RFC 5448 · INFORMATIONAL · 2009

Improved Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement

Overview

RFC 5448, “Improved Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement”, is an Informational document published in May 2009 by J. Arkko, V. Lehtovirta, P. Eronen. It updates RFC 4187. It has since been updated by RFC 9048, RFC 9678. The canonical text is published by the RFC Editor.

Abstract

This specification defines a new EAP method, EAP-AKA', which is a small revision of the EAP-AKA (Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement) method. The change is a new key derivation function that binds the keys derived within the method to the name of the access network. The new key derivation mechanism has been defined in the 3rd Generation Partnership Project (3GPP). This specification allows its use in EAP in an interoperable manner. In addition, EAP-AKA' employs SHA-256 instead of SHA-1.

This specification also updates RFC 4187, EAP-AKA, to prevent bidding down attacks from EAP-AKA'. This memo provides information for the Internet community.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 5448 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
This RFC updates
RFC 4187
Updated by
RFC 9048 RFC 9678
Other RFCs from 2009

Who Is Online

In total there are 106 users online: 0 registered, 96 guests and 10 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Googlebot Majestic Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372