RFC 9678 · PROPOSED STANDARD · 2025

Forward Secrecy Extension to the Improved Extensible Authentication Protocol Method for Authentication and Key Agreement

Overview

RFC 9678, “Forward Secrecy Extension to the Improved Extensible Authentication Protocol Method for Authentication and Key Agreement”, is a Proposed Standard document published in March 2025 by J. Arkko, K. Norrman, J. Preuß Mattsson. It updates RFC 5448, RFC 9048. The canonical text is published by the RFC Editor.

Abstract

This document updates RFC 9048, "Improved Extensible Authentication Protocol Method for 3GPP Mobile Network Authentication and Key Agreement (EAP-AKA')", and its predecessor RFC 5448 with an optional extension providing ephemeral key exchange. The extension EAP-AKA' Forward Secrecy (EAP-AKA' FS), when negotiated, provides forward secrecy for the session keys generated as a part of the authentication run in EAP-AKA'. This prevents an attacker who has gained access to the long-term key from obtaining session keys established in the past. In addition, EAP-AKA' FS mitigates passive attacks (e.g., large-scale pervasive monitoring) against future sessions. This forces attackers to use active attacks instead.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9678 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Relationships to other RFCs
This RFC updates
RFC 5448 RFC 9048
Other RFCs from 2025

Who Is Online

In total there are 47 users online: 0 registered, 39 guests and 8 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372