RFC 5448: Improved Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA')
In plain English — editorial summary, not part of the RFC
This specification defines a new EAP method, EAP-AKA', which is a small revision of the EAP-AKA (Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement) method. The change is a new key derivation function that binds the keys derived within the method to the name of the access network. The new key derivation mechanism has been defined in the 3rd Generation Partnership Project (3GPP). This specification allows its use in EAP in an interoperable manner. In addition, EAP-AKA' employs SHA-256 instead of SHA-1. This specification also updates RFC 4187, EAP-AKA, to prevent bidding down attacks from EAP-AKA'. This memo provides information for the Internet community.
Document record
- Document ID
- RFC5448
- Published
- May 2009
- Authors
- J. Arkko; V. Lehtovirta; P. Eronen
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- —
- Pages
- 29
- Also known as
- —
- Updates:
- RFC 4187
Topics
Referenced by
2 later RFCs formally update or obsolete part of this document.
- RFC 9048Improved Extensible Authentication Protocol Method for 3GPP Mobile Network Authentication and Key Agreement (EAP-AKA')Updated
October 2021
- RFC 9678Forward Secrecy Extension to the Improved Extensible Authentication Protocol Method for Authentication and Key Agreement (EAP-AKA' FS)Current
March 2025
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7458Extensible Authentication Protocol (EAP) Attributes for Wi-Fi Integration with the Evolved Packet CoreCurrent
February 2015
- RFC 5433Extensible Authentication Protocol - Generalized Pre-Shared Key (EAP-GPSK) MethodCurrent
February 2009
- RFC 5516Diameter Command Code Registration for the Third Generation Partnership Project (3GPP) Evolved Packet System (EPS)Current
April 2009
- RFC 5609State Machines for the Protocol for Carrying Authentication for Network Access (PANA)Current
August 2009
- RFC 5281Extensible Authentication Protocol Tunneled Transport Layer Security Authenticated Protocol Version 0 (EAP-TTLSv0)Updated
August 2008
- RFC 5279A Uniform Resource Name (URN) Namespace for the 3rd Generation Partnership Project (3GPP)Current
July 2008
- RFC 5191Protocol for Carrying Authentication for Network Access (PANA)Updated
May 2008
- RFC 5749Distribution of EAP-Based Keys for Handover and Re-AuthenticationCurrent
March 2010
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?