KDF (Key Derivation Function)

Also known as: Key derivation function

A Key Derivation Function derives one or more cryptographic keys from a shared secret, password or master key using a deterministic pseudo-random construction. 3GPP defines KDFs based on HMAC-SHA-256 in TS 33.220 (Annex B) that are used across 5G-AKA, EAP-AKA', N32 key hierarchy and USIM authentication vectors.

Categories: Protocols and StandardsEncryption and Cryptography

KDF in context

Telecom security is written into standards from 3GPP, GSMA, ETSI, IETF and ITU-T. Understanding which body owns which specification, and how they interlock, is essential for both design and audit work.

Cryptography in telecom spans air-interface ciphers (A5/1, A5/3, ZUC, SNOW, NEA/NIA), transport (IPsec, TLS) and identity (AKA, 5G-AKA, EAP-AKA'). Weak or downgradeable ciphers remain a live risk on 2G/3G fallback.

To place KDF in the wider telecom-security picture, review Jitter, MEC, WPA2, XMPP, Zigbee and ETSI ISG MEC — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.