Forward Secrecy Extension to the Improved Extensible Authentication Protocol Method for Authentication and Key Agreement
RFC 9678, “Forward Secrecy Extension to the Improved Extensible Authentication Protocol Method for Authentication and Key Agreement”, is a Proposed Standard document published in March 2025 by J. Arkko, K. Norrman, J. Preuß Mattsson. It updates RFC 5448, RFC 9048. The canonical text is published by the RFC Editor.
Abstract
This document updates RFC 9048, "Improved Extensible Authentication Protocol Method for 3GPP Mobile Network Authentication and Key Agreement (EAP-AKA')", and its predecessor RFC 5448 with an optional extension providing ephemeral key exchange. The extension EAP-AKA' Forward Secrecy (EAP-AKA' FS), when negotiated, provides forward secrecy for the session keys generated as a part of the authentication run in EAP-AKA'. This prevents an attacker who has gained access to the long-term key from obtaining session keys established in the past. In addition, EAP-AKA' FS mitigates passive attacks (e.g., large-scale pervasive monitoring) against future sessions. This forces attackers to use active attacks instead.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9678 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9676 LEX: A Uniform Resource Name Namespace for Sources of Law
- RFC 9690 Use of the RSA-KEM Algorithm in the Cryptographic Message Syntax
- RFC 9665 Service Registration Protocol for DNS-Based Service Discovery
- RFC 9664 An EDNS Option to Negotiate Leases on DNS Updates
- RFC 9692 RIFT: Routing in Fat Trees
- RFC 9693 Benchmarking Methodology for Stateful NATxy Gateways
- RFC 9694 Guidelines for the Definition of New Top-Level Media Types
- RFC 9695 The 'haptics' Top-Level Media Type