Allot reveals: 60% of mobile traffic remains sensitive for years

The 60% of traffic managed by mobile operators contains data that remains sensitive for years, according to an analysis by Allot. Among these, subscriber identity mappings, billing records, and call metadata represent critical information exposed to quantum risks. The discovery emerges from an exclusive interview with VP CTO Yaakov Stein, who reveals how most operators underestimate the risk of long-term breaches.

Quick Answer

The most at-risk data in mobile operators includes: subscriber identity mappings, billing records, and call metadata. The first protective measures should focus on TLS key exchanges, followed by interventions on IPsec. Vendor responses to be considered alarming are: "we are waiting for the stabilization of standards" and "our system is already quantum-safe".

The hidden priority: traffic shelf-life and its importance in quantum security

The concept of traffic shelf-life is crucial in assessing quantum readiness (PQC readiness). While most of the operators' control traffic becomes obsolete quickly, some information remains sensitive for years. This includes personal and financial data, but also internal topology information that could compromise relationships between operators.

The 12-week plan for quantum migration

For a second-level operator without a PQC program, the migration process begins with a complete inventory of all cryptographic uses. This includes identifying 5G SBA interfaces, IKE for protected IPsec links, DNSsec, and encrypted APIs. The second phase involves migrating to hybrid key exchanges on all TLS interfaces.

This is followed by interventions on IPsec and other public-key-based protocols. Only after covering all key exchanges can long-term connection authentication be considered. Short-term connections and hardware authentication can wait, unless required by enterprise or government clients.

Where to focus efforts: the critical point of quantum security

If an operator can implement only one PQC measure this year, the most critical point is protecting TLS key exchanges. Implementing hybrid ML-KEM (X25519 ECC with ML-KEM and, if possible, with backup crypto-agile to HQC) on all SBA and management interfaces is the simplest and most impactful measure.

Vendor responses that should alarm

Some vendor responses should be considered red flags. Among these, "we are waiting for the stabilization of standards" is the most concerning. Although it is true that not all RFCs are finalized yet, PQC standardization is proceeding faster than any other innovation in the history of telecommunications.

Other alarming responses include "quantum computers are not yet a reality" and "our system is already quantum-safe". These indicate a lack of understanding or a deliberate intent to deceive.

The weak point of migration: incomplete inventory

The most likely point of failure in PQC migration is the omission of an interface. An operator might update most security mechanisms but overlook an interface such as a device accessible via SSH, an outdated RADIUS interface, or an orchestration tool not used for years. This creates a false sense of security, as quantum resistance is only as strong as its weakest link.

Another problem is represented by new mechanics that can break the assumptions of legacy devices. This is what happened when Kyber was first introduced: its multi-packet TLS client hello violated the assumptions of various middleboxes, forcing a rollback.

Implications for mobile security and next moves

Allot's revelation underscores the urgency of implementing PQC measures in mobile operators. Protecting long-term sensitive data requires a structured approach and an in-depth understanding of quantum vulnerabilities. Operators should start with a complete inventory and proceed with the migration of TLS and IPsec key exchanges.

It is also essential to be aware of vendor responses that may indicate a lack of preparedness or understanding. Only with a proactive and comprehensive approach can operators ensure the security of sensitive data in a quantum era.

Next steps for operators: how to prepare

Mobile operators should start by evaluating their traffic to identify long-term sensitive data. Next, they should create a complete inventory of all cryptographic uses and begin migrating to hybrid key exchanges. It is also important to be aware of vendor responses that may indicate a lack of preparedness.

Finally, operators should consider implementing PQC measures on all critical interfaces, thus ensuring comprehensive security against quantum threats. With a structured and proactive approach, operators can protect sensitive data and ensure long-term security.

The industrial context and challenges of PQC migration

The migration to post-quantum security (PQC) does not occur in an industrial vacuum. Mobile operators must navigate competitive pressures, technological limitations, and customer expectations. Companies providing PQC solutions vary widely in their understanding of these challenges.

A guide like "The ultimate guide to network operations management" can be a useful starting point for operators seeking to modernize their management capabilities. However, it is important to note that managing PQC solutions requires specialized skills that may not be available internally.

The challenges of training and staffing

Another critical aspect is staff training. PQC migration requires advanced technical skills that many telecommunications professionals may not possess. Operators must invest in continuous training and, in some cases, in recruiting new hires with specific skills in post-quantum cryptography.

Collaboration with universities and research centers can be an effective way to access specialized talent. Additionally, participation in industry forums and workshops can help keep staff updated on the latest innovations.

Next steps for operators: a strategic approach

In light of these considerations, mobile operators should adopt a strategic approach to PQC migration. This includes:

  • Priority assessment: Identify which data and interfaces are most critical for long-term protection.
  • Vendor selection: Choose partners that not only offer technical solutions but also understand the operational and strategic challenges of operators.
  • Training planning: Create a plan to develop the internal skills necessary to manage and maintain new PQC solutions.
  • Communication with customers: Establish clear communication channels with enterprise and government customers to discuss the security measures implemented.

With a structured and proactive approach, operators can not only address quantum threats but also strengthen their position in the telecommunications market.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not perform real-time information activities.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.

In the Crypto sector, every investment involves risks: the reader is invited to always inform themselves autonomously before making any decision.