SEAF (SEcurity Anchor Function)

Also known as: Security Anchor Function

SEAF is the 5G core function (3GPP TS 33.501) that anchors the primary authentication of the UE and holds the resulting anchor key KSEAF, from which the AMF derives KAMF and further NAS and AS keys. Co-located with the AMF in current deployments, the SEAF isolates long-term key material from serving-network mobility functions and is central to 5G-AKA and EAP-AKA' security.

Categories: Core NetworkSecurity ControlsProtocols and Standards

SEAF in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

To place SEAF in the wider telecom-security picture, review AES, OpenSSL, N3IWF, TNGF, EAP-AKA′ and N12 — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.