Tuesday, September 22, 2026

Signalling Fallback Exposing Gaps in Mobile Roaming Protection

Note* - All images used are for editorial and illustrative purposes only and may not originate from the original news provider or associated company.

Related stories

Vulnerability Reporting Obligations Reaching Telecom Equipment Suppliers

Telecom security responsibility is increasingly extending beyond network operators...

VodafoneThree Brings Ericsson Cloud Native 5G Core Live

VodafoneThree and Ericsson have reached a significant milestone with...

Ericsson and Erillisverkot Demonstrate 5G ISAC Drone Detection...

Ericsson and Finland’s Erillisverkot have demonstrated how 5G networks...

Mobile roaming is increasingly operating across a mix of 5G, 4G and legacy network technologies, creating different signalling paths with different security characteristics. A subscriber using a 5G device does not necessarily remain on a 5G Standalone roaming architecture throughout the entire service experience. The home network, visited network, device capabilities and available interworking arrangements can all influence which signalling path is used. Roaming signalling security is therefore becoming an end-to-end issue spanning multiple network generations and inter-operator connections. TeleInfoToday is examining how this mixed environment is shaping the next stage of mobile roaming protection.

5G Roaming is Operating Across Multiple Signalling Generations

5G Standalone roaming can use HTTP/2-based signalling protected through Security Edge Protection Proxies, or SEPPs, at the inter-operator boundary. This provides a stronger security model than some legacy roaming arrangements because signalling can be authenticated, integrity-protected and, in supported scenarios, confidentiality-protected across the relevant security perimeter segments. GSMA’s 5GS Roaming Guidelines v14.0, published in January 2026, identifies 5G SA with end-to-end HTTP/2 signalling between SEPPs as one of the scenarios with the strongest protection capability.

The challenge arises because international roaming does not consist exclusively of that architecture. GSMA also identifies 5G Non-Standalone scenarios using standard Diameter, without DESS enhancements, as less protected. It further notes that when a 5G user is supported through 2G or 3G paging, roaming signalling can rely on SS7. These scenarios can therefore introduce different security characteristics into an otherwise modern roaming environment.

Fallback Paths Can Carry Different Protection Levels

This creates an important distinction between a legitimate network fallback or interworking event and a deliberate downgrade attack. A device moving between radio technologies does not automatically create a security breach. The concern is that the resulting signalling path may have weaker protections than the preferred 5G SA path, particularly where legacy signalling systems remain part of the roaming architecture.

GSMA’s guidelines explicitly describe standard Diameter without DESS enhancements and SS7-based scenarios as less protected, while identifying enhanced Diameter and 5G SA with SEPP-based HTTP/2 as stronger protection models.

That makes roaming signalling security dependent on the complete path between the home and visited networks rather than the generation displayed by the customer’s handset. An operator can therefore have a highly protected 5G core while still needing to account for less-protected signalling paths created through interworking with older network generations.

Signalling Transitions are Becoming a Security Boundary

The issue is also receiving greater attention from standards bodies. ITU-T Q.3066, approved in January 2026, explicitly classifies cross-generational signalling attacks as a distinct threat category involving interactions between legacy protocols such as SS7 and newer environments using Diameter, SIP or other modern signalling protocols. The recommendation identifies subscriber location, IMSI, IMEI and call or session data among the assets that can be exposed through signalling attacks.

3GPP’s Release 19 work on TR 33.701 likewise addresses bidding-down attacks involving attempts to move LTE/NR connectivity toward decommissioned GERAN or UTRAN systems. The study examines multiple mitigation approaches for preventing or detecting these downgrade scenarios.

The direction is therefore moving toward greater scrutiny of the transitions between network generations, not simply the security of each generation in isolation. Roaming signalling security increasingly depends on controlling those interworking points and maintaining visibility across the full signalling chain.

Cross-Protocol Security is Becoming More Important

The security challenge created by mixed-generation roaming extends beyond individual signalling protocols. Modern mobile networks can carry SS7, Diameter, SIP and GTP traffic across different interfaces and network generations, creating opportunities for attackers to exploit inconsistencies between signalling environments. roaming signalling security therefore increasingly requires operators to examine how signalling flows interact across the wider network rather than securing each protocol in isolation.

Bidding-Down Risks are Bringing Legacy Networks into Focus

The transition between network generations creates particular concern when modern networks remain connected to legacy infrastructure. 3GPP’s work on bidding-down attacks examines scenarios in which an attacker attempts to influence a device or network toward an older access technology despite stronger security capabilities being available. The concern is not that every fallback event represents an attack, but that weaker legacy paths can introduce different security characteristics into an otherwise modern roaming environment.

ITU-T Recommendation Q.3066, approved in January 2026, formally identifies four signalling attack categories: single-request, single-protocol multi-request, multi-protocol and cross-generational attacks. It also identifies assets including subscriber location, IMSI, IMEI and call or session data as potential targets.

These categories show why roaming signalling security is moving beyond isolated protocol controls. Cross-generational and multi-protocol attacks can exploit relationships between signalling systems, making it increasingly important to understand whether information and events remain consistent across the network.

As signalling environments become more interconnected, protection also needs to account for subscriber identity information that can move across different signalling paths. Protecting those identity-related assets becomes part of securing the wider roaming environment.

Signalling Monitoring is Moving Across Protocol Boundaries

Detection is increasingly becoming a layered process. ITU-T Q.3066 describes five detection approaches covering unauthenticated message detection, allow-list and rate checks, heuristic analysis, anomaly detection and cross-protocol consistency checks. Cross-protocol analysis can compare related information across signalling systems to identify inconsistencies that may be difficult to detect when each protocol is examined separately.

The recommendation also groups mitigation into four areas: correct network configuration, authenticity validation, heuristic mitigation and blocking anomalous signalling flows. This creates a broader security model in which signalling gateways, filtering, behavioural analysis and cross-protocol correlation work together.

Key Takeaway: Telecom signalling protection is expanding from protocol-specific filtering toward a layered model covering four attack categories, five detection approaches and four mitigation areas.

The direction is toward a more connected security model in which operators monitor signalling behaviour across protocols and generations rather than relying on isolated controls. Roaming signalling security increasingly depends on visibility across those boundaries and on the ability to identify inconsistencies before they affect sensitive subscriber or network functions.

Roaming Protection is Becoming an End-to-End Security Problem

Mobile roaming security increasingly depends on the complete signalling path connecting home and visited networks. The continued interaction between 5G, 4G and legacy systems means operators need visibility across different protocols, interfaces and interworking arrangements rather than relying on the security of the newest network generation alone.

This makes roaming signalling security an end-to-end requirement spanning signalling gateways, protocol controls, monitoring and subscriber protection. Stronger authentication and filtering can reduce exposure, while cross-protocol analysis can help identify suspicious activity that may move between different signalling environments.

As roaming architectures continue to evolve, roaming signalling security will increasingly depend on securing transitions between network generations as well as individual signalling systems. TeleInfoToday will continue to examine how these boundaries are creating new priorities for telecom security.

Tele Info Today brings together the global telecoms industry — from network operators and connectivity providers to technology innovators and digital services leaders — through trusted editorial, market intelligence, and digital engagement.

Our 2026 Media Pack offers integrated solutions to reach your audience:

  • Magazine & Digital Editions Showcase your brand within premium telecoms industry coverage read by executives and decision-makers worldwide.
  • Industry Insights & Reports Align with data-driven analysis, trend reports, and regional roundups across the global telecommunications and digital services value chain.
  • Brand Authority & Credibility Position your company as a thought leader through expert commentary, interviews, and special features.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from any location or device.

Media Packs

Expand Your Reach With Our Customized Solutions Empowering Your Campaigns To Maximize Your Reach & Drive Real Results!

– Access the Media Pack Now

– Book a Conference Call

Leave Message for Us to Get Back

Latest stories

Related stories

Vulnerability Reporting Obligations Reaching Telecom Equipment Suppliers

Telecom security responsibility is increasingly extending beyond network operators...

VodafoneThree Brings Ericsson Cloud Native 5G Core Live

VodafoneThree and Ericsson have reached a significant milestone with...

Ericsson and Erillisverkot Demonstrate 5G ISAC Drone Detection...

Ericsson and Finland’s Erillisverkot have demonstrated how 5G networks...

US Spectrum Auctions Enter a New Phase as...

The landscape of US spectrum auctions is shifting as...

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from any location or device.

Media Packs

Expand Your Reach With Our Customized Solutions Empowering Your Campaigns To Maximize Your Reach & Drive Real Results!

– Access the Media Pack Now

– Book a Conference Call

Leave Message for Us to Get Back

Translate »