore needs its own protection, such as TLS or a VPN. The threats commonly taught are a fake base station, the IMSI catcher, which can ask a handset for its permanent identity, and forcing a handset down to an older, weaker generation.

Exam relevance: scenarios in this area tend to test whether a candidate over-trusts the cellular link. Three points are worth keeping straight: 4G already authenticates mutually, between the SIM and the network; its encryption ends at the base station; and it authenticates the SIM, not the user.