MILENAGE vs TUAK
MILENAGE and TUAK are the two example algorithm sets 3GPP specifies for AKA on the USIM. MILENAGE is AES-based and dominant. TUAK is Keccak-based (SHA-3 permutation) and offered as a diversification option.
| Attribute | MILENAGE | TUAK |
|---|---|---|
| Primitive | AES-128 | Keccak-f[1600] |
| Introduced | 3GPP TS 35.205 (Rel-99) | 3GPP TS 35.231 (Rel-12) |
| Adoption | Near-universal | Limited |
| Rationale | Well-analyzed, hardware-accelerated | Algorithm diversification |
| Post-quantum posture | Symmetric — 128-bit safety margin | Symmetric — larger internal state |
Verdict
Both are symmetric and both survive post-quantum key-size doubling. Choosing TUAK for "post-quantum readiness" is misinformed — AKA is not the PQC weak link, the SUCI ECIES public-key wrap is.