RFC 9678: Forward Secrecy Extension to the Improved Extensible Authentication Protocol Method for Authentication and Key Agreement (EAP-AKA' FS)
In plain English — editorial summary, not part of the RFC
This document updates RFC 9048, "Improved Extensible Authentication Protocol Method for 3GPP Mobile Network Authentication and Key Agreement (EAP-AKA')", and its predecessor RFC 5448 with an optional extension providing ephemeral key exchange. The extension EAP-AKA' Forward Secrecy (EAP-AKA' FS), when negotiated, provides forward secrecy for the session keys generated as a part of the authentication run in EAP-AKA'. This prevents an attacker who has gained access to the long-term key from obtaining session keys established in the past. In addition, EAP-AKA' FS mitigates passive attacks (e.g., large-scale pervasive monitoring) against future sessions. This forces attackers to use active attacks instead.
Document record
- Document ID
- RFC9678
- Published
- March 2025
- Authors
- J. Arkko; K. Norrman; J. Preuß Mattsson
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 25
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7458Extensible Authentication Protocol (EAP) Attributes for Wi-Fi Integration with the Evolved Packet CoreCurrent
February 2015
- RFC 9820Authentication Service Based on the Extensible Authentication Protocol (EAP) for Use with the Constrained Application Protocol (CoAP)Current
September 2025
- RFC 9509X.509 Certificate Extended Key Usage (EKU) for 5G Network FunctionsCurrent
March 2024
- RFC 9191Handling Large Certificates and Long Certificate Chains in TLS-Based EAP MethodsCurrent
February 2022
- RFC 8983Internet Key Exchange Protocol Version 2 (IKEv2) Notification Status Types for IPv4/IPv6 CoexistenceCurrent
February 2021
- RFC 8940Extensible Authentication Protocol (EAP) Session-Id Derivation for EAP Subscriber Identity Module (EAP-SIM), EAP Authentication and Key Agreement (EAP-AKA), and Protected EAP (PEAP)Current
October 2020
- RFC 7833A RADIUS Attribute, Binding, Profiles, Name Identifier Format, and Confirmation Methods for the Security Assertion Markup Language (SAML)Current
May 2016
- RFC 7832Application Bridging for Federated Access Beyond Web (ABFAB) Use CasesCurrent
May 2016
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?