Improved Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement
RFC 5448, “Improved Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement”, is an Informational document published in May 2009 by J. Arkko, V. Lehtovirta, P. Eronen. It updates RFC 4187. It has since been updated by RFC 9048, RFC 9678. The canonical text is published by the RFC Editor.
Abstract
This specification defines a new EAP method, EAP-AKA', which is a small revision of the EAP-AKA (Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement) method. The change is a new key derivation function that binds the keys derived within the method to the name of the access network. The new key derivation mechanism has been defined in the 3rd Generation Partnership Project (3GPP). This specification allows its use in EAP in an interoperable manner. In addition, EAP-AKA' employs SHA-256 instead of SHA-1.
This specification also updates RFC 4187, EAP-AKA, to prevent bidding down attacks from EAP-AKA'. This memo provides information for the Internet community.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 5448 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5447 Diameter Mobile IPv6: Support for Network Access Server to Diameter Server Interaction
- RFC 5449 OSPF Multipoint Relay Extension for Ad Hoc Networks
- RFC 5446 Service Selection for Mobile IPv4
- RFC 5450 Transmission Time Offsets in RTP Streams
- RFC 5445 Basic Forward Error Correction Schemes
- RFC 5451 Message Header Field for Indicating Message Authentication Status
- RFC 5444 Generalized Mobile Ad Hoc Network Packet/Message Format
- RFC 5452 Measures for Making DNS More Resilient against Forged Answers