Improved Extensible Authentication Protocol Method for 3GPP Mobile Network Authentication and Key Agreement
RFC 9048, “Improved Extensible Authentication Protocol Method for 3GPP Mobile Network Authentication and Key Agreement”, is a Proposed Standard document published in October 2021 by J. Arkko, V. Lehtovirta, V. Torvinen, P. Eronen. It updates RFC 4187, RFC 5448. It has since been updated by RFC 9678. The canonical text is published by the RFC Editor.
Abstract
The 3GPP mobile network Authentication and Key Agreement (AKA) is an authentication mechanism for devices wishing to access mobile networks. RFC 4187 (EAP-AKA) made the use of this mechanism possible within the Extensible Authentication Protocol (EAP) framework. RFC 5448 (EAP-AKA') was an improved version of EAP-AKA.
This document is the most recent specification of EAP-AKA', including, for instance, details about and references related to operating EAP-AKA' in 5G networks.
EAP-AKA' differs from EAP-AKA by providing a key derivation function that binds the keys derived within the method to the name of the access network. The key derivation function has been defined in the 3rd Generation Partnership Project (3GPP). EAP-AKA' allows its use in EAP in an interoperable manner. EAP-AKA' also updates the algorithm used in hash functions, as it employs SHA-256 / HMAC-SHA-256 instead of SHA-1 / HMAC-SHA-1, which is used in EAP-AKA.
This version of the EAP-AKA' specification defines the protocol behavior for both 4G and 5G deployments, whereas the previous version defined protocol behavior for 4G deployments only. While EAP-AKA' as defined in RFC 5448 is not obsolete, this document defines the most recent and fully backwards-compatible specification of EAP-AKA'. This document updates both RFCs 4187 and 5448.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9048 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9047 Propagation of ARP/ND Flags in an Ethernet Virtual Private Network
- RFC 9049 Path Aware Networking: Obstacles to Deployment
- RFC 9046 Babel Information Model
- RFC 9050 Path Computation Element Communication Protocol Procedures and Extensions for Using the PCE as a Central Controller of LSPs
- RFC 9045 Algorithm Requirements Update to the Internet X.509 Public Key Infrastructure Certificate Request Message Format
- RFC 9051 Internet Message Access Protocol - Version 4rev2
- RFC 9044 Using the AES-GMAC Algorithm with the Cryptographic Message Syntax
- RFC 9043 FFV1 Video Coding Format Versions 0, 1, and 3