EAP-AKA′ (Extensible Authentication Protocol – AKA Prime)

Also known as: EAP-AKA', EAP AKA Prime, RFC 5448

EAP-AKA′ is an EAP method that carries 3GPP AKA authentication between a UE and an AAA server, with an extra key derivation step that binds the resulting keys to the access network name. It is used for non-3GPP access to the 5G core (Wi-Fi, wireline) and for trusted non-3GPP access to EPC, and is specified in RFC 5448 and 3GPP TS 33.402 / TS 33.501. Compared to EAP-AKA, the prime variant prevents key reuse across heterogeneous access networks.

Categories: Core NetworkSecurity ControlsProtocols and Standards

EAP-AKA′ in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

To place EAP-AKA′ in the wider telecom-security picture, review AES, OpenSSL, N3IWF, TNGF, SEAF and N12 — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.