EAP-AKA’ (RFC 5448) is one of the two mandatory primary authentication methods in 5GS
(the other being 5G-AKA). The UDM/ARPF selects the method per subscriber. For EAP-AKA’
the AUSF acts as the EAP server (back-end authentication server), the SEAF/AMF is a
transparent EAP pass-through, and the UE is the EAP peer. Unlike 5G-AKA — where the AUSF
only verifies RES* — in EAP-AKA’ the AUSF runs the full EAP method: it builds the
EAP-Request/AKA’-Challenge, verifies the EAP-Response/AKA’-Challenge (RES + AT_MAC), and
on success derives K_AUSF from the EMSK.
This procedure is distinct from 5G-AKA (TS 33.501 §6.1.3.2, already implemented):
In scope (this task, AUSF + UDM control plane): UDM CK’/IK’ derivation gated on the
per-subscriber AuthMethod; the full AUSF EAP-AKA’ method (key hierarchy + packet codec +
state machine); K_SEAF returned to the AMF on success.
Out of scope: UERANSIM v3.2.8 has no EAP-AKA’ peer, so the live N1 leg is not
exercised E2E (mirrors the 5G-AKA test posture — verified by golden-vector unit tests +
in-process godog round-trip). The AMF NAS pass-through of the EAP payload (transparent
EAP relay in Authentication Request/Response) is a follow-up; today the AMF forwards RES*
for 5G-AKA only.
Unit: shared/crypto/eapaka golden vector (RFC 5448 App. C Case 1) — CK’/IK’, PRF’,
K_encr/K_aut/K_re/MSK/EMSK; EAP packet encode/decode + AT_MAC round-trip.
Unit: AUSF EAP-AKA’ init + eap-session handlers (success, bad MAC, bad RES, unknown ctx).
Functional (godog, in-process): AMF drives the EAP round-trip; AUSF returns
AUTHENTICATION_SUCCESS with a non-empty kSeaf; a tampered AT_MAC yields FAILURE.