5G • Security

5G-AKA

5G Authentication and Key Agreement

The primary challenge-response mutual authentication protocol in 5G that generates cryptographic keys between the UE and the 5G network.

Technical Explanation

5G-AKA is an enhanced version of EPS-AKA. It provides mutual authentication: the network proves its authenticity to the device (via AUTN), and the device proves its authenticity to the network (via RES*). In 5G-AKA, the serving network (AMF) receives a hashed response (HXRES*) to verify that the UE is attempting authentication, while final verification of the full RES* is performed by the home network (AUSF). This prevents serving networks from fabricating authentication successes.

Key Functions

  • Cryptographic mutual verification of UE identity and Home Network validity
  • Derivation of 256-bit anchor master key K_SEAF in Home AUSF
  • Serving network isolation preventing rogue visiting networks from spoofing UE profiles
  • Support for non-3GPP access authentication via EAP-AKA'
Specifications
3GPP TS 33.501 Section 6.1.3
Interfaces
N1 (NAS)N12 (AMF-AUSF)Nausf (SBI)

Related 5G Concepts

Want to memorize 5G concepts like this one?
Study it with SuperMemo SM-2 spaced repetition flashcards.
Practice 5G Flashcards